Privacy Policy — XCreOS

1. Who we are

XCreOS ("XCreOS", "we", "us", "our") is operated by [LEGAL ENTITY NAME], located at [BUSINESS ADDRESS]. We provide a web-based platform that helps multifamily real estate operators source, underwrite, operate, and dispose of deals ("the Service"), available at xcreos.com and its subdomains.

This Privacy Policy explains what information we collect, why, how we use and share it, and the choices you have. It applies to visitors of our website and users of the Service.

2. Information we collect

You give us: - Account data — name, work email, company name, password (stored hashed), and role. - Billing data — for paid plans, your billing name and contact details. Card numbers are collected and stored by Stripe, our payment processor — we never see or store full card numbers. - Deal data you input — the property, financial, and underwriting information you enter or upload (rent rolls, T-12s, assumptions, notes). This is your content; we process it only to provide the Service to you. - Communications — messages you send us (support, email, forms).

We collect automatically: - Usage data — pages and features used, actions taken, timestamps, and similar product-analytics events. - Device & log data — IP address, browser type, device, and access logs. - Cookies & similar technologies — see our Cookie Notice.

We do not intentionally collect special-category data and ask that you not enter it into deal fields.

3. How we use your information

  • Provide, operate, and secure the Service.
  • Create and manage your account; authenticate you.
  • Process payments and send billing notices (paid plans).
  • Provide support and respond to requests.
  • Understand and improve product usage (analytics).
  • Send service and transactional messages; send marketing messages only where permitted, with an unsubscribe in every marketing email.
  • Detect, prevent, and address fraud, abuse, and security issues.
  • Comply with legal obligations.

4. Legal bases (EEA/UK users)

Where GDPR/UK GDPR applies, we rely on: contract (to provide the Service you signed up for), legitimate interests (to secure and improve the Service), consent (for non-essential cookies and marketing where required), and legal obligation.

5. How we share information — sub-processors

We do not sell your personal information. We share it only with vendors that process data on our behalf to run the Service, each bound by contract to protect it:

Sub-processor Purpose Data involved
Stripe Payments & billing Billing contact; card data handled directly by Stripe
GoHighLevel CRM, email/SMS, scheduling Name, email, phone, communications
PostHog Product analytics Usage events, device/IP
Google (GA4 + Workspace) Web analytics & email Usage data; email content
Vercel Application hosting IP, server logs
Resend (if/when enabled for transactional email) Transactional email delivery Email address, message content

This list is kept current. If we add a vendor that processes personal data, we update this table. We may also disclose information to comply with law, enforce our Terms, or protect rights and safety, and in connection with a merger or acquisition (with notice).

6. Data retention

We keep account and deal data for as long as your account is active, then delete or anonymize it within a reasonable period after closure, except where we must retain records to meet legal, tax, or security obligations. You can request earlier deletion (Section 8).

7. Security

We use industry-standard safeguards — encryption in transit (TLS), access controls, and hosting on reputable infrastructure. No method of transmission or storage is 100% secure, but we work to protect your information and to notify you of material breaches as required by law.

8. Your rights & choices

Depending on where you live (e.g. GDPR/UK, CCPA/CPRA), you may have the right to access, correct, delete, export (portability), or restrict/object to processing, and to opt out of sale/sharing (we do not sell). To exercise any right, email [email protected]. We will verify and respond within the timeframe required by law. You may also unsubscribe from marketing at any time via the link in those emails. You will not be discriminated against for exercising your rights.

9. International transfers

We are based in the United States and may process data there and in other countries where our sub-processors operate. Where required, we use appropriate transfer mechanisms (e.g. Standard Contractual Clauses).

10. Children

The Service is for business users and is not directed to anyone under 18. We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy. Material changes will be posted here with a new effective date and, where appropriate, notified to you. Continued use after changes means you accept the updated policy.

12. Contact

Questions or requests: [email protected] · [LEGAL ENTITY NAME], [BUSINESS ADDRESS].