Lease Lineage

Legal

Privacy Policy

Last updated: September 4, 2026

What we collect

When you register, we collect your identity, contact, brokerage or company information, and the market and property preferences you provide. When you connect Gmail or Outlook, we encrypt OAuth tokens. Gmail uses send-only access to deliver outreach. Outlook also uses mailbox-read permission to identify campaign replies and stop follow-ups. We do not import or retain your general mailbox.

When you request CRE outreach updates or subscribe to educational and product emails, we collect your first name, email address, broker practice, asset class, signup source, and the consent you provide. Klaviyo processes that subscription and sends the double-opt-in confirmation. You are not added to the marketing list unless you confirm.

Prospect search, enrichment, and verification requests pass through Treg, our managed provider gateway, to Apollo.io, Hunter.io, or another contact-data provider selected for the request. The request may include names, company domains, titles, or email addresses needed to provide the feature. For usage and cost tracking, we send Treg internal customer and workspace identifiers plus a feature label as separate metadata; that usage metadata does not include email addresses. We may cache discovered contacts in our database to avoid redundant provider calls.

When you use AI features, the prompt, relevant account context, and requested source material may be processed by our AI service providers. Reply signals and limited reply context may be stored in your deal pipeline.

How we use your data

  • To operate the platform: send outreach campaigns, track opens/clicks/replies, and manage your prospect pipeline.
  • To improve the product: aggregate usage metrics (no personal data shared).
  • To notify you: campaign activity, new inbound inquiries, and platform updates.
  • To send requested resources and educational or product emails after you explicitly subscribe and confirm.

We do not sell your data. We do not share contact data with other brokers.

Google account and Gmail data

When you choose to connect Gmail, LeaseLineage requests your primary Google Account email address and permission to send campaign messages that you approve through LeaseLineage. Gmail access is send-only.

LeaseLineage does not read or search your Gmail inbox or Sent mail, automatically detect Gmail replies, or retrieve Gmail reply previews. Read and answer replies in Gmail and pause remaining campaign follow-ups yourself. Previously connected users must reconnect to replace the earlier read-access grant.

We encrypt Google OAuth access and refresh tokens at rest. We store the connected email address, granted scopes, token-expiration information, message and thread identifiers returned when sending, and campaign delivery events as needed to provide and secure sending. Historical campaign reply records from the earlier integration remain subject to the retention and deletion terms below.

Google user data is not sold, used for advertising, or transferred to data brokers. It is processed only by LeaseLineage and infrastructure providers acting on our behalf as necessary to provide or secure the connected-inbox feature, comply with law, or respond to a user-directed support request. Humans do not read Google user data except with the user's affirmative agreement for support, when required for security or abuse investigation, or when required by law.

You can revoke LeaseLineage's Gmail access at any time from the Connected inbox section of Account settings. Disconnecting Gmail revokes the Google authorization and deletes the stored mailbox connection and tokens. Campaign event metadata remains with your account until it is deleted or otherwise removed under the retention terms below.

LeaseLineage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Email outreach & CAN-SPAM compliance

All outbound emails sent through LeaseLineage include an unsubscribe link. We honor unsubscribe requests immediately and permanently suppress those addresses. Brokers are responsible for ensuring their outreach complies with CAN-SPAM, GDPR, and any applicable local regulations.

Data retention

Your account data is retained while your account is active. Pseudonymous provider-usage and billing audit records may be retained after account deletion as needed to reconcile costs, detect abuse, and meet accounting or legal obligations; Treg usage metadata does not contain contact email addresses. Marketing subscriber data is retained while you remain subscribed and as needed to document consent or honor an opt-out. You may unsubscribe from any marketing email or request deletion at any time using the protected email button for . Suppressed email addresses are retained indefinitely to honor opt-out requests.

Cookies and analytics

We use session cookies for authentication. Meta Pixel remains off unless you choose “Allow” in the marketing-measurement privacy prompt. If enabled, Meta Pixel may use cookies and similar technologies for advertising measurement and attribution. Meta may receive the public page URL, referrer, browser and device information, IP address, and Meta cookie identifiers when available.

On public marketing pages, we use DataFast in cookieless mode to measure aggregate pageviews and traffic sources. The tracker may use session-only browser storage and processes limited technical signals, including IP address, browser user agent, site domain, approximate location, and screen or viewport size. DataFast uses a pseudonymous identifier with a salt that rotates approximately every 24 hours; we do not use this analytics data to create long-term visitor profiles or identify account holders.

We also use first-party, session-only attribution to connect a completed broker access request, broker account creation, or tenant requirement creation with the public page and call to action that led to it. This record is limited to public paths without query strings, the external referrer hostname when available, the public event and action labels, a random session identifier, and the completed outcome. It does not add names or email addresses to the conversion event or send registration details to Meta or DataFast.

We exclude login, registration, billing, authenticated application, and other sensitive routes from human analytics. DataFast receives sanitized page paths without query strings. We do not intentionally send Meta or DataFast names, email addresses, account IDs, property requirements, or CRM data, and we honor supported Global Privacy Control and Do Not Track signals. You can revisit the optional Meta choice through “Privacy choices” in the public footer.

Third-party services

We use DataFast for cookieless, aggregate traffic measurement on public marketing pages and to measure AI and search crawler requests. For analytics and likely crawler traffic, DataFast may receive a sanitized public page path, hostname, referrer origin and path, browser or crawler user-agent, IP address for pseudonymous measurement or crawler verification, limited device information, and response status when available. We use Meta Pixel for public-page advertising measurement and attribution. We also use Klaviyo for consented email subscriptions; Resend for account notifications and verified Brokerage sending domains; Stripe for billing; Google and Microsoft for connected mailboxes; Treg as our contact-data gateway and usage-metering provider; Apollo.io, Hunter.io, and other contact-data providers selected through Treg as downstream subprocessors; OpenAI and Anthropic for AI features; Vercel for application and object-storage hosting; and Neon for database hosting. Each provider processes data under its own terms and privacy policy.

Contact

Questions? Use the protected email button for , or visit the support page.