Privacy Policy
Effective July 31, 2026 · Last updated July 31, 2026
The short version.
- We do not sell your personal information, and never have.
- We do not use your workspace data to train AI models.
- We never see or store your full card number — Stripe handles payments.
- Your workspace is visible only to people you invite.
- You can export or delete everything, at any time.
The sections below are the complete, binding version.
1. Who we are and what this covers
Fox Valley Digital LLC ("Fox Valley Digital," "we," "us") operates TrackMyFlip at trackmyflip.com. This policy explains what personal information we collect, why, who we share it with, and the choices you have. It applies to the TrackMyFlip website and application, on both free and paid plans.
For information you put into your workspace about other people — sellers, buyers, tenants, contractors, partners — you are the controller of that data and we process it on your behalf under our Terms of Service. You are responsible for having a lawful basis to collect and store it.
2. Information we collect
Information you give us. Your name, email address and password when you register (the password is stored only as a salted hash — we cannot read it). Optionally your business name, job title, phone number, business focus and deal volume.
Workspace content. Everything you create in the product: properties and addresses, leads and their contact details, deals and financial assumptions, budgets, expenses, uploaded receipts and photographs, rehab estimates, tasks, appointments, notes, documents and vendor or contractor records.
Payment information. If you subscribe, Stripe collects and processes your card details directly. We never receive your full card number, CVC or bank credentials. We store only a Stripe customer reference, subscription identifier, plan, status and renewal date, plus the billing name and email you provide.
Technical information. A session token in a cookie, plus the IP address, browser and device signature associated with a sign-in, and server logs of requests (including timestamps, paths and error details) used to operate, secure and debug the Service.
Support communications. The contents of emails or messages you send us.
We do not intentionally collect government identifiers, health information, biometric data or other special-category data. Please do not upload it.
3. How we use information, and our legal bases
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Provide the Service, render your workspace, generate reports | Performance of a contract |
| Authenticate you and keep accounts secure | Contract; legitimate interests (security) |
| Process subscriptions, billing and invoices | Contract; legal obligation (tax records) |
| Run an AI feature you invoke on the input you submit | Contract (you requested it) |
| Diagnose faults, prevent abuse, enforce limits | Legitimate interests (service integrity) |
| Respond to support requests | Contract; legitimate interests |
| Send service and billing notices | Contract; legal obligation |
| Send product or marketing email | Consent — withdrawable at any time |
| Comply with law and defend legal claims | Legal obligation; legitimate interests |
We do not sell your personal information, share it for cross-context behavioural advertising, use your workspace data to advertise to you, or use it to train third-party or general-purpose AI models.
4. AI features
When you invoke an AI feature — the deal analyzer, rehab estimator, receipt scanner or copilot chat — the specific text or image you submit for that request is sent to an AI model provider to produce the result, and the result is returned to you. Only the input for that request is sent; we do not bulk-transmit your workspace.
When no AI provider is configured, or the provider is unavailable, these features fall back to a deterministic calculation engine that runs on our own servers and sends nothing externally. Replies produced this way are labelled in the product.
Do not submit information to AI features that you are not permitted to disclose to a third-party processor.
5. Cookies and similar technologies
We use a single strictly-necessary cookie, tmf_session, which holds an opaque session token so you stay signed in. It is HTTP-only, restricted to same-site requests, and marked Secure in production. It expires after 30 days or when you sign out.
We also use your browser's local storage for interface preferences such as theme and recent searches. That data stays on your device.
We do not use advertising cookies, third-party analytics trackers, or cross-site tracking pixels, which is why you are not shown a cookie consent banner. Because we do not track across sites, we do not respond differently to Do Not Track signals.
6. Who we share information with
Inside your workspace. Your content is visible to members of your workspace. The owner controls membership and can view, export or delete workspace content. If you share a report or portal link with a lender, investor or partner, you control who receives it.
Service providers (subprocessors). We use a small number of vendors to run the Service. They may process data only on our instructions and under confidentiality obligations:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Managed PostgreSQL database — stores all workspace content | United States |
| Vercel | Application hosting, edge network and request logging | United States / global edge |
| Stripe | Payment processing, subscription billing and invoicing | United States |
| AI model provider | Processes the specific text or image you submit to an AI feature (deal analysis, rehab estimates, receipt scanning) | United States |
Legal and safety. We may disclose information if required by law, subpoena or court order, or where we believe in good faith that disclosure is necessary to protect rights, safety, or the integrity of the Service. Where lawful, we will try to notify you first.
Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction. We will give notice before your information becomes subject to a materially different policy.
7. The public demo workspace
The demonstration workspace is shared by all visitors and contains fictional sample data. Anything entered there is visible to other visitors and may be reset or deleted at any time. Do not put real, personal or confidential information into the demo.
8. Retention
We keep workspace content for as long as your account is active. When you delete an item it is removed from your workspace; when you delete your account we delete your workspace content within 30 days, except where we must keep records longer — for example, billing and tax records, which we retain for up to seven years, and limited security logs, retained up to 12 months.
Residual copies may persist in encrypted backups for a limited period before being overwritten on the normal backup cycle.
9. Security
We protect the Service with measures including TLS encryption in transit, salted and computationally-hardened password hashing, HTTP-only session cookies, server-side authorization checks that scope every request to your workspace, rate limiting on authentication endpoints, and a restrictive content-security policy. Payment card data is handled entirely by Stripe, a PCI-DSS Level 1 provider.
No system is perfectly secure, and we cannot guarantee absolute security. Please use a strong, unique password. If you believe you have found a vulnerability, report it to security@trackmyflip.com — we welcome good-faith reports and will not pursue researchers who act responsibly.
10. Your rights and choices
You can view and correct most of your information directly in the product, export your data, and delete your workspace from Settings. You can unsubscribe from marketing email at any time; we will still send essential service and billing notices.
Depending on where you live you may also have the right to: access the personal information we hold; correct inaccuracies; request deletion; request a portable copy; object to or restrict certain processing; withdraw consent; and not be discriminated against for exercising these rights.
California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. We collect the categories described in section 2 for the business purposes in section 3.
UK/EU residents. Our legal bases are in section 3. You have the right to lodge a complaint with your local supervisory authority.
To exercise any right, email privacy@trackmyflip.com from your account address. We respond within 30 days (45 days for CCPA requests where an extension is permitted). We may need to verify your identity first.
11. International transfers
We operate from the United States and our providers store data in the United States. If you access the Service from outside the U.S., your information is transferred to and processed there, where data-protection law may differ from your own. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
12. Children's privacy
The Service is intended for business use by adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@trackmyflip.com and we will delete it.
13. Changes to this policy
We may update this policy as the product evolves. If a change is material we will give reasonable notice by email or in-product notice before it takes effect, and we will always update the effective date above.
14. Contact
Fox Valley Digital LLC
Wisconsin, United States
Privacy: privacy@trackmyflip.com
Security: security@trackmyflip.com