Introduction
Galleon Technologies, Inc., a Delaware corporation ("Galleon," "we," "us," or "our"), operates Operator, a portfolio intelligence platform for real estate investors. This Privacy Policy explains our practices regarding the collection, use, and disclosure of information we receive through our website at galleon.io, our mobile application, and all related services (collectively, the "Services").
This Privacy Policy does not apply to any third-party websites, services, or applications, even if they are accessible through the Services.
PLEASE READ THIS PRIVACY POLICY AND THE TERMS OF USE CAREFULLY. IF YOU DO NOT AGREE WITH THE PROVISIONS OF THIS PRIVACY POLICY OR THE TERMS OF USE, DO NOT USE THE SERVICES. BY USING THE SERVICES, YOU AGREE TO THIS PRIVACY POLICY.
Revisions to This Privacy Policy
Information we collect is covered by the Privacy Policy in effect at the time of collection. We may revise this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy within the Services or by sending you an email, and we will update the "Last Updated" date above. Your continued use of the Services after changes become effective constitutes acceptance of the revised Policy.
Scope
This Privacy Policy applies to all users of the Services, including site visitors and account holders across all subscription tiers (Free, Awareness at $25/month, and Foresight at $40/month). Users must be 18 years of age or older. We do not knowingly collect information from individuals under 18. If you believe we have inadvertently received information from a minor, please contact us at info@galleon.io and we will delete it promptly.
Information We Collect
Information You Provide Directly
Account Information. When you create an account (including through third-party authentication services), we collect your name and email address.
Portfolio Data. When you use Operator to build or manage your portfolio, we collect: property addresses and descriptions; deal details including purchase price, financing terms, rental income, and operating expenses; portfolio valuation data and transaction history; notes and custom data you add to properties or deals.
Buy Box Criteria. When you use buy box monitoring (Foresight Tier, $40/month), we collect the acquisition criteria you define, including target price range, property type, geographic filters, and any additional screening parameters you configure. This criteria is transmitted to third-party MLS proxy providers to surface matching listings. See the Buy Box Monitoring section below for detail.
Profile Information. You may optionally provide additional profile information including a username, location, or short bio.
Communications. When you contact us for support or with feedback, we collect your name, email address, and the content of your communication.
Payment Information. Subscription payments are processed by Stripe, Inc. We do not retain credit card numbers or personally identifiable financial information. Payment processing is governed by Stripe's privacy policy at stripe.com/privacy.
Information Collected Automatically
Device and Technical Information. When you use the Services, we may collect: IP address, user agent information, network and connectivity information, device identifiers, language preferences, and software and operating system information.
Location Information. We may derive a general geographic location from your IP address. We do not collect precise GPS location data unless you explicitly enable location services.
Cookies and Web Technologies. We use cookies, web beacons, and similar technologies for: Necessary Cookies (user authentication and account security); Performance Cookies (site traffic and usage analysis); Preference Cookies (storing your settings and preferences); Analytics Cookies (usage tracking via services including Google Analytics). You may refuse cookies through your browser settings, though some features may not function properly if you do.
Interaction Data. We collect information about actions you take while logged in, such as which calculators you use, which properties you view, and how you navigate the product.
How We Use Your Information
We use the information we collect for:
- Providing the Services: delivering portfolio management, rent comp monitoring, financing calculators, buy box monitoring, lender-ready PDF exports, and customer support
- Account Administration: creating and maintaining your account, verifying identity, and ensuring account security
- Payments: processing subscriptions and billing
- Product Improvement: understanding usage patterns, identifying bugs, and improving features through aggregated, de-identified analysis
- Communications: sending product updates, billing information, and security alerts. You may opt out of promotional emails but cannot opt out of essential account communications
- Legal Compliance: enforcing our Terms of Use, responding to valid legal requests, and detecting fraud
- Fraud Prevention: detecting unauthorized activity and protecting account and platform security
Third-Party Data Providers
Operator integrates with third-party data providers to deliver core product functionality. The following providers may receive property-level information as described:
Property Valuation and Attribute Data. REAPI: receives property addresses to return real estate valuation and comparable sales data. BatchData: receives property addresses to return property attribute data.
Rent Comparable Data. Rentometer: receives property addresses to return rent comparable data by bedroom count and location. RentRange: receives property addresses to return rent comparable data by bedroom count and location. Rent comp monitoring is available only to subscribers on the Awareness Tier ($25/month) or above.
Important: We do not share your financial calculations, deal analysis, scenario modeling, notes, or personal investment strategy with any of the above data providers. These providers receive only the property address or identifier necessary to return the requested data point. Each provider's own privacy policy governs their data retention and use practices.
Buy Box Monitoring and MLS Proxy Providers
Buy box monitoring is available exclusively to subscribers on the Foresight Tier ($40/month). When this feature is active, Operator transmits your full buy box criteria, including target price range, property type, geographic filters, and any additional parameters you configure, to third-party MLS proxy providers in order to surface matching property listings.
The following applies:
- Your buy box criteria are transmitted only for the purpose of returning matching listings. They are not used for advertising, profiling, or any purpose other than executing the search on your behalf.
- We do not name individual MLS proxy providers in this policy because our provider relationships may change as the feature matures. We will update this section when a specific provider is designated as a long-term partner.
- MLS proxy providers are contractually prohibited from retaining your buy box criteria beyond the time necessary to execute the search and return results.
- Disabling buy box monitoring in your account settings immediately stops transmission of your criteria to MLS proxy providers.
Information You Should Not Store in Operator
Operator will not prevent you from uploading certain types of sensitive information, but we strongly advise against storing the following in the Services: bank account passwords or login credentials; Social Security numbers or tax identification numbers; tenant personally identifiable information such as names, email addresses, or phone numbers; sensitive personal documents such as divorce decrees or wills.
These data types fall outside Operator's core functionality, create unnecessary security risk, and are not encrypted differently than other data. All data receives the same encryption protection regardless of sensitivity.
Product Analytics and De-Identified Data
We analyze usage data in aggregate, de-identified form to understand and improve the product. Examples: average deal metrics by geography; popular calculator features and usage patterns; portfolio size distribution across the user base; market trends visible across aggregated, anonymized portfolios.
De-identification standard: we strip your name, email address, account ID, and all personal identifiers before any analysis. We aggregate across a minimum of 5 to 10 users per data point and do not report on small cohorts that could identify you. Individual deal details and property addresses are never included in aggregate analytics.
We do not sell your data to third parties. We do not share your portfolio with competitors, investors, or researchers. We do not use your data for targeted advertising or marketing. We do not license our analytics to any real estate platform. We do not feed individual user portfolios into any external algorithm or model.
Planned Features
The following features are part of our product roadmap but are not yet available. This policy will be updated, with notice, before each feature launches.
Tax Export (Schedule E)
We plan to offer Schedule E export functionality in a future release. When available, exports will be generated from your Portfolio Data. Once you download an export, it becomes your document. Operator's responsibility ends at the point of download. You and your tax professional are responsible for review, accuracy, and filing. Errors in your inputs will produce errors in exports. We are not liable for tax penalties, interest, or audit exposure resulting from exported data.
Document Storage
We plan to add the ability to store property photos, mortgage documents, repair receipts, and other deal-related files in a future release. When available, documents will be encrypted at rest (AES-256) on AWS US East infrastructure and will not be shared with data processors unless you explicitly export them. We will not scan document content for analytics purposes.
Professional Partner Access
We plan to allow CPAs and accountants to access client portfolios directly via Operator in a future release, with permission controls and access logging. When this feature launches, Professional Partners will be required to sign a separate Data Processing Addendum covering confidentiality obligations, data handling requirements, audit trail commitments, and indemnification. You will retain full control over Professional Partner permissions and will be able to revoke access at any time.
Data Storage and Security
All Operator data is stored on Amazon Web Services (AWS) US East (N. Virginia) data centers. Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Backups are stored in geographically redundant AWS facilities within the United States. We do not transfer data outside the US for processing.
We implement reasonable administrative, physical, and electronic measures to protect information from unauthorized access, use, or disclosure, including restricted server access with logging and two-factor authentication for critical systems.
No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. If we discover a security breach affecting your information, we will notify you by email or by posting a notice within the Services.
Data Retention
Active Accounts (All Tiers)
Portfolio Data is retained for the duration of your account regardless of subscription tier. The free tier is a permanent product offering, not a trial, and free tier accounts are treated the same as paid accounts for data retention purposes.
Inactivity: if your account has no login activity for 24 consecutive months, we will send a warning notification to your registered email address. If you do not log in within 60 days of that notice, we may delete your account and all associated Portfolio Data. You can prevent deletion by logging in at any time before the 60-day window closes.
Cancelled Paid Subscriptions
When you cancel a paid subscription and downgrade to the free tier, your Portfolio Data is retained under free tier terms (indefinitely, subject to the inactivity policy above). If you close your account entirely, your data is retained for 90 days from the date of account closure, during which you may download a complete export of your Portfolio Data in CSV format. After 90 days, all Portfolio Data is permanently deleted.
Account Deletion Requests
You may request immediate account deletion at any time through Settings or by contacting info@galleon.io. Upon deletion: Live Portfolio Data is deleted immediately; backup copies are retained for 30 days, then permanently purged; you have 30 days following deletion to contact us for data recovery (restoration is not guaranteed).
Fraud and Security Holds
If your account is disabled for fraud or security reasons, we may retain account information indefinitely to prevent future abuse, even if you are an active subscriber.
Data Portability
You may export your complete portfolio (properties, deals, and calculations) at any time in portable CSV format through your account settings. This allows you to migrate to another platform if desired. Exports do not include access logs or system metadata.
Information Shared with Third Parties
We share your information with third parties only in the following circumstances:
- Service Providers. We engage third-party service providers including cloud hosting (AWS), payment processing (Stripe), analytics services, and customer support partners. These providers have access to your information only to perform services on our behalf and are contractually prohibited from using it for other purposes.
- Data Providers. We share property addresses with REAPI, BatchData, Rentometer, and RentRange as described in the Third-Party Data Providers section. We share buy box criteria with MLS proxy providers as described in the Buy Box Monitoring section.
- At Your Request. We may share your information when you explicitly request it, such as when you export Portfolio Data for a CPA or advisor.
- Aggregated and De-Identified Data. We may share de-identified, aggregated data derived from use of the Services. This data is not tied to your identity.
- Business Transactions. If Galleon is acquired, merged, or subject to a sale of assets, your Personal Data may be transferred to the acquiring party. We will provide notice before your data becomes subject to a different privacy policy.
- Legal Requirements. We may disclose information to government or law enforcement officials if required by law or in response to valid legal process, including subpoenas and court orders.
- Protection of Rights. We may disclose information to protect our property, rights, and safety or those of third parties, including to detect fraud, investigate Terms violations, and address security issues.
We do not share your data with marketing partners, advertising networks, data brokers, competitors, or third-party researchers.
Your Choices
Email Communications
We send product updates, billing information, and security alerts. You may opt out of promotional emails through your account settings or by following the unsubscribe instructions in any promotional email. You cannot opt out of essential account communications including billing notices, Terms updates, and security alerts.
Cookies
You may opt out of non-essential cookies by configuring your browser settings or using cookie-blocking browser extensions. Opting out of necessary cookies may impair core product functionality.
Modifying Your Information
You may access and update the Personal Data associated with your account by logging in. To request deletion of your Personal Data or your account, contact us at info@galleon.io.
Your Privacy Rights
Depending on the laws applicable in your jurisdiction, you may have the following rights with respect to your Personal Data: Access; Correction; Deletion; Portability; Objection; Withdraw Consent. To exercise any of these rights, contact us at info@galleon.io. We will respond within the timeframe required by applicable law.
California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA): Right to Know; Right to Know What We Share (we do not sell your Personal Data); Right to Opt Out of Sale (we do not sell; if we ever do, we will provide a method to opt out); Right to Delete; Non-Discrimination. You may submit two free requests within any 12-month period. We will respond within 45 days, extendable to 90 days if necessary. To make a CCPA request, contact us at info@galleon.io and state that you are a California resident. We will verify your identity before processing the request.
Links to Third-Party Sites
The Services may contain links to third-party websites and services we do not own or control. We are not responsible for the content, privacy policies, or practices of any third-party sites. We encourage you to review the privacy policies of any third-party services you access through the Services.
Processing in the United States
We are headquartered in the United States. Your Personal Data is processed and stored on servers located in the US East (N. Virginia) AWS data centers. By using the Services, you consent to the transfer of your information to the United States. We implement security measures consistent with applicable law to protect your data from unauthorized access or disclosure.
Contact Us
If you have questions about your Personal Data, our data practices, or this Privacy Policy, please contact us at:
Galleon Technologies, Inc.
697 3rd Ave., Suite #222
New York, NY 10017
info@galleon.io