Legal · privacy

Privacy Policy

Effective April 1, 2026 · Last updated August 26, 2026

This Privacy Policy explains what personal information Yapii LLC ("Yapii", "we", "us") collects, why we collect it, how we use and share it, and the controls available to you. It applies to the Yapii product, the marketing site at yapii.com, our mobile applications, and any related services. For details on how Yapii processes personal data on behalf of customers under the Terms of Service, see the Data Processing Addendum.

Scope of this policy

This Policy describes how we handle personal information in two distinct roles. As a "controller", Yapii determines the purposes and means of processing personal information about visitors to our marketing site, prospective customers, billing contacts, and account administrators. As a "processor" (or "service provider"), Yapii handles personal information that customers upload to their workspaces (such as their own contacts and leads) on behalf of, and according to the documented instructions of, those customers.

When Yapii acts as a processor, our customer is the controller of that data. The contractual terms in the DPA take precedence over this Policy for that processing, and individuals should direct privacy requests about workspace data to the relevant Yapii customer.

Categories of personal information

We collect personal information from four broad sources: data you give us directly, data your workspace generates as you use the product, behavioral and device signals collected automatically, and data we infer through modeling.

SourceExamplesHow collected
Account & billingName, work email, hashed password, role, billing contact, plan, payment last-4 (via Stripe).You provide it on sign-up, in Settings, or at checkout.
Workspace contentContacts, lead sources, notes, segments, campaigns, message templates, attached files.You or your team upload, sync, or create it inside the product.
Behavioral & deviceIP address, browser, OS, page paths, click events, error reports, session timing.Automatically by our app, with strictly necessary cookies; see the Cookie Policy.
Derived & AIPredictive seller scores, lead-quality bands, AI-drafted message suggestions, intent labels.Computed from your workspace content; never sold; see Automated Decision-Making below.

How we use personal information

We use personal information to operate, secure, support, bill for, and improve the Service; to communicate with you about your account and product updates; to detect and prevent fraud and abuse; and to comply with our legal obligations. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Workspace content uploaded by customers is used solely to deliver the Service to that customer. We do not use one customer's workspace content to train foundation models or improve features for another customer. Aggregate, de-identified statistics may be used to monitor product health and to publish high-level usage metrics.

Where your information is stored

Production data is hosted on managed virtual private servers operated by Hostinger; the current server region is listed on the Sub-processors page. Customer Data and account data are encrypted in transit using TLS. Database backups are taken regularly and stored off-site, separate from the production server, for disaster recovery.

Some operational data (logs, error traces) and integration data may transit through service providers in other regions. Where personal data of EEA, UK, or Swiss data subjects is transferred outside its origin region, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) to provide an adequate level of protection. Customers receive these clauses automatically through the DPA.

Who sees your information

Inside your workspace, your information is visible to your Authorized Users according to the roles and permissions you configure. Yapii personnel access workspace data only on a least-privilege basis - for example, when responding to a support ticket you have raised, or when investigating a security incident - and all such access is logged and reviewed.

We share personal information with vetted Sub-processors that help us deliver the Service (see Subprocessors below), with professional advisors under confidentiality, and where required by law (subpoenas, court orders, or other lawful requests). Where lawful, we will notify the affected customer before disclosing their workspace data in response to a government request.

Retention periods

Updated 2026-07-04

We retain personal information only as long as necessary for the purposes described in this Policy, then delete or aggregate it.

CategoryRetention
Active account & workspace contentFor the duration of the subscription. After cancellation, a final export is available for 30 days; data is removed from production within 30 days and from backups within 90 days.
Billing records and invoicesUp to 7 years after the transaction, to satisfy tax and accounting obligations.
Authentication and security logsUp to 18 months in active systems; longer in cold storage if required for an open investigation.
Marketing-site analyticsAggregated event counts retained up to 13 months. Raw events purged within 90 days.
Suppressed contacts (opt-outs)Retained indefinitely as a hash, so we never re-message someone who has opted out. See the AUP.
Support correspondenceRetained for 24 months after closure of the ticket.

Your rights

Depending on where you live, you may have the right to access, correct, port, delete, restrict, or object to processing of your personal information, and to withdraw any consent you have given. You can exercise most of these rights directly inside the product, or by emailing privacy@yapii.com.

We will verify your identity before responding (typically by confirming control of the email on the account) and respond within 30 days, or 45 days if your request is complex, in which case we will tell you why more time is needed. You may also lodge a complaint with your local supervisory authority - but we hope you'll give us a chance to resolve it first.

If your personal information is held in a Yapii customer's workspace, please direct your request to that customer. We will assist them in responding within the timelines required by law, as described in the DPA.

Region-specific disclosures

Updated 2026-08-26

California (CCPA / CPRA)

California residents have the right to know what personal information we collect, to access and delete that information, to correct inaccuracies, and to opt out of "sale" or "sharing" of personal information. Yapii does not sell personal information and does not share it for cross-context behavioral advertising. We do not knowingly collect personal information of consumers under 16 without affirmative consent. To exercise your rights, email privacy@yapii.com or use the in-product privacy form.

EEA, UK, and Switzerland (GDPR / UK GDPR / FADP)

Residents of these regions have the rights described under "Your rights" above, including the right to lodge a complaint with a supervisory authority. Our EU representative under Art. 27 GDPR can be reached at eu-rep@yapii.com. International transfers rely on Standard Contractual Clauses; copies of the relevant clauses are available on request.

Canada (PIPEDA)

Canadian residents may direct privacy questions, access requests, and challenges to our compliance with PIPEDA to privacy@yapii.com. We will respond within 30 days. Our privacy practices are designed to meet PIPEDA's accountability, consent, and openness principles.

Automated decision-making & AI

Yapii's predictive seller scores, lead-quality bands, and AI-drafted message suggestions are produced by machine-learning models that combine workspace content, market signals, and behavioral signals. These outputs are decision-support: a Yapii user (a real estate agent or operator) decides what to do with them. The outputs do not produce legal or similarly significant effects on data subjects without human review.

Workspace administrators can disable predictive scoring per workspace in Settings → AI. Individual contacts can be excluded from scoring at the contact level. Our models are evaluated for bias and drift on a recurring basis, and we publish a high-level model card on request.

We do not use customer workspace content to train foundation models for other customers. When we use third-party LLM providers, we contractually require them to process content as a data processor (no training, short retention) and we list them as Sub-processors in the DPA.

Subprocessors

Updated 2026-08-26

We engage a small set of vetted Sub-processors to deliver the Service. The current list includes Hostinger (production hosting), Google (backup storage), Stripe (billing), Twilio (SMS and voice), Vapi (AI voice calls), Mailgun (transactional and broadcast email), Scrape.do (property and listing data retrieval), and OpenAI and OfoxAI (LLM inference for AI features).

The up-to-date list, processing purpose, and processing location for each Sub-processor is maintained on the Sub-processors page. Customers may subscribe to advance notification of changes.

Cookies and similar technologies

We use a minimal set of strictly necessary and functional cookies to keep you signed in and to remember your preferences. We do not run third-party advertising trackers or cross-site profiling cookies in the product.

For the per-cookie list, retention, and how to manage cookies in your browser, see the Cookie Policy.

Security incident notification

Yapii maintains a written security incident response plan that defines roles, severity levels, communication procedures, and post-incident review. We monitor our environment continuously and run tabletop exercises against the plan.

If we determine that a confirmed personal data breach affects your account, we will notify you without undue delay, and in any event within 72 hours of confirmation, with the information required by applicable law: nature of the breach, categories and approximate number of records affected, likely consequences, and the measures taken or proposed to address it. The same timeline applies to customers in the DPA.

Children's privacy

The Service is intended for business use by real estate professionals and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@yapii.com and we will delete the information promptly.

Changes to this Policy

We may update this Policy to reflect changes to the Service, our practices, or legal requirements. If a change is material, we will provide at least 30 days' advance notice by email and an in-product banner before the change takes effect. The "Effective" date at the top of the Policy reflects the most recent version.

Contact us / DPO

Privacy questions, requests, and complaints can be sent to privacy@yapii.com. Our Data Protection Officer can be reached at dpo@yapii.com. Our EU representative under Article 27 GDPR can be reached at eu-rep@yapii.com.

Postal mail: Yapii LLC, Attention: Privacy, 1883 W Royal Hunte Dr, Ste 200A, Cedar City, UT 84720, United States.

Change history

Meaningful updates to this document, most recent first. Minor copy edits and typo fixes aren't tracked here.

  1. Region-specific disclosures

    Added a Texas Data Privacy and Security Act notice and refreshed the EU Art. 27 representative contact.

  2. Subprocessors

    Corrected the sub-processor list to reflect the platform's actual providers.

  3. Retention periods

    Reduced default marketing-site analytics retention from 24 months to 13 months.

This document is provided as a plain-English template to help you understand how Yapii operates. It is not legal advice, and it is not a substitute for review by your own counsel. Please have your attorney review before relying on it for a binding obligation or compliance decision.

Questions? Email legal@yapii.com.