1. Scope and controller
This Privacy Policy explains how ListingRoyale, referred to as we, us, or our, collects, uses, discloses, retains, and protects personal information through https://listingroyale.com/, customer and administrator portals, email, inquiries, prospect outreach, ordering, production, billing, domain services, and related operations.
ListingRoyale is the controller or business responsible for the personal information described here, except when we process information solely on a customer behalf under a separate agreement. Contact us at office@listingroyale.com or office@listingroyale.com.
This Policy applies to customers, prospective customers, listing agents, brokerage personnel, property owners, website visitors, inquiry senders, and people whose information is included in submitted property materials. It does not govern an independent third party website or service.
2. Information we collect
Depending on how you interact with us, we collect the following categories:
- Identity and contact data, including name, email, telephone number, company, brokerage, title, mailing and billing address, preferred contact method, and account identifiers
- Account and authentication data, including password hashes, email-verification status, magic-link and password-reset records, roles, login events, device or browser information, IP address, and security logs
- Order and transaction data, including selected packages and services, order status, coupons, invoices, payment status, refunds, taxes, transaction identifiers, policy acceptances, and related communications
- Property and campaign data, including listing address, MLS number, price, property characteristics, descriptions, key features, agent and brokerage information, desired launch date, special instructions, domains, DNS details, and website URLs
- Content and media, including photographs, headshots and their versions, video, floor plans, brochures, logos, copy, external asset links, supporting documents, uploaded file metadata, feedback, and revision requests
- Communications and CRM data, including inquiries, email content, replies, call or text notes entered by staff, templates used, delivery status, unsubscribe choices, follow-up dates, and conversation history
- Technical and usage data, including pages requested, timestamps, session and security information, referrer information, cookie or similar identifiers, error records, and analytics information if analytics is enabled
- Prospect information from public or professional sources, including agent name, business email, brokerage, market, professional website, and publicly advertised listing details
- Compliance data, including records of consent, policy version, acceptance date, IP address, user agent, marketing preferences, and evidence needed to handle legal requests or disputes
Stripe processes full payment card details. We receive transaction status and identifiers but do not store full card numbers. We do not intentionally collect government identification numbers, health data, precise consumer geolocation, or biometric templates through ordinary use. A headshot is treated as media and is not used by us for biometric identification.
3. Sources of information
We receive information directly from you, from another person acting for a customer or listing, from uploaded files and communications, automatically from browsers and servers, from payment, registrar, hosting, email, and security providers, and from public listing pages, brokerage websites, professional profiles, referrals, or other lawful business sources.
If we obtain professional contact information from another source and plan to contact that person, we provide relevant privacy and opt-out information at or before the first communication when required by law.
4. Why we use information
We use personal information to:
- Create and secure accounts, authenticate users, and provide magic-link access
- Prepare quotes, create orders, process payments, issue invoices, apply coupons, and administer refunds
- Collect listing requirements, receive media, produce and host property websites, manage revisions, and deliver final work
- Check, register, connect, renew, transfer, and support domains and DNS when requested
- Display customer-approved agent, brokerage, property, and contact information on customer cards and listing websites
- Provide support, respond to inquiries, maintain conversation history, send transactional notices, and manage customer relationships
- Send relevant business-to-business prospect outreach and follow-up, subject to applicable consent, identification, and opt-out rules
- Monitor performance, diagnose errors, prevent fraud and abuse, enforce agreements, protect systems, and maintain backups
- Comply with tax, accounting, payment, sanctions, legal-process, recordkeeping, consumer-protection, and regulatory obligations
- Improve services, templates, workflows, accessibility, and user experience using aggregated or appropriately minimized information
- Establish, exercise, or defend legal claims and support a merger, financing, reorganization, or sale subject to appropriate safeguards
We do not use sensitive personal information to infer characteristics about a person. We do not use personal information for solely automated decisions that produce legal or similarly significant effects.
5. Legal bases for EEA, UK, and similar laws
Where a law requires a legal basis, we rely on:
- Contract, to create an account, process an order, produce and deliver a website, handle payment, and provide requested support
- Legitimate interests, to operate and secure the service, prevent fraud, maintain business records, improve workflows, communicate with business prospects in a proportionate way, and establish legal claims, after considering individual rights
- Consent, when a specific law requires it for optional marketing, nonessential tracking, sensitive information, or another particular activity. Consent can be withdrawn without affecting earlier lawful processing
- Legal obligation, to satisfy tax, accounting, sanctions, payment, consumer, court, and regulatory duties
- Vital interests or public interest only when applicable and permitted by law
You may object to processing based on legitimate interests. You have an unconditional right to object to direct marketing.
6. How we disclose information
We disclose only the information reasonably needed for the purpose to:
- Hosting, infrastructure, security, analytics, storage, file-delivery, and technical support providers
- Email delivery and inbound-email providers
- Stripe and other payment, invoicing, fraud-prevention, accounting, and tax providers
- NameSilo and other domain registrars, registries, DNS, privacy, and hosting providers
- Production vendors and contractors providing photography, video, floor plans, Matterport, drone, design, copy, or other ordered work
- Customer-authorized users, agents, brokerage personnel, property owners, and public website visitors for approved listing content
- Professional advisers, insurers, auditors, courts, regulators, law enforcement, or another person when required by law or reasonably necessary to protect rights, safety, and security
- A buyer, investor, lender, successor, or transaction adviser in a proposed or completed business transaction, subject to confidentiality and applicable notice requirements
Service providers may use information only for contracted services and permitted operational purposes. Their independent services are governed by their own notices and terms.
7. Public property websites and customer instructions
Information selected for a property website is intended to be public. This may include a property address, listing facts, media, agent name, headshot, brokerage, logo, telephone number, email, and inquiry link. Search engines, social networks, MLS systems, and visitors may copy or retain public information. Customers control what they submit and must have authority to publish it.
When a customer asks us to process personal information on its behalf, the customer is responsible for its own notices, lawful basis, instructions, and responses to affected people. We will assist as required by contract and law.
8. Payments and domains
Stripe collects payment details under its own privacy policy. We store payment status, amount, identifiers, invoice, and refund records. We do not store full card numbers or card security codes.
Domain registration can require contact and ownership information to be sent to registrars, registries, escrow providers, ICANN-related services, or verification services. Domain privacy is requested where available, but registry rules, legal process, transfer requests, or technical requirements may require disclosure.
9. Cookies, sessions, analytics, and privacy signals
We use cookies or similar technologies needed for sessions, authentication, checkout state, security, preferences, and fraud prevention. Optional analytics may be enabled to understand site use. We do not currently use third-party cross-site behavioral advertising or sell information for advertising.
Where required, we honor recognized browser-based opt-out preference signals, such as Global Privacy Control, for sale, sharing, or targeted advertising. Because we do not currently sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising, such a signal does not change our current practice. If our practices change, we will provide required controls and notices.
When an inquiry form is submitted, we may collect browser and device characteristics, IP and forwarding information, language, referrer, screen and viewport sizes, time zone, and aggregate interaction signals such as elapsed time, field count, typing cadence, edit count, paste count, pointer distance, touch, scroll, focus, and visibility changes. We use these signals to assess spam and automated abuse. We do not record the actual keys pressed, clipboard contents, or a detailed pointer path, and copy-and-paste activity alone is not treated as proof of automation. The assessment is a review aid and does not make a legal or similarly significant decision.
10. Marketing and prospect communications
We may send business-relevant outreach to professional addresses using public listing and brokerage information where permitted. Messages identify the sender, accurately describe their purpose, include our postal address, and provide an unsubscribe method when required. We record opt-outs and suppress future prospect marketing. We do not require marketing consent as a condition of buying a service unless a specific optional program clearly says otherwise.
Customers may receive order, account, security, payment, domain, support, and significant policy-update messages even after opting out of marketing because those messages administer an existing relationship. You can update communication preferences through available account tools or by emailing office@listingroyale.com.
11. Sale, sharing, targeted advertising, and financial incentives
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising and do not process it for targeted advertising as those terms are defined by applicable U.S. state privacy laws. We have not knowingly sold or shared personal information of consumers under 16.
Coupons, package discounts, and individual promotional codes are based on commercial criteria and are not offered in exchange for personal information unless we provide a separate legally required financial-incentive notice.
12. Retention
We retain information only as long as reasonably necessary for the purposes described, including service delivery, customer support, security, backups, dispute resolution, and legal, tax, accounting, and payment obligations. Retention depends on the record:
- Account and customer records generally remain while the account or business relationship is active and for a reasonable period afterward
- Orders, invoices, payments, refunds, policy acceptances, and contracts may be kept for the applicable tax, accounting, limitation, and legal-record periods
- Project assets and delivered files may be kept through production, hosting, support, and a reasonable archival period, but we are not a permanent backup service
- Prospect and inquiry records are reviewed based on recency, relevance, opt-out status, and legal requirements
- Security, login, email-delivery, and system logs are kept for periods reasonably necessary to detect abuse, investigate incidents, and operate the service
- Backups expire on rotating schedules, and deletion from active systems may not immediately remove a backup copy
We may retain information longer when required by law, subject to a legal hold, needed for a dispute, or requested by the person. We may keep deidentified information that cannot reasonably identify an individual.
13. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the information and our operations. Measures include encrypted transport, password hashing, role-based access, CSRF protection, secure session settings, restricted file storage, validation, logging, provider access controls, and recovery practices. No internet service is completely secure. You must protect credentials and use secure methods when sharing files or links.
If a breach creates a legally reportable risk, we will notify affected people and regulators as required by applicable law.
14. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to:
- Know or confirm whether we process your information and obtain access to it
- Correct inaccurate information
- Delete information
- Receive a portable copy of information you provided
- Restrict or object to processing
- Opt out of sale, sharing, targeted advertising, profiling that produces significant effects, or direct marketing
- Limit certain uses or disclosures of sensitive personal information
- Withdraw consent where processing relies on consent
- Appeal a denied request where state law provides an appeal
- Use an authorized agent and receive equal service without unlawful discrimination
- Complain to a privacy, data-protection, consumer-protection, or other regulator
Submit a request to office@listingroyale.com with the subject Privacy Request. Describe the right, account email, state or country, and information involved. We may verify identity and authority using information proportionate to the request. We will respond within the period required by applicable law. Some records cannot be deleted or disclosed because of legal obligations, security, another person rights, privilege, fraud prevention, completed transactions, or other statutory exceptions.
To appeal a refusal, reply with Privacy Appeal. A person may also contact the regulator identified by applicable law. Authorized agents must provide proof of authority, and we may verify the request directly with the consumer where allowed.
15. California notice
For California residents, the categories collected in the preceding twelve months may include identifiers, customer-record information, commercial information, internet or electronic activity, approximate location derived from IP address, professional or employment-related information, audio or visual information, account authentication data, and inferences limited to customer or prospect relationship needs. Sources, purposes, and recipients are described in Sections 2 through 10.
We disclose these categories for business purposes to the provider and recipient categories in Section 6. We do not sell these categories or share them for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics or beyond permitted purposes. California residents may request to know, access, correct, delete, or receive information about collection and disclosure, and may exercise opt-out and limitation rights if our practices ever trigger them. We will not discriminate for exercising CCPA rights.
California Shine the Light requests concerning certain direct-marketing disclosures may be sent to office@listingroyale.com. We do not currently disclose personal information to third parties for their own direct marketing as contemplated by that law.
16. Other U.S. state rights
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with applicable comprehensive privacy laws may exercise the rights their law grants. These can include access, correction, deletion, portability, opt-out, sensitive-data consent or limitation, non-discrimination, and an appeal. Rights, definitions, exceptions, and business thresholds differ, and a listed law applies only when its scope and thresholds are met.
We process recognized universal opt-out signals as described in Section 9. Nevada residents may submit a verified request concerning covered sales even though we do not currently engage in such sales. State-specific requests and appeals may be sent to office@listingroyale.com.
17. EEA, United Kingdom, and Switzerland
Individuals protected by the GDPR, UK GDPR, Swiss data law, or similar law may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent. You may object at any time to direct marketing. You may complain to the supervisory authority where you live, work, or believe a violation occurred.
We operate from the United States. When required for a restricted international transfer, we use an adequacy decision, approved standard contractual clauses, the UK addendum or international data transfer agreement, contractual and technical safeguards, or another lawful mechanism. You may request information about applicable safeguards at office@listingroyale.com.
We do not currently engage in solely automated decision-making that produces legal or similarly significant effects. We do not appoint a data protection officer or EU or UK representative unless and until applicable law requires one. Privacy inquiries may be sent directly to office@listingroyale.com.
18. Canada
Where PIPEDA or a substantially similar provincial law applies, we follow principles of accountability, identified purposes, meaningful consent, limited collection, limited use and retention, accuracy, safeguards, openness, access, correction, and complaint handling. Canadian residents may request access to and correction of their personal information and challenge compliance through office@listingroyale.com. They may also complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.
19. Australia and New Zealand
Where the Australian Privacy Act applies, this Policy describes the kinds of personal information collected, collection and use, access and correction, complaints, and likely overseas disclosure. Information may be processed in the United States and in countries where our providers operate. Australian inquiries may be sent to office@listingroyale.com, followed by a complaint to the Office of the Australian Information Commissioner where available.
Where the New Zealand Privacy Act applies, individuals may exercise access and correction rights and complain to the Office of the Privacy Commissioner. Cross-border disclosures are handled using comparable safeguards, contractual protections, authorization, or another permitted basis when required.
20. Brazil and other jurisdictions
Where the Brazilian LGPD applies, data subjects may request confirmation, access, correction, anonymization, blocking or deletion when legally available, portability, information about sharing and consent, consent withdrawal, review of applicable automated decisions, and a petition to the National Data Protection Authority. Requests may be sent to office@listingroyale.com.
Residents of other countries may have additional rights under local law, including South Africa POPIA and comparable privacy laws. We will honor applicable mandatory rights and provide information needed to contact the appropriate regulator. Nothing in this Policy limits a right that cannot lawfully be waived.
21. Children
The service is intended for real estate professionals, property owners, and other adults and is not directed to children. We do not knowingly collect personal information from a child under 13 in the United States or below the minimum digital-consent age in another jurisdiction. Do not upload identifiable child information unless it is lawful, necessary for the project, and supported by all required parental or guardian permissions. Contact office@listingroyale.com to request removal of child information.
22. Third-party links and services
Property websites and portals may link to MLS pages, maps, videos, virtual tours, cloud folders, payment pages, registrars, social networks, or other services. Those parties independently determine their practices. Review their privacy notices before submitting information. We are not responsible for an independent service policy or conduct.
23. Changes to this Policy
The public page identifies the effective date and version. We may make minor updates for clarity, contact details, or operational accuracy. If a change materially alters how we collect, use, disclose, or protect personal information, or otherwise qualifies as significant, we will email customers and require a new one-time acknowledgment before a later order or payment when appropriate. We will obtain consent before a new use when law requires it.
24. Contact and complaints
Privacy requests, questions, objections, appeals, and complaints may be sent to:
ListingRoyale office@listingroyale.com office@listingroyale.com
We will investigate and respond within the period required by applicable law. You may also complain to the privacy, data-protection, attorney-general, or consumer-protection authority where you live.
Effective date: August 2, 2026
Questions about this policy? Email office@listingroyale.com →