TourLytics
TermsPrivacySign In

Privacy Policy

Last Updated March 18, 2026 · TourLytics and its affiliates

Table of Contents
1. Information We Collect2. How We Use Information3. How We Share Information4. Third-Party Services and Data Processing5. Data Retention6. Data Security7. Your Rights8. Children's Privacy9. International Data Transfers10. Cookies and Tracking Technologies11. Do Not Track Signals12. Changes to This Policy13. Data Processing Addendum14. Contact Information

TourLytics is an AI-powered commercial real estate intelligence platform that helps enterprise CRE teams process broker survey documents, visualize properties on interactive maps, generate tour books, perform financial modeling, and conduct commute studies.

By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the practices described in this Policy, please do not use the Platform. If you are accepting this Policy on behalf of an organization, you represent and warrant that you have the authority to bind that organization to this Policy, and references to "you" or "your" shall refer to that organization.

Capitalized terms not defined in this Privacy Policy shall have the meanings ascribed to them in our Terms of Service, available at tourlytics.ai/terms.

1. INFORMATION WE COLLECT

We collect information in several categories as described below. The types and amounts of information we collect depend on how you interact with the Platform.

1.1 Account Information

When you register for an account on the Platform, we collect the following personal information:

  • Full name
  • Email address
  • Company or organization name
  • Job title or role
  • Password (stored in hashed form via Supabase Auth)
  • Account preferences and settings

1.2 Customer Content and Customer Data

When you use the Platform, you may upload or create content that contains information about third parties and commercial real estate transactions ("Customer Content" and "Customer Data"). This may include:

  • Broker survey PDFs containing commercial property data, building addresses, landlord names, and rental rates
  • Financial documents such as requests for proposals (RFPs) and letters of intent (LOIs) containing deal terms, pricing, and tenant information
  • Annotations, shortlists, tour book configurations, and other materials created within the Platform
  • Project-level data and collaboration content shared with team members

Important: You are responsible for ensuring that you have the right to upload and process any Customer Data and Customer Content through the Platform, and that doing so complies with all applicable laws and any obligations you may have to third parties.

1.3 AI Interaction Data

When you use AI-powered features of the Platform, we collect:

  • Prompts, queries, and instructions submitted to the AI chatbot and other AI Features
  • AI-generated outputs, including parsed building data, financial models, commute studies, and chatbot responses
  • Token consumption records associated with AI actions

1.4 Usage Data

We automatically collect information about how you interact with the Platform, including:

  • Features accessed and actions performed
  • Token consumption and purchase history
  • Pages and screens visited within the Platform
  • Frequency and duration of Platform sessions
  • Error logs and performance data

1.5 Device and Technical Data

We automatically collect technical information from your device and browser, including:

  • IP address
  • Browser type and version
  • Operating system and device type
  • Screen resolution and display settings
  • Referring URL and exit pages
  • Date and time of access
  • Unique device identifiers

1.6 Payment Data

When you purchase tokens or subscribe to the Platform, payment transactions are processed by Stripe, our third-party payment processor. We receive and store:

  • Billing name and billing address
  • Transaction history and amounts
  • Subscription status and plan details
  • Last four digits of your payment card (for display purposes only)

Important: We do not store, process, or have access to your full credit card numbers, CVV codes, or other sensitive payment credentials. All payment card data is processed and stored exclusively by Stripe in accordance with PCI DSS requirements. Please refer to Stripe's Privacy Policy for more information.

1.7 Geolocation Data

We process geolocation data derived from building addresses that you upload or enter into the Platform for purposes of geocoding and map visualization using Google Maps Platform. This geolocation data pertains to commercial real estate properties -- not to your personal physical location. We do not collect or track your real-time geographic location.

1.8 Cookies and Similar Technologies

We use cookies and similar tracking technologies to collect information about your interactions with the Platform. For detailed information about the cookies we use, please see Section 10 (Cookies and Tracking Technologies) of this Policy.

2. HOW WE USE INFORMATION

We use the information we collect for the following purposes:

2.1 Providing and Operating the Service

  • Creating, maintaining, and securing your account
  • Processing and parsing uploaded documents using AI Features
  • Generating AI outputs, including financial models, commute studies, tour books, and chatbot responses
  • Geocoding building addresses and rendering interactive maps
  • Facilitating team collaboration within Projects based on role-based access permissions
  • Processing payments and managing token balances

2.2 Communications

  • Sending account-related notifications (e.g., registration confirmations, password resets, security alerts)
  • Providing service notifications (e.g., changes to features, scheduled maintenance)
  • Responding to your inquiries and support requests

2.3 Improvement and Development

  • Analyzing usage patterns to improve Platform functionality and user experience
  • Identifying and resolving technical issues, bugs, and errors
  • Developing new features and services
  • Conducting internal research and analytics

2.4 Security and Fraud Prevention

  • Detecting, preventing, and responding to security incidents, fraud, and abuse
  • Monitoring for unauthorized access to accounts and Projects
  • Enforcing our Terms of Service and other policies

2.5 Legal Compliance

  • Complying with applicable laws, regulations, and legal processes
  • Responding to lawful requests from government authorities
  • Establishing, exercising, or defending legal claims

2.6 Important Limitations on Use

We do NOT use Customer Data or Customer Content to train, improve, or fine-tune artificial intelligence or machine learning models. Your uploaded documents and data are processed solely to provide the Service to you and are not used for any other purpose.

We do NOT sell your personal information. We have not sold personal information in the preceding twelve (12) months and do not intend to do so. For purposes of the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), we do not "sell" or "share" personal information as those terms are defined under applicable law.

3. HOW WE SHARE INFORMATION

We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following limited circumstances:

3.1 Service Providers

We engage trusted third-party service providers to perform functions and provide services on our behalf. These providers have access to your information only to the extent necessary to perform their functions and are contractually obligated to protect your information. Our key service providers include:

  • Supabase -- Database hosting and user authentication
  • Google (Gemini) -- AI-powered document processing and analysis
  • Google Maps Platform -- Geocoding and map visualization
  • Stripe -- Payment processing and billing
  • Vercel -- Platform hosting and content delivery

3.2 Team Members and Collaborators

When you participate in a Project on the Platform, certain information may be visible to other Authorized Users within that Project based on the role-based access control system. Project Owners and Admins may have access to broader information within the Project than Members or Viewers. You should only share information within Projects that you are comfortable making available to other Project participants.

3.3 Legal Compliance and Protection

We may disclose your information if we believe in good faith that such disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or governmental request, including court orders and subpoenas
  • Enforce our Terms of Service, this Privacy Policy, or other agreements
  • Protect the rights, property, or safety of Company, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues

3.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will provide notice to you via email and/or a prominent notice on the Platform prior to any such transfer and before your information becomes subject to a different privacy policy. You will have the opportunity to delete your account before such transfer takes effect.

3.5 Aggregated and De-Identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you for purposes such as industry analysis, market research, and Platform improvement. Such information is not considered personal information under applicable law.

4. THIRD-PARTY SERVICES AND DATA PROCESSING

The Platform integrates with and relies upon third-party services to provide its functionality. Each of these services has its own privacy policy governing the collection and use of data processed through their systems. We encourage you to review the privacy policies of these services:

  • Google Gemini (AI Processing): Customer Data submitted through AI Features is processed by Google's Gemini AI models. Google's processing of this data is subject to Google's Privacy Policy and Google's Cloud Data Processing Addendum.
  • Google Maps Platform (Geocoding): Building addresses are processed through Google Maps Platform for geocoding and map visualization. This processing is subject to Google's Privacy Policy.
  • Supabase (Database and Authentication): Account data and Customer Data are stored and processed using Supabase. This processing is subject to Supabase's Privacy Policy.
  • Stripe (Payment Processing): Payment information is processed by Stripe. This processing is subject to Stripe's Privacy Policy.
  • Vercel (Hosting): The Platform is hosted on Vercel's infrastructure. This processing is subject to Vercel's Privacy Policy.

We are not responsible for the privacy practices of these third-party services. We encourage you to review their respective privacy policies to understand how they handle your information.

5. DATA RETENTION

We retain your information for as long as necessary to fulfill the purposes for which it was collected, as described in this Policy, unless a longer retention period is required or permitted by law. Our specific retention periods are as follows:

5.1 Account Data

We retain your account information for the duration of your active account. Upon account deletion, we will delete or anonymize your account data within ninety (90) days, except as required by law or as necessary to comply with our legal obligations, resolve disputes, or enforce our agreements.

5.2 Customer Content and Customer Data

Customer Content and Customer Data are retained for as long as the associated Projects remain active. Upon account termination or deletion of a Project, we will delete Customer Content and Customer Data within thirty (30) days, unless retention is required by law or is necessary for the establishment, exercise, or defense of legal claims.

5.3 Usage and Analytics Data

Usage and analytics data are retained in aggregated form for a period of twenty-four (24) months from the date of collection. After this period, such data is permanently deleted or further anonymized so that it cannot be associated with any individual user.

5.4 Payment Records

Payment and transaction records are retained as required by applicable tax, financial, and accounting regulations, which typically require a retention period of seven (7) years. These records are retained solely for compliance purposes and are not used for marketing or other unrelated purposes.

5.5 AI Interaction Logs

AI interaction logs -- including prompts, queries, and associated outputs -- are retained for a period of ninety (90) days for purposes of quality assurance, debugging, and service improvement. After this period, such logs are permanently deleted. AI interaction logs are not used to train or improve AI models.

6. DATA SECURITY

We implement and maintain commercially reasonable administrative, technical, and physical security measures designed to protect your information from unauthorized access, disclosure, alteration, and destruction. These measures include:

6.1 Encryption

  • All data transmitted between your device and the Platform is encrypted in transit using Transport Layer Security (TLS) version 1.2 or higher
  • Customer Data and Customer Content stored on our servers and in our database infrastructure are encrypted at rest using industry-standard encryption algorithms

6.2 Access Controls

  • Role-based access controls within the Platform limit access to Customer Data based on assigned user roles (Owner, Admin, Member, Viewer)
  • Internal access to production systems and user data is restricted to authorized personnel on a need-to-know basis
  • Multi-factor authentication is supported for user accounts

6.3 Security Assessments

  • We conduct regular security assessments and vulnerability scans of our infrastructure and application code
  • We perform periodic reviews of our security policies and procedures

6.4 Incident Response

We maintain incident response procedures to detect, respond to, and recover from security incidents. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law.

6.5 SOC 2 Compliance

We are actively pursuing SOC 2 Type II compliance certification. We will update this section when certification is achieved.

6.6 Limitations

No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially reasonable means to protect your information, we cannot guarantee its absolute security. You acknowledge and accept that you transmit information to and through the Platform at your own risk.

7. YOUR RIGHTS

7.1 Rights of California Residents (CCPA/CPRA)

If you are a California resident, you have certain rights under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"). These rights include:

7.1.1 Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which that information is collected, the business or commercial purpose for collecting the information, the categories of third parties with whom we share the information, and the specific pieces of personal information we have collected about you.

7.1.2 Right to Delete

You have the right to request that we delete personal information that we have collected from you, subject to certain exceptions as provided by law (e.g., if the information is necessary to complete a transaction, detect security incidents, comply with legal obligations, or for other purposes permitted by law).

7.1.3 Right to Correct

You have the right to request that we correct inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes for which we process it.

7.1.4 Right to Opt-Out of Sale or Sharing

You have the right to opt out of the "sale" or "sharing" of your personal information, as those terms are defined under the CCPA/CPRA. As stated in this Policy, we do not sell or share personal information and have not done so in the preceding twelve (12) months.

7.1.5 Right to Limit Use of Sensitive Personal Information

You have the right to limit the use and disclosure of sensitive personal information to uses that are necessary to perform the services reasonably expected by an average consumer. We only use sensitive personal information for purposes permitted under the CCPA/CPRA.

7.1.6 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you access to the Platform, charge you different prices, provide you a different level or quality of service, or suggest that you will receive a different price or level of service for exercising your rights.

7.1.7 How to Submit a Request

To exercise any of the rights described above, please submit a verifiable consumer request to us by:

  • Email: privacy@tourlytics.ai

Only you, or a person you have authorized to act on your behalf (an "authorized agent"), may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.

7.1.8 Verification Process

Upon receiving a request, we will verify your identity by matching identifying information provided in your request against information we already have on file. We may ask you to provide additional information to verify your identity. If you use an authorized agent to submit a request, we may require that you provide the authorized agent written permission to do so and that you verify your own identity directly with us.

7.1.9 Response Timeline

We will respond to verifiable consumer requests within forty-five (45) days of receipt. If we require additional time, we will inform you of the reason and extension period in writing. Any extension will not exceed an additional forty-five (45) days, for a maximum total response time of ninety (90) days. If we are unable to fulfill a request, we will explain the reason in our response.

7.2 General Rights for All Users

Regardless of your location, we provide all users of the Platform with the following rights:

7.2.1 Access

You may request access to the personal information we hold about you and receive a copy of such information in a commonly used electronic format.

7.2.2 Correction

You may request that we correct any inaccurate or incomplete personal information we hold about you.

7.2.3 Deletion

You may request that we delete your personal information, subject to applicable legal requirements and our legitimate retention needs.

7.2.4 Data Portability

You may request a copy of your personal information in a structured, commonly used, and machine-readable format, and you may request that we transmit such data to another service provider where technically feasible.

7.2.5 Withdrawal of Consent

Where we process your personal information based on your consent, you may withdraw that consent at any time. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.

7.2.6 Objection to Processing

You may object to the processing of your personal information where we process it based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

To exercise any of these rights, please contact us at privacy@tourlytics.ai. We will respond to your request in accordance with applicable law.

8. CHILDREN'S PRIVACY

The Platform is not directed to, and we do not knowingly collect personal information from, children under the age of sixteen (16). If we become aware that we have inadvertently collected personal information from a child under 16, we will take steps to delete such information as soon as practicable. If you believe that we may have collected personal information from a child under 16, please contact us at privacy@tourlytics.ai so that we can investigate and take appropriate action.

9. INTERNATIONAL DATA TRANSFERS

The Platform is operated from the United States, and your information is primarily processed and stored in the United States. If you access the Platform from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate.

By accessing or using the Platform, you consent to the transfer of your information to the United States and other jurisdictions that may not provide the same level of data protection as the laws of your country of residence.

For enterprise customers that require additional safeguards for international data transfers, we offer standard contractual clauses and other appropriate transfer mechanisms upon request. Please contact us at privacy@tourlytics.ai to discuss your specific requirements.

10. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies to enhance your experience on the Platform. This section describes the types of cookies we use and how you can manage them.

10.1 Types of Cookies We Use

10.1.1 Essential Cookies

These cookies are strictly necessary for the operation of the Platform. They enable core functionality such as user authentication, session management, and security features. Essential cookies cannot be disabled without impairing the functionality of the Platform.

10.1.2 Analytics Cookies

These cookies help us understand how users interact with the Platform by collecting information about pages visited, features used, and usage patterns. We use this information to analyze and improve the Platform's performance and user experience. Analytics data is collected in aggregated or anonymized form where possible.

10.1.3 No Advertising or Marketing Cookies

We do not use advertising, marketing, or behavioral tracking cookies on the Platform. We do not serve targeted advertisements, and we do not share cookie data with advertising networks.

10.2 Managing Cookie Preferences

You can manage your cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. Please note that disabling essential cookies may impair the functionality of the Platform. You may also manage analytics cookie preferences through the Platform's cookie settings, if available.

For more information about cookies and how to manage them, you can visit www.allaboutcookies.org.

11. DO NOT TRACK SIGNALS

"Do Not Track" ("DNT") is a privacy preference that users can set in certain web browsers. We respect your privacy choices. However, because there is no accepted standard for how to respond to DNT signals, the Platform does not currently alter its data collection and use practices in response to DNT signals. We will continue to monitor developments in DNT technology and update our practices accordingly if a uniform standard is adopted.

12. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes to this Policy, we will:

  • Provide at least thirty (30) days' advance notice before the changes take effect
  • Notify you by email at the address associated with your account
  • Update the "Last Updated" date at the top of this Policy
  • Post the updated Policy on the Platform

Your continued use of the Platform after the effective date of any updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with any changes, you must discontinue your use of the Platform and delete your account before the effective date of the updated Policy.

13. DATA PROCESSING ADDENDUM

For enterprise customers that require a formal Data Processing Addendum (DPA), we offer a comprehensive DPA that covers:

  • Company's obligations as a data processor, including the scope, nature, and purpose of data processing
  • Technical and organizational security measures implemented to protect personal information
  • Sub-processor engagement policies, including a list of current sub-processors and a notification process for changes to sub-processors
  • Data subject rights assistance and cooperation obligations
  • Data breach notification procedures and timelines
  • Data return and deletion obligations upon termination of the agreement
  • Audit and inspection rights

To request a Data Processing Addendum, please contact us at privacy@tourlytics.ai. Our DPA is provided at no additional cost and is designed to satisfy the requirements of applicable data protection regulations, including the CCPA/CPRA.

14. CONTACT INFORMATION

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

TourLytics and its affiliates

Email: privacy@tourlytics.ai

Website: tourlytics.ai

State of Incorporation: California

We strive to respond to all inquiries within thirty (30) days of receipt. For requests related to your privacy rights under the CCPA/CPRA, please see Section 7.1.9 for specific response timelines.

* * *

© 2026 TourLytics. All rights reserved.
Terms of ServicePrivacy PolicyCreated with Perplexity Computer