Privacy

Last updated 12 August 2026.

This page describes what VestorsHub records, why it records it, and who can see it. It describes the product as it actually works today. Where something does not exist yet — email delivery, text messages, payments — it says so instead of describing an intention.

Your account

Creating an account stores your email address, your name if you give one, a hashed password, and your role on the platform. You can browse the deal board at /marketplace without an account; the pages that hold your own state require one.

Signing in with Google.Choosing “Continue with Google” on the sign-in or create-account page hands us the name, email address and profile-picture URL on your Google account, plus the opaque account identifier Google uses for you and the access token it issues. We store those, linked to your VestorsHub account, so that the next sign-in recognises you. We do not ask Google for anything beyond your name, email address and picture, and we never use the token to read anything else.

Signing in with Apple.Choosing “Continue with Apple” hands us the opaque account identifier Apple uses for you and an email address, and we store both, linked to your VestorsHub account, so that the next sign-in recognises you. Two things are different from Google and both are worth stating plainly. We never receive your name.Apple sends it only once, on the very first authorisation, in a field separate from the identity token, and the code we use to read that token does not look at it — so no name from Apple is ever stored, and an account created this way has none until you set one. The email address may not be your real one.If you choose “Hide My Email”, Apple gives us a forwarding address at privaterelay.appleid.com instead, and that relay address is the only one we hold. We receive no profile picture, and we ask Apple for nothing else.

An account created either way has no password, and gets the same role — buyer — as one created with an email address and a password. Signing in with Google or Apple using an address that already has a password account does not merge the two: it is refused, so that control of a mailbox at a provider cannot take over an account here.

Your password, and the one thing we record about it. You can change it at /security. We never store the password itself — only a bcrypt hash of it, which is what your sign-in is checked against. When you change it we additionally store the date and time you did, and nothing else: not the old hash, not where you were, not what the password was. That timestamp exists so that page can tell you when the password last moved, which is how you would notice a change you did not make. An account that has never changed its password has no such timestamp, and the page says so rather than guessing a date.

We keep no record of your sessions, and cannot end them. Being signed in is a signed token your browser holds; there is no table of sessions, devices or sign-in locations anywhere in our database. That means we cannot show you a list of where you are signed in, and changing your password does not sign other browsers out. It also means we hold nothing about which devices you use. The trade is stated on /security rather than left for you to discover.

Signing in inside the iPhone app writes one short-lived row. When you choose Google or Apple in the app, the sign-in happens in a system browser window rather than inside the app, and those two are separate as far as your phone is concerned. To carry the result across, we store a single random code — hashed, never in readable form — next to your account for sixty seconds. The app redeems it once, and it can never be redeemed again. It records no device, no location and no network address, and it is not a session: it is the one thing that has to cross between the two windows, and it is worthless a minute later. This does not happen on the website, where there is nothing to cross.

Being invited to somebody's team

A company on VestorsHub can invite you to their team by email address, and we store that address before you have agreed to anything. The invitation holds: the address they typed, the access level they chose for you, the person who invited you, when, and when it stops working. If you already have an account with us, none of that is linked to it until you accept.

We do not email you. There is no mail or messaging system in this product at all, so an invitation reaches you only because the person who created it sent you the link themselves, over whatever they normally use. Nothing about the invitation is passed to any third party.

Accepting is your decision and it is never made for you. If the address already has an account, we ask you to sign in and press a button; we will not add an account to a company on the strength of a link somebody forwarded. If it does not, the account is created at that address and no other. Declining is one press, needs no account, and stores only the fact that this invitation was refused.

An invitation is never deleted, and neither is what became of it. Accepted, declined, withdrawn or expired — the row stays, so the company can see what they asked and what the answer was. We never store the link itself, only a one-way digest of it, which is why nobody here can read one back to you.

If you are removed from a team, the membership is deleted and you keep your account, your email address and everything you did with it. Removal does not tell us anything new about you.

Deals you open

We record every view of a deal detail page.Each view is stored as its own event containing: which deal was opened, when, the page you came from (your browser’s referrer), your browser’s user-agent string, and a random per-visit identifier we use so that refreshing a page is not counted twice. That identifier lives in your browser tab and disappears when you close it.

If you are signed in, the view is recorded against your account. That makes it a record of which off-market deals you personally looked at. If you are not signed in, the same event is recorded with no account identifier attached.

We keep these events because they are how we measure demand for a deal — how many people opened it, and how quickly. That measurement is about the deal rather than about you, which is also why the events survive account deletion: see Deleting your account below.

Our staff can also see the recent listings a single account has opened. An internal admin page shows, for one account at a time, the most recent deals recorded against it. We use it to tell a real buyer from an automated one and to answer questions about an account. It is not shown to sellers, to other buyers, or to anyone outside this company, and it is not used to contact you — nothing on this platform sends you a message about a deal you looked at. This paragraph was added when that page was built: the sentence above it is true of how we measure demand, and on its own it would have understated what a person here can look up.

These events are ours. They are not the view count shown on a mirrored listing, which is the originating wholesaler’s own number.

Saved deals, buy boxes and saved searches

Deals you save, the buy boxes you define, and legacy property searches you save are private to your account. Nobody browsing the site can see them, and no other user can.

Staff can see counts, never boxes.Our internal demand view reports aggregates — how many buyers have a given state, price band or property type somewhere in a buy box — and it is built from grouped counts. It never loads an individual box, a box name or a user identifier, and any bucket covering fewer than five buyers is not published at all, so a count cannot be used to identify one buyer’s strategy.

Saving a mirrored deal is not, and is never presented to anyone as, an expression of interest to the wholesaler who listed it. We do not tell third-party sellers who saved their deals.

Email, and the digest you have not received

VestorsHub does not send email yet. There is no mail delivery in the product at the time of writing. When you choose a digest frequency on a buy box, we record that choice together with the date, the screen it was given on and the exact wording you were shown agreeing to it. That record exists so that when digests are switched on, we can show what you agreed to and when — and so that anyone who did not agree is not emailed.

Buyers are never asked for a phone number.No screen on the buying side collects one, and nothing on that path reads one — when an address is released, what reaches the seller is a name and an email address.

If you post listings, you can choose to give a phone and a WhatsApp number on your profile, and they are published on your listings so a buyer can reach you. They are optional, you can clear them, and no other part of the product reads them.

We have never sent a text message and there is no way for us to. No provider is connected. If that changes we will ask first and record what you agreed to, and this page will say so before anything is sent — and note that we cannot currently receive a reply either, so no “reply to unsubscribe” instruction would work today.

We do not sell or rent your email address or your phone number.

Technical data

Your IP address is used in memory, at the moment of a request, to rate-limit abusive traffic.

It is also written down, permanently, for certain acts on a deal — see Access events below. Until this page was last updated that was not true, and this paragraph used to say so. It changed at the same time as the code did.

Signing in sets a session cookie. The only other cookie is a language preference: if you use the language control, we store the language you chose on your own browser for a year, so that the site keeps opening in it — nothing else is recorded, it is never set unless you press that control, and pressing it again changes or replaces it. The per-visit identifier described above is browser storage, not a cookie.

Photographs you upload to a listing

Photographs on a published listing are public. They are served from an ordinary web address with no sign-in, so anyone holding the link can open one, and search engines may index the page they appear on.

Two things are deliberately kept out of that web address. Your account identifier is not in it— uploads are filed under a random value that means nothing outside our database and cannot be matched to you, or to your other listings, by anyone reading the address. The filename you uploaded is not in it either, because a file called 4812 SW 82nd Ave.jpg would publish the street address the listing itself withholds.

We also remove location metadata from every photograph before storing it. Phones record the exact coordinates a picture was taken at, and on a listing whose address is only given on request, that metadata would give the property away to anyone who downloaded the image.

Documents are not photographs and are not public. Settlement documents are covered separately below; no public web address exists for one.

Access events, and why we keep them

When a signed-in account does certain things on a deal, we write an event recording what was done, when, your IP address, your browser’s user-agent string, the page you came from, and the account that did it. The acts we record are: asking for a property’s street address, receiving it, uploading a document, downloading one, and a member of our team verifying or rejecting a closing.

These records exist to settle arguments about money. Our fee becomes payable when a transaction this platform introduced is verified as having closed, and the whole of what makes that claim checkable is being able to show that two parties met here, on a date, through an act one of them performed. That is also the honest reason we keep the full address rather than a shortened or hashed version: a hash proves two things are equal and nothing else, and we would then be describing it to you as proof of something it cannot prove.

These events are append-only. Nobody at VestorsHub can edit one, including us — the database refuses the change. The single exception is deleting an account, which removes the link to you and leaves the event.

They are used for this and for nothing else. They are not used for advertising, profiling, scoring, or resale, and we do not run third-party analytics on this site.

Changing a listing’s status is recorded the same way. If you sell on this platform, every time you move one of your listings between available, pending, under contract, sold and delisted we write down which listing, the change, when, your account, and the name on your account at that moment— kept as it was then, so a later change of name does not rewrite what earlier records appear to say. When you delist, the sentence you type explaining why is kept with it.

These records exist because our fee depends on your own statement that a sale happened, so the statement itself has to be evidence. They are append-only in the same way: nobody here can edit one or delete one, and the database refuses both.

Deleting your account removes the link to you, exactly as it does for the events above, and leaves the record. One difference is worth stating plainly: the name that was on your account stays on it, because it was copied at the time. A record of who declared something is not worth much without some answer to “who”, so what survives is that name and no longer a link to your account.

We keep them for 7 years from the date of the event. That is how long a fee arising from an introduction could still be disputed.

A property you tell us about

If you fill in the form at Sell a property, we keep what you typed: the address, what you told us your relationship to it is — whether your name is on the deed, whether you can sell it without being on the deed, or whether you are an agent acting for the owner — and then the property itself: what kind it is, roughly when it was built, the condition band you picked, whether anyone is living in it, whether it is already listed with an agent, an asking price if you gave one, and anything you wrote in the notes. If you told us you are an agent, we also keep the licence state, licence number and brokerage as you stated them.

We check the address against a public government geocoder— the United States Census Bureau’s address service — which means the address you type is sent to them. That happens twice: once while you are still on the address step, so we can show you the version they recognise before you go on, and once again when you submit. We keep what came back beside what you typed, and never instead of it, so the record still shows the difference. If they do not recognise it, we accept it anyway. Their data misses real houses, and an address we cannot look up is not a reason to turn somebody away.

The last step creates an account, so we keep your email address, your name and your password the same way as any other account. The form does not ask for a phone number. There is nowhere in this product that a phone number on this kind of account would be read or shown, and asking for one we would then keep and never use is not something we want to do. If one reaches the route behind the form by some other route it is discarded rather than stored, and the reply says so rather than accepting it in silence.

We work out which country you appeared to be in, and we keep that. Every request to this site carries the internet address of the connection it came from. When you submit the form we look that address up in a database of address ranges and countries, keep the country and the name of the database that said so, and we do not keep the address itself. The database sits on our own servers, so nobody outside this company is sent your address in order to answer the question. The database is not ours and its licence asks us to say so wherever we use it, so: IP geolocation by DB-IP (db-ip.com), IP to Country Lite, used under CC BY 4.0.

It is there for one reason: somebody on our team, reading a submission and deciding whether to believe it, can see it. Nothing is refused, blocked, held or delayed because of it. A submission from any country reaches the same queue in the same state it would have reached before we recorded this, and a person decides. We also want to be straight about how much it is worth: it is approximate, it is no more precise than a country, and a VPN, a work network or a phone on a mobile network defeats it completely — and we do not detect any of those. It is a question for a person to hold in mind, not a check that passed.

Submitting the form publishes nothing.It does not create a listing, it does not put your property on the marketplace, and no buyer can see it. What it does is put a record in front of our own team, who are told in the site’s own notifications that a submission arrived — that message names the city and state and not the street address, your name or your email.

Nobody outside this company is told anything about it. We do not contact the owner, an agent, a buyer or anyone else, and at the time of writing this site has no email or text-message provider connected at all, so we cannot write to you either. The screen you see after submitting says so rather than promising a reply.

When somebody on our team looks at a submission, we record who looked, when, and the reason they gavefor the decision. That history cannot be edited or removed once written, for the same reason as the other records on this page: a note of who decided something is only worth having if it cannot be quietly changed afterwards. We also record what our own checks observed about the submission — for example, whether the address had already been submitted by a different account. Those observations are not accusations and are never acted on by themselves; a person reads them.

Nothing here is deleted.A submission’s status changes and the change is kept. No retention period has been set for it— that is the honest position rather than a number we have not decided.

Deleting your account does not remove it. The submission stays, including the address you gave, the notes, and the country we worked out, attached to an account that by then carries no name, no email address and no password. It stays because somebody on our team may already have read and decided on it, and the record of that decision names who and why. It is listed among the things deletion keeps, on the screen where you delete the account and in the section below.

Asking for an address, and what we send the seller

Before we take your first address request you are shown one agreement and asked to tick it. When you do, we record the exact wording you were shown, the moment you agreed, and which account agreed, on your account. We keep the wording itself rather than a reference to it, so that the record still says what you read even if we change the wording later. We show you the agreement again on every request; the date we keep is the first one, and agreeing again does not move it.

Most listings on this site are reproduced from another marketplace, and for those we do not hold the street address at all. When you ask for one, we do not have it to give you — what we do instead is pass your request to the seller, so that they can send it to you directly.

The message we prepare for them contains your name and the email address on your account, together with the listing you asked about. It has to: the seller is being asked to reply to you, and a request with no way to answer it is not a request. Pressing the button is the only thing that prepares it; we do not put your details in front of a seller for any other reason, and your phone number is never in it, because we do not have one.

We keep a copy of each message we prepare — who it was addressed to, what it said, and whether it was ever actually sent. At the time of writing, nothing is sent at all: this site has no email or text-message provider connected, so requests are recorded and held. The page tells you which of those has happened when you press the button rather than implying delivery either way.

The sellers’ own contact details come from the listings they published on the marketplace we reproduce; we did not collect them from the sellers directly.

Who is supplying a listing, and when you can see it

A listing’s page does not tell you who is supplying it, and it tells nobody by default. The supplying company and the name of the disposition rep who published the listing are both shown as Withheld. That is not a decision about you: a listing page is rendered once and the identical copy is served to every visitor for fifteen minutes, so anything printed on it is printed for everyone, signed out included. The two names are left out of that copy altogether rather than merely left off the screen.

Accepting the non-circumvention agreement described above is what reveals them. Once your account has accepted it, opening a listing makes one further request from your browser, and we answer it with the supplying company, the disposition rep, and how many of that company’s listings are on our board. Nobody else gets a different page; you get an addition to the same one. We check the agreement against your account on our side every time, so the answer does not depend on anything your browser claims.

It never includes a phone number or an email address.Accepting the agreement does not release the seller’s direct line or direct email, because we do not publish those on this site at all — not on the listing, not in this answer. What you receive is a company, a person’s name and a count.

Asking for it records nothing. That request writes nothing to your account or to ours: the only thing stored anywhere in this is your acceptance of the agreement, which is described in the section above and is recorded once.

If you are the person named as the disposition rep, this is about you. The name comes from the listing itself — for the listings we reproduce from another marketplace, it is the name that marketplace published on it — and we did not collect it from you. What changed is who can read it here: before this, anyone opening the listing could; now it is buyers who have accepted the agreement.

This is the listing page, and it is not the whole site. The deal board at /marketplace still lets anyone filter by supplying company, and its search box still matches both the company name and the rep’s name, so both are still inside what that page sends to every visitor whether or not they have agreed to anything. We state that here rather than leave the rule above to be read as covering the site, which it does not.

Offers you make

When you make an offer or press Buy now, we record what you offered: the amount, the earnest money you say you will put up, how long you want to close and inspect, how you are funding it, and any note you write. Your account is on that record, and so is the listing.

Nothing about it is sent anywhere.Approaching sellers is switched off on this platform — not because a mail provider is missing, but because contacting a seller requires an authorisation that nobody has granted, and the database refuses to queue a message without one. Your offer is recorded and it stays with us. The screen says so when you press the button, and it says it by reading the record rather than by carrying a stock sentence.

Whether the seller ever seesit depends on whose listing it is, and the two cases are not alike. Most of the board is reproduced from another marketplace: those sellers hold no account with us, so nobody reads your offer but us, and nobody can answer it. On a listing posted here the seller does hold an account, and your offer appears in their own panel — with the terms, your note, and not your name, email, phone number or account. Introducing the two sides of a transaction is a separate, recorded act on this platform, and it does not happen because somebody made an offer.

They can answer, and answering sends nothing either.A seller on a listing posted here may accept your terms, decline them, or counter with different ones; you can then accept, decline, or counter back, for as long as the two of you keep going. Every move is a new record pointing at the one it replaces, so the whole exchange stays readable and nothing is edited after the fact. What is stored on a counter is the terms, the account that wrote it, and any note that account typed. You find out inside this site — see Being told things happenedbelow — because there is still no mail or SMS here to reach you with. Accepting records that both sides agreed on a set of terms and nothing more: it does not create a contract, move any money, or produce a document.

The terms are frozen as written. We do not edit an offer after the fact — improving one writes a new record that points at the old one — so what you offered remains readable as what you offered on the day. You can withdraw an offer at any time; withdrawing marks it withdrawn rather than deleting it, because a negotiation that vanishes cannot be shown to have happened.

The control is on the listing itself. Open the deal you offered on and the two transaction buttons are replaced by your offer and a Withdraw offer button; pressing it is the whole of it, and it frees you to make a different offer on the same listing. Nothing is sent to anybody when you withdraw, for the same reason nothing was sent when you offered.

That right covers the terms youproposed. A counter the seller wrote is their record, not yours: you answer it — accept, decline or counter back — rather than withdrawing it, and declining closes it just as finally.

Proof of funds you attach to an offer

Only if you choose to.An offer can be made without one, and the step that asks for it can be skipped. If you do attach something, we store the file itself — a PDF, JPG or PNG — together with its size, its type, a fingerprint of its contents, and which account uploaded it and when. Typically that file is a bank statement or a lender letter.

It is never published and never linked. There is no address for it anywhere on this site: the file is held in private storage under a name that contains neither your account nor the name you gave the file, and it can only be fetched through a route that checks who is asking. If you upload a photograph, the location data cameras write into image files is removed before we store it.

Two parties can open it: you, and our staff. Sellers cannot, and there is no setting that changes that — what you put up to support an offer is not, on this platform, something the other side reads.

Withdrawing the offer does not remove the file, and neither does anything else in the product: these records refuse deletion by design, for the same reason the rest of this page describes. The route to removal is the personal-data request described below. No retention period has been set, and rather than name one we have not decided, this page says so.

Messages you write about a listing

What we store is what you wrote.A message holds the text itself, the account that wrote it, which side of the thread that account is on — investor, supply side, or our own team — and when it was written. The thread it sits in holds which listing it is about, the account that opened it, and, for each of those three sides, when that side last read it. There is one thread per listing per investor, so nobody else looking at the same listing is in it with you.

Nothing about a message leaves this platform.We do not email it, we do not text it, and there is no provider of either connected to this path — the only way anybody reads a message is by opening this site while signed in. That is the same position the rest of this page describes, and on a listing reproduced from another marketplace it is the whole of the arrangement: the supplier never signed up with us and is told nothing at all, so a thread about their listing is a thread with our own team.

A message names a side and never a person.Neither you nor whoever is on the other side is identified to the other: what is shown against each message is “investor”, “supply side” or “the VestorsHub team”. The account that wrote a message is stored, because a record with no author is not a record, and it is not part of what the other side is sent. That is the same rule that keeps a bidder’s identity off a seller’s offers page.

You can take a message back, and taking it back is not deleting it.The message keeps its place in the thread and its time, and what it said is withheld from the other side; the text itself stays in our database, where nobody can edit it. We record who took it back, when, and the reason they typed — the reason is required, and it is never shown to the other side, because it is frequently a note by a member of our team about their own decision.

Who can read a thread.The investor whose thread it is; the account that holds the listing and every member of the company holding it, where a company does; and members of our team, who can read every thread on the platform. Staff can also take back any message on any thread. This is the one place on this site where a customer can put text of their own choosing in front of another customer, and a moderation path nobody can use would not be one — every such act stores which member of our team did it, when, and why.

Nothing here is ever deleted, and there is no expiry. The database refuses to delete a message or a thread outright, so no part of this product removes one; deleting your account does not remove them either, which is stated again in the list below rather than left to be discovered. If we ever build a job that removes them, this page changes in the same commit.

Reporting something, and blocking somebody

What a report stores. When you report a message, a listing, an offer or a question, we store which of the offered reasons you picked, anything you typed, which thing you were reporting, the thread you were reading if there was one, your account, and when. Our own team can read all of it. The person you reported is not told that you reported them, and is not told who did.

A report is about something that was posted, never about a person. There is no field naming an accused account, and there is nowhere to type one: a report points at the message, listing, offer or question itself. Our team can of course see who wrote the thing being reported, because that is stored with it.

What happens to it. A member of our team decides it and records what they decided, why, and — where they did something — what they did. There are exactly two outcomes and we keep them apart: something was done, or there was nothing to do. A decision is final and is not edited afterwards. We cannot tell you what was decided, because there is no email, no text message and no push notification on this platform; nothing about a report leaves this website.

A report is never deleted, including by you.The database refuses it outright. This is the one place where something you wrote about somebody else is kept after you might want it gone, and it is deliberate: an allegation is the record of a complaint about a third party’s conduct, and removing it because the person who made it changed their mind would destroy the only account of it. Deleting your account does not remove it either — your row is reduced to a tombstone carrying no name and no email address, and the report remains attached to that.

What blocking does.You can block the other side of a message thread. We store which account placed it, which party it is against — a person, a company, or our own team — the thread you placed it from, and when. From that moment nothing that party writes reaches you, and you are not told about it. It applies everywhere, not just in the thread you pressed it in: if you block a company, that company does not reach you on another listing either.

Blocking does not stop the other side writing, and does not delete anything. Their words are still recorded — every message on this platform is, and the database refuses to delete one — and what was already in the thread stays there. What changes is that nothing new is delivered to you and nothing is announced to you. You can unblock, and unblocking works forwards: anything written while the block was on stays withheld, because it was not delivered at the time.

A block is never deleted either.Lifting one records that you lifted it, when, and why; it does not remove the record that you had asked. If you block our own team, that is stored the same way and has the same effect — our team stops reaching you.

Some wording is refused before it is stored. A short, fixed list of terms is checked against a message before it is written, and a message containing one is refused rather than being stored and hidden. When that happens we store nothing at all— not the message, not the term, not the attempt. The list is not published, and it is not a statement of what is or is not permitted here.

Being told things happened

When somebody makes an offer on a listing you posted, answers an offer you made, withdraws one, asks a question about your listing, or writes in a message thread you are part of, we write a short notice to your account: what happened, which listing it was about, and where to go and act on it. You see them on the bell in the top bar and at /notifications.

When you ask for an address, somebody here is told.Asking for the street address of a listing writes a notice to whoever handles that listing. If the person who posted it has an account with us, that is them. On listings we publish from another source — which is nearly all of them — nobody on the selling side has an account here, so the notice goes to our own staff instead. In both cases the notice says a buyer asked and names the listing; it does not name you, and it does not carry your email address or anything else about you. What does reach a seller, and what you agree to first, is described under Asking for an address above.

Saving a listing means we tell you when its status moves.If you save a listing and it later changes — to pending, sold, delisted or back to available — we write you a notice saying so, whether the change was made by the person selling it or by our staff. Your saved list stays private: nobody is told that you saved anything, the notice names nobody, and it says only what the public listing page already says.

A notice never leaves this site.We do not email it to you, we do not text it to you, and there is no provider configured that could — the only way you are told anything is by opening this site while signed in. If you are waiting on something, that is where to look.

A notice never names the other party.It says what happened and what the terms were — “the seller countered at…” — never who they are. There is no sender on the record at all, deliberately, so that one side’s identity cannot reach the other through a notification when it does not reach them through the page the notification points at.

What it says is frozen.The wording is written once and the database refuses to change it afterwards: a notice telling you an offer came in at a particular figure still says that after the offer is superseded or withdrawn, because it is a record of what you were told rather than a live view. The single thing that changes is whether you have read it, which we record as the moment you first did — opening it again does not move that.

What we keep, and for how long. The notice, the account it was written to, the listing it concerns, and the instant it was read. Nothing is deleted and there is no expiry: the same rule the rest of this page describes. Removing your account removes them with it.

Signing something, and the separate system that would hold it

Nothing on this site can be signed today, and nothing has been. The list of documents this product is able to send for signature is empty and every attempt is refused before anything is prepared, so no record of the kind described below exists yet. What follows is the mechanism, written down before it is used rather than afterwards.

What we would store here. For each signature we ask for: your name and your email address as they stood at that moment, kept as they were then rather than followed if you change them; the listing it concerns; which member of our team raised it; the times we looked at it; and a one-way digest of the link that would let somebody sign. We never store the link itself — whoever holds it can sign — and the database refuses a row that tries to. Alongside it we keep every status we ever observed, including whether the document was opened, with the moment we read it. That is a record of your behaviour, not only of ours, which is why it is named here rather than folded into “we keep the status”.

Your name and email address would be passed to another system. Signature is handled by Documenso, running on infrastructure this company operates — it is not an account with a third-party service, but it is a separate system with its own database and its own file storage, and the transfer is real either way. It is told not to email anybody, and there is no parameter beside that instruction. What it holds, and we do not, is: the signed document itself, the signature you type or draw, and its own audit trail — which records the network address and browser you signed from. No signed document, no signature image and no signing credential is stored in this application’s database.

A signature can be asked of somebody who never signed up here. That is possible by design, and it is the case the standing authorisation covers: a request to anyone who holds no account with us cannot be created at all unless the Project Owner has authorised that approach, and the database refuses it rather than a setting somewhere declining to send. Where you do hold an account, no such authorisation is involved and none is claimed.

These records are kept indefinitely and cannot be deleted.Both tables refuse a delete outright, so no part of this product removes one — a request we made and then thought better of is itself worth keeping, and it is the only record that a person’s name and address were handed to another system at all. The one route to removal is a person exercising their own data-deletion right, and that has to be carried out in both systems: removing a row here would leave the document, the signature and the audit trail sitting in the other one.

Listings we post to Instagram, Facebook and TikTok

Nothing has been published to any social platform, and no comment has ever been read. This site holds no credentials for Instagram, Facebook or TikTok, and a post cannot leave this system at all unless a named person has signed it off first — the database refuses it otherwise. What follows is the mechanism, written down before it is used rather than afterwards.

What a post would contain. Photographs of the property, the city or the county it is in, and the asking price. Never the street address, which is released to one investor at a time and never published; and never a valuation we worked out ourselves. Photographs are published only where this platform holds the file and has already stripped its metadata, because a photograph carrying GPS coordinates would give away the address that the rest of this page describes us withholding.

What leaves, and who receives it.The caption and the photographs are sent to Meta (for Instagram and for Facebook) and to TikTok, who then show them publicly and keep their own records under their own policies. No account holder’s name, email address or telephone number is part of a post, and the company supplying a listing is not named in one.

If you comment on one of our posts, we store what you wrote.That is your handle as the platform publishes it, the platform’s own identifier for the comment and for you, the text of the comment, and when it was written — kept as we first read it, so an edit on the platform does not change our copy. You do not need an account with us for this to happen, and nothing in this product turns that identifier into a person, a contact record or a mailing list. If we answer you, the answer is stored too, together with who wrote it and who approved it.

An answer may be drafted by an AI system, and if it is, your words are sent to the company that runs it. Nothing has been sent to any such company, because none is configured. When one is, what would be sent is the text of your comment and nothing else— not your handle, not the platform’s identifier for you, and nothing else we hold. We would name the company here before the first comment was sent, because which company receives your words is part of what this page is for.

An answer may also be published without a person reading that particular answer first.Where that happens, a named person has signed a standing instruction in advance — a manner of answering, and which accounts it covers — rather than approving those specific words, and the record stores which instruction and which manner of answering produced the reply. Every draft is checked first, and anything the check is not certain about is not published at all: it waits for a person. We are telling you this rather than leaving you to assume a human wrote every answer.

These records are kept indefinitely and cannot be deleted. Every one of these tables refuses a delete outright, so no part of this product removes one: a post we published under our own name, and a question somebody asked us in public, are both records of things that actually happened. The one route to removal is a person exercising their own data-deletion right. Deleting a comment on the platform itself removes it there and not here, and removing it here would not touch the copy Meta or TikTok hold.

If you are a seller and you want us to stop

Every message we prepare for a seller carries a one-click link that stops all of it.Opening the link is enough — there is no form, no confirmation step, and you do not need an account with us. Until this page was last updated the message promised this and the mechanism did not exist; it does now, and this paragraph describes it rather than an intention.

Using that link does three things, together:

  • Every email address and phone number we hold for you is blocked — not just the one you were contacted on, and not just the channel you were contacted on. If the same address or number appears under another storefront in our copy of the marketplace, it is blocked there too.
  • Messages we had already prepared for you are stopped. Nothing has ever been delivered from this site, so those are requests sitting in a queue; they are marked as stopped and cannot be picked up later. This matters more than it sounds: without it, connecting an email provider one day would send everything that had been waiting, to people who had already told us not to.
  • Any unused invitation to open an account here, issued to those details, is cancelled. An invitation is a working link; stopping the message that carries it is not the same as stopping the link.
  • The block is recorded as a decision of ours, separately from the listing data we copy. Re-importing the marketplace cannot clear it, and nothing in our software is able to.

The link identifies you to us and to nobody else. It contains no email address, no phone number and no database identifier — only a code signed with a key we hold, which is also why a link that is guessed, altered or truncated does nothing. The page it opens tells you what was blocked, showing only enough of the address or number for you to recognise it.

What we keep after thatis the block itself, the contact details it applies to, and the messages that were prepared — marked as stopped. We keep the block because deleting it is how somebody gets contacted again by accident, and we keep the messages for the reason given above: nothing on this site is deleted, because a record that changes retroactively is worse than no record.

Public records: recorded deeds, and the people behind a company

We hold a copy of a county recorder’s official records, and it names people who have never heard of us. A county Clerk publishes the index of every instrument recorded there — deeds and mortgages — free and without an account, and we import it. Each row holds what the register holds: the instrument number, the date, the document type, the consideration, the parcel, and the names of the parties who conveyed and received. Those names are the clerk’s, spelled as the clerk spelled them, and many of them are private individuals selling or buying their own home. We did not collect any of it from the people named; it is a public record and we obtained it the way the recorder publishes it. Today one county is loaded, Broward.

We use it to find a property that was bought and resold within days — a double closing — and the company that sat in the middle. That is an internal page for our own staff. It is not published, it is not on the public site, and nothing about it is shown to buyers or to sellers.

An internal export of that list can name a company’s decision maker and the address they filed with the state. Only a signed-in administrator can produce it — the whole of our admin panel requires one — and it is downloaded by the person who asked for it rather than sent anywhere. Where the state corporate register names an officer for a company on that list, the file carries that person’s name and the address on their filing. We hold no telephone number and no email address for any of them, and we look none up: there is no skip tracing anywhere in this product. The filed address is the only address we have for an officer. Resolving a company to the natural persons behind it happens only under a standing, state-scoped authorisation recorded in our database, and the database refuses to store an officer without one. A file that has been downloaded is a file: what a member of our team then does with it is outside what this software controls, and saying otherwise would be describing an intention rather than a mechanism.

The separate internal list of companies read off county tax rolls has no export at all.

Nobody named in any of this is contacted. There is no contact control on these pages, no message is prepared from them, and we hold no contact details to prepare one with. Approaching anyone at all on this platform requires the authorisation described under Offers you make above, which nobody has granted.

We record where each of these records came from, and stopping using a source does not destroy what it told us. Every deed row carries the source it was imported from. If we decide a source is unreliable we retract it: it is withdrawn from use, and the rows and the reason are kept rather than deleted, so what did we once rely on, and when did we stopstill has an answer and a mistaken retraction can be undone. The same applies to a decision about a single company on that list — excluding it, or confirming it after somebody checked it against the clerk — which is recorded with the reason instead of the row quietly disappearing.

Those decisions are recorded against the member of our team who made them. Retracting a source, restoring one, and excluding or confirming a company each store which of our staff did it and when. A source’s standing is kept as a history of those events rather than as a single current value, so a retraction that was later undone is still readable afterwards. This is therefore a record about our own people as well as about the data, which is the honest way to describe it: without it, “this company was removed from the list and nobody knows why” is indistinguishable from a bug.

Closing documents

To have a closing verified, a customer uploads the settlement document from the transaction — a HUD-1, a Closing Disclosure, a settlement statement, or a title or escrow confirmation. In some states a seller also uploads evidence that they hold an interest in the property before their listing can go public.

These documents contain other people’s information, including the buyer’s and the seller’s. We ask for them because the alternative is asking a customer to tell us whether they closed, and the answer to that question decides what they owe us.

They are stored privately and are never served from a public address. No public URL exists for one, and the part of our system that serves images refuses these files outright. The only way to open one is a signed-in request we check against your account first: that is the download control on your Documents page, which lists the documents your account may read, and the equivalent control the members of our team reviewing a closing use. They are read by: the person who uploaded the document, other members of that customer’s organisation, and members of our team reviewing it. Every download is itself recorded as an access event, so who read a document, and when, is part of the record.

We store the file as it was sent to us. We do not alter it, because it is evidence and a document we had rewritten would no longer match anybody else’s copy of it.

Closing documents are kept for 7 years from upload, for the same reason as the access events above.

Fees, and what we do not do with money

No funds pass through VestorsHub at any point.There is no payment method in this product. We do not hold deposits, we do not hold earnest money, we do not receive assignment proceeds, and we do not disburse closing funds — those go through the title company or attorney, as they always did.

When a closing is verified we write a record of what is owed to us under our software agreement. That record contains the deal, the organisation, the fee schedule version it was priced under, and the arithmetic. It contains no payment details, because we have none.

Getting a copy of what we hold

Signed in, you can download a copy from your profile. It is a JSON file holding your profile, the deals you saved and looked at, the addresses you asked for, the offers and questions you sent, the notifications you were shown, the agreements you accepted together with the wording you accepted them against, and the IP address and browser recorded against each of those acts. It is composed when you ask for it and kept nowhere afterwards, and nobody but the account holder can ask for an account’s copy.

A deal appears in it as the number in its marketplace URL, and nothing else. No property record is copied into the file, because a property record carries the address and releasing an address is a deliberate act described further up this page rather than something that rides along in a download. Messages appear as the lines you wrote, not as the threads they sit in — the other side of a thread is not your record. Your password is never in it, and neither is the token behind a linked Google sign-in.

Deleting your account

You can delete your account yourself, from Security when you are signed in, or from this page, which works the same way and exists so that you never have to install anything to leave. Both ask for your password, if the account has one, and both run the same single operation. It cannot be undone, and signing up again later gives you a new account rather than this one back.

The account record itself is emptied rather than removed.Your name, email address, password, phone number, WhatsApp number, company name and pictures are cleared from it, and what remains is an identifier that names nobody, marked as terminated. We do it that way because 55 separate records in this database refuse to let an account row be removed while anything at all references it — and every one of those references is evidence about a transaction that involved somebody else. A terminated account cannot sign in and cannot act: any browser still holding a signed-in session for it stops being recognised on its very next request.

When an account is deleted:

  • Your saved deals, buy boxes, saved searches and favourites are deleted with it. They are your state and they have no life after the account. So is any listing you had started and not finished.
  • Every notification you were shown is deleted with it.
  • Your deal-view events are kept, with the link to your account removed. The event becomes indistinguishable from an anonymous view. We keep it because deleting it would silently rewrite how much interest a deal drew last quarter, and a number that changes retroactively is worse than no number.
  • Your access events are kept, with the link to your account removed. The IP address, the user agent and the act stay; the account identifier is cleared. We keep them because they are the evidence behind fees that may already have been charged to somebody else, and deleting one side of a two-party record does not make it a smaller record, it makes it a false one.
  • Closing documents you uploaded are kept. They are the evidence for a transaction that involved other people, and they are part of a commercial record we cannot unilaterally rewrite. So are the offers you filed and the questions you asked.
  • Messages you wrote are taken back rather than deleted.The other side stops being able to read them. The line itself stays in the thread, marked as withdrawn, because a message cannot be deleted by anything in this product — the database refuses it — and because a negotiation had two people in it, so a record with one side removed is not a smaller record, it is a false one. A message names a side rather than a person, so what survives is that a line was written and withdrawn.
  • The non-circumvention terms you accepted are kept, together with the wording you accepted them against. It is the agreement under which a supplier’s contact details were released to you, and an agreement a party can delete by leaving is not evidence of an agreement.
  • A linked Google or Apple sign-in is deleted with the account. The provider identifier and the stored token go with it, including an Apple private-relay address if that is what we hold. They are only ever a way of recognising you at the door, and they evidence nothing about anybody else.
  • If your role on this platform ever changed, that change is kept, together with the name the account carried at the time. A role change is the record of a decision somebody made about this account, and it is the evidence for what the account was permitted to do while it held that role. Removing the name would leave a decision with no subject.
  • Reports you filed are kept.A report is an account of somebody else’s conduct, made to us, and it is often about a person who never knew it was made. Removing it because the person who filed it left would destroy the only record of the complaint and of what our team decided about it. It stays attached to your terminated row, which carries no name and no address.
  • Blocks you placed are kept, and they stay in force.They record that an account asked not to be contacted by a party; a block that vanished with the account would silently reopen a route somebody had closed. Nothing about them names you to the party they are against — that was never disclosed while the account existed either.
  • A record that the account was deleted is kept— the date, and that the account holder was the one who did it. It carries no name, because there is no longer one to carry.

Third parties

Most deals on the board are mirrored from a third-party off-market marketplace. We publish the property information; we deliberately do not republish the originating seller’s phone number, email address or profile link.

We do not run third-party analytics, advertising or tracking scripts on this site. The Google and Apple marks on the sign-in buttons are drawn by this site as inline artwork, not fetched from either company, so simply opening the sign-in page tells neither of them anything. They learn nothing until you press the button.

The only place anything about you is deliberately passed out of this application is the signature mechanism described under Signing something, and the separate system that would hold itabove — and nothing has been signed, because there is nothing to sign.

Maps are drawn by somebody else’s servers.Wherever this site shows a map, your browser fetches the map imagery directly from the map provider, and that request carries your IP address and your browser’s user-agent to them, the same way loading any image from another site would. We do not send them anything about you, we receive nothing back about you, and no listing you looked at is included in the request — but the connection is between you and them, not between us and them, so it is theirs to see and we cannot speak for what they keep. Today those tiles come from OpenStreetMap. A page with no map on it makes no such request.

Changes

When the product starts doing something new with your data — sending email, releasing a property address to a seller on your behalf, taking payment — this page changes at the same time as the code does, not afterwards.

How to reach us about your data

Questions about this page, or about what we hold on you, go to the address below. It is the same address published on /contact, and there is no separate privacy mailbox — one address that a person reads is worth more than two, one of which nobody opens.

support@vestorshub.com
260 CRANDON BLVD, STE 32
KEY BISCAYNE, FL 33149

We publish no telephone number, because there is no telephone line to publish. That is the honest state rather than an omission, and this page will carry one on the day it exists.

You do not need to write to us to get your data or to delete it. Both are buttons in the product, described under Getting a copy of what we hold and Deleting your account above.

Back to VestorsHub