Rental Institute CRM · Legal
Privacy Policy
Last updated September 30, 2026 · Version 2026-09-30-draft.2
1. What this policy covers
This policy explains how Sound Properties Group LLC (“we,” “us”) handles personal information in connection with Rental Institute CRM, our software for real-estate investors, and its sales pages. It does not cover Sound Properties Group LLC’s own real-estate buying business, which has its own privacy policy.
2. Two kinds of data, two roles
Data about our customers and their users — we decide how it is used
When a company signs up, we collect information about that company and the people who use the product for it. For this data we are responsible for how it is used (a “business” or “controller” under privacy laws).
Data our customers put into the product — they decide, we process it for them
Our customers load and create information about other people: mostly property owners, but also buyers, agents and anyone else they deal with. For that data, our customer decides why and how it is used, and we process it only on their behalf and on their instructions, as their “service provider” or “processor.” The Data Processing Addendum sets out those terms.
If you are a property owner or other person in a customer’s records, the company that contacted you is the one responsible for your information. See section 9 for how to reach them, or us.
3. What we collect
Account and billing information
- Company name, state, time zone, letterhead and business contact details.
- Each user’s name, email address, phone number, role and sign-in activity.
- Billing contact and subscription details. Card and bank details are collected and held by our payment processor, not by us.
- Messages you send us for support or feedback.
Customer Data (held for our customers)
- Leads and property owners: names, mailing and property addresses, phone numbers, email addresses, property details, notes, tags and the history of contact with them.
- Skip-trace results: phone numbers, emails, relatives or associates where the provider returns them, phone type, and Do Not Call registry flags.
- Calls and texts: call logs, text messages, voicemails, and — only if the customer turns recording on — call recordings, plus the transcripts and AI summaries made from them.
- Consent and opt-out records: when and how someone agreed to be texted, and when someone asked not to be contacted.
- Deals, offers, proposals, buyer lists, contracts, and electronic signatures, including each signer’s typed name, the time, IP address and browser.
Usage and device information
Pages and features used, the time and length of calls, amounts of each metered service used, error reports, IP address, browser and device type, and similar technical information. We use cookies and similar storage that are needed to sign you in and keep the product working.
Sales pages
If you join the waitlist or contact us, we collect what you type into the form. Our sales pages may use Google Analytics to count visits and see which pages are read; it uses cookies to do that.
4. How we use it
- To provide the product: place calls, send texts and email, store and show records, run features the customer uses.
- To create accounts, secure them, and stop fraud, abuse and unlawful calling or texting.
- To bill, meter usage against plan allowances, and enforce plan limits.
- To support customers and tell them about changes, outages and their account.
- To find and fix errors and improve the product, using usage information that does not identify people in Customer Data.
- To meet legal obligations, respond to lawful requests, and protect rights and safety.
We do not sell personal information, and we do not use Customer Data to advertise to anyone or to build our own contact lists. We do not use Customer Data to train AI models, and our AI providers are engaged on terms that [do not allow them to train on it — to be confirmed per provider].
5. AI features
When a customer uses call recording and AI features, recordings are sent to a transcription provider and transcripts, notes and property details are sent to an AI model provider to write summaries and deal reads. The results are stored with the customer’s records. They can be wrong, and customers are told to review them. See the providers in section 7.
6. Who we share it with
- Service providers that host, run and support the product, listed in section 7, under contracts that limit their use of the data.
- Data providers, which receive an address or owner name when a customer asks the product to look something up.
- The customer’s own users and the people they choose — for example a buyer viewing a proposal, or a seller signing a contract.
- Authorities and others where the law requires it, or where needed to protect rights, safety or the product, such as responding to a subpoena or a carrier’s investigation of a complaint.
- A buyer or successor if our business is sold or reorganized, under the same protections.
7. Service providers and data sources
These are the outside companies and public sources the product uses today. The data sources in the last group mostly supply data to us rather than process it for us; they are listed because a lookup sends them an address or name.
Hosting, storage and accounts
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Hosts the application and runs its server code. | All data passing through the application; request logs. |
| Neon | Primary database. | Account data and Customer Data stored in the product. |
| Clerk | Sign-in and user identity. | Users' names, email addresses, sign-in activity. |
| Sentry | Error monitoring. | Error reports with a user ID and role; no session replays. |
| Stripe(when billing launches) | Subscription billing and payments. | Billing contact, payment details (held by Stripe, not us), invoices. |
Calls, texts, email and notifications
| Provider | What it does | What it receives |
|---|---|---|
| Twilio | Phone numbers, calls, texts, voicemail, call recordings and the spoken recording notice. | Phone numbers, message content, call audio and recordings (stored by Twilio), call metadata. |
| Resend | Sends email: signature requests, portal and handoff emails, reports. | Recipient names and email addresses, email content. |
| Browser push services (Google, Apple, Mozilla) | Deliver notifications Users switch on. | Encrypted notification payloads. |
AI
| Provider | What it does | What it receives |
|---|---|---|
| OpenAI | Transcribes call recordings and voicemails (Whisper). | Recording audio. |
| Anthropic | Summarizes calls and voicemails; writes deal reads. | Transcripts, lead and property details, notes. |
Maps
| Provider | What it does | What it receives |
|---|---|---|
| Google Maps Platform | Map, satellite and Street View images of a property. | Property addresses. |
| OpenStreetMap tile servers | Background map tiles on comps and deal maps. | The map area viewed and the viewer's IP address. |
Property and contact data sources
| Provider | What it does | What it receives |
|---|---|---|
| DealMachine | Skip tracing, comparable sales, property details and photos. | Property addresses and owner names sent to look up; results returned. |
| RentCast | Rent estimates, comparable sales, listings and listing agents. | Property addresses. |
| U.S. Department of Housing and Urban Development (HUD USER) | Fair Market Rents for Section 8 underwriting. | ZIP code or county. |
| FEMA National Flood Hazard Layer; USGS elevation service | Flood zone and elevation for a property. | Map coordinates. |
| County property appraiser and GIS services (currently Sarasota and Manatee counties, City of Bradenton) | Public property records, sales and code-enforcement data for lists and comps. | Addresses or parcel IDs queried; public records downloaded. |
Your browser may also send data to its own maker when you use built-in features — for example, dictation uses the browser’s speech recognition, which in Chrome is processed by Google.
We will update this list before adding a provider that receives Customer Data.
8. How long we keep it
- Account data: while the account is open and for [period] afterwards for billing, tax, legal and dispute purposes.
- Customer Data: while the customer’s subscription is active, then deleted [30] days after it ends, unless the customer asks for earlier deletion or the law requires us to keep it. Backups roll off within [backup retention period].
- Call recordings and transcripts: until the customer deletes them or the account ends. [A default retention period for recordings has not yet been set.]
- Opt-out records: kept for as long as the customer’s account exists, because forgetting a “stop” request is how people get called again.
- Logs and error reports: [period].
9. Your choices and rights
Depending on where you live, you may have the right to know what personal information we hold about you, get a copy, correct it, delete it, and opt out of its sale or sharing for targeted advertising. We do not sell personal information. We will not treat you differently for using these rights.
If you use the product, or signed up on our sales pages
Email sales@soundpropertiesgroup.com. We will confirm your identity before acting, and respond within 45 days (or the time the law in your state allows). An authorized agent may ask for you with your written permission.
If a company using the product contacted you
Your information belongs to that company, and it decides what to do with it. Please ask them directly. If you write to us instead, we will pass your request to the company within [10] business days and help them answer it, as their service provider. If you reply STOP to a text sent through the product, that number is blocked from further texts and calls from that company automatically.
10. Security
We use encryption in transit, access controls limited by role, separation of each customer’s data, signed webhooks from our phone provider, rate limits on costly actions, and monitoring for errors. No system is perfectly secure; if a breach affects your information we will notify you and our customers as the law and the Data Processing Addendum require.
11. Where data is processed
The product is run from the United States, and our providers process data mainly in the United States. It is intended for businesses operating in the United States.
12. Children
The product is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
13. Changes to this policy
We will post changes here with a new version number and date. If a change is material, we will tell customers by email or in the product before it takes effect.
14. Contact
Sound Properties Group LLC
[company mailing address]
sales@soundpropertiesgroup.com