REI Boss — Legal
Privacy Policy
Last updated: June 11, 2026
1. Who we are and what this policy covers
REI Boss, Inc., a Delaware corporation doing business as “REI Boss” (“REI Boss,” “we,” “us,” or “our”), provides back-office operations support and informational software to real estate investors and operators. This Privacy Policy explains what personal information we collect through our website at reiboss.ai and our client application, how and why we use it, who we share it with, how long we keep it, how we protect it, and the choices and rights you have.
This policy applies to people who visit our website, submit our forms, and use our services. It does not apply to third-party websites or services we link to, which have their own privacy practices.
2. Information we collect
(a) Information you give us through our website and forms
When you submit our “bring us a deal” form, our checklist request, or otherwise contact us, we collect the information you provide, which may include your name, business name, email address, phone number, the markets you operate in, the number of doors and notes you hold, deals in flight, deal type, the property address or city, your intended exit, and any free-text you share about your back-office needs.
(b) Information we process when you become a client
To run your back office, you or the platforms you authorize give us financial and operational records, which may include loan and mortgage balances, payment history, ledgers, escrow and tax data, insurance policy details, investor reports, property records, and tenant, lease, and rent records. Where you choose to connect a financial account, we receive bank-account information through Plaid (see Section 8). Some of this information relates to your borrowers, note-payors, sellers, or tenants; you are responsible for having the rights and consents needed to share it with us.
(c) Information we collect automatically
When you use our website or application, we automatically collect limited technical data such as your IP address, device and browser type, and log and usage data, through cookies and similar technologies (see Section 4).
(d) Information from other sources
We receive information from the platforms you authorize us to access on your behalf (for example, Money Lender Pro, Innago, and Plaid) and from our service providers that help us operate (for example, our CRM and email and messaging providers).
3. Sources of information
We collect personal information (1) directly from you when you submit a form, create an account, or upload documents; (2) from financial accounts and platforms you connect or authorize us to access on your behalf; and (3) automatically from your device when you use our site or application.
4. How we use your information
We use your personal information to:
- respond to your inquiry and evaluate whether REI Boss is a fit;
- provide the back-office operations, deal reads, and portfolio monitoring you engage us for;
- perform document, title, insurance, utilities, and servicing-handoff coordination at your direction;
- communicate with you by email, phone, and text message about your inquiry, your account, and our services;
- process payments and manage billing;
- secure our systems, prevent fraud, debug, and improve our services; and
- comply with our legal, tax, and recordkeeping obligations.
We do not use your information for cross-context behavioral advertising, we do not sell it, and we use your sensitive financial-account information only to provide the services you requested.
5. Cookies and tracking technologies
Our website uses a small number of cookies and similar technologies that are strictly necessary to run the site and our lead and contact forms, which are hosted by our CRM provider, GoHighLevel / LeadConnector. These remember your form session and help pages load correctly. We do not use third-party advertising cookies, behavioral-ad pixels, or cross-site advertising trackers, and we do not currently use Google Analytics or comparable analytics tools. If we add analytics in the future, we will update this section and, where required, provide a cookie control.
Our website currently loads its typefaces (Geist and Geist Mono) from Google Fonts’ content-delivery network. When your browser requests these fonts, Google receives your IP address and standard request data in order to serve the font files. We are working to self-host these fonts to remove this third-party request.
You can block or delete cookies in your browser settings; our contact forms may not function without strictly-necessary cookies. We honor recognized browser opt-out preference signals such as Global Privacy Control (see Section 13).
6. How we share your information
We share personal information only with vendors that process it on our behalf under contracts that prohibit them from selling it, using it for their own purposes, or combining it with data from other sources. Under California and other state laws, these vendors are our “service providers,” “contractors,” or “processors,” and their receipt of personal information for these purposes is not a “sale” or “share.” Our service providers and sub-processors include:
| Service provider | Role |
|---|---|
| GoHighLevel / LeadConnector | CRM; email, SMS, and call follow-up for inquiries you submit |
| Resend | Transactional email |
| Cloudflare; Vercel | Website and application hosting, content delivery, and security |
| Supabase | Database and authentication for the application |
| Plaid Inc. | Secure bank and financial-account connectivity (account aggregation), used only with your consent — see plaid.com/legal |
| Google Workspace | Internal document handling and storage |
| ClickUp | Internal operations and task management |
| Innago | Rental and lease records, for clients who use it |
| AI processing provider(s) | Power software features and deal reads under contract; not permitted to use your data to train general models except as needed to provide the service to us |
We may also disclose information (1) to comply with law, legal process, or a lawful request; (2) to protect the rights, safety, or property of REI Boss, our clients, or others; (3) to our professional advisors; and (4) in connection with a merger, financing, acquisition, or sale of assets, subject to this policy. A current list of our sub-processors is available on request at privacy@reiboss.ai, and for paying clients we will provide advance notice of material changes to our sub-processors.
We do not sell or share your information
We do not sell your personal information for money or other valuable consideration, and we have not done so in the preceding 12 months. We do not share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. Because we do not sell or share personal information, we do not provide a “Do Not Sell or Share My Personal Information” link.
7. Financial information and data security
To run your back office we handle nonpublic personal financial information, which may include bank-account connections (via Plaid), mortgage and note balances, payment history, ledgers, escrow and tax data, insurance policy details, investor reports, and property, lease, and rent records. We use this information only to provide and improve the services you engage us for. We do not sell your financial information, and we do not share it with anyone outside REI Boss for their own marketing. We share it only with the service providers in Section 6 under contracts that require them to protect it and use it only on our instructions.
Our security commitments
We maintain a written information-security program designed to meet the standard of the FTC Safeguards Rule (16 C.F.R. Part 314). A designated individual oversees it. We encrypt your information in transit and at rest, require multi-factor authentication for access to systems holding customer information, limit access on a need-to-know basis, log and monitor access, and securely dispose of information we no longer need. We connect to your bank data through Plaid using read-only, token-based access — we do not store your bank or financial-institution login credentials. We require our service providers to maintain comparable safeguards by contract. No system is perfectly secure, and we cannot guarantee against every threat, but we work to protect your information and to improve our controls over time.
Not a credit bureau or lender
REI Boss is not a consumer reporting agency under the Fair Credit Reporting Act, and our deal assessments and reports are not consumer reports. We provide operational and informational support to you about your own transactions and portfolio. We do not assemble or evaluate information to furnish consumer reports to third parties, and you may not use our materials for any decision about a person’s eligibility for credit, insurance, employment, or housing. REI Boss is not a lender, loan servicer, or escrow agent.
8. Bank and financial-account connections (Plaid)
When you choose to connect a bank, lender, or other financial account to REI Boss, we use Plaid Inc. (“Plaid”) to securely facilitate that connection. Plaid is an independent third-party service provider; REI Boss is not a bank and does not see or store your account login credentials.
With your authorization, Plaid accesses information from the accounts you connect so we can provide portfolio monitoring. Depending on the account, this can include account identifiers (such as financial-institution name, account name and type, and account and routing numbers), current and available balances, transaction history, and loan or mortgage details (such as balances owed, payment amounts and dates, interest rate, and repayment status). We use this information only to provide and support the REI Boss monitoring and reporting services you have asked for. We do not sell it, and we do not use it for advertising. If we ever use de-identified or aggregated account data for any other purpose, we will disclose that use clearly and consistent with Plaid’s End User Privacy Policy.
By connecting an account, you agree to Plaid’s End User Privacy Policy, available at plaid.com/legal, which explains how Plaid collects, uses, and shares your data; you will also be asked to review and agree to it inside Plaid’s secure connection window before any account is linked. You can disconnect any account and revoke REI Boss’s access at any time from your account settings or directly through Plaid at my.plaid.com. To keep monitoring active, you may be asked to reconnect each account at least once every 12 months. If you disconnect an account, we stop receiving new data from it.
9. Phone calls and text messaging
When you give us your phone number and consent to be contacted, you authorize REI Boss and our messaging provider (GoHighLevel / LeadConnector) to contact you by phone call and SMS/text message, including with automated technology, about your deal read, your account, and REI Boss services. Message frequency varies. Message and data rates may apply. Reply STOP to any text to opt out, and HELP for help. Consent is not a condition of any purchase.
No mobile information — your phone number, opt-in, or consent — will be shared with or sold to third parties or affiliates for their own marketing or promotional purposes. Text-message opt-in data and consent are shared only with the subcontractors and providers (such as GoHighLevel / LeadConnector and the underlying carrier or aggregator) that help us deliver the messaging service. To stop texts, reply STOP; to stop calls, tell us by phone, text, or email at privacy@reiboss.ai. We honor opt-out requests within 10 business days. We keep a record of your consent — the date, the consent language you agreed to, and the phone number you provided — to document your authorization and honor your preferences.
10. Email communications
We send transactional and relationship emails (for example, account, login, and service notices) and, where you have opted in, occasional informational and marketing emails. Every marketing email identifies us, includes our physical mailing address, and offers a working way to unsubscribe; we honor unsubscribe requests promptly and within 10 business days. If you unsubscribe, we suppress your address across our lists and will not sell, rent, or transfer it to anyone for their own marketing.
11. Sensitive information and consent
Some information we process for paying clients is treated as “sensitive” under state privacy laws — including financial-account numbers and the bank-account information you connect through Plaid, and (if ever collected) precise geolocation. We collect and use this information only with your affirmative consent and only as reasonably necessary to deliver the services you ask us to perform, such as portfolio monitoring, ledger reconciliation, and deal reads. We do not use it to infer characteristics about you, we do not sell or share it, and we do not use it for advertising. You may withdraw consent at any time by emailing privacy@reiboss.ai; withdrawing consent may limit our ability to provide certain services.
12. Data retention
We keep personal information only for as long as reasonably necessary for the purposes described in this policy and to meet our legal, tax, accounting, and recordkeeping obligations, then we delete or de-identify it. Our general approach:
- Lead and inquiry information (name, email, phone, and deal details submitted through our forms): retained while we are in active contact and for up to 24 months after our last interaction, unless you ask us to delete it sooner;
- Client account and service records (portfolio, loan, ledger, escrow, insurance, and document records, including investor reports): retained for the term of your engagement and for up to 7 years afterward to meet recordkeeping, tax, and dispute-resolution needs, except where law requires longer;
- Financial-account connection data accessed through Plaid: retained only as long as the connection is active and as needed to provide the service, after which we delete or direct deletion of that data; and
- Operational and security logs: retained for up to 24 months.
You may request deletion of your information at privacy@reiboss.ai, subject to the exceptions above.
13. Your privacy rights
Depending on where you live, U.S. state privacy laws (including in California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states) may give you the right to:
- confirm whether we process your personal information and access it;
- correct inaccurate personal information;
- delete personal information;
- obtain a portable copy of personal information you provided;
- opt out of any “sale” or “sharing” of personal information, targeted advertising, and certain profiling (we do none of these);
- limit our use of your sensitive personal information to what is necessary to provide our services (we already limit it in this way); and
- not be discriminated or retaliated against for exercising these rights.
How to exercise your rights
Email privacy@reiboss.ai (you can use the subject line “Privacy Request”) and tell us which right you wish to exercise. We will verify your identity using information already associated with you and will not require you to create an account to make a request. You may use an authorized agent, who must provide your written permission and whose authority we may verify directly with you. We will respond within the time required by law — generally 45 days, with one extension where reasonably necessary, and we will tell you why. We do not charge a fee, except for manifestly unfounded or excessive requests as the law permits.
Appeals
If we decline your request, you may appeal by replying to our decision or writing privacy@reiboss.ai. We will respond to your appeal within 60 days and, where required, give you a way to contact your state Attorney General.
Opt-out preference signals (Global Privacy Control)
Because we do not sell your personal information or share it for cross-context behavioral advertising, there is nothing to opt out of in that respect. If we ever introduce such activities, we will treat a Global Privacy Control (GPC) or other recognized opt-out preference signal sent by your browser or device as a valid request to opt out, and we will display confirmation that your opt-out has been honored.
Your California privacy rights
This subsection applies to California residents. REI Boss is an early-stage company and does not currently meet the thresholds that make it a “business” under the California Consumer Privacy Act (CCPA), as amended by the CPRA. We nonetheless describe our practices here and will honor the rights above as a matter of policy. The categories of personal information we collect, our sources, the purposes for which we use it, and the categories of third parties to whom we disclose it are described throughout this policy and summarized in the Notice at Collection table in Section 14. We do not sell your personal information or share it for cross-context behavioral advertising. When you use our software, we may process information that California law treats as sensitive personal information — specifically, financial-account numbers and account log-in credentials used to connect your accounts. We use and disclose this information only to perform the services you requested and as permitted by Civil Code § 1798.121; we do not use it to infer characteristics about you, so we are not required to offer a “Limit the Use of My Sensitive Personal Information” option. If our practices ever change, we will provide that choice.
14. Notice at Collection (California)
The following table summarizes, by statutory category under California Civil Code § 1798.140(v)(1), the personal information we collect, our sources, the purposes, whether we sell or share it, and how long we keep it.
| Category | Examples | Source | Purpose | Sold / shared? | Retention |
|---|---|---|---|---|---|
| (A) Identifiers | Name, email, phone, account name, IP address | You; your device | Respond to inquiries; account; service delivery; communicate | No / No | Leads: up to 24 mo. after last contact; account: life of account + 7 yrs |
| (B) Customer records (§ 1798.80(e)) | Loan/note balances, payment history, ledgers, escrow, investor reports, insurance, property records | You; connected accounts (Plaid); Money Lender Pro; Innago | Provide the back-office service; monitoring; document chase | No / No | Engagement + 7 yrs |
| (D) Commercial information | Markets, doors/notes held, deals in flight, deal type, exit strategy, services purchased | You (forms) | Evaluate deals; informational deal reads; service delivery | No / No | Leads: 24 mo.; clients: engagement + 7 yrs |
| (F) Internet / network activity | Site interaction and log data | Your device | Operate, secure, and improve the site/app | No / No | 12–24 mo. |
| (G) Geolocation (general, not precise) | Deal address or city; markets | You (forms) | Deal evaluation; service delivery | No / No | As above |
| (K) Inferences | Green / yellow / red deal-read assessment | Generated by us from the above | Provide informational assessment to you | No / No | Engagement + 7 yrs |
| Sensitive PI (§ 1798.140(ae)(1)(D)) | Financial-account numbers; account login credentials (bank connections via Plaid) | You; your connected accounts | Only to provide the requested service; not used to infer characteristics | No / No | Life of engagement; access tokens revoked at offboarding |
15. Children’s privacy
REI Boss is a business-to-business service intended only for businesses and individuals who are at least 18 years old. Our website and application are not directed to children, and we do not knowingly collect personal information from anyone under 18. Consistent with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from any child under 13. If you believe a minor has provided us personal information, contact privacy@reiboss.ai and we will delete it.
16. International users
REI Boss is based in the United States, and our services are intended only for users located in the United States. We do not target, market to, or offer our services to individuals in the European Union, the United Kingdom, or other jurisdictions outside the United States, and we do not monitor the behavior of individuals in those regions. If you access our website or submit information from outside the United States, you do so on your own initiative, you are responsible for compliance with local law, and you consent to your information being transferred to, stored in, and processed in the United States, where data-protection laws may differ from those in your jurisdiction.
17. Changes to this policy and security-incident notification
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, where required by law or where the changes are material, provide additional notice. Your continued use of our services after an update means you accept the revised policy.
If we determine that a security incident has compromised your personal information, we will notify you and any applicable regulators as required by, and within the timeframes set by, applicable law, and without unreasonable delay.
18. How to contact us
For any privacy question or request, contact us at:
REI Boss, Inc.
Privacy: privacy@reiboss.ai
Mailing address: 16192 Coastal Highway, Lewes, DE 19958