← Back to AIREI

Privacy Policy

Last updated: [PLACEHOLDER: effective date]

This Privacy Policy explains how AI REI ("AI REI," "AIREI," "we," "us," or "our") collects, uses, shares, and protects personal information when you visit myairei.com, use our app at app.myairei.com, or otherwise use our AI-powered CRM and messaging services (together, the "Services"). AI REI provides a customer relationship management platform built for real estate wholesalers and investors, including AI agents that text and call leads over SMS, phone, and ringless voicemail, done-for-you A2P 10DLC registration, pre-built investor workflows, and contact and pipeline tools.

Please note: This document is a template provided for general informational purposes only. It is not legal advice. You should have a licensed attorney review and customize this policy for your specific business, jurisdiction, and data practices before publishing or relying on it. Bracketed [PLACEHOLDER] items must be completed with accurate information before this policy is used.

Who We Are and How to Reach Us

AI REI is operated by [PLACEHOLDER: legal entity name], located at [PLACEHOLDER: mailing address]. If you have questions about this policy or our privacy practices, you can contact us using the details at the end of this page.

This policy applies to personal information we handle as part of providing the Services. It does not cover third-party websites, apps, or services that we do not control, even if they link to or from our Services.

Our Two Roles: Controller and Service Provider

AI REI handles personal information in two different capacities, and it matters which one applies:

  • When we handle information about our own customers and website visitors — for example, your account details, billing information, and how you use our platform — we act as the business or "controller" that decides how and why that information is used.
  • When our customers upload, import, or generate lists of sellers, leads, and other contacts inside the platform ("Customer Data"), we act as a "service provider" or "processor." In that role, our customer is the business/controller that decides how that data is used, and we process it only to provide the Services on the customer's behalf and under our agreement with them.

If you are a seller, lead, or other contact who received a message from a business using AI REI, that business — not AI REI — is the party responsible for its list, its consent practices, and its messages. Please direct requests about your information first to the business you interacted with. We will support that business in responding to your request, and where required by law we will assist you directly.

Information We Collect

The information we collect depends on how you interact with us.

Account and contact information. When you sign up or communicate with us, we collect information such as your name, business name, email address, phone number, username, password, and details about your business (including your EIN and business registration details needed for A2P 10DLC carrier registration).

Billing and payment information. Subscriptions, the one-time setup fee, and pay-as-you-go usage charges are processed by our payment processor, Stripe. Stripe collects and handles your payment card or bank details directly; we receive limited billing information such as the last four digits of a card, billing contact details, transaction amounts, and payment status. We do not store full payment card numbers on our own systems.

Customer Data (seller and lead information you upload). To use the Services, customers provide contact data about their sellers and leads — such as names, phone numbers, email addresses, property addresses, and notes about a property or deal. As explained above, we process this data as a service provider on the customer's behalf.

Messaging and call content and metadata. Because the Services send and receive SMS, place and receive phone calls, and deliver ringless voicemails, we collect the content of those communications and related metadata — for example, phone numbers involved, timestamps, call duration, delivery and response status, recordings or transcripts where enabled, and AI-generated message content and qualification results.

Usage, device, and technical information. When you use our websites and apps, we automatically collect information such as IP address, browser and device type, operating system, pages and features viewed, referring pages, and dates and times of access.

Cookies and similar technologies. We and our providers use cookies, pixels, local storage, and similar technologies to operate the Services, remember your preferences, keep you signed in, and understand usage. See the "Cookies and Analytics" section below.

Communications with us. If you contact support, request a demo, or otherwise communicate with us, we keep records of those communications and their contents.

How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the Services, including running AI agents that text, call, and leave voicemails, qualify leads, and book appointments;
  • Set up and manage your account, including done-for-you A2P 10DLC carrier registration and provisioning of phone numbers;
  • Process subscriptions, the setup fee, and pay-as-you-go usage charges through Stripe, and send billing and transactional messages;
  • Deliver, route, and troubleshoot SMS, calls, and ringless voicemail, and measure delivery and performance;
  • Provide customer support and respond to your requests;
  • Monitor, secure, and improve the Services, develop new features, and analyze usage;
  • Detect, prevent, and address fraud, abuse, security incidents, and technical issues;
  • Comply with legal obligations and enforce our agreements and policies.

We do not use the content of Customer Data for our own independent purposes. We process Customer Data to provide the Services to the customer that supplied it, as instructed by that customer and permitted by our agreement and applicable law.

Legal Bases for Processing

Where data protection laws such as the EU/UK GDPR apply, we rely on one or more of the following legal bases to process personal information:

  • Performance of a contract — to provide the Services you or your organization signed up for;
  • Legitimate interests — to operate, secure, analyze, and improve the Services, provided those interests are not overridden by your rights;
  • Consent — where required, for example for certain cookies, marketing communications, or specific messaging activities (you may withdraw consent at any time);
  • Legal obligation — to comply with laws, regulations, and lawful requests.

For Customer Data that we process as a service provider, our customer is responsible for establishing an appropriate legal basis and valid consent for the contacts in their lists.

SMS Consent and How We Handle Phone Numbers

Business text messaging in the United States is subject to carrier requirements (including A2P 10DLC registration) and to laws such as the Telephone Consumer Protection Act (TCPA) and state "mini-TCPA" laws. Sending marketing or informational texts and calls generally requires valid prior express consent from the recipient.

The customer is responsible for lawful use of the Services. This includes obtaining and maintaining proper consent before messaging or calling any contact, honoring opt-out requests (such as STOP) and help requests (such as HELP), scrubbing against Do-Not-Call lists where required, observing quiet-hours and frequency rules, and complying with TCPA, state mini-TCPA laws, call-recording laws, and any rules that require disclosing the use of AI-generated or automated calls and texts.

Consent collected by our customers is used only to enable the messaging the customer is authorized to send, and mobile opt-in data is not shared with third parties or affiliates for their own marketing purposes.

Opt-outs. When a recipient replies with STOP (or a similar keyword) or otherwise opts out, the platform is designed to record that opt-out and stop further messages of that type. Customers must not override or ignore opt-outs.

Phone numbers we register for A2P 10DLC are used to provision compliant messaging on the customer's behalf. We share registration and campaign details with the platform, telephony and carrier providers, and industry registries as needed to enable and maintain messaging.

Cookies and Analytics

We use cookies and similar technologies that are necessary to run the Services (for example, to keep you signed in), as well as optional cookies that help us understand and improve how the Services are used.

We may use analytics tools to collect usage and device information described above. Depending on your location, you may be asked to consent to non-essential cookies, and you can manage cookies through your browser settings. Some browsers offer a "Do Not Track" or Global Privacy Control signal; where required by law, we honor recognized opt-out preference signals.

Blocking some cookies may affect how the Services function.

How We Share Information

We share personal information only as described below.

Service providers and sub-processors. We use trusted third parties to help us operate the Services, and we share information with them only to the extent needed to perform their functions. These include:

  • Stripe — to process subscription, setup, and usage payments;
  • The HighLevel / LeadConnector platform — the CRM and messaging platform on which the Services are built;
  • Telephony and carrier providers — to deliver and receive SMS, phone calls, and ringless voicemail;
  • Cloud hosting providers — to host and store data and run our infrastructure.

Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or when we believe disclosure is necessary to protect the rights, property, or safety of AI REI, our customers, or others, or to detect and prevent fraud or abuse.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy.

With your direction. We share information with third parties when you or your organization direct us to (for example, integrations you enable).

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We also do not sell or share Customer Data; we process it only to provide the Services.

Data Retention

We keep personal information for as long as needed to provide the Services, maintain your account, comply with our legal and contractual obligations, resolve disputes, and enforce our agreements.

For Customer Data, retention is generally directed by the customer that controls the data. After an account is closed or a customer instructs us to delete data, we delete or de-identify personal information within a reasonable period, except where we are required or permitted to retain it (for example, billing records, or logs kept for security, fraud-prevention, or legal-compliance purposes).

Specific retention periods may vary by data type and legal requirement. [PLACEHOLDER: specify any defined retention periods, and any refund/cancellation-related data handling, if applicable.]

How We Protect Information

We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, use, alteration, and loss. These measures include access controls, encryption in transit, and restricting access to personnel who need it.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for using the Services in a secure manner.

International Users

AI REI is operated from the United States, and our providers may process and store information in the United States and other countries. If you access the Services from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States and other countries whose data protection laws may differ from those in your country.

Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers of personal information.

Your Privacy Rights

Depending on where you live and the role in which we hold your information, you may have some or all of the following rights:

  • Access — to request a copy of the personal information we hold about you;
  • Correction — to ask us to correct inaccurate or incomplete information;
  • Deletion — to request that we delete your personal information;
  • Portability — to receive certain information in a portable format;
  • Opt-out — to opt out of marketing communications, and to opt out of any "sale" or "sharing" of personal information (note: we do not sell or share personal information as those terms are defined under applicable law);
  • Restriction or objection — to limit or object to certain processing;
  • Withdraw consent — where we rely on consent, to withdraw it at any time.

To exercise these rights, contact us using the details below. We will verify your request and respond within the timeframe required by applicable law. You may designate an authorized agent to make a request on your behalf where the law allows. We will not discriminate against you for exercising your privacy rights.

California residents. Under the California Consumer Privacy Act (as amended by the CPRA), California residents have the rights to know, access, correct, and delete personal information, the right to opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under California law. To make a request, use the contact details below.

EEA/UK residents. If you are in the European Economic Area or the United Kingdom, you may exercise the GDPR rights listed above and have the right to lodge a complaint with your local data protection authority.

If you are a seller or lead who received messages from a business using AI REI, that business controls your information. We will forward your request to the relevant customer and assist them in responding, and we will respond directly where the law requires.

Children's Privacy

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under 16 (or the age defined by applicable law). If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate or required by law, provide additional notice. Your continued use of the Services after an update means you accept the revised policy.

Questions, concerns, or privacy requests? Contact us at [PLACEHOLDER: support email] or by mail at [PLACEHOLDER: mailing address]. This policy is governed by the laws of [PLACEHOLDER: governing-law state], without regard to its conflict-of-laws rules.