> ## Documentation Index
> Fetch the complete documentation index at: https://developers.investorlift.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy notice

> What Investorlift Data Services collects about developers and about the people in the Data, who receives it, how long it is kept, your rights, and how to ask for a removal.

Version data-services-beta-v2026-09-17. Effective \[publication date]; a later version takes effect on the date it states (section 17).

Investorlift Inc. ("Investorlift", "we") gives this notice for Investorlift Data Services: the API at `api.investorlift.com`, its MCP endpoint, the developer console and this documentation site. **Part A** (sections 1 to 6) is for developers and console users; **Part B** (sections 7 to 12) for people in the data the API serves (the "Data"): property owners and buyers, members of entities that hold property, real estate licensees, owners of licensed short-term rentals and marketplace listing parties; **Part C** (sections 13 to 18) for both. It describes our practices and is not a contract; the Investorlift Data Services Developer Agreement (Beta) at [Developer Agreement](/guides/terms) (the "Developer Agreement") governs a developer's use.

**Part A. Developers and console users**

## 1. Who we are, and the Mogul Privacy Policy

Investorlift Inc., reachable as section 18 says, is responsible for the personal information this notice describes. The console uses your Investorlift marketplace account (`mogul.investorlift.com`); there is no separate developer account. The Privacy Policy of Mogul, a division of Investorlift Inc. (updated June 3, 2026, [https://mogul.investorlift.com/privacy-policy](https://mogul.investorlift.com/privacy-policy), the "Mogul Privacy Policy") covers the marketplace's own use of that account; this notice is the complete notice for Data Services and controls where the two differ about it. A developer that displays or uses the Data is independently responsible for its own product, end users, privacy notice and compliance, as the Developer Agreement provides.

## 2. What we collect

* **Your Investorlift account, at sign-in:** account identifier, name, email address and whether it is verified, profile picture. The marketplace also logs a sign-in it routes to the consent page (user id, reason) and rate-limits sign-ins by IP address.
* **The acceptance record:** agreement version, time by our server clock, your browser's IP address and user-agent string, recorded against your account when you accept the Developer Agreement (the page says so and links this notice), and your permission for the console to read your account details.
* **Subscription and billing:** our gateway provider, Zuplo, keeps a customer record (account identifier, email address, subscription, API key, usage against your plan). For every plan, the Free plan included, Stripe holds your payment method and billing details (nothing is charged on the Free plan); we receive the customer record, invoices and payment status, never your card number.
* **Usage records:** the gateway records every API or MCP request (method, full URL including what you searched, source IP address, user-agent, plan and subscription, status, timing, request id). Our servers write one request line and one usage line per call (route, status, duration, rows, data version, request id, your Investorlift account or gateway customer identifier, and the URL with search text, coordinates, parcel numbers and record identifiers masked but viewport, radius, buyer-match subject facts and filter identifiers as sent). A buyer match also logs its subject facts (price, value, size, condition), radius, weights and up to 100 ranked investor identifiers, never a coordinate; a name search that matched a person behind an investor logs the request id, your account identifier and the investor identifiers matched, never the name typed.
* **Never on our request or usage lines:** request bodies; MCP tool arguments beyond the buyer-match line; your IP address, removed by the gateway before a request reaches us; your API key, replaced by the gateway with its own.
* **Correspondence:** what you send to the addresses in section 18.
* **This site and AI clients:** the documentation host may keep standard server logs (IP address, pages, browser); we run no analytics or advertising tracker here. Page content reaches an AI assistant or code editor, and a query reaches the host-run documentation search server, only when you choose it, under that provider's terms; on the MCP endpoint your prompts go to your model provider and results land in your client's transcript and the provider's logs under its terms.

## 3. How we use it

To provide the service (authenticate you, issue keys, meter usage, apply rate limits); to bill paid plans (invoice, collect, suspend or restore a key); to secure the service and prevent abuse (detect key sharing, scraping, market tiling and other misuse, hold a payment method on the Free plan to deter duplicate and fake accounts, keep the evidence behind an enforcement step, respond to incidents, and for these purposes review your Data Services usage with your marketplace activity); to keep the records of use we owe our data licensors; to support you, comply with law, enforce our agreements, protect rights and understand usage in aggregate; never to advertise to you. Legal bases, where the law requires one: our agreement with you; our legitimate interests in the security, abuse-prevention, licensor-records and usage purposes; legal obligations, including tax and accounting; and consent where the law requires it, which you may withdraw.

## 4. Who we disclose it to

Service providers under contract: Zuplo, Inc. (API gateway, console hosting, key storage, metering, subscriptions); Stripe, Inc. (payments, checkout, invoices, billing portal, tax where turned on; independently responsible for its own use of payment data); Amazon Web Services (hosting, databases, logs, archives); Mintlify (documentation hosting); Google (Workspace email); Intercom, Inc. (our support desk: mail to [support@investorlift.com](mailto:support@investorlift.com) lands in Intercom, where each request is tagged and tracked until it is closed). Our data licensors: usage records, in aggregate or for a specific account where that requires it, to show the Data was used within our license, answer their audits and act on their deletion or compliance demands. Investorlift's marketplace systems, which hold your account, acceptance record and payment events; staff who operate both see both. Legal: to comply with law or a lawful request, enforce our agreements and protect rights, safety and property. A counterparty in a corporate transaction, under this notice. Anyone at your direction. We do not sell the personal information in this Part A, share it for cross-context behavioral advertising or use it for targeted advertising; the marketplace's own use of your account, including any advertising use of your name or email address, is under the Mogul Privacy Policy (section 1).

## 5. Security

Every connection is encrypted; keys are authenticated at the gateway and never written to our request logs; access to our logs and databases is limited to Investorlift staff over our private network, our gateway provider's staff can read its gateway logs under its contract with us, and payment data is held by Stripe, not by us. No system is perfectly secure: keep your key secret, and if it may have leaked, roll it, delete the old key from the same page, and report the compromise to the support address in section 18 within 72 hours, as the Developer Agreement asks.

## 6. Your choices, and children

The only sensitive personal information Data Services holds about you is your API key, held by our gateway provider to authenticate your requests. Edit your name and picture in your Investorlift account settings; before changing a subscribed account's email address, write to the support address in section 18 so the billing record follows. Records we must keep: the usage records for our data licensors, the acceptance record, invoices. You must be 18 or older to hold an Investorlift account; we do not knowingly collect personal information from anyone under 18.

**Part B. People who appear in the Data**

## 7. What the Data is

The Data is a compilation of public records, publicly available information, MLS listing data licensed through BatchData and Investorlift's own marketplace listing records about real property in the markets on [Coverage](/guides/concepts/coverage): parcels and their assessed characteristics, and deeds and other recorded transfers with parties, dates, prices and document types (county assessor and appraisal offices; BatchData, which licenses recorder, assessor and MLS records nationally); MLS listings with brokerage and agent; short-term rental licenses and building permits (city open-data registries); and a state real estate licensing roll where we publish an agent registry. We derive which buyers are investors, how long an owner has held, whether a purchase was a flip or a distressed sale, and how a marketplace listing ended according to the deed, and we group deed parties by deed mailing address to identify the people and entities behind an investor. We use no state business filings, credit files, telephone carrier or call records, or social media. We collect nothing from you directly except what you send under sections 10, 11, 14 and 15; listing companies supplied the marketplace records under their Investorlift account terms.

## 8. What the public API shows about a person, and what it does not

Every key on `api.investorlift.com` receives the same fields. Exactly what identifies a person:

* **Shown:** property address, coordinates and parcel number; dates, prices and document types of recorded transfers; owner kind (person, trust or entity), owner-occupancy, holding period, the state of a mailing address, rental registration and short-term rental license status, permit counts; MLS listing dates, prices and status, brokerage and MLS number; marketplace listing dates, asking price, stated after-repair value and condition, offer and contract dates, the listing's and company account's identifiers in the Investorlift app, and how the deed says the listing ended (a hidden-address listing is served under the company without an address until a recorded deed closes it); business names (listing companies as they appear on Investorlift, with brands, legal entities and account state; brokerages; short-term rental managers; companies that bought property; an entity named as a borrower on a recorded instrument); the lender of record on each recorded mortgage, as the instrument spells it, with the count and balance of the loans recorded under it; and each registry investor's display name, a registry investor being a buyer our registry identified as an investing operation from its recorded purchases (nobody registers themselves).
* **That registry name can be a person's name.** The registry labels each operation with the name of its member with the most deeds, so someone who buys under their own name is labeled with that name as spelled on the deed, and every key sees it wherever the investor appears. Trust names among an investor's members, often carrying a family surname, are also shown. The lender of record on a recorded mortgage can be a person's name too: someone who lent under their own name is shown as the lender, as the instrument spells it, with the count and balance of the loans recorded under that name. A property address can be a person's home address.
* **Withheld from every key** (returned empty, marked `contact_redacted: true`, except in the responses of the property search, financing, history, listing-history and lender-loans endpoints, where a withheld field is omitted from the response altogether and no marker is carried): a parcel's current owner names; the people behind an entity; every mailing address and skip-trace target; the name of a buyer who is a household rather than a registry investor; a person named as a borrower on a mortgage or as a party to a lien; listing agents' names, phone numbers, email addresses and license numbers; a person's name matched by a name search. One exception: a diagnostic string can quote a member's deed name that matched a brand pattern, rarely a person's; we treat a request about one as a removal request under section 10. Short-term rental permit holders and the homeowner behind a marketplace listing are not in the served Data at all. The party to a marketplace offer is not served as such: no field carries the offer party's name or account. The Data records only whether the buyer on the accepted offer is the buyer on the closing deed (a match flag and a buyer tier), and when it is, that buyer is shown under the rules above (a registry investor or a company is named; a person, trust or owner-occupant without an investor id is not). The offer names we compare internally are never served. The public API carries no phone numbers or email addresses. Counts and flags about withheld data are shown.
* **Where the withheld fields go:** only to a separate host the public API cannot reach, for keys with a contact permission: Investorlift staff, the Investorlift marketplace application, for the accounts Investorlift permits, and partners under a written agreement with Investorlift; every such response is audited by key, requester identity, dataset version and records served.

## 9. Why we process it, and how we make it available

We process the Data to provide real estate market and investor intelligence to Investorlift's marketplace and to developers building products for investors, wholesalers and agents, a legitimate business purpose. The Data is not a consumer report; the Developer Agreement forbids using it to decide credit, insurance, employment, housing or a tenancy, for tenant screening, or to discriminate in housing or lending, and it carries no consent to call, text, email or visit anyone.

We make the Data available to API customers under a license. Most of it comes from records governments make public, which most state privacy laws exclude from "personal information", as they generally exclude information lawfully made available to the general public; the rest was published through listing services or on Investorlift's marketplace, and our classifications derive from those records. The facts we derive about an identified person (section 7) may be personal information under some of those laws, and where they are, making the Data available to API customers is a "sale" as those laws use the word. We sell no other category of information about you and share none for cross-context behavioral advertising; section 14 says how to opt out.

## 10. Asking for a removal

Email the privacy address in section 18 with "Removal request" as the subject line, giving the property address or parcel number, the name as it appears in the record, a way to reach you and any record identifier a developer showed you. Say whether to remove the property, transaction, investor or lender record, or all of them; if you do not say, we remove each that identifies you. Those four are the removals this notice offers; listing agents' names and contact details are withheld from every key already (section 8). A trust named for you among an investor's members is removed by removing that investor's record and deals, unless we can remove the member entry alone. If something is missing we tell you what within 5 business days; the 10 business days below run from the day a complete request reaches us.

Within 10 business days of a complete request we add the record to our suppression list. From then on it is left out of every copy of the Data we publish, on the public API and on the internal host our staff and partners use alike, starting with the next publish, whose date we tell you; where the law sets a date by which we must stop disclosing, we publish before it. A suppressed investor's record, members, aliases and purchases leave, and its identifier and name leave other parties' deals, which keep their date and price; a suppressed property's record and every deal on it leave; a suppressed deal's record leaves; a suppressed lender's registry record leaves, and its name leaves every loan, property and history-event record that carried it, which keep their amounts and dates. A removed record answers as if it never existed, and the suppression follows the same recorded parties through every rebuild of our records, so it does not return under a new identifier.

**What a removal cannot do.** Developers who retrieved your record before it was removed may hold a copy. The Developer Agreement requires them to delete every copy within the cache period it sets or within one business day after we publish a new version of the Data, whichever is first (every removal is a new version), and in any case within 10 business days after our removal notice, which goes to every active developer account and carries only the record's identifier, never your name or address. They may keep aggregates and scores that do not reproduce your record and the identifier as a reference, and may have shown the record to their own users. A result obtained through an AI assistant also sits in the assistant's transcript and its model provider's logs; the Developer Agreement (its sections 7.3 and 9.5) requires the developer to delete it from its own devices and provider account when we notify it of the removal, and only the provider's residual copy stays, under the provider's terms. We cannot remove the record from the county, the listing service, our data provider, developers' users or other companies' copies, and we do not pass your request or details to our data provider; ask it directly. We keep your request while the suppression is in force; the suppression entry holds only a case number and record identifiers, never your name.

## 11. New Jersey covered persons (Daniel's Law), and similar laws

If you are a covered person under New Jersey's Daniel's Law (judicial officers, law enforcement officers, child protective investigators in the Division of Child Protection and Permanency and prosecutors, active, formerly active or retired, and immediate family in their household), you, an authorized person under that law, or anyone acting for you including a notice service may notify us in writing to stop disclosing your home address and unpublished home telephone number: email [support@investorlift.com](mailto:support@investorlift.com) with "Removal request" in the subject line, stating that you are a covered person or authorized to act for one, the address to be protected and the name as it appears in our records. We do not ask you to prove your status; section 15 does not apply. Within 10 business days of receiving the notice, as the law requires, we stop disclosing the address on every host we operate, to developers, staff and partners alike, by removing the property record and any investor record that identifies you as section 10 describes, and do not re-disclose it. If another law entitles you to have a business stop disclosing your home address on notice, including the federal Daniel Anderl Judicial Security and Privacy Act for federal judges and their immediate family, send the notice the same way; we act within 10 business days.

## 12. Sensitive information

We do not knowingly collect or infer sensitive personal information as the state privacy laws define it: no government identification or financial account numbers, health, biometric or genetic data, precise device location, or race, ethnicity, religion, sexual orientation, citizenship or union membership. The Data holds public-record facts about a property that some regard as private (owner-occupancy inferred from the deed mailing address, a foreclosure, trustee or tax sale, rental and short-term rental status, the recorded price), shown on the public API with the property address but without the current owner's or buyer's name, except under the display name of a registry investor that is a person's name (section 8): its purchases appear under that name with the recorded price and any foreclosure, trustee or tax-sale flag; a property it still holds with whether the owner appears to live there, since when, and its rental or short-term rental status; and a sale in which it was the seller, including a foreclosure, trustee or tax sale.

**Part C. Both audiences**

## 13. How long we keep it

| Record                                                                                                       | Kept for                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Gateway request logs and analytics                                                                           | About one day (logs) and seven days (analytics) under our gateway provider's plan with us, then its terms                                                                                                                                                     |
| Our request, buyer-match and name-search audit lines                                                         | 28 days                                                                                                                                                                                                                                                       |
| Usage records (no query text or IP address)                                                                  | 28 days in our logs; up to five years where kept for our licensor record-keeping obligations and billing disputes                                                                                                                                             |
| The record identifiers an account has been charged for (the credit ledger)                                   | In the gateway-side store for 400 days after the account's last charged request, then dropped                                                                                                                                                                 |
| Agreement acceptance record                                                                                  | While your account exists and four years after it closes, or longer while a claim or legal hold is open; a copy is kept when an account is deleted                                                                                                            |
| Sign-in routing log; console permission record                                                               | As the marketplace's server-log retention provides; while your account has console access                                                                                                                                                                     |
| Enforcement record (date, account, action, rule, evidence location), if we warn, throttle, revoke or close   | While we operate the service and the evidence it points to is kept                                                                                                                                                                                            |
| Provider records (gateway customer and subscription record; Stripe payment records; documentation host logs) | The subscription's life, then the provider's terms; as tax and accounting law require, under Stripe's terms; the host's terms                                                                                                                                 |
| Correspondence, including support and privacy requests                                                       | In the support desk for as long as needed to handle the request, then three years after the matter closes                                                                                                                                                     |
| The served Data                                                                                              | Rebuilt at each refresh; a record stays while our sources carry it and its market is covered; a suppressed record stays out (section 10); the previous set and its export are kept unserved briefly against a failed refresh                                  |
| Working tables and source files                                                                              | Replaced at each refresh, except, kept while we operate the service: identifier assignments, load and run registries, and an internal ledger of marketplace outcomes that can hold a buyer's name and company from marketplace records (Mogul Privacy Policy) |

## 14. Your rights

If you live in a state with a comprehensive privacy law (California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others), you may have the right to know whether we process personal information about you and to access it and receive a portable copy; to correct or delete it; to opt out of its sale, of sharing for cross-context behavioral advertising, of targeted advertising and of profiling in furtherance of decisions that produce legal or similarly significant effects; to limit the use of sensitive personal information; and to appeal our decision. Email the privacy address in section 18 with "Privacy request" as the subject line; section 15 says how we verify and when we respond.

For people in the Data: a removal request under section 10, which anyone may make whether or not a privacy law applies to them, is a request to delete and an opt-out of sale; the [Do Not Sell or Share My Personal Information](#10-asking-for-a-removal) link on this site opens it. The categories we may sell are identifiers (a property address that is also a home address, a buyer's name as recorded on a deed, a lender's name as recorded), commercial information (recorded transfers and listings) and the inferences section 7 lists; the recipients are API customers (the developers and real estate businesses that license the Data). We do not use the Data for targeted advertising or profile anyone in furtherance of decisions with legal or similarly significant effects; our automated classifications and rankings of buyers and owners, including people who buy under their own name (as investors of a kind and scale, likely buyers of a property, or occupants), are market analysis from which we make no decision about anyone, and section 9 says what developers may not decide with them. We do not edit records; the Data repeats what a county recorder or assessor, a listing service, a city registry or our data provider recorded. If a record about you is inaccurate, tell us what is wrong, without proof of the error, and we act by removing the record under section 10 (unless removal rather than correction would disadvantage you, when we ask your consent first) or tell you why we decline; a removed record stays removed through every later refresh, so also ask the source to correct its record, and correct a marketplace listing record through your Investorlift account or at the address in section 18.

## 15. Verification, authorized agents and response times

* **Developers:** we verify against your account email and, where needed, a one-time code sent to it.
* **People in the Data:** for a removal (section 10) or a Daniel's Law notice (section 11) we need only the property address or parcel number, the name as recorded and a way to reach you; we never ask for proof of identity or a document, though we may decline a request we have a good-faith, documented reason to believe is fraudulent, and will tell you why. For a request to know or correct we may ask for one document connecting you to the property (a deed, tax bill or utility bill with account numbers removed), used only to verify and deleted once the request is resolved. You do not need an Investorlift account.
* **Authorized agents** need your signed permission; we may confirm with you directly.
* **Response times:** a removal within 10 business days (sections 10 and 14); a Daniel's Law notice as section 11 says; a request to know, access or correct within 45 days, or we tell you why we need 45 more; an appeal within 45 days, and if we deny it you may complain to your state attorney general. We do not discriminate against anyone for exercising a right. A business day is any day other than a Saturday, Sunday or United States federal holiday, as the Developer Agreement defines it.

## 16. International transfers

We process personal information in the United States; our service providers may process it there or in other countries where they operate. Data Services is offered from the United States, and the Developer Agreement lets Investorlift refuse or close access from outside it; if you use it from elsewhere, your information is transferred to the United States, whose laws may differ from yours. During the beta, Data Services is offered only to developers in the United States, as the Developer Agreement (its section 1.2) requires; we do not offer it in the European Union, the United Kingdom or elsewhere.

## 17. Changes to this notice

We post changes here and update the date at the top; a change takes effect on the date it states. If a change materially reduces your protections and you have an Investorlift account, we email the address on it at least 30 days before it takes effect; if you have asked us for a removal or a Daniel's Law protection, we email the address you gave us before a change affecting that request takes effect. We do not use information collected before a material change for a purpose the change first describes without telling you and, where the law requires, asking your consent. The covered markets on [Coverage](/guides/concepts/coverage) can change without a change to this notice.

## 18. Contact

Privacy, removal and rights requests: [support@investorlift.com](mailto:support@investorlift.com), subject "Privacy request" or "Removal request". Developer support: [support@investorlift.com](mailto:support@investorlift.com). Email is the only channel for these requests; Investorlift offers no telephone line, request form or postal address for them. California residents may report complaints to the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or (800) 952-5210.


## Related topics

- [Terms and attribution](/guides/terms.md)
- [Acceptable use and abuse policy](/guides/acceptable-use.md)
- [The MCP endpoint](/mcp/overview.md)
- [Changelog](/changelog.md)
- [Quicklists](/guides/concepts/quicklists.md)
