LEGAL
Privacy Policy
Last updated: April 2026 ยท Effective immediately
DealFlow AI ("we", "us", or "our") is a Customer Relationship Management (CRM) platform built for Indian real estate brokers. This Privacy Policy explains how we collect, use, and protect your information when you use our services at dealfinx.com.
๐
Information We Collect
We collect information you provide directly when creating an account, and information generated through your use of our platform.
- Account information: Your name, email address, phone number, and brokerage name when you sign up.
- Lead data: Contact information of property buyers (name, phone, budget, location) captured through integrated channels.
- Gmail data: When you connect Gmail, we read unread emails from property portals (99acres, MagicBricks, Housing.com etc.) to extract lead information. We do not read, store, or process any other emails.
- Usage data: How you interact with the platform โ pages visited, features used, actions taken.
- Meta Lead Ads data: Lead form submissions from your Facebook and Instagram ad campaigns, including buyer name and phone number.
When you connect your Gmail account to DealFlow AI, we request permission to read and modify your Gmail messages. Here is exactly what we do and do not do with this access:
- We only read emails from known property portal domains: 99acres.com, magicbricks.com, housing.com, squareyards.com, proptiger.com, makaan.com, and olx.in.
- We extract lead data (buyer name, phone number, budget, location) from these emails using AI parsing.
- We mark emails as read after successfully processing them.
- We never read, store, or share any personal emails, drafts, sent mail, or emails from any other sender.
- We never sell or share Gmail data with third parties for advertising or any other purpose.
- Your Gmail refresh token is stored securely and used solely to poll for new portal emails every 5 minutes.
- You can disconnect Gmail at any time from the Integrations page, which immediately revokes our access.
๐
How We Use Your Information
We use the information we collect to provide, maintain, and improve DealFlow AI. Specifically:
- To create and manage your broker account and team
- To capture and organise leads from connected channels into your pipeline
- To send automated follow-up reminders and notifications
- To generate analytics and performance reports for your brokerage
- To send transactional emails (account invitations, password resets) via Brevo
- To provide customer support and respond to inquiries
๐ค
Data Sharing and Third Parties
We do not sell your personal data or your leads data to any third party. We share data only with the following service providers necessary to operate DealFlow AI:
- Supabase โ PostgreSQL database hosting for storing your CRM data securely
- Railway โ Backend application hosting
- Vercel โ Frontend application hosting
- Brevo โ Transactional email delivery (invites, password resets)
- Google โ Gmail OAuth for portal lead capture
- Meta โ Facebook/Instagram Lead Ads integration
- Google Gemini โ AI-powered email parsing to extract lead details
We take the security of your data seriously. DealFlow AI implements the following security measures:
- All data is transmitted over HTTPS/TLS encryption
- Passwords are hashed using bcrypt โ we never store plaintext passwords
- JWT tokens are used for authentication with configurable expiry
- Each broker's data is strictly isolated โ agents can only access their own broker's leads
- OAuth tokens are stored encrypted in our database
- Database access is restricted to application servers only
We retain your data for as long as your account is active. If you cancel your subscription or request account deletion:
- Your lead data, notes, and call logs are retained for 30 days after cancellation, then permanently deleted
- Account information is deleted within 30 days of a deletion request
- Gmail and Meta OAuth tokens are immediately revoked upon disconnection
- You may request a full export of your data at any time from the Settings page
You have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request permanent deletion of your account and data
- Portability: Export your leads and CRM data as CSV from Settings
- Revocation: Disconnect Gmail or Meta integrations at any time
DealFlow AI uses minimal cookies. We use localStorage in your browser to store your authentication token for session management. We do not use third-party tracking cookies or advertising pixels.
We do not display advertisements. DealFlow AI is a paid SaaS product โ your data is never used for advertising purposes.
๐
Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email and display a notice within the DealFlow AI dashboard.
Continued use of DealFlow AI after changes are posted constitutes your acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
ยฉ 2026 DealFlow AI ยท Real Estate CRM for Indian Brokers ยท dealfinx.com