Smooth FlowHow we handle information

Privacy Policy

Effective 2026-07-29

This policy explains what Smooth Flow ("we," "us") does with personal information in connection with Smooth Flow, our software for real-estate agents and licensed mortgage loan originators. Please read the first section — who is responsible for your information depends on who you are.

1. Who We Are, and the Two Roles We Play

Our paying customers are real-estate agents, brokerages and dual-licensed loan originators (Agents). They use Smooth Flow to run their own business: to publish listing pages and intake forms, to manage the people they work with, and to follow up with buyers, sellers, investors and borrowers (Clients).

If you are a Client and want to know why an agent has your information, or want it corrected or deleted, contact that agent first. Section 12 explains what we can do if you come to us instead.

2. An Honest Note About White-Label Pages

Smooth Flow is white-label by design. When a Client fills out a home-value request, an open-house sign-in, a listing inquiry or an intake form, the page carries the agent's name, brand and contact details. Our name does not appear on those pages, and they do not link to this policy today.

We say this plainly because it has a real consequence: a Client generally does not know we exist at the moment they hand over their information. We therefore do not assume you have read this policy, and we do not treat use of an agent-branded page as consent to anything. Agents are responsible for providing their own privacy notice and for obtaining any consent the law requires before collecting information or contacting anyone.

3. Text Messages (SMS) and Mobile Opt-In

Texts sent through Smooth Flow go out on behalf of an individual Agent, from that Agent's own registered messaging number and provider. The Agent is responsible for obtaining consent before texting anyone.

How opt-in happens. You opt in by giving an Agent your mobile number and asking to be contacted — by submitting a showing request, an intake form, a home-value request or an open-house sign-in on their page, by replying to their text, or by telling them directly. A limitation worth stating: the intake forms in the product do not currently display a separate SMS consent checkbox or disclosure. Submitting a form is what the Agent treats as your request to be contacted, and any additional consent language is the Agent's responsibility to present.

Opting out. Opt-outs are permanent, and enforced by the software rather than by policy alone. A STOP-type reply is written to a durable consent ledger before we try to update the CRM, so a CRM outage cannot make it disappear, and opt-out records are exempt from routine trimming. Send paths re-check opt-out status immediately before sending and fail closed: if we cannot confirm that a recipient is clear to contact, we do not send. We match STOP-type keywords against the whole message, so a phrase like "stop by anytime" does not unsubscribe you. You can also revoke consent by any other reasonable means — replying in plain language, telling the Agent, or emailing — and we will act on it within ten business days.

4. Messages That Send Automatically

Some messages leave the system without a person pressing send. These include acknowledgements sent shortly after someone submits one of an Agent's forms, scheduled multi-step email follow-up sequences, and — where an Agent has switched them on — replies drafted by AI, a short courtesy line to a new inbound lead, and a one-time nudge when a Client opens a page an Agent shared. Several are on by default; each can be turned off by the Agent. Acknowledgements and scheduled sequences use fixed templates written in advance rather than AI.

5. Information We Collect

Agent account data (we are the controller)

An email address and a password, which is stored hashed. A professional profile — name, business contact details, brokerage, NMLS number, market area, headshot, branding, and a home-base address used for drive-time and routing. Integration settings and credentials for the services an Agent connects, including CRM, MLS, webhook and ad-account settings. Tokens for calendar and e-signature accounts connected by OAuth are held in an encrypted vault; other integration credentials, such as a CRM key or an MLS feed credential, are stored on our server without additional encryption at rest and are protected by access controls and by never being sent to the browser. Usage and cost telemetry, and device push subscriptions if notifications are enabled.

Client data (we are the processor; the Agent controls it)

Automatically collected data

An ordinary public listing link records view counters with no personal information attached, and some shared pages record nothing at all. A link an Agent sends to a specific person is minted for that person, so an open of it — or a showing request made from it — is recorded against that Client's record with a timestamp and feeds a follow-up list.

We use IP address and browser user agent for bot filtering, rate limiting and duplicate detection. The application holds these in memory rather than saving raw addresses, with a narrow exception: a short hash fragment of an IP is stored inside a de-duplication key for reactions left on a video-message page. Our web server also writes standard access logs that include IP addresses.

6. How We Use Information

To provide the product — publishing an Agent's pages, capturing inquiries into their CRM, drafting and queuing follow-up, and building packages, tour routes, valuations, snapshots and video messages. To send the messages described in Sections 3, 4 and 8. To authenticate Agents, keep accounts secure, enforce rate limits, block abuse, and meter usage and cost for billing and support. To operate safety controls: opt-out enforcement, quiet hours, send caps, fair-housing filtering and required legal disclosures. And to comply with law and respond to lawful requests.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not upload contact lists, hashed emails or custom audiences to advertising networks.

7. AI, Automated Output and Non-Discrimination

8. Service Providers, Email and Cookies

Service providers

Because the product is white-label, a Client generally does not see these names in the product. What each receives depends on the features an Agent turns on, and some integrations ship disabled and transmit nothing until provisioned.

Email

Our own platform email goes to Agents — password reset, morning digest and new-lead alerts. Each carries a footer that names us as the sender, says why you are receiving it, and points to the per-message toggles in account settings.

A limitation, stated plainly: these messages do not currently include a one-click unsubscribe link or a List-Unsubscribe header, and the toggles that switch them off are behind the login wall. If you want them stopped and you cannot or will not log in, write to and we will act within ten business days at no cost to you. We do not currently send commercial marketing email through the product.

Email an Agent sends to their Clients — including the acknowledgements and sequences in Section 4 — goes out through the Agent's connected CRM under the Agent's own sending identity, and carries whatever footer and unsubscribe mechanism that CRM applies. We do not add one. Agents are responsible for including a valid postal address and a working unsubscribe in their commercial email and for honoring opt-outs. You can also stop that mail by replying to it, by telling the Agent, or by writing to .

Cookies and similar technologies

Public pages in the product do not set cookies or use browser storage, which is why you will not see a cookie banner on an agent's page. Most run no JavaScript at all, and they do not request microphone or camera access. We run no analytics suite, tag manager, ad pixel, session replay or cross-site tracking anywhere in the product.

Agent login uses cookies. Signing in sets a session cookie and a longer-lived sign-in cookie, both HttpOnly and SameSite=Lax, so the app does not log you out each day. There is no "remember me" checkbox — the persistent cookie is set on sign-in, and signing out clears both. The logged-in application also uses local storage for display preferences, which stay on your device. Third-party embeds are the exception: an embedded map, tour, video or booking widget can set its own cookies, governed by that company's policy rather than ours.

9. Data Retention and Deletion

Closing a Smooth Flow account is self-serve and there is no retention wall — but it is a request, not an automatic purge. It records a dated entry, marks the account as closure-requested and notifies us; a person on our side performs the login disable and the data removal. There is no automated deletion job in the product, and we will not pretend otherwise. An Agent's data export stays available throughout, and a request can be withdrawn.

There is also no self-service deletion path for Clients in the product today, and no consumer-facing endpoint that verifies and executes a deletion request on its own. If you are a Client and want your information removed, see Section 12 — the route runs through your agent, or through us at , and it is handled by a person. Some information is retained after a deletion request where the law requires it, in particular the records proving that you opted out of messaging; keeping that record is what stops you being contacted again.

10. Security

What we will not claim: we hold no SOC 2, ISO 27001 or comparable certification, and we do not claim blanket encryption of every file at rest — the encrypted vault above covers connected-account tokens. No system is perfectly secure, and we cannot guarantee absolute security.

If a breach affecting personal information occurs, we will notify affected individuals and the appropriate regulators within the timeframes the law requires, and we will notify affected Agents promptly so they can meet their own obligations.

11. Where Your Information Is Handled

Smooth Flow is intended for use by professionals and consumers in the United States. Our service providers operate global infrastructure, so information can be processed or delivered from systems outside the United States — hosted video, for instance, is delivered from whichever content-delivery edge is nearest the viewer. We do not offer the service to individuals in the European Economic Area, the United Kingdom or Switzerland, and this policy is not written to satisfy the GDPR.

12. Your Rights and How to Exercise Them

If you are a Client, contact the agent you dealt with first. They control your information — they decided to collect it, they decide how long to keep it, and they hold the CRM record. Their name, phone and email are on the page you used.

If you cannot reach them, or do not know who they are, write to with enough detail for us to find the record — the phone number or email address you gave, the property address, and roughly when. This is handled by people, not by an automated endpoint. We identify the responsible Agent, pass your request to them, and tell you what we did and who they are unless we are legally barred from doing so. Two things we do immediately, without waiting on anyone: we permanently record a stop-messaging request, and we halt scheduled follow-up. We aim to complete the rest within the period the law allows, and in any event within forty-five days.

If you are an Agent, a one-click export bundles your workspace data into a downloadable file, with capability-granting credentials redacted to yes/no indicators — we redact capabilities, not your data. Your contacts live in your connected CRM and are exportable there. Edit your profile and settings in the product, request closure there or by writing to (a person finalizes it), and turn platform email off with the toggles in your settings.

State privacy rights. Depending on where you live, you may have rights to know what personal information is collected, to access, correct or delete it, to opt out of sale or of sharing for targeted advertising, to limit the use of sensitive information, to be free from discrimination for exercising these rights, and to appeal a denial. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. To exercise a right, write to . We will verify your request using information we already hold, respond within the period the applicable law allows, tell you how to appeal if we decline, and route it to the responsible Agent if it concerns data they control.

Mortgage and lending customers. Loan originators using Smooth Flow are financial institutions under federal law and owe you their own privacy notice describing how they handle your nonpublic personal financial information. We act as their service provider, using that information to provide the service they engaged us for and not for other purposes. Their notice, not this one, governs their handling of your loan information.

13. Children

Smooth Flow is business software for licensed real-estate and mortgage professionals. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child's information has been submitted through a page in our product, write to and we will work with the responsible Agent to remove it.

14. Changes to This Policy

We will update this policy when the product changes. For a material change we will update the effective date at the top and notify Agents by email or in the product before the change takes effect. Continued use after the effective date means the updated policy applies. Prior versions are available on request.

15. Contact Us

Questions, requests or complaints about this policy or about your information: Smooth Flow, .

If you are a Client of an agent who uses Smooth Flow, please contact that agent first — they hold and control your information. We will help if you cannot reach them.