Privacy Policy
Last updated: April 18, 2026
Yavay ("we," "our," or "us") provides a real estate professional platform including Yavay Hub, Yavay Studio (virtual staging), Yavay CRM, Yavay Social, digital business cards, link hubs, mini pages, leads management, calendar, and scan-to-lead features. This Privacy Policy describes how we collect, use, share, retain, and protect your information when you use our mobile app, our website at yavay.app, and related services (collectively, the "Service").
This Policy should be read alongside our Terms and Conditions. Capitalized terms not defined here have the meaning given in the Terms.
1. Who is the controller
Yavay is the data controller for personal information collected directly from registered users of the Service. Our business address is 14359 Miramar Pkwy #309, Miramar, FL 33027, USA. For privacy questions, contact privacy@yavay.app.
The Service is offered from and intended for users in the United States. We do not currently target or actively offer the Service in the European Union or United Kingdom and have not appointed an Article 27 GDPR representative. If you are a resident of the EU or UK and choose to use the Service, this Policy still describes how we handle your personal data.
When a real-estate professional (the "page owner") uses Yavay to operate a public link hub, mini page, lead-capture form, or similar tool that collects information from their own visitors, the page owner is the controller of that visitor data and Yavay is the processor acting on the page owner's instructions. Visitors who have questions about such data should contact the page owner first.
2. Information we collect
Account and profile data. When you create an account, we collect your email address and a password (authentication is handled by Firebase Authentication, which stores only hashed credentials). If you set up a profile, we may store your name, profile photo, bio, contact email, phone number, company or broker name, professional title, card branding (accent color, tagline, logo), your custom link-hub page slug and sections, and related preferences.
Single sign-on (Apple / Google). If you choose to sign in with Apple or Google, we receive from the identity provider the fields you authorize — typically your email address, name, and (in the case of Google) your avatar — for the purpose of creating and authenticating your account. We do not receive your password from the identity provider.
User Content. In Yavay Studio and related features, you upload images of rooms, exteriors, floor plans, and similar material ("User Content") that you want the Service to process. User Content is stored in your account and transmitted to our model providers only to generate the Outputs you request.
Image metadata (EXIF). Uploaded images may contain embedded metadata (EXIF) including device information and, where present, GPS coordinates. We do not use this metadata for marketing. You may strip metadata from images before uploading if you prefer.
Sensitive Personal Information (SPI). We do not intentionally collect Sensitive Personal Information as defined under the CCPA/CPRA or comparable laws. Incidental SPI that may be contained in uploaded images (for example, a person visible in the background of a photo) is processed solely to provide the Service and is not used to infer characteristics about individuals.
Leads, clients, and CRM activity. We store leads, contacts, notes, tags, calendar events, tasks, and other CRM activity associated with your account.
Visitor data on Yavay-powered pages. When visitors submit information (for example, name, email, phone) on a public link hub, mini page, lead-capture form, or scan-to-lead flow powered by Yavay, that information is collected by the page owner and stored in the page owner's Yavay account for their follow-up. Yavay processes and stores this data on the page owner's behalf.
Scan-to-lead (OCR). When you use scan-to-lead, you upload images (for example, business cards, sign-in sheets). Those images are sent to our servers and processed using Google Cloud Vision and Google Gemini to extract contact information. Processed lead data is saved to your account as you choose.
Billing data. Subscription and credit-pack purchases are processed by Stripe. Yavay receives a transaction reference, plan or pack identifier, last four digits of the card, country, and amount. We do not receive or store full payment-card details.
Usage, device, and log data. We collect information about how you interact with the Service (for example, features used, render volumes, pages visited, error events), along with basic device and log data such as IP address, browser/OS, timestamps, and crash diagnostics. This data helps us operate, secure, and improve the Service.
Communications. If you email us, book a demo, or contact support, we retain the contents of the communication and related metadata.
Cookies and similar technologies. Our website uses a small number of first-party cookies for authentication, session management, and basic analytics. We may use third-party analytics that set their own cookies in accordance with their policies. Where required by law, we will ask for consent before non-essential cookies are set.
3. How we use your information
We use the information we collect to: provide, operate, secure, and improve the Service; generate Outputs you request; personalize your experience and your public mini page; process scan-to-lead and store leads; sync your profile, CRM, and link sections across devices; process payments and manage subscriptions and credits; communicate with you about your account, product changes, and support; detect, prevent, and respond to fraud, abuse, or security incidents; enforce our Terms and protect our legal rights; and comply with applicable law.
Legal bases (EU/UK users). We rely on contract (to provide the Service you request), legitimate interests (to secure and improve the Service and protect against abuse), consent (for non-essential cookies and optional marketing), and legal obligation (where required by law).
4. AI training and model improvement
We do not use your uploaded photos, generated Outputs, your leads, or the contents of your CRM to train our AI models without your consent, and we do not sell or license those materials to third parties to train their generally available generative AI models.
We may use your feedback and interaction signals — such as ratings, accept/reject actions, retries, edits, and whether you download an Output — to evaluate and improve the Service, including training and fine-tuning the AI models that power it. Feedback signals used for model improvement are aggregated and de-identified where practical. You may contact privacy@yavay.app to opt out of the use of your feedback for model training; opting out does not affect aggregated or previously incorporated data.
To generate Outputs you request, User Content is transmitted to our upstream generative AI model providers (for example, Google Gemini). Those providers process content under their own API terms, which generally include commitments not to train generally available models on API content. We may additionally use aggregated, de-identified operational metadata (for example, error rates, render timings, and feature-usage statistics) to operate, secure, debug, and improve the Service. Enterprise and brokerage customers may request additional written assurances through a separate signed agreement.
5. How we share information
We share personal information only as described below:
Service providers (subprocessors). We share data with vendors who help us run the Service under written data-processing terms. Current categories and examples include:
• Hosting and infrastructure: Google Cloud / Firebase (Authentication, Firestore, Storage), Vercel.
• Generative AI: Google (Gemini), Google Cloud Vision.
• Payments: Stripe.
• Email and transactional messaging: Resend.
• Analytics and error monitoring: Vercel Analytics, Sentry.
We will update this list as we add or replace vendors, and we will revise the "Last updated" date at the top of this Policy when we do.
Data Processing Addendum (DPA). Enterprise and brokerage customers may request our Data Processing Addendum (DPA), including Standard Contractual Clauses (SCCs) where applicable, by contacting privacy@yavay.app.
Page owners. Visitor data submitted through a Yavay-powered link hub, mini page, or lead-capture flow is shared with the page owner who operates that page.
Legal and safety. We may disclose information to comply with law, respond to lawful requests from public authorities, protect our rights and the safety of users, or investigate and prevent abuse and security incidents.
Business transfers. If we are involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction, subject to the acquirer's commitment to honor this Policy or give you notice of any changes.
We do not sell your personal information for advertising, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
6. International data transfers
Yavay is based in the United States, and our service providers are primarily located in the United States and the European Union. Where personal data of individuals in the EU, UK, or Switzerland is transferred to the United States, we rely on appropriate safeguards such as the Standard Contractual Clauses (and the UK Addendum where applicable). You may contact us at privacy@yavay.app to request a copy of the relevant transfer mechanism.
7. Data retention and deletion
We retain account and profile data, User Content, Outputs, CRM records, and related data while your account is active and as needed to operate and secure the Service. You may delete specific items (including leads, renders, and uploads) through the Service at any time. You may also request deletion of your entire account from within the app (for example, More → Delete account) or by contacting privacy@yavay.app.
Following account termination (by you or by us), we will make your User Content and Outputs available for export for thirty (30) days and will then delete or irreversibly de-identify them from our production systems within a reasonable period, except where retention is required by law, necessary to resolve disputes, or maintained in routine encrypted backups that cycle out over time. Billing and tax records are retained for the period required by applicable law (typically up to seven years).
Visitor data submitted to a page owner's Yavay-powered page is retained based on the page owner's decisions and settings.
8. Your rights and choices
Depending on where you live, you may have the following rights in relation to your personal information:
EU/UK/EEA (GDPR, UK GDPR). Right of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests). Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. You have the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA). Right to know what personal information we collect and how we use it, right to access and receive a copy, right to correction, right to deletion, right to opt out of "sale" or "sharing" of personal information (we do not sell or share in the CCPA/CPRA sense), right to limit use of "sensitive personal information," and right to non-discrimination for exercising your rights. We honor Global Privacy Control (GPC) signals as a valid opt-out of the "sale" or "sharing" of personal information where applicable.
Other U.S. state laws. Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Montana, Oregon, and others) generally have comparable rights of access, correction, deletion, and opt-out; we honor these in the same process described below.
How to exercise your rights. You can update your profile in the app at any time. For other requests, email privacy@yavay.app from the email address associated with your account. We will respond within the period required by applicable law (generally 30 days for GDPR/UK GDPR and 45 days for CCPA/CPRA). We may need to verify your identity before fulfilling a request. You may use an authorized agent where permitted by law.
Appeals. If we deny your rights request, you may appeal by replying to our denial email within 60 days. We will respond to appeals within the timeframe required by applicable law (typically 45–60 days).
9. Security
We use industry-standard measures to protect your data, including encryption in transit (TLS), encryption at rest for stored User Content and backups, access controls, least- privilege administrative access, and logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as required by law.
10. Children
The Service is a business tool for real-estate professionals and is not directed to children. You must be at least 18 years old to use the Service. We do not knowingly collect personal information from children under 18 (or, in any event, under 13 for U.S. COPPA purposes). If you believe we have collected information from a child, contact privacy@yavay.app and we will delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. Material changes may be communicated through the Service or by email where appropriate. Continued use of Yavay after changes become effective constitutes acceptance of the revised Policy.
12. Contact us
For privacy-related questions or requests, contact us at:
Yavay
14359 Miramar Pkwy #309
Miramar, FL 33027, USA
Privacy: privacy@yavay.app
General support: support@yavay.app
Legal notices: legal@yavay.app
DMCA: dmca@yavay.app
© 2026 Yavay. All rights reserved.