Privacy Policy

Effective date: 29 May 2026

Last updated: 29 May 2026

This Privacy Policy explains how MyBrokery Technologies LLC ("we", "us", "our") collects, uses, shares, and protects information about you when you use the MyBrokery web application, mobile applications, and related services (collectively, the "Services"). By using the Services you agree to the practices described below.

1. Who we are

MyBrokery is operated by MyBrokery Technologies LLC. For any questions about this policy or your personal data, contact us at support@mybrokery.com.

2. The data we collect

2.1 Information you provide

  • Account data — name, email address, password (hashed), profile photo, phone number, language and timezone preferences.
  • Workspace data — company / brokerage name, billing address, tax information, team members you invite, and roles you assign them.
  • CRM content — properties, leads, clients, contacts, viewings, deals, notes, files, photos, and messages you create or import into the Services. This frequently contains personal data about your own clients and prospects (third parties).
  • Payment data — for paid subscriptions and add-ons we use our payment processor, Stripe. Stripe collects and stores your card details directly; we receive only a token, the last 4 digits, card brand, and billing country.
  • Support communications — messages you send us, attachments, and metadata about those exchanges.

2.2 Information collected automatically

  • Device and log data — IP address, browser type, operating system, device identifiers, app version, crash reports, and approximate location derived from IP.
  • Usage data — pages visited, features used, search queries within the app, and aggregate performance metrics. Used to improve the product and detect abuse.
  • Cookies and similar technologies — strictly-necessary cookies for authentication and session management, plus optional analytics and preference cookies. See section 8.

2.3 Information from third parties

If you sign in with a third-party identity provider (e.g. Google, Apple), we receive your name, email, and profile image from that provider. We never receive your password.

3. How we use your data

  • To provide, operate, and maintain the Services.
  • To authenticate you, prevent fraud, enforce our Terms, and protect the integrity of the platform and other users' data.
  • To process payments, manage subscriptions, send invoices, and recover failed payments.
  • To send service notifications (security alerts, billing notices, lead-assignment emails, viewing reminders) — these are operational and cannot be disabled while your account is active.
  • To send product updates, tips, and marketing communications — only with your consent where required by law. You can opt out at any time from the email footer.
  • To analyse usage and improve features, performance, and security.
  • To comply with legal obligations and respond to lawful requests.

4. Legal bases for processing (EEA/UK)

If you are in the European Economic Area or the United Kingdom, our legal bases are:

  • Contract — to deliver the Services you have subscribed to.
  • Legitimate interests — to operate, secure, and improve the Services, and to prevent abuse.
  • Consent — for optional cookies and marketing emails. You can withdraw consent at any time.
  • Legal obligation — to comply with tax, accounting, and law enforcement requirements.

5. Who is the data controller?

For your own account data (your name, email, billing details), MyBrokery Technologies LLC is the data controller.

For CRM content you import about your clients and leads, you (or your workspace's company) are the data controller and MyBrokery Technologies LLC acts as a data processor on your behalf. You are responsible for having a lawful basis to upload that data, for honouring data-subject requests from your contacts, and for executing a Data Processing Addendum with us where required. Contact support@mybrokery.com to request a DPA.

6. Sharing your data

We do not sell your personal data. We share data only as follows:

  • Sub-processors — cloud hosting (e.g. AWS), email delivery (e.g. Amazon SES), payments (Stripe), error monitoring (e.g. Sentry), and analytics providers. All sub-processors are bound by contract to protect your data.
  • Within your workspace — team members of the workspace you belong to can see CRM content you contribute according to the permissions assigned by the workspace owner.
  • Legal and safety — when required by law, court order, or to protect the rights, property, or safety of MyBrokery, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, in which case the acquirer will be bound by this policy.

7. International data transfers

We are headquartered outside the EEA/UK and our infrastructure may process data in the United Arab Emirates, the European Union, and the United States. Where required, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.

8. Cookies and tracking

We use strictly-necessary cookies for authentication and CSRF protection. We may also use optional analytics or product-tour cookies, which load only after you consent on first visit (where the cookie banner is enabled by your administrator).

9. How long we keep your data

  • Active account data is retained while your account is active and for a reasonable period afterwards to handle disputes, comply with legal obligations, and recover from backups.
  • Closed accounts are anonymised or deleted within the data-retention window set by your workspace administrator (defaults to 730 days).
  • Backups are rotated on a regular schedule and may contain personal data for up to 90 days after deletion from the live system.
  • Audit logs are retained for compliance purposes — typically 365 days.

10. Your rights

Subject to your local law, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Export your data in a portable format.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email support@mybrokery.com. We will respond within the time required by applicable law (typically 30 days).

11. Security

We implement industry-standard technical and organisational measures including TLS encryption in transit, AES-256 encryption at rest for sensitive fields, role-based access control, audit logging, multi-factor authentication for administrators, regular backups, and least-privilege access for our staff. No method of transmission or storage is 100% secure; you use the Services at your own risk and should keep your password confidential.

12. Children's privacy

The Services are not intended for children under 16. We do not knowingly collect personal data from children. If we learn that we have done so, we will delete it promptly.

13. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app banner at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

14. Contact us

MyBrokery Technologies LLC
Email: support@mybrokery.com
Web: app.mybrokery.com