Legal · privacy
Privacy Policy
This Privacy Policy explains what personal information Yapii LLC ("Yapii", "we", "us") collects, why we collect it, how we use and share it, and the controls available to you. It applies to the Yapii product, the marketing site at yapii.com, our mobile applications, and any related services. For details on how Yapii processes personal data on behalf of customers under the Terms of Service, see the Data Processing Addendum.
Scope of this policy
This Policy describes how we handle personal information in two distinct roles. As a "controller", Yapii determines the purposes and means of processing personal information about visitors to our marketing site, prospective customers, billing contacts, and account administrators. As a "processor" (or "service provider"), Yapii handles personal information that customers upload to their workspaces (such as their own contacts and leads) on behalf of, and according to the documented instructions of, those customers.
When Yapii acts as a processor, our customer is the controller of that data. The contractual terms in the DPA take precedence over this Policy for that processing, and individuals should direct privacy requests about workspace data to the relevant Yapii customer.
Categories of personal information
We collect personal information from four broad sources: data you give us directly, data your workspace generates as you use the product, behavioral and device signals collected automatically, and data we infer through modeling.
| Source | Examples | How collected |
|---|---|---|
| Account & billing | Name, work email, hashed password, role, billing contact, plan, payment last-4 (via Stripe). | You provide it on sign-up, in Settings, or at checkout. |
| Workspace content | Contacts, lead sources, notes, segments, campaigns, message templates, attached files. | You or your team upload, sync, or create it inside the product. |
| Behavioral & device | IP address, browser, OS, page paths, click events, error reports, session timing. | Automatically by our app, with strictly necessary cookies; see the Cookie Policy. |
| Derived & AI | Predictive seller scores, lead-quality bands, AI-drafted message suggestions, intent labels. | Computed from your workspace content; never sold; see Automated Decision-Making below. |
How we use personal information
We use personal information to operate, secure, support, bill for, and improve the Service; to communicate with you about your account and product updates; to detect and prevent fraud and abuse; and to comply with our legal obligations. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Workspace content uploaded by customers is used solely to deliver the Service to that customer. We do not use one customer's workspace content to train foundation models or improve features for another customer. Aggregate, de-identified statistics may be used to monitor product health and to publish high-level usage metrics.
Legal bases for processing (GDPR Art. 6)
Where the EU/UK GDPR applies, we rely on the following legal bases for processing personal information about controllers (account, billing, behavioral and marketing-site data):
| Purpose | Legal basis (Art. 6) |
|---|---|
| Provide the Service you have signed up for, including authentication and billing. | Performance of a contract - Art. 6(1)(b). |
| Secure the Service, prevent fraud, monitor abuse, maintain audit logs. | Legitimate interests - Art. 6(1)(f) - in operating a safe service. |
| Send service-related and transactional emails (receipts, security alerts). | Performance of a contract - Art. 6(1)(b). |
| Send product news or marketing emails to non-customer prospects. | Consent - Art. 6(1)(a) - withdrawable any time. |
| Comply with tax, accounting, and other legal obligations. | Legal obligation - Art. 6(1)(c). |
For workspace content processed on behalf of a customer, the customer (as controller) is responsible for identifying the legal basis for its own processing. The DPA sets out our role as processor.
Where your information is stored
Production data is hosted on managed virtual private servers operated by Hostinger; the current server region is listed on the Sub-processors page. Customer Data and account data are encrypted in transit using TLS. Database backups are taken regularly and stored off-site, separate from the production server, for disaster recovery.
Some operational data (logs, error traces) and integration data may transit through service providers in other regions. Where personal data of EEA, UK, or Swiss data subjects is transferred outside its origin region, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) to provide an adequate level of protection. Customers receive these clauses automatically through the DPA.
Who sees your information
Inside your workspace, your information is visible to your Authorized Users according to the roles and permissions you configure. Yapii personnel access workspace data only on a least-privilege basis - for example, when responding to a support ticket you have raised, or when investigating a security incident - and all such access is logged and reviewed.
We share personal information with vetted Sub-processors that help us deliver the Service (see Subprocessors below), with professional advisors under confidentiality, and where required by law (subpoenas, court orders, or other lawful requests). Where lawful, we will notify the affected customer before disclosing their workspace data in response to a government request.
Retention periods
Updated 2026-07-04We retain personal information only as long as necessary for the purposes described in this Policy, then delete or aggregate it.
| Category | Retention |
|---|---|
| Active account & workspace content | For the duration of the subscription. After cancellation, a final export is available for 30 days; data is removed from production within 30 days and from backups within 90 days. |
| Billing records and invoices | Up to 7 years after the transaction, to satisfy tax and accounting obligations. |
| Authentication and security logs | Up to 18 months in active systems; longer in cold storage if required for an open investigation. |
| Marketing-site analytics | Aggregated event counts retained up to 13 months. Raw events purged within 90 days. |
| Suppressed contacts (opt-outs) | Retained indefinitely as a hash, so we never re-message someone who has opted out. See the AUP. |
| Support correspondence | Retained for 24 months after closure of the ticket. |
Your rights
Depending on where you live, you may have the right to access, correct, port, delete, restrict, or object to processing of your personal information, and to withdraw any consent you have given. You can exercise most of these rights directly inside the product, or by emailing privacy@yapii.com.
We will verify your identity before responding (typically by confirming control of the email on the account) and respond within 30 days, or 45 days if your request is complex, in which case we will tell you why more time is needed. You may also lodge a complaint with your local supervisory authority - but we hope you'll give us a chance to resolve it first.
If your personal information is held in a Yapii customer's workspace, please direct your request to that customer. We will assist them in responding within the timelines required by law, as described in the DPA.
Region-specific disclosures
Updated 2026-08-26California (CCPA / CPRA)
California residents have the right to know what personal information we collect, to access and delete that information, to correct inaccuracies, and to opt out of "sale" or "sharing" of personal information. Yapii does not sell personal information and does not share it for cross-context behavioral advertising. We do not knowingly collect personal information of consumers under 16 without affirmative consent. To exercise your rights, email privacy@yapii.com or use the in-product privacy form.
EEA, UK, and Switzerland (GDPR / UK GDPR / FADP)
Residents of these regions have the rights described under "Your rights" above, including the right to lodge a complaint with a supervisory authority. Our EU representative under Art. 27 GDPR can be reached at eu-rep@yapii.com. International transfers rely on Standard Contractual Clauses; copies of the relevant clauses are available on request.
Canada (PIPEDA)
Canadian residents may direct privacy questions, access requests, and challenges to our compliance with PIPEDA to privacy@yapii.com. We will respond within 30 days. Our privacy practices are designed to meet PIPEDA's accountability, consent, and openness principles.
Automated decision-making & AI
Yapii's predictive seller scores, lead-quality bands, and AI-drafted message suggestions are produced by machine-learning models that combine workspace content, market signals, and behavioral signals. These outputs are decision-support: a Yapii user (a real estate agent or operator) decides what to do with them. The outputs do not produce legal or similarly significant effects on data subjects without human review.
Workspace administrators can disable predictive scoring per workspace in Settings → AI. Individual contacts can be excluded from scoring at the contact level. Our models are evaluated for bias and drift on a recurring basis, and we publish a high-level model card on request.
We do not use customer workspace content to train foundation models for other customers. When we use third-party LLM providers, we contractually require them to process content as a data processor (no training, short retention) and we list them as Sub-processors in the DPA.
Subprocessors
Updated 2026-08-26We engage a small set of vetted Sub-processors to deliver the Service. The current list includes Hostinger (production hosting), Google (backup storage), Stripe (billing), Twilio (SMS and voice), Vapi (AI voice calls), Mailgun (transactional and broadcast email), Scrape.do (property and listing data retrieval), and OpenAI and OfoxAI (LLM inference for AI features).
The up-to-date list, processing purpose, and processing location for each Sub-processor is maintained on the Sub-processors page. Customers may subscribe to advance notification of changes.
Security incident notification
Yapii maintains a written security incident response plan that defines roles, severity levels, communication procedures, and post-incident review. We monitor our environment continuously and run tabletop exercises against the plan.
If we determine that a confirmed personal data breach affects your account, we will notify you without undue delay, and in any event within 72 hours of confirmation, with the information required by applicable law: nature of the breach, categories and approximate number of records affected, likely consequences, and the measures taken or proposed to address it. The same timeline applies to customers in the DPA.
Children's privacy
The Service is intended for business use by real estate professionals and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@yapii.com and we will delete the information promptly.
Changes to this Policy
We may update this Policy to reflect changes to the Service, our practices, or legal requirements. If a change is material, we will provide at least 30 days' advance notice by email and an in-product banner before the change takes effect. The "Effective" date at the top of the Policy reflects the most recent version.
Contact us / DPO
Privacy questions, requests, and complaints can be sent to privacy@yapii.com. Our Data Protection Officer can be reached at dpo@yapii.com. Our EU representative under Article 27 GDPR can be reached at eu-rep@yapii.com.
Postal mail: Yapii LLC, Attention: Privacy, 1883 W Royal Hunte Dr, Ste 200A, Cedar City, UT 84720, United States.
Change history
Meaningful updates to this document, most recent first. Minor copy edits and typo fixes aren't tracked here.
- Region-specific disclosures
Added a Texas Data Privacy and Security Act notice and refreshed the EU Art. 27 representative contact.
- Subprocessors
Corrected the sub-processor list to reflect the platform's actual providers.
- Retention periods
Reduced default marketing-site analytics retention from 24 months to 13 months.
This document is provided as a plain-English template to help you understand how Yapii operates. It is not legal advice, and it is not a substitute for review by your own counsel. Please have your attorney review before relying on it for a binding obligation or compliance decision.
Questions? Email legal@yapii.com.