Last updated September 4, 2026
Privacy Policy
Last updated: September 4, 2026
1. Overview
Riya Platforms, Inc. operates FlipFindr, a subscription software-as-a-service platform for real estate investors. FlipFindr collects publicly available property listing data, organizes it into leads within the counties a customer subscribes to, and provides tooling for our customers to review, approve, and send SMS outreach to listing agents and property owners, together with reporting on the replies they receive. This Privacy Policy explains how we collect, use, and handle information when you visit our website or use the platform.
It covers two groups of people, and it says which is which throughout. Our customers and their users hold accounts with us. The agents and owners our customers contact do not, and they have not agreed to anything with us. Both groups have the rights described in Section 11.
2. Information We Collect
- Account Information: Information you provide when registering, such as names, email addresses, billing details, and business credentials.
- Public Listing Data: Business contact details for property listings, such as a listing agent's name and phone number, collected on our behalf by a third-party data partner from publicly available property listings.
- User-Provided Content: Data, lists, or custom configurations uploaded or fed into the platform by our customers.
- Billing and Payment Information: Business and billing details, the subscription and counties you are billed for, and limited payment method details. Card numbers go directly to our payment processor and are never stored by us. See Section 7.
- Messaging Data: The content, phone numbers, timing, and delivery status of the SMS messages our customers send and receive through the platform. See Section 8.
- Diagnostic Data: Technical information generated automatically when the platform errors or performs poorly, such as error messages, stack traces, browser and device type, the page you were on, and details of the session it occurred in, including your email address and IP address. See Section 5.
- Usage and Analytics Data: Information about how you use the platform, collected automatically and linked to your account, including your IP address and recordings of your sessions in the platform. See Section 6.
- Agreement Records: When you accept our Terms of Service or this Privacy Policy, we record which document and version you accepted, the date and time, and the IP address and browser user agent the acceptance was submitted from. See Section 9.
3. How We Use Information
We use the information collected through our platform to:
- Operate, maintain, and improve our software infrastructure and automation tools.
- Enable our customers to execute workflow and messaging campaigns.
- Take payment, administer subscriptions and county coverage, issue invoices, and calculate and pay commissions to referral partners who introduce new customers to us.
- Send service, security, and billing communications to account holders.
- Detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service.
- Maintain internal suppression and opt-out lists to prevent unwanted contacts where processed by our systems.
4. Platform Role and Third-Party Data
- Customer-Managed Data: For any data uploaded, imported, or explicitly targeted by our customers, our customers act as the controllers of that campaign, and we act strictly as a technical service provider processing instructions on their behalf.
- Sourced Listing Data: Listing data reaches the platform through a third-party data partner that collects publicly available property listings. We do not create that data and we do not independently verify it. We stage it as a software utility so that our customers can decide who to contact.
5. Diagnostic Data and Session Replay
We use a third-party error monitoring service to detect, diagnose, and fix faults in the platform. This is limited to operating and securing the service. We do not use diagnostic data for advertising, and we do not sell or share it as those terms are defined under the California Consumer Privacy Act.
- Error and performance monitoring: When the platform encounters an error, we record technical details of the fault together with information identifying the session it occurred in: your user identifier, name, email address, role, workspace, and IP address. We use these to reproduce the fault, to tell whether it affects one account or many, and to investigate abuse. Authentication credentials are filtered out before events are transmitted.
- Session replay: For a limited sample of sessions we capture a reconstruction of the interface, meaning the structure of the page and the actions taken on it, to understand how a fault occurred. Replay is not applied to every session. It is normally triggered only after an error occurs, and even then only for a fraction of those sessions. We may adjust these sampling rates over time to diagnose specific issues.
- What replay does not capture: Replays are redacted at the point of capture. Text content, form and input values, and images and other media are masked or blocked before the recording leaves your browser, so the replay shows the shape and flow of the session rather than its contents.
- Retention: Diagnostic events and replays are retained by our monitoring provider for a limited period under that provider's standard retention schedule and are then deleted.
To request access to, or deletion of, diagnostic data associated with your account, contact us using the details in Section 16.
6. Analytics and Product Usage
We use a third-party product analytics service to understand how the platform is used so that we can improve it. This is not anonymous website measurement. When you are signed in, your activity is linked to your account, including your user identifier, name, email address, role, and the workspace you belong to.
- What is collected: the pages and features you use within the platform, the actions you take and their timing and sequence, your browser and device type, and your IP address, from which an approximate location such as city or region may be derived.
- How we use it: to measure which features are used, to find and fix usability problems, and to decide what to build next. We do not use analytics data for advertising, and we do not sell or share it as those terms are defined under the California Consumer Privacy Act.
- Session replay: We record reconstructions of your sessions in the platform, meaning the structure of the pages you visit and the actions you take on them, and review them to understand how features are used and how problems arise. Recordings are redacted in your browser before they are transmitted. Text content, form and input values, and images and other media are masked or blocked, so a replay shows the shape and flow of a session rather than the information displayed during it.
- Retention: Analytics data and session recordings are retained by our analytics provider for a limited period under that provider's retention schedule and our configured settings, and are then deleted.
Session recordings are made of the platform as used by our customers. Where a customer's screen displays information about third parties, that information is masked by the redaction described above. To request access to, or deletion of, analytics data or session recordings associated with your account, contact us using the details in Section 16.
7. Billing and Payment Information
FlipFindr is a paid subscription. Payments are processed by a third-party payment processor, and card details are collected by that processor directly in a form it hosts.
- What we hold: your business name and billing contact details, your customer and subscription identifiers with the processor, the plan and the counties you are billed for, your billing interval, your renewal date, whether a cancellation is pending, and the brand and last four digits of your payment method. We do not receive or store full card numbers, expiry dates, or security codes.
- How we use it: to charge your subscription, to invoice you, to apply referral discounts and trial eligibility, to recover failed payments, and to keep the accounting and tax records the law requires of us.
- The processor's own role: our payment processor handles payment data as an independent controller for payment processing, fraud prevention, and its own legal obligations, under its own privacy policy. We do not control that use. We will tell you which processor we use, and where to find its policy, if you ask us using the details in Section 16.
- Referral data: If you signed up through a referral link, we record the association between your account and that referral, and we calculate a commission from the invoices you pay. We share with the referral partner the fact of the referral, its status, and the commission amount. We do not give referral partners access to your account, your leads, or your messages.
- Retention: Billing and transaction records are retained for as long as required by tax, accounting, and audit obligations, which is generally longer than the life of your account.
8. Messaging Data
The platform sends and receives SMS on our customers' behalf through third-party messaging providers and the phone carriers they connect to. We work with more than one provider, and which one carries a given message depends on the customer and the sending number.
- What we hold: the full content of outbound and inbound messages, the sending and receiving phone numbers, timestamps, delivery status, and any carrier error returned. Outbound messages are stored from the moment a customer's user drafts them, whether or not they are ever sent.
- Who this is about: most recipients are listing agents and property owners whose phone numbers came from listing data rather than from a relationship with us. They have no account and have not agreed to anything with us. The rights in Section 11 and the suppression route in Section 12 are still theirs, and they do not need an account to use either.
- How we use it: to deliver messages and display conversations in our customer's inbox, to classify replies automatically, including recognizing opt-outs and negative responses so that further automated messages are suppressed, and to operate, secure, support, and debug the platform.
- Opt-out handling: When a recipient replies with a standard opt-out keyword, including STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT, we record the opt-out and suppress further automated sends to that number within the workspace that contacted them. We keep a record of the opt-out itself, because we need it in order to keep honoring it.
- Our role: our customer decides who to contact and what to say, and each message is approved by one of their users before it is sent. For messaging, the customer is the controller and we act as their service provider.
- Carrier registration: Business messaging in the United States requires A2P 10DLC brand and campaign registration with the carriers and industry registries. Where a customer asks us to file that registration, we do so using business details the customer supplies, and those details are shared with the registry and the carriers for that purpose. Customers who already hold an active registration, or who register directly, keep their own, and we file nothing on their behalf.
- Retention: Message content and conversation history are retained for as long as the customer's workspace is active, and are then deleted on the schedule described in Section 11. Suppression and opt-out records outlive the workspace, because deleting them would defeat their purpose.
9. Agreement Records and Retention
When you accept our Terms of Service or this Privacy Policy, we create a record of that acceptance. Each record identifies the accepting user and contains the document and version accepted, the date and time of acceptance, and the IP address and browser user agent the acceptance was submitted from.
- Why we collect this: An electronic acceptance is only enforceable if the act can be attributed to the person who performed it. We collect the IP address, user agent, and timestamp for that evidentiary purpose, so that we can demonstrate who agreed to which version of a document, and when. We do not use this information to profile you, to target you, or to build advertising audiences.
- Retention: Agreement records are append-only. We do not alter or delete them, and accepting a newer version adds a further record rather than replacing an earlier one. We retain them for as long as the agreement may need to be evidenced.
- Effect on deletion requests: Where you ask us to delete your personal information, we will do so except where an exception applies. Agreement records fall within the exceptions available under California Civil Code section 1798.105(d), which permit a business to retain personal information where necessary to complete a transaction, to perform a contract with you, or to comply with a legal obligation. Where we rely on this exception we will tell you, and the exception applies only to the agreement record itself, not to your other personal information.
10. How We Share Information
We do not sell your personal information, and we do not share it as that term is defined under the California Consumer Privacy Act.
We share limited information with service providers who help us operate the platform and deliver our services, and only to the extent necessary for them to perform those functions on our behalf. Those providers fall into the following categories:
- Cloud infrastructure and hosting providers, which hold platform data at rest and in transit.
- Authentication and database providers, which hold account identities and application data.
- A payment processor, which handles the billing and payment information described in Section 7.
- Messaging providers and the phone carriers they connect to, which carry the messaging data described in Section 8.
- A data partner, which collects publicly available property listings on our behalf.
- Error monitoring and product analytics providers, which receive the data described in Sections 5 and 6.
- An email delivery provider, which sends service and account emails on our behalf.
Each provider is bound by contract to use the information only to perform its function for us. If you want to know which specific providers we use, write to us at the address in Section 16 and we will tell you.
We may also disclose information where required by law, and in connection with a merger, acquisition, or sale of assets, in which case we will tell you before your information becomes subject to a different policy.
11. Your Rights
Depending on where you live, you may have rights under privacy laws such as the California Consumer Privacy Act (CCPA/CPRA), including the right to access, correct, or delete the personal information we hold about you, and the right not to be discriminated against for exercising those rights. These rights are subject to the exceptions those laws provide. In particular, we retain agreement records evidencing your acceptance of our terms even after a deletion request, as described in Section 9. Where we rely on an exception, we will tell you.
How to make a request. You do not need an account, and we will not charge you or treat you differently for asking. There are three ways to reach us, and all are answered on the same terms:
- Online. Use the form on our Do Not Sell or Share My Personal Information page. If you do have an account, Settings then Privacy also lets you download a copy of your data or delete your account directly.
- By email. Write to support@riyaplatforms.com with what you are asking for.
- By post. Write to us at the address in Section 16.
We will respond within 45 days, as the CCPA requires. We may need to ask you for information to verify who you are before we act, particularly where a request would delete or disclose personal information.
Downloading your data. If you have an account, Settings then Privacy will assemble a copy of the personal information we hold about you. It covers your account, your workspace memberships, the agreements you accepted, and a record of what you did in FlipFindr. It does not include replies to messages you sent or the phone numbers you messaged, because those identify other people, and their personal information is not yours to receive.
Deleting your account. Deletion is confirmed by a link we email you, and then waits seven calendar days before it runs, so that you can cancel if the request was not yours. When it runs we delete your account and the personal information we hold about you.
What survives a deletion. Three things, all narrow. Records of your acceptance of our Terms and this Policy are retained under the exception in California Civil Code section 1798.105(d), with your identity removed from them, as described in Section 9. Our internal record of administrative actions is retained for security purposes under the same section, with your identity removed and your email address stripped out of it. And billing and transaction records are retained where tax and accounting law requires us to keep them, as described in Section 7.
12. Opt-Out and Contact Suppression
If your business contact information appears within our platform and you wish to be removed or suppressed from our databases, you do not need an account to ask. Use the form on our Do Not Sell or Share My Personal Information page, or write to us using the details in Section 16. Upon verification, we will take commercially reasonable steps to suppress your information from our active databases.
This applies to you whether or not you have ever used FlipFindr. If your details reached us from a property listing rather than from you, the rights in Section 11 are still yours.
If you have received a text message from a FlipFindr customer, replying STOP to that message stops further automated messages from that customer immediately. We also honor STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT, as described in Section 8. Replying to a message stops that one customer. Using the form above suppresses your details across the platform.
13. Security
We implement commercially reasonable technical and organizational measures designed to protect personal information. These include isolation of each customer's data at the database level, encryption of data in transit, access controls scoped to a user's role and workspace, and configuration of our error monitoring so that authentication credentials are not transmitted with diagnostic events. No system can be guaranteed secure, and we do not claim otherwise.
14. Children
FlipFindr is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, write to us using the details in Section 16 and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post any updates directly on this page with a revised "Last updated" date.
Where a change is material, we will ask you to review and acknowledge the updated version the next time you sign in, and we keep a record of that acknowledgement as described in Section 9.
16. Contact Us
For privacy questions, data rights requests, or suppression requests:
Email: support@riyaplatforms.com
Post: Riya Platforms, Inc. 131 Continental Dr, Suite 305 Newark, DE 19713 United States
Also read the Terms of Service.