Privacy at Property Debut.
This policy explains what Property Debut collects, why we use it, and the choices available when you preview, purchase, download, or publish a campaign.
Information we handle
- Listing facts, source URLs, property media, agent contact details, campaign reviews, and generated campaign files.
- Verified account email, account and session records, brand profile, listing projects, campaign grants, rights attestations, audio choices, and customer-supplied audio validation metadata.
- Preview, download, checkout, and campaign-status events needed to deliver and support the service.
- Support requests, customer-visible replies, consented diagnostic context, safe provider references, and audited recovery actions.
- When you connect Instagram: your professional account ID, username, optional profile image, granted permissions, encrypted access token, connection status, and publishing history.
- Payment status and transaction references from Stripe. Property Debut does not receive or store full payment-card numbers.
- Basic technical information supplied with web requests, such as network address, browser information, rate-limit records, safe error codes, security events, and application logs.
- Partial property-address text sent to Mapbox when you use the optional address suggestions.
How we use information
We use this information to create and deliver campaigns, protect private previews and account downloads, process one-time and recurring purchases, determine account access, prevent duplicate or abusive first-campaign redemptions, connect the Instagram account you select, publish only after your explicit click, recover interrupted jobs, provide support, and maintain service security.
For the $1 first-campaign offer, the server reads the email from the verified account identity, trims whitespace, and case-folds it. We use the normalized value only to enforce one fulfilled offer per verified email and to diagnose the account’s own state. We do not reveal another account’s identifying information when the same verified email has already fulfilled the offer.
Property Debut does not sell personal information and does not use connected Instagram data for advertising or audience profiling.
Instagram publishing
Property Debut supports Instagram Business and Creator accounts through Instagram API with Instagram Login. We request only the basic professional-account and content-publishing permissions needed for this feature.
Your access token is encrypted at rest, is never placed in campaign files or browser JavaScript, and is decrypted only when Property Debut communicates with Instagram. Publishing is user initiated; connecting an account never causes an automatic post.
Listing Countdown for Canva
When you use Listing Countdown in Canva, Property Debut receives the property address, launch date, time zone, whether you selected a photo, and the launch settings you submit. Canva also provides opaque user and team identifiers in a signed token; Property Debut hashes those identifiers before storing ownership data.
The selected photo stays inside your Canva design. Its file and Canva asset reference are not sent to or stored by Property Debut. Publishing the linked live debut is optional.
When you remove the app from Canva, Canva sends Property Debut a signed uninstall notice. We delete the launches, generated launch metadata, analytics events, and buyer leads associated with that Canva user and team.
Public feeds and buyer alerts
An associated agent or authorized submitter may separately opt a property into public property, city, neighborhood, agent, or open-house pages. Search indexing is a separate control, and expired properties are removed from those feeds.
A buyer alert is created only after the buyer selects an alert and consents to email notifications. Sharing buyer contact information with the associated agent requires a second optional choice. Every alert email includes an unsubscribe control.
Service providers and disclosure
We disclose information only as needed to operate the service: Mapbox for property-address suggestions, Meta for Instagram authorization and publishing, Supabase for private storage and database services, Vercel for application hosting, Stripe for payment processing, and email infrastructure for service delivery. These providers process information under their own terms and privacy commitments.
We may also preserve or disclose information when reasonably necessary to comply with law, enforce service terms, protect users, or investigate fraud and security incidents.
Retention and deletion
We keep active account, project, campaign, support, billing-status, rights, and publishing records while needed to provide the service. Completed campaign grants and manifests remain associated with the verified account so purchased work can stay downloadable. Temporary signed media links expire automatically and are not stored as permanent publishing records.
Operational logs, rate-limit records, safe diagnostics, and failed-upload metadata are retained only as reasonably needed for reliability, abuse prevention, support, and security. Payment, refund, dispute, tax, fraud-prevention, and security audit records may be retained after account deletion when required by law or reasonably necessary to establish, exercise, or defend legal claims. We minimize those retained records and do not retain full card numbers.
Disconnecting Instagram revokes local reuse and removes the stored token ciphertext. Minimal publish history, such as job status and the published media ID, may be retained for operational and duplicate-prevention records.
To request an account export or deletion, sign in and submit a Data export or deletion request. We verify the account before acting. A deletion request can require cancellation of active Unlimited billing, revocation of sessions, a pause on new work, deletion of owned uploads/projects/campaign files/support content, and preservation of legally required records. We explain the affected data and any required retention before completing the request.
For Instagram-only instructions, visit Instagram data deletion.
Access, export, correction, and deletion choices
- Request an export of the account profile and brand, project facts, campaign manifests and download references, support requests and messages, billing-status summaries, first-campaign redemption status, audio-upload metadata, and consent or attestation records. The export does not contain full card data, secret keys, raw security credentials, or another account’s information.
- Request correction or deletion through the verified account support path. We may need fresh verification and may ask for confirmation of the consequences before acting.
- Do not connect Instagram; the downloadable campaign ZIP remains the manual alternative.
- Disconnect Instagram from an eligible campaign page to revoke browser reuse and remove the stored credential.
Security, children, and changes
We use technical and organizational safeguards designed to protect information, but no internet service can guarantee absolute security. Property Debut is a business service and is not directed to children under 13.
We may update this policy as the service changes. The effective date above will change when a revised policy is published.
Contact
Questions or privacy requests can be sent to william@propertydebut.com.