Privacy Policy
Draft for counsel review. Not yet in effect.
Proferral is operated by Solimark LLC ("Solimark", "we", "us"). This policy explains what information Proferral collects, why, how long we keep it, who we share it with, and the choices you have. It covers proferral.app, app.proferral.app, the Proferral apps, and the email we send.
Proferral serves two kinds of people. Agents are real estate agents and the other professionals who hold a Proferral account. Consumers are the agent's clients and anyone who opens a list, card or link an agent shares. Consumers never need an account.
1. Our role
For agent accounts, billing, and the usage records described in section 4, Solimark decides how the information is used. For the client and referral records an agent keeps in Proferral, the agent decides what goes in and how it is used, and Solimark processes those records on the agent's behalf and on the agent's instructions. We never match or combine one agent's clients with another agent's, and we use client records only to run Proferral for that agent, including the sharing the agent chooses and the anonymous counts described in section 3.
2. Agent accounts and sign-in
When you create an account we collect your name and email address and, depending on what you provide, your photo, city, phone number, postal address, brokerage and office, and real estate license state and number. We record when you created the account and last signed in, how you arrived (for example, the invitation or link you followed), and your trial and plan dates. Your name, photo, brokerage and contact details appear on the lists and cards you share, including in link previews.
Sign in with Google, Microsoft or Apple
If you sign in with Google or Microsoft, we request only your basic identity: an identifier for your account,
your name and your email address (the openid email profile scopes). We do not request access to your
mailbox, contacts, calendar or files, and we do not keep the provider's access tokens.
If you sign in with Apple, Apple gives us an identifier for your Apple account, your email address and, the first time only, the name you choose to share. We use this data only to create and sign you in to your Proferral account. Apple also gives us a token that we store encrypted and use for one purpose: telling Apple to revoke Proferral's access when you delete your account.
If you choose Apple's Hide My Email, we receive a private relay address. We send account email (sign-in codes, inquiries, alerts) to that address, and Apple forwards it to you. We never show a relay address to consumers. You may add a regular email address later, for example for inbound mail or the contact details on your card, but you don't have to. If you stop using Sign in with Apple for Proferral, we end your sessions but keep your account. If you delete your Apple account and your Proferral account has only that sign-in and a relay address, we can no longer reach you, so we begin deleting your Proferral account as described in section 10.
We email the address on your account whenever a sign-in method is linked or your email address changes.
License verification
We check the license details you give us against public state licensing records, either automatically or by a member of our staff. We keep copies of public license rosters (for example Oregon real estate licensees and Oregon and Washington contractors), which include licensees' names, cities and business phone numbers, to verify agents and to show whether a provider's license is current.
3. Client and referral records
Agents use Proferral to keep a record of their clients, the providers they recommend (for example contractors, lenders and inspectors), their notes about those providers, the referrals they make, and how those referrals turned out. A client record can include the client's name, email address, phone number, how the client came to the agent, the area they are moving to, their closing date, and whether they have opted out of the agent's email.
When an agent asks a client how a referral went, we keep the client's answer (hired, not hired, a problem, or not yet) and how the client would like to be named, if at all.
These records belong to the agent who entered them. They stay with that agent whatever plan the agent is on, and we never transfer an agent's client records to a brokerage, an office or another agent. An agent may choose to share particular providers, with the agent's notes about them, with verified colleagues in the same office, and a colleague may copy a shared provider to their own list. An agent may also email a question to those colleagues, who can answer with a provider from their own list. Client details are never shared this way. We also count referral outcomes across verified agents (for example, how many agents have had clients hire a provider) and show office benchmarks; these counts never identify a client or an individual colleague.
If you are a client and want to access, correct or delete what an agent holds about you, contact that agent; you may also write to us and we will pass your request on and help the agent respond.
When an agent adds a provider, Google Places suggests matching businesses as the agent types. We store only Google's place identifier; the provider's name and contact details are the ones the agent confirms or enters.
Invitations
When an agent invites a colleague, we store a one-way keyed hash of the invited email address, not the address itself, to limit how often the same person is invited. If an invitee opts out, we keep the hash on a suppression list so they are not invited again. Both are kept after the inviting agent deletes their account.
4. Lists, cards, the device cookie and usage beacons
An agent can give each client a link to the agent's go-to list, and clients can forward a provider's card to others. Opening a list or card does not require an account. To tell the agent whether their list is being used, the page reports a small set of events after it loads: a list or card was opened, a contact button was tapped, a card was forwarded, a contact was saved, the list was opened from a home screen, or the "make your own list" button was tapped. These events record what happened, when, and which link, card or recommendation it was about. They do not record your name, your contact details or your IP address, and nothing that identifies the person who forwarded a card is stored. A link an agent made for one client is tied to that client's record, so events on that link relate to that client.
On list, card, check-in, invitation and unsubscribe pages we set a cookie, pfd. It holds a random
identifier, lasts 400 days, and lets us count repeat visits from the same device instead of counting them as new
people. These pages also set pf_src, which records the list, card or invitation that brought you, so
that if you later create an account we know how you arrived. Pages with a form set a security cookie that
protects the form from forgery. None of these cookies is used for advertising or shared with anyone. Our servers
process your IP address to deliver pages and to limit abuse, but it is not kept in these event records.
Signed-in agents also have a session cookie, which is necessary for the service to work and lasts 90 days from last use. Our website stores your light or dark theme choice in your browser; it never leaves your device.
Global Privacy Control
If your browser sends a Global Privacy Control signal (Sec-GPC: 1), we do not set the
pfd cookie, and the events from your visit are recorded without any device identifier.
[Counsel and engineering to confirm whether pf_src is also withheld under GPC.]
5. Consumer inquiries
A list or card may let you ask the agent a question. The form tells you, for example, "Jane will keep your name and email" before you send it. If you send it, we deliver your name, email or phone number, your message, and who referred you to the agent by email, with replies going straight back to you. We keep the inquiry and record which version of that notice you saw. The agent may then add you as a client, and the record becomes part of the agent's client records described in section 3. If the agent is on Proferral Pro, you may receive an automatic acknowledgement, labeled as automatic.
If you are moving, an agent may share a partner agent's list for your new area. If you ask to be introduced, your details go to the partner agent, who receives you as a client, and your original agent is told that you asked. Your original agent's record about you is not copied to the partner.
Your contact details reach an agent only when you send an inquiry or ask for an introduction. We do not sell them, and we do not pass them to any provider.
6. Inbound mail (BCC)
Each agent gets a private address at log.proferral.app. When the agent copies (BCCs) that address
on an email, or forwards an email thread to it, we receive the whole message, including what other people wrote
in a forwarded thread. We scan it for spam and viruses, check that it came from the agent's
own account address, and compare its recipients with the agent's own clients and providers so the agent doesn't
have to log the referral by hand. We store the raw message for 30 days and then delete it. We keep a record of
what we did with each message (for example, that a referral was logged, or that the message was rejected and
why).
7. Email we send
Proferral email comes from notify.proferral.app, is sent by Proferral, and is always
labeled as automated. It includes sign-in and verification codes, inquiries, alerts, digests, monthly reports and
account notices such as the deletion confirmation.
Pro email comes from pro.proferral.app and is sent in an agent's name to the
agent's clients and to providers the agent thanks. We send only messages the agent has drafted or reviewed and
approved. Nothing reaches a client or provider in an agent's name unless the agent sent it. Every Pro email has
an unsubscribe link and the agent's postal address. A client who unsubscribes gets no more such email from that
agent. Replies go to the agent.
We keep the delivery record of each email we send for 30 days after delivery succeeds or fails, then delete it. The drafts of Pro email, including their text, are part of the agent's records and are kept as section 9 describes.
8. Payments
Paid plans are billed through Stripe. Stripe collects your card details directly; we never see or store your full card number. We receive your subscription status, plan, billing interval and renewal date from Stripe; your invoices stay in Stripe's billing portal. Deleting your account cancels any subscription immediately.
9. How long we keep information
| Information | How long |
|---|---|
| Usage events (section 4) | 25 months |
| Raw inbound BCC messages | 30 days |
| Invitation hashes and the invitation suppression list | Kept after the inviting agent's account is deleted, so an opt-out keeps working |
| Delivery records of email we sent | 30 days after delivery succeeds or fails |
pfd device cookie | 400 days in your browser |
| Session cookie | 90 days from last use |
| Account, client and referral records, inquiries, check-in answers and Pro drafts | Until the agent deletes them or deletes the account, then purged 30 days after deletion (section 10) |
| Database backups | 7 days, so deleted information can remain in a backup for up to 7 days after it is purged |
10. Export and account deletion
Export. An agent can download their own clients, referrals, recommendations, inquiries and check-ins at any time as CSV files in a ZIP archive. For security we ask you to have signed in within the last 24 hours or to enter a code we email you.
Deletion. An agent can delete their account in Settings. Deletion takes effect immediately from the agent's point of view: the agent's links stop working, any subscription is cancelled, Sign in with Apple access is revoked, and we email a confirmation with the date the data will be purged. Thirty days later we purge the account and the agent's client and referral records. A small number of records that other people's data depends on are kept with all personal information removed, for example a placeholder showing "Deleted agent" and a provider recommendation with the note and contact details erased.
11. Who we share information with
We do not sell personal information, we do not share it for advertising, and we do not show ads. We share it only with the service providers below, who process it for us under contract, and when the law requires it.
| Service provider | What for |
|---|---|
| Amazon Web Services (including Amazon SES) | Hosting, database, file storage and sending and receiving email, in the United States |
| Stripe | Subscription billing and tax |
| Google (Places) | Suggesting provider businesses while an agent types |
| Google, Microsoft and Apple | Sign-in, when you choose that method |
| Microsoft 365 | Our own mailbox, including mail you send to hello@proferral.app |
| Zapier | Only if an agent connects Zapier: sending that agent's chosen events to the agent's own Zapier account |
If Solimark is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, subject to this policy.
12. No paid placement, no referral rewards
Providers cannot pay to appear on an agent's list or to be ranked higher, and a list's order never depends on any plan. Proferral does not pay or reward anyone, agent or consumer, for making or receiving a referral, and we do not collect information for that purpose.
13. Your choices and rights
Agents can see, correct, export and delete their information in the app. Anyone can ask us to access, correct or delete personal information we hold about them, or to stop processing it, by writing to hello@proferral.app. We will verify the request and answer it within the time the law allows, and we will not treat you differently for making it. If you are an agent's client, see section 3. Depending on where you live (for example California or Oregon), you may have additional rights under state law, including the right to appeal a decision we make about your request by replying to our answer.
14. Security
We encrypt information in transit, keep each agent's records separate from every other agent's, store sign-in codes and API keys only as one-way hashes, encrypt the Apple token described in section 2 and our database, and limit staff access to what is needed to run the service. No system is perfectly secure; if a breach affects your information we will notify you as the law requires.
15. Children
Proferral is for adults. We do not knowingly collect information from children under 13.
16. Changes
If we change this policy, we will post the new version here with a new effective date. If a change is material, or adds a new kind of information we collect, we will email agents before it takes effect.
17. Contact
Solimark LLC, [postal address], hello@proferral.app.