Skip to main content

Privacy Policy

Last updated: September 21, 2026

Introduction

Pierce Industries LLC, doing business as PREP ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our real estate management platform.

Information We Collect

Personal Information

  • Name and contact information
  • Email address and phone number
  • Real estate license information
  • Payment and billing information
  • Property and transaction data
  • Signup attribution data (where available at the time you create your account): the referring URL, landing page URL, and UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) associated with the session that led to your signup. These are captured once at account creation and stored in your account record.

Usage Information

  • Platform usage and activity
  • Device and browser information
  • IP address and location data
  • Cookies and tracking technologies: We use two categories of cookies. Strictly necessary — NextAuth session cookies keep you signed in for the duration of your browser session (deleted when you close your browser or sign out). Analytics — Google Analytics 4 sets _ga and _gid cookies to distinguish users and sessions; these persist for up to 2 years and 24 hours respectively. Analytics cookies are off by default and are set only after you opt in — see "Cookie Consent and Analytics" below for how to control them.

Analytics and Measurement

We collect analytics data through two distinct systems, described separately below.

First-Party Product Analytics (authenticated users only)

When you are signed in to PREP, we record certain in-product actions (such as creating a deal, applying a checklist from a template, or setting a follow-up date on a contact) in a first-party analytics event store in our own PostgreSQL database. Each event is keyed to your user account ID and includes the event name and structured metadata about the action (for example, the deal type). These events do not contain personally identifiable information such as your name, email address, or phone number.

Legal basis: We rely on legitimate interest (GDPR Art. 6(1)(f); CCPA business purpose, not a sale or share) to collect this data. Our legitimate interest is understanding how our product is used so we can improve it, measure feature adoption, and track the “activation” journey that leads to a successful real estate workflow. This data is never shared with third parties and is never used for advertising. This paragraph describes usage-analytics events. It does not describe the client and deal records you keep in PREP — see "User-Directed AI Connections" for how those can leave PREP at your direction.

Attribution data at signup: When you create a PREP account, we capture (where available) the UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the HTTP referrer, and the landing page URL associated with the session that led to your signup. This information is stored in your account record and is used only for internal measurement of which marketing channels are effective. It is not shared with advertising networks.

You may object to this processing at any time by contacting privacy@the-prep.casa (GDPR Art. 21). If you object, we will suppress further product analytics writes to your account. This does not affect our ability to operate your account or provide the service. If you submit a right-to-erasure request, all product analytics events tied to your account are hard-deleted as part of that process.

Third-Party Website Analytics (Google Analytics 4)

We use Google Analytics 4 (GA4) to understand how visitors use our marketing website. GA4 collects the following information:

  • Pages visited and time spent on pages
  • Device type, browser, and operating system
  • Approximate geographic location (city and region level)
  • Referral source and session behavior
  • Core Web Vitals performance metrics (page load time, interactivity, and visual stability) to monitor and improve site performance

GA4 uses cookies and similar technologies to collect this data. Data collected through GA4 is processed by Google LLC under their privacy policy. We use this data to improve our website, understand usage patterns, and optimize the user experience. We do not use GA4 to collect personally identifiable information.

Google Analytics is loaded only after you opt in. See "Cookie Consent and Analytics" below for the controls available to you.

Cookie Consent and Analytics

We use Google Consent Mode v2 to keep analytics off until you choose to allow it. When you first visit the site, all analytics and advertising storage signals default to denied, so no Google Analytics cookies are set and no analytics measurement occurs unless and until you opt in. PREP runs no advertising pixels, and the advertising signals are kept permanently denied regardless of your choice. You have the following controls:

  • Consent banner: On your first visit, a banner lets you Accept or Decline analytics cookies. Analytics stays off unless you select Accept. Declining or dismissing the banner keeps analytics off. You can change your choice at any time using the "Do Not Sell or Share My Personal Information" control described below.
  • Global Privacy Control (GPC): If your browser or an extension sends a Global Privacy Control signal, we honor it automatically: analytics is kept denied and the consent banner is suppressed. A GPC signal overrides any prior opt-in.
  • "Do Not Sell or Share My Personal Information": A control with this label is available in the site footer. Selecting it turns analytics off for this browser at any time, including after a prior opt-in. PREP does not sell or share your personal information for cross-context behavioral advertising and runs no ad trackers; this control ensures analytics is opted out.
  • Browser settings: You can also remove or block cookies through your browser settings, or install the Google Analytics Opt-out Browser Add-on.

How We Use Your Information

  • Provide and maintain our services
  • Process payments and subscriptions
  • Send important updates and notifications
  • Improve our platform and user experience
  • Comply with legal obligations

Product Update Emails

We send weekly product update emails to all account holders by default. You can unsubscribe via the link in any email, or by toggling Product Updates off in /account/notifications. Public subscribers (non-account-holders) confirm via double opt-in and can unsubscribe from any email. We retain consent records (timestamp, IP address, user agent, and source) for GDPR compliance and never share or sell email addresses. To request deletion of your consent record, contact privacy@the-prep.casa.

Data Security

We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption, secure servers, and regular security audits.

Third-Party Services and Sub-Processors

We use trusted third-party services to operate PREP. These sub-processors receive only the information required to perform their service and are bound by their own privacy and security commitments:

  • Stripe — payment processing (card data is sent directly to Stripe and never stored on PREP servers). We store a Stripe customer identifier in our database to link your account to your payment history.
  • Google — authentication (Sign in with Google) and optional Google Calendar integration (details below)
  • Google Analytics 4 — aggregate website usage measurement and Core Web Vitals
  • Google Places API — address autocomplete in property and contact forms (the partial address you type is sent to Google to return matching address suggestions)
  • Vercel — application hosting (United States)
  • Supabase — managed PostgreSQL database (United States)
  • Amazon Web Services (AWS) — cloud infrastructure including Amazon S3 (document storage), Amazon SES (email delivery), and Amazon Bedrock (AI document and email extraction, described below). Data is processed in the AWS us-east-1 region (United States).
  • Resend — transactional email delivery and optional inbound email ingestion
  • Cloudflare Turnstile — bot and spam protection on public lead-capture forms (described below)

All sub-processors listed above operate in the United States. International customers should be aware that submitted information will be transferred to, stored, and processed in the United States. By using PREP or submitting information through a PREP-powered form, you consent to this transfer.

Public Handles and Campaign Link Addresses

When you create your first campaign form or share link, PREP automatically assigns your workspace a public "handle" — a short, URL-friendly name derived from your account name (for a personal workspace) or your team's name (for a team workspace). For example, an account for "Ryan Pierce" may receive the handle ryan-pierce.

Your handle is public. It appears in the web address of every campaign form and share link you share (for example, https://www.the-prep.casa/p/ryan-pierce/open-house). Anyone you share a link with, and anyone who visits that page, can see your handle.

You can change your handle at any time from within PREP. In a personal workspace, you control your own handle. In a team workspace, the team's owner controls the team's handle. Changing a handle updates the address of all of that workspace's existing campaign links at once; links that used the previous handle will stop working. Because a handle is derived from a name, you may also change it to remove or alter that name if you prefer — in a team workspace, ask the team's owner to do so.

We do not use your handle for advertising, and we do not sell or share it. If you ask us to delete your account, your handle is deleted as part of that process (see "Data Retention" and "Your Rights"). When a handle is released — because you renamed it, or because the account or team it belonged to was deleted — we keep the released text on a short reservation list so that it cannot be claimed straight away by someone else and used to inherit the previous owner's links. See "Data Retention" below.

Your Public Page

PREP offers an optional public page — a simple "link in bio" page at your handle's address (for example, https://www.the-prep.casa/p/ryan-pierce) that lists the lead-capture forms you choose to share. This page is off by default. Nothing is published until you turn it on yourself from within PREP. In a personal workspace, you control your own page; in a team workspace, the team's owner controls the team's page.

When you publish your public page, the following becomes visible to anyone on the internet: your workspace's display name (your account name, or your team's name) and the initials drawn from it; your handle, which forms the page's web address; the tagline you write; the brokerage or license line you enter; the public email address and public phone number you enter; and, for each active lead-capture form you have chosen to show, the name it appears under — either the form's own name or a label you write for it — together with its link. We do not display your sign-in email address or your account phone number on this page — the only contact details shown are the ones you type into the public-page settings yourself.

A published public page is an ordinary public web page. Search engines may crawl it, index it, and show it in search results; other people may link to it, share it, or copy what is on it; and anything you put on it — including an email address or phone number — can be collected by others, including automated services that harvest contact details for marketing lists. Please put only contact details on the page that you are comfortable making permanently public.

You can unpublish your page at any time using the same control you used to publish it. When you unpublish, the page immediately stops being served and returns a "not found" response. Search engines normally drop a page from their results within a few days of finding that it is gone, but we do not control their timing, and copies may persist in search caches, web archives, or other third-party services outside our control. If you need a page removed from search results urgently, contact privacy@the-prep.casa and we will ask the major search engines to remove it.

We do not use your public page for advertising, and we do not sell or share the information on it. If you turn the page off, the tagline and contact details you entered remain in your settings so you can publish again later. If you ask us to delete your account, your own public page and everything you entered on it are deleted along with the rest of your account data (see "Data Retention" and "Your Rights"). If you own a team workspace, deleting your account also removes the public contact details you supplied on that team's page and turns the team's page off, so it stops being served; the team's remaining page content is kept but is no longer published.

Public Lead-Capture Forms

PREP customers (real estate agents, teams, and brokerages) can publish public lead-capture forms at PREP-hosted URLs (for example, https://www.the-prep.casa/p/<handle>/<slug>). If you submit information through one of these forms:

  • The information you provide (name, email, phone, and any other fields the agent has configured) is delivered to the PREP customer who owns that form. That customer is the primary recipient and controller of your information and will contact you directly.
  • PREP acts as the service provider (processor) that stores and routes the submission on behalf of the customer.
  • To prevent spam and abuse, we also collect technical metadata: your IP address, browser user agent, the referring URL, UTM parameters from the link you clicked, and timing signals about your interaction with the form.
  • We set a first-party cookie (pierce_portal_visited, 30-day lifetime) to recognize returning visitors for spam scoring. This cookie is used only for anti-abuse purposes and does not track you across other websites.
  • We use Cloudflare Turnstile to verify that form submissions come from a human and not an automated bot. Turnstile may process technical signals from your browser according to Cloudflare's privacy policy.

If you want your information removed after submitting a form, please contact the agent who operates the form first (they are the primary recipient). You may also contact us at privacy@the-prep.casa and we will route the deletion request to the appropriate customer.

Inbound Email Lead Ingestion

PREP customers on eligible plans can forward lead emails (for example, notifications from Zillow or Realtor.com) to a unique PREP-hosted inbound address. When an email is forwarded to that address, we process its subject, body, and sender information so that we can create a contact record for the customer. This may include parsing personal information (name, email, phone) about a third-party lead whose email was forwarded to PREP.

This inbound email data is stored only for the PREP customer who received it and is never used to train AI models. If you believe an email containing your personal information has been forwarded to PREP without your consent, please contact us at privacy@the-prep.casa.

Use of Artificial Intelligence

PREP uses large language models operated by Amazon Web Services (Amazon Bedrock, Anthropic Claude family) to assist with specific tasks:

  • Extracting contact information from inbound emails forwarded to a customer's PREP inbound address
  • Mapping columns in uploaded CSV files to PREP contact fields during import
  • Extracting structured fields from real estate documents uploaded by customers
  • Scoring inbound leads on a 1-5 scale based on fields you provided (such as timeline, budget, and pre-approval status). This score is a private organizational aid for the customer and is not a consumer-facing credit, insurance, or housing decision.
  • Generating a deal briefing on request. For customers on eligible plans, PREP can generate a short, plain-language summary of one of the customer's own real estate transactions when the customer clicks "Generate." The summary is based on the customer's existing deal data — such as the transaction stage, key dates and deadlines, checklist items, and whether an earnest-money amount has been recorded — and is produced by a large language model via Amazon Bedrock. When PREP generates this summary, the content is not used to train the underlying models, is not used to make any automated decision about housing, credit, insurance, or employment, and is advisory only: the customer is instructed to verify it before relying on it.

Content sent to Amazon Bedrock for processing is transmitted over encrypted connections and is not used to train the underlying models (see AWS Bedrock data privacy). PREP does not use customer or lead information to train its own AI models. PREP does not make automated decisions about housing, credit, insurance, or employment based on AI output. Protected- class attributes (such as race, religion, national origin, or familial status) are not collected by PREP and are not used as inputs to lead scoring. These assurances describe AI processing that PREP performs on your behalf, inside PREP's own systems. They do not extend to data you direct out of PREP to an AI client you connect yourself. That data is governed by your AI provider's terms, which may permit them to retain it or use it to improve their models. See "User-Directed AI Connections" below.

User-Directed AI Connections

This section is effective September 21, 2026. AI connections are being rolled out gradually: the feature is available only on eligible plans and only to accounts PREP has opened it to. Until you have connected a tool yourself, nothing in this section describes how your data is handled.

This is your connection, not ours. PREP lets you connect an AI client that you choose and control — for example a desktop or web AI assistant — to your own PREP account, so you can ask questions about your own deals inside the tool you already use. PREP does not select that tool for you, does not have a relationship with its provider on your behalf, and never opens a connection you did not authorize.

Nothing is connected unless you connect it. There is no connection on your account until you complete an authorization screen inside PREP that tells you which tool is asking, what it will be able to read, how long access lasts, and — if you belong to a team — which workspaces it covers. You can decline, and you can disconnect later.

What a connected tool can read. Access is read-only: a connected tool cannot create, change, or delete anything in PREP, and it can only read records you can already see yourself. Only a fixed list of fields is available to it. That list covers your deals' status and stage, key dates and deadlines, checklist task names and due dates, property addresses, your own deal amounts (such as purchase price, earnest money, and your own offer amount), and your contacts: their names, email addresses, phone numbers, mailing addresses, any budget range you recorded, and their role and contact type.

Some information never leaves PREP through a connection. That includes: commission and other compensation amounts; information about a client's financial capacity (such as a credit-score range, income range, or pre-approval amount); scores and behavioural ratings that PREP derives about a contact; free-text notes and the personal-preference fields that go with them (motivation, lifestyle, household details, timeline, preferred locations); the contents of any document or file you have uploaded; and the terms of offers submitted by other agents on a property you have listed.

No Google data is available to a connected tool. Information PREP receives from Google APIs, including your Google Calendar, is not readable through an AI connection. See "Google API Limited Use Disclosure" below.

What happens once data leaves PREP. This is the part to read twice. Once information leaves PREP at your direction, it is held by the AI tool you chose and is governed by that provider's terms and privacy policy, not this one. PREP cannot control, and does not promise anything about, how that provider stores the information, how long it keeps it, who can see it, or whether it is used to develop or improve that provider's AI models. Some consumer AI plans do permit that use; business and enterprise plans often do not. Read your tool's terms and check its settings before you connect.

Who is responsible for what. For the client and contact information you keep in PREP, you are the controller and PREP is the processor acting on your instructions. Connecting an AI client is such an instruction: you are directing PREP to make your data available to a provider you selected. That provider is acting for you, not for PREP, which is why it does not appear in the list of PREP sub-processors above — PREP has not engaged it, assessed it, or contracted with it on your behalf. Where the information you make available includes another person's personal data, you remain responsible for having a lawful basis for that disclosure and for giving whatever notice or obtaining whatever consent the law and your own agreements require.

Disconnecting, and the one thing it cannot do. You can disconnect at any time from Account → Integrations → Connected apps, or revoke access from the AI tool itself. Disconnecting takes effect immediately: the connection is switched off and the tool cannot read anything further. A connection also ends on its own if it goes unused for long enough; the authorization screen tells you how long when you connect. Either way the switched-off connection record is kept for a limited period and is then deleted — see Data Retention below. Disconnecting cannot claw back information the tool already received. Deleting your PREP account has the same limit. To remove a copy that is already inside your AI tool you have to delete it there, using that provider's own controls.

What PREP records about a connection. PREP keeps a metadata-only log of connection activity: which tool connected, what kind of record was read, how many rows, when, and whether the request succeeded. These logs contain no names, email addresses, phone numbers, no text of the questions asked, and no AI output. If you ask us to erase your account, the connection and its credentials are deleted outright and your account identifier is removed from these logs. Your active connections are included in the data you receive if you request a copy of your information.

Team workspaces. Your connection covers your personal workspace, plus the workspace of any team you own. A team you belong to but do not own is included only where that team's owner has allowed AI access for members in PREP; the owner can withdraw that at any time and it takes effect on the next request; you are notified either way. Once it is on you cannot keep your connection and exclude that team; your choice is whether to stay connected. The workspace list your AI app sees reports how many of your teams are not available, without naming them.

Data Retention

We retain personal information for as long as needed to provide the service and to meet legal, tax, and audit obligations:

  • Account and customer data — retained while your account is active and for up to 30 days after deletion, after which personal data is removed except where longer retention is required by law
  • Released handles (the text of a handle you renamed away from, or that belonged to a deleted account or team) — kept on a reservation list for 30 days, so the same address cannot be immediately claimed by someone else and used to inherit your previous links, then deleted. The list holds only the released text, the date it was released, and the date it becomes available again.
  • Transaction, offer, and agreement records — customers may be required by state real estate regulations to retain these records for 3-7 years; we retain them for the customer accordingly
  • Form-submission metadata (IP address, user agent, referring URL) — retained for the life of the submission record for audit, anti-abuse, and dispute-resolution purposes
  • Raw form payloads (the unmodified JSON of a lead-capture submission) — retained for audit and debugging and are automatically purged 90 days after submission
  • Product analytics events (first-party behavioral telemetry keyed to your account, collected while you are signed in) — automatically purged 760 days (approximately 25 months) after the event is recorded, to support year-over-year product analysis while remaining proportionate to our business need. This telemetry is not subject to real-estate record-keeping regulations, which do not apply to internal product-usage data. Hard-deleted on a valid right-to-erasure request.
  • Billing records (invoices, payment status) — retained as required by applicable tax and accounting law (typically 7 years)
  • AI usage metering records (token counts, task names, model tier, duration, and per-account usage) — retained for 13 months from the date of the call, linked to your account during that period, then anonymized or deleted. On account deletion, the personal identifiers in these records are removed (nulled out) while the aggregate token-count data is retained for billing-integrity purposes.
  • Security and access logs — retained for up to 12 months for incident-response and audit purposes
  • System audit logs (records of administrative actions, billing-status changes, and configuration changes) — retained for 7 years. We keep these to satisfy tax and accounting law and to maintain a reliable audit trail if billing or account questions come up — the same reason most accounting software keeps records this long. These logs contain account identifiers and action records; they do not contain card numbers or full contact information. If you request deletion of your account, we anonymize your name and email in these records but retain the action entries themselves, which we are required to keep.
  • AI-connection credentials (the authorization records behind an AI client you have connected) — kept while the connection is active. When you disconnect, or when the connection expires because it has gone unused, it is switched off immediately and can no longer be used to read anything; once it has been switched off for 30 days, a daily sweep deletes the record and the stored credentials with it. If you delete your PREP account, these records are deleted outright at that point.
  • AI-connection activity logs (metadata only: which tool, record type, row count, timestamp, and outcome — never names, contact details, the text of any question asked, or AI output) — kept for 365 days for security, incident-response and audit purposes, after which a daily sweep deletes them. On a valid erasure request your account identifier is removed from these records while the activity entries themselves remain.

To request earlier deletion of your personal information, contact privacy@the-prep.casa. We will honor valid deletion requests except where retention is required by law or by the legitimate business purposes listed above.

Data Breach Notification

If we learn of a security incident that affects your personal information, we will notify you and, where required, regulators in accordance with applicable law. We aim to notify affected users without undue delay and, where GDPR applies, within 72 hours of discovering the breach.

Google Calendar Integration

PREP offers an optional Google Calendar integration that allows you to sync critical real estate transaction dates directly to your Google Calendar. When you connect your Google Calendar, the following applies:

Data Accessed

When you connect your Google Calendar, we access calendar event titles, dates, times, locations, and attendees from your primary Google Calendar. We use the calendar.events scope, which provides read and write access to your primary Google Calendar.

Purpose

Calendar access is used solely to sync real estate transaction dates — including closing dates, inspection deadlines, contract expiration dates, and option periods — to your Google Calendar so you never miss critical deadlines. We do not read or process your existing calendar events for any other purpose.

Storage

OAuth access and refresh tokens are stored securely in our database using encryption at rest. Calendar event metadata (event IDs and sync status) is stored for synchronization tracking purposes only.

Sharing

Google Calendar data is never shared with third parties, advertisers, or data brokers. We do not sell, trade, or transfer Google user data to third parties.

Disconnecting and Deletion

You can disconnect your Google Calendar integration at any time from your Account settings. Disconnecting immediately deletes stored tokens and calendar sync data from our systems. You can also revoke PREP's access to your Google Calendar at any time from your Google Account permissions page.

Google API Limited Use Disclosure

PREP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell, trade, or transfer Google user data to third parties.

Your Rights

  • Access and update your personal information
  • Request deletion of your data
  • Opt-out of marketing communications
  • Export your data
  • Withdraw consent for data processing

These rights apply to all users; see the CCPA and GDPR sections below for region-specific details.

Your Choices

You have several options to control how your information is collected and used:

  • Analytics consent: Analytics cookies are off by default. You can decline them on the consent banner, or turn them off at any time using the "Do Not Sell or Share My Personal Information" control in the footer. We also honor Global Privacy Control (GPC) browser signals automatically. See "Cookie Consent and Analytics" above for details
  • Cookie preferences: You can also manage or disable cookies through your browser settings. Most browsers allow you to refuse new cookies, delete existing cookies, or be notified when a new cookie is set
  • Marketing communications: You may opt out of marketing emails at any time by clicking the unsubscribe link in any email we send or by contacting us at privacy@the-prep.casa

California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:

  • Right to know: You have the right to know what personal information we collect, the sources from which we collect it, the purposes for which we use it, and the categories of third parties with whom we share it
  • Right to delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions
  • Right to opt out of sale: We do not sell personal information to third parties

PREP does not sell personal information, and we do not run advertising trackers. Analytics data collected through Google Analytics may, however, constitute "sharing" of personal information under the CCPA/CPRA. Analytics is off by default and is enabled only if you opt in. To exercise your right to opt out, you can use the "Do Not Sell or Share My Personal Information" control in our footer (which turns analytics off for your browser), decline analytics on the consent banner, or send a Global Privacy Control (GPC) signal from your browser, which we honor automatically as a valid opt-out request.

To exercise your California privacy rights, please contact us at privacy@the-prep.casa. We will respond to verified requests within 45 days as required by law.

European User Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and applicable national laws provide you with the following rights regarding your personal data:

  • Right of access: You have the right to request a copy of the personal data we hold about you
  • Right to erasure ("right to be forgotten"): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller
  • Right to restriction of processing: You have the right to request that we restrict the processing of your personal data under certain circumstances
  • Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of your personal data infringes the GDPR

To exercise any of these GDPR rights, please contact us at privacy@the-prep.casa. We will respond within 30 days of receiving your request.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: privacy@the-prep.casa

For terms-of-service questions, email legal@the-prep.casa.