Privacy Policy

How we collect, use, and protect your data · Last updated April 2026

Estaty ('we', 'our', or 'us') operates the Estaty platform, a SaaS tool for real estate agents to manage listings, leads, and their public profile. This Privacy Policy explains how we collect, use, disclose, and protect information about you and your clients when you use our services.

1. Information We Collect

Information you provide directly

  • Account registration: your name, email address, and password.
  • Profile information: display name, job title, bio, phone number, and profile photo.
  • Listing data: property details, photos, pricing, and descriptions you create.
  • Payment information: billing name and address. Card data is processed by Lemon Squeezy and never stored on our servers.
  • Communications: messages you send to our support team.

Information collected automatically

  • Usage data: pages visited, features used, clicks, session duration.
  • Device data: browser type, operating system, screen resolution, IP address.
  • Cookies and similar technologies: see our Cookie Policy for details.
  • Log data: server logs including request timestamps, errors, and response times.

Information from third parties

  • If you sign in with Google, we receive your name, email, and profile picture from Google.
  • Payment confirmations and subscription status from Lemon Squeezy.

2. How We Use Your Information

  • To create and manage your account.
  • To provide and improve the Estaty platform and its features.
  • To process payments and manage your subscription.
  • To send transactional emails (account confirmation, password reset, billing receipts).
  • To send optional notifications you've opted into (new lead alerts, weekly summaries).
  • To analyse usage patterns and improve platform performance and reliability.
  • To respond to your support requests.
  • To comply with legal obligations.

3. Lead Data You Collect Through Estaty

When visitors submit enquiries through your public profile or listing pages, their name, email, phone number, and message are stored in your Estaty account as leads. You are the data controller for this lead data. We process it on your behalf as a data processor. You are responsible for ensuring you have a lawful basis for collecting and using your leads' personal data.

4. How We Share Information

We do not sell your personal data. We share data only in the following circumstances:

  • Service providers: we use trusted third-party services (Supabase, Vercel, Lemon Squeezy, Resend) to operate the platform. Each is bound by data processing agreements.
  • Legal requirements: if required by law, court order, or to protect the rights and safety of Estaty or others.
  • Business transfers: in the event of a merger, acquisition, or asset sale, your data may be transferred. We will notify you in advance.
  • With your consent: for any other purpose with your explicit agreement.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we permanently erase your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (typically up to 7 years for billing records).

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate data.
  • Erasure: request deletion of your data ('right to be forgotten').
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to certain types of processing.
  • Restriction: request that we limit how we use your data.
  • Withdraw consent: where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email us at hello@estaty.io. We will respond within 30 days.

7. Security

We implement industry-standard security measures including TLS encryption for data in transit, AES-256 encryption for data at rest, role-based access controls, and regular security reviews. See our Security page for full details.

8. Children's Privacy

Estaty is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. International Transfers

Our infrastructure is primarily hosted in the EU (Supabase EU region). Some service providers may process data outside the EU/EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the 'Last updated' date at the top of this page. Continued use of Estaty after changes take effect constitutes acceptance of the updated policy.

11. Contact

If you have questions or concerns about this policy or how we handle your data, contact our privacy team at hello@estaty.io.

Questions about this document? hello@estaty.io