Privacy Policy

Effective: 9 May 2026CCPA / state-privacy conscious

Two kinds of people show up in this policy: customers (you, the wholesaler running your account) and property-record subjects (the owners of parcels surfaced in our data). We treat them differently because the data sources are different. Read §02 and §03 together.

01What this covers

This policy describes how terminal.house, LLC (“we”) collects, uses, and shares information when you use the website at terminal.house, the API at api.terminal.house, and the MCP server at mcp.terminal.house.

02What we collect from customers

  • Account data: name, email, password hash (via Clerk), profile photo if uploaded.
  • Billing data: handled by Stripe. We see card brand and last-four; we never see the full number.
  • Usage data: API calls, MCP tool calls, watchlist fires, lead-views consumed, feedback you submit on leads.
  • Device & log data: IP, user-agent, request timestamps. Retained 30 days for security and abuse detection.
  • Support comms: emails to support@, sales@, security@.

03Public-records subjects

terminal.house surfaces parcel and ownership information from publicly available government records: county property appraisers, code compliance, clerks of court, tax collectors, and state business-entity registries. This is information already published by government agencies. We index, normalize, and score it; we don't enrich it with any third-party identity, skip-trace, or contact data.

If you're a property-record subject who wants your information removed from terminal.house: email privacy@terminal.house with the parcel folio and proof of ownership. We will suppress the record from our public discovery surface within 7 days. We cannot remove the upstream public record — that lives at the originating county, not with us.

04How we use it

  • Provide the service: serve your queries, fire your webhooks, run your watchlists.
  • Bill you under your tier and notify you of usage.
  • Improve scoring and signal quality using aggregate, de-identified usage patterns and your explicit feedback. We don't train scoring on your private notes or pipeline tags.
  • Detect and prevent abuse, fraud, and TCPA violations originating from our platform.
  • Send transactional emails (trial expiry, billing, system status). Marketing email is opt-out at any time.

05Sharing & sale

We don't sell your customer data. We don't share it with advertisers. We share with sub-processors that operate parts of the service, all bound by data-protection terms:

  • Clerk — authentication and session management
  • Stripe — payment processing
  • Vercel — hosting and edge delivery
  • AWS — primary database, object storage
  • Resend — transactional email delivery

We may disclose information if compelled by valid legal process. We will challenge overbroad requests and notify you when legally permitted.

06Retention

  • Active accounts: data retained for the life of your subscription.
  • Account-paused: data preserved 90 days after cancellation, then permanently deleted (matches §07 of Terms).
  • Logs: 30 days, then aggregated and stripped of identifiers.
  • Backups: rolling 35 days. Deletion requests honored against backups within 90 days.

07Your rights

Under applicable state privacy laws (e.g. CCPA), you can request:

  • Access — a copy of the personal information we hold about you
  • Correction — fix inaccurate account data
  • Deletion — wipe your account; subject to legal retention obligations
  • Portability — your watchlists, feedback log, and exports as JSON or CSV
  • Opt-out of “sale” or “share” — already in effect by default; we don't sell or share for cross-context advertising

Email privacy@terminal.house. We respond within 30 days. We will verify your identity before fulfilling sensitive requests.

08Cookies & analytics

We use essential cookies for authentication and session management. We use privacy-respecting analytics (Plausible) on the marketing site — no IP retention, no cross-site tracking, no ad-tech. We don't run third-party advertising scripts. There's no tracking pixel on our outbound emails.

09Children

terminal.house is not directed to children under 18. We don't knowingly collect personal information from children. If you believe we have, email privacy@terminal.house and we'll delete it.

10International

terminal.house is operated from the United States. Data is stored in US-East AWS regions. If you access the service from outside the US, you consent to transfer of your information to the United States, where data-protection laws may differ from your jurisdiction.

11Changes to this policy

We may update this policy. Material changes get at least 30 days notice via email and an in-product banner. The “Last updated” date at the top of this page reflects the most recent revision.

12Contact

Privacy requests: privacy@terminal.house. Security: security@terminal.house. Legal / mailing address available on request via legal@terminal.house.