Privacy

Privacy Policy

This draft explains what information the current TransactionOS MVP handles, why it is needed, and which service providers help operate the product.

First draft · Last updated July 30, 2026

Draft for review. This page describes the current TransactionOS MVP from the available product information. It is not legal advice and should not be published as final until the marked business details are supplied and qualified counsel reviews it.

Business information requiredAdd the full legal name, business address, country of establishment, and privacy contact for the company that operates TransactionOS.

1. Who operates TransactionOS

TransactionOS is a web application for independent residential real estate brokerages. In this draft, “TransactionOS,” “we,” “us,” and “our” refer to the business operating the service.

2. Information handled by the service

Account and brokerage information

  • Name, work email address, password-protected account, account role, account status, and account creation date.
  • Brokerage name, brokerage workspace identifier, and team invitation information, including an invited agent’s email address, invitation status, and expiration date.
  • Authentication session information needed to keep users signed in.

Passwords and authentication are handled through Supabase Authentication. TransactionOS application code does not store readable passwords.

Transaction and client-file information

  • Property address, transaction side, client name, assigned agent, status, expected closing date, notes, creation date, update date, and archive date.
  • Brokerage checklist templates and transaction checklist items, including whether an item is missing, uploaded, or not required.
  • Uploaded PDF, Word, and image files, plus file name, type, size, storage location, uploader, and upload date.

Brokerage customers and their users decide what information they enter or upload. They should avoid adding information that is not needed for transaction-file organization and oversight.

Subscription and email information

  • Lemon Squeezy customer, subscription, product, and variant identifiers; subscription status; renewal date; end date; and record timestamps.
  • Email address, welcome-email delivery identifier, and limited delivery outcomes used to send and troubleshoot the welcome email.

Payment checkout is hosted by Lemon Squeezy. The current application does not directly collect or store full payment-card details.

Technical records

The application records limited operational events such as email acceptance or failure, checkout configuration errors, and subscription-webhook outcomes. These records may include internal user, message, or subscription identifiers and error information. Hosting and infrastructure providers may also process request and device information when delivering the service.

3. How information is used

  • Create and secure user and brokerage accounts.
  • Show brokers permitted brokerage transactions and show agents their assigned transactions.
  • Create property-based transaction folders and track required documents.
  • Store and provide authorized access to transaction documents.
  • Invite team members and manage brokerage access.
  • Send the welcome email requested after completed signup.
  • Open hosted checkout and keep subscription status synchronized.
  • Diagnose failures and protect the reliability and security of the service.

4. Service providers

The current product relies on these providers to perform specific functions:

  • Supabase: authentication, Postgres database, and private file storage.
  • Vercel: application hosting and server-side application execution.
  • Resend: transactional welcome-email delivery.
  • Lemon Squeezy: hosted subscription checkout, payment handling, and subscription events.

Information is shared with these providers only as needed to perform the described functions. Each provider also operates under its own terms and privacy practices.

5. Brokerage and role-based access

TransactionOS applies brokerage and role-based access controls. Brokers can access transactions within their brokerage. Agents can access transactions assigned to them. Uploaded transaction files are kept in private storage and are not intentionally made publicly accessible.

6. Cookies and sessions

TransactionOS uses authentication cookies or similar session technology supplied through Supabase so users can sign in and access protected pages. No advertising or behavioral-tracking use is evidenced in the current application.

7. Retention and deletion

Business information requiredDefine how long accounts, transaction records, archived files, invitations, subscription records, email logs, and infrastructure logs are retained. Also define the verified process and timeframe for account or brokerage deletion.

Until a final retention schedule is approved, users may contact us at team@mail.transactionos.jessicabuenavista.com with a deletion or access request. This sentence does not promise a particular outcome or response timeframe.

8. Privacy requests and legal rights

Legal review requiredIdentify the laws and user rights that apply based on the operating company’s location and customers’ locations. Add the required identity-verification, response-time, appeal, regulator, and authorized-agent language.

9. International processing

Legal review requiredConfirm where Supabase, Vercel, Resend, and Lemon Squeezy process or store data and add any required international-transfer mechanism or notice.

10. Children’s privacy

Business information requiredConfirm the minimum permitted user age and whether the service is intended only for business users before adding a final children’s privacy statement.

11. Changes to this policy

Business information requiredDefine how users will be notified of material policy changes and when an updated policy becomes effective.

12. Contact

Questions about this draft or the service may be sent to team@mail.transactionos.jessicabuenavista.com.