Legal
Privacy Policy
1. Who we are
Vireal LLC(“VIREAL”, “we”, “us”) provides software for real estate professionals: a client database, property search websites, comparative market analyses, calling and messaging, and email tools. This policy explains what information we collect, how we use it, and the choices you have.
Questions about this policy: info@vireal.com.
2. Two roles: our customers, and their clients
VIREAL serves real estate agents and brokerages (“customers”). Our customers use VIREAL to work with their own buyers and sellers (“their clients”).
- For information about our customers and their users, VIREAL is the controller and this policy describes our own practices.
- For information about their clients— the buyers and sellers stored in a customer’s account — VIREAL acts as a processor on that customer’s behalf. If you are a buyer or seller and want your information corrected or removed, contact the agent or brokerage you are working with; you may also contact us and we will route your request to them.
3. Information we collect
3.1 Website visitors
Our marketing website uses only cookies that are essential to serve and secure the site. We do not run third-party advertising or analytics trackers on it, and we do not sell visitor data.
3.2 Platform users
When you create an account we collect your name, email address, phone number where you provide one, your brokerage or team, authentication credentials, and records of your activity in the product. We collect the business content you put into VIREAL — contacts, notes, tasks, appointments, listings, saved searches, and messages.
3.3 Connected mailbox data
If you connect a mail account, we access the messages in that mailbox to show conversations inside VIREAL and match them to the right contact. Section 5 describes this in detail, including the specific limits that apply to Google data.
3.4 Email open and click tracking
VIREAL can tell an agent whether an email they sent was opened, and whether a link in it was clicked. This is off by default. It is enabled for an individual user, never for a whole company at once, and it stays with that user if they reconnect their mailbox. If it is on for you, email us and we will turn it off.
When it is on, we record only:
- that a message was opened or a link was clicked, and when;
- which link position in the message was clicked;
- a coarse device category — desktop, mobile, email-proxy, or unknown.
We do notrecord the recipient’s email address, IP address, browser details, or location alongside these events. Each tracked message stops accepting new events after a set period. Many email providers pre-fetch images on a recipient’s behalf, so an “opened” signal is an indication, not proof that a person read the message.
4. How we use information
- To provide, operate, secure, and support the product.
- To show you your own client conversations and match them to the right records.
- To send email and text messages that you write, schedule, or approve — including recurring property updates you set up for a client who asked for them.
- To authenticate you, prevent abuse, and investigate security incidents.
- To meet legal, tax, and regulatory obligations.
We do not sell personal information, and we do not share it with advertising networks or data brokers.
5. How VIREAL uses Google user data
VIREAL’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
If you choose to connect your Google account, VIREAL requests the gmail.modify scope together with your basic profile and email address (openid, userinfo.email, userinfo.profile). We use that access only to:
- read messages in your connected mailbox so we can show conversations with your clients inside VIREAL and match them to the correct contact record — we store message envelopes (subject, snippet, addresses, timestamps) and fetch message bodies on demand for display, without storing bodies in our database;
- create drafts and send email that you write, approve, or schedule, from your own address, in the correct conversation;
- update read state and labels on messages when you act on them inside VIREAL;
- identify the connected mailbox address and display name so replies send from the right account.
What we do not do
We do not permanently delete your mail. We do not send bulk or marketing broadcast email through your connected mailbox, and we do not use it to contact people who are not your own clients. Where VIREAL sends recurring messages on your behalf — for example a property update a client asked to receive — each message goes to one recipient, only to a client in your own account, only after you turn the feature on, and every message carries a way for the recipient to stop receiving them. You can switch it off at any time.
We do not sell or transfer your Google data to advertising platforms, data brokers, or information resellers. We do not use it for advertising, retargeting, or credit assessment. We do not use your Gmail data to develop, improve, or train generalized artificial intelligence or machine-learning models. Where VIREAL uses AI to draft or summarize email on your behalf, we send that request with retention switched off, we do not permit your content to be used for training, and the output is shown to you before anything is sent.
Open and click tracking on mail you send
Where the open- and click-tracking described in section 3.4 is enabled for your account, it applies to messages you send from your connected mailbox. VIREAL adds a tracking image and rewrites links in those messages so it can report opens and clicks back to you. It is off unless it has been enabled for your account, and we will switch it off on request. The resulting records contain no recipient address, IP address, or browser details, are used only to show you engagement on your own messages, and are never used for advertising or sold to anyone.
Human access
No VIREAL employee reads your email except (a) with your specific, affirmative consent to view a particular message, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and de-identified for internal operations.
Where the data lives
We store the message metadata described above in our primary database, hosted in the United States on Supabase (Amazon Web Services), encrypted in transit and at rest. The provider credentials our own systems hold are kept in encrypted vault storage and are never written to application logs.
Mailbox connectivity subprocessor
VIREAL uses Nylas, Inc.(United States region) to connect to your mail provider. Nylas performs the OAuth handshake on VIREAL’s own Google OAuth application and holds and refreshes your Google OAuth tokens. VIREAL never stores your Google access or refresh tokens and never stores your Google password — our systems keep only an opaque reference to the connection, so your Google credentials are not present in our database. See Nylas’s privacy notice.
Who can see your email inside VIREAL
Email that VIREAL links to a lead or contact record is visible to the people on your team who already have access to that lead. Email in your connected mailbox that is not linked to a lead or contact is private to you and is not shown to anyone else on your team. The mailbox owner controls whether lead-linked messages are shared with the team; when sharing is off, lead-linked email is visible only to the mailbox owner. Your team administrator can see that a mailbox is connected and whether it is healthy, but cannot read your messages unless the rules above allow it.
How to revoke access
You can disconnect a mailbox at any time in VIREAL under Settings → Integrations → Connected Mailbox, which revokes our access and deletes the stored tokens. You may also revoke access directly at your Google account permissions page. To request deletion of mailbox data we already hold, email info@vireal.com.
6. Subprocessors
We use these providers to run the service:
- Supabase (Amazon Web Services, United States) — primary database, authentication, and file storage.
- Vercel (United States) — application hosting and delivery.
- Nylas (United States) — connected mailbox access, described in section 5.
- Resend (United States) — transactional and platform email delivery.
- Twilio (United States) — calling and text messaging.
- AI providers — drafting and summarizing. We send these requests with retention switched off and do not permit your content to be used for training.
7. When we share information
We share personal information only with the subprocessors above, with people inside your own team or brokerage according to the permissions in your account, where you direct us to, and where required by law or to protect our rights and the safety of others. If VIREAL is involved in a merger, acquisition, or sale of assets, we will give notice before your information becomes subject to a different privacy policy.
8. Data retention
We keep information for as long as your account is active and for as long as we need it to provide the service, resolve disputes, and meet our legal obligations. When you disconnect a mailbox, we revoke and delete the stored access tokens at that time.
You can ask us to delete data we hold about you or your account at any time by emailing info@vireal.com, and we will do so unless we are required to keep it. Backup copies are removed on our normal backup rotation.
9. Security
We encrypt data in transit and at rest, isolate each customer’s data at the database level, hold secrets in encrypted vault storage, and keep credentials out of application logs. No system is perfectly secure, but we work to protect your information and to respond quickly if something goes wrong.
10. Your rights and choices
- Access, correct, export, or delete your information.
- Disconnect a mailbox or revoke access at any time.
- Unsubscribe from any recurring email we send on a customer’s behalf.
- Ask us to turn email open- and click-tracking on or off for your account.
- Close your account.
To exercise any of these, email info@vireal.com. If you are a buyer or seller in an agent’s account, see section 2.
11. California privacy notice
If you are a California resident, you may request access to, correction of, or deletion of your personal information, and you may ask us to tell you what categories we collect and why. We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising these rights. Submit a request to info@vireal.com.
12. Changes to this policy
We may update this policy. When we do, we will change the “Last updated” date above, and for material changes affecting how we use Google user data we will give notice in the product before the change takes effect.
13. Contact
Vireal LLC
info@vireal.com