Privacy Policy
Effective date: August 10, 2026
Keplify LLC ("we," "us," or "our") operates SplitRE at splitre.app and app.splitre.app (collectively, the "Service"). This Privacy Policy describes what information we collect, how we use it, with whom we share it, how long we keep it, and the rights you have over it. It applies to all visitors of our marketing website and to registered subscribers of the SplitRE application.
The Service is offered only to businesses located in the United States, and this Policy is written for US privacy law. We do not knowingly direct the Service at, or collect personal information from, individuals in the European Economic Area, the United Kingdom, or Switzerland, and we do not represent that our practices satisfy the GDPR, UK GDPR, or similar non-US frameworks.
By using the Service you agree to the practices described in this policy, which is incorporated into our Terms of Service by reference. If you do not agree, please do not use the Service.
1. Information we collect
1.1 Account and billing information
When you sign up or manage your subscription we collect: your full name, email address, brokerage name, and billing details. Payment card numbers are processed directly by Stripe, Inc. and are never stored on our servers. We retain only the last four digits of your card, card type, and expiration date as returned by Stripe for display purposes.
1.2 Brokerage data you enter
Commission plans, agent profiles (names, license numbers, split percentages, annual cap amounts), and deal records (property addresses, sale prices, gross commission income, buyer/seller sides) are stored on your behalf. This is your data. With respect to anything you enter about your agents and transactions, we act as a service provider / processor, not as the party that decides why and how it's collected — see Section 9 for what that means under US state privacy law, and Section 7 of our Terms of Service for the contractual terms that go with it.
1.3 Usage and log data
Our servers automatically record: IP address, browser type and version, operating system, referring URL, pages viewed, timestamps, and error events. We use this data to maintain uptime, diagnose bugs, and understand aggregate feature usage. Log data is retained for up to 90 days.
1.4 Analytics
Our marketing pages (splitre.app) use Cloudflare Web Analytics, a cookieless analytics service. It does not set tracking cookies, does not use persistent cross-site identifiers, and reports aggregate metrics (page views, visits, load performance) that are not tied to an individually identifiable visitor. We do not deploy advertising networks, behavioral retargeting pixels, or session-replay tools on our website or inside the application.
1.5 Cookies and local storage
We use strictly necessary cookies for session management and authentication tokens. We do not use third-party advertising cookies. The application may store user preferences (such as sidebar state or selected date ranges) in your browser's local storage; this data never leaves your device.
1.6 Communications
If you email us at [email protected] or our support addresses, we retain the content of that correspondence to resolve your issue and improve the Service.
2. How we use your information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process your subscription payments through Stripe
- Generate QuickBooks Online-ready CSV exports of your deal and commission data at your direction
- Send transactional emails necessary for the Service to function: deal-confirmed notifications, cap-reached alerts, billing receipts, and auto-renewal / cancellation confirmations. These emails are sent from [email protected] or [email protected] and are necessary for the Service to function.
- Send product update and marketing emails to active subscribers. You may opt out of marketing emails at any time using the unsubscribe link in any such email or by emailing [email protected]. Opting out of marketing emails does not affect transactional emails related to your account.
- Respond to support requests and enforce our Terms of Service
- Detect, investigate, and prevent fraud, abuse, or security incidents
- Analyze aggregate, de-identified usage patterns to improve existing features and prioritize new ones
- Comply with applicable law and legal process
We do not use your data to train AI or machine-learning models. We do not sell, rent, or share your personal data or brokerage data with third parties for their marketing purposes. We do not engage in automated decision-making that produces a legal or similarly significant effect on you or your agents.
3. Third-party sub-processors
We engage a limited number of trusted sub-processors to operate the Service. Each sub-processor is bound by data protection agreements and is permitted to use your data only to perform services on our behalf.
| Provider | Purpose | Data location |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication, row-level security | United States |
| Stripe, Inc. | Payment processing and subscription management | United States |
| Resend, Inc. | Transactional and marketing email delivery | United States |
| Cloudflare, Inc. | Content delivery network, DNS, DDoS protection, cookieless web analytics | Global edge (US primary) |
| Intuit Inc. (QuickBooks Online) | Accounting sync — accessed only using your own OAuth credentials at your instruction | United States |
We do not share your data with these providers beyond what is necessary to deliver the specific service they provide. If you disconnect your QuickBooks integration, we immediately stop transmitting data to Intuit on your behalf. If we add or change a sub-processor in a way that materially changes how your data is handled, we will update this table and, for a material change, notify active subscribers by email.
4. Data security
We implement the following technical and organizational safeguards to protect your data:
- All data is encrypted in transit using TLS 1.2 or higher
- All data is encrypted at rest using AES-256
- Row-level security policies in our database ensure that your brokerage data is logically isolated from other customers' data
- Production system access is limited to authorized personnel using multi-factor authentication
- Stripe handles all payment data; we never receive or store raw card numbers
- We perform regular dependency audits and apply security patches promptly
Despite these measures, no system is perfectly secure. If you discover a security vulnerability, please report it promptly to [email protected] so we can address it. We do not publicly disclose security issues until a fix is in place.
Breach notification.If we experience a security incident that compromises your personal information in a way that triggers a notification obligation under applicable law, we will notify affected customers without unreasonable delay and consistent with the timing and content requirements of the law that applies (which varies by state, but is generally “without unreasonable delay,” and in some states subject to a specific outer limit such as 30 or 45 days).
5. Data retention and deletion
While your subscription is active, we retain your account data for as long as the account exists.
If you voluntarily cancel (turn off auto-renewal and let your subscription run to the end of its billing period), your account is locked at that point but your data is not automatically deleted— it's retained, and reactivating your subscription restores everything. Because self-service export isn't available once locked, export your data before your final billing period ends if you don't plan to come back. See our Refund / Cancellation Policy for the full mechanics.
If a payment fails and is never resolved through the retry-and-grace-period process described in our Terms of Service, your account is locked and, separately from the voluntary-cancellation case above, your data is automatically and permanently deleted 30 calendar days after that lock, with reminder emails sent before deletion.
At any time, whether or not your subscription is active, you may request that we delete your personal information sooner, by emailing [email protected]. We will verify the request comes from an authorized account owner and complete it within 30 days. Billing records and invoices are retained for 7 years regardless of a deletion request, as required by US tax law, and server log data is retained for up to 90 days and then automatically purged.
6. Your CAN-SPAM rights
Marketing emails from us include a functioning unsubscribe mechanism, our postal address, and a subject line that accurately reflects the email's content, consistent with the CAN-SPAM Act. Unsubscribe requests are honored within 10 business days. Transactional and relationship emails necessary to operate your account (billing receipts, security notices, service announcements) are not marketing emails and are not affected by an unsubscribe request.
7. Do Not Track and Global Privacy Control
Some browsers send a "Do Not Track" (DNT) signal to websites. Because there is no common industry standard for responding to DNT signals, we do not currently alter our data collection practices in response to DNT signals — but as stated throughout this Policy, we do not sell or share personal information or engage in cross-site behavioral advertising regardless of any signal, so there is nothing DNT would meaningfully change.
We do honor the Global Privacy Control (GPC) signal, where technically detectable, as a valid opt-out-of-sale/sharing preference signal under the CCPA and equivalent state laws. Because we do not sell or share personal information in the first place, honoring GPC has no practical effect on how your data is treated — you are already opted out.
8. Links to third-party sites
Our website and application may contain links to third-party websites (such as QuickBooks Online, Stripe billing portal, or external documentation). We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies before sharing any personal information.
9. California privacy rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the rights below. This applies whether you are the brokerage account holder or an individual whose information was entered into the Service by a brokerage — for example, an agent.
Note on roles:where your brokerage entered information about you (an agent) into SplitRE, your brokerage is the party that decided to collect and use that information, and we process it on the brokerage's behalf as a service provider. You may submit a rights request to us directly, and we will either honor it or route it to the brokerage as appropriate; you may also have rights directly against your brokerage as the entity that controls that decision.
- Right to Know. You may request a disclosure of: (a) the categories of personal information we have collected about you; (b) the categories of sources from which we collected it; (c) the business purpose for collecting it; (d) the categories of third parties with whom we share it; and (e) the specific pieces of personal information we hold about you.
- Right to Delete. You may request deletion of personal information we have collected from you, subject to certain exceptions (such as information required to complete a transaction or comply with legal obligations).
- Right to Correct. You may request that we correct inaccurate personal information we hold about you.
- Right to Opt Out of Sale or Sharing. We do not sell or share your personal information for cross-context behavioral advertising — there is nothing to opt out of, and we honor Global Privacy Control signals as described in Section 7 as a matter of policy regardless.
- Right to Limit Use of Sensitive Personal Information. We do not use sensitive personal information for purposes beyond those necessary to provide the Service.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA rights.
- Right to Appeal. If we decline a request, you may appeal by replying to our decision email; we will respond to the appeal within 45 days.
How to submit a California rights request: Email [email protected] with the subject line "California Privacy Rights Request." Include your name, email address associated with your account (if applicable), and a description of the right you wish to exercise. We will verify your identity and respond within 45 calendar days. If we need more time (up to an additional 45 days), we will notify you in writing.
You may designate an authorized agent to make a request on your behalf by providing written authorization and verifying your identity directly with us.
Categories of personal information collected
In the preceding 12 months, we have collected the following CCPA categories:
- Identifiers — name, email address, IP address, account ID
- Commercial information — subscription plan, billing history, transaction records you enter
- Internet or network activity — server logs, feature usage, error reports
- Professional or employment-related information — brokerage name, agent data entered by a brokerage
We do not collect Social Security numbers, financial account credentials, biometric data, precise geolocation, health information, or the contents of private communications, except that a brokerage may choose to enter an agent's license number or income figures as part of ordinary commission tracking — this is professional/commercial information, not a sensitive category we independently seek out. We do not use or disclose sensitive personal information for any purpose requiring an additional CCPA notice beyond what's described here.
10. Other US state privacy rights
As of 2026, roughly twenty US states — including Virginia, Colorado, Connecticut, Utah, Texas, and others — have their own comprehensive consumer privacy laws. They differ in detail, but they share a common core, and if you are a resident of one of these states, you generally have rights similar to the California rights in Section 9: to know what personal information we hold about you, to access or obtain a copy of it, to correct inaccuracies, to request deletion, to opt out of the sale of personal information or its use for targeted advertising, and to appeal a denied request. We do not sell personal information or use it for targeted advertising under any of these laws' definitions.
To exercise a right under any of these laws, email [email protected] with your state of residence and the right you wish to exercise; we will verify your identity and respond within the timeframe the applicable law requires (generally 45 days, sometimes extendable).
11. Children's privacy
The Service is a business tool intended for use by adults (18 years of age or older). We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, contact us at [email protected] and we will promptly delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and notify active subscribers by email at least 14 days before the changes take effect. If you continue to use the Service after the effective date of the revised policy, you accept the updated terms.
13. Contact us
For privacy-related questions, data access requests, or to exercise your rights, please contact: