Privacy Policy
This policy explains what information InfoRealEstate.ai uses, why it needs it, and how you can control your data.
Last updated: August 19, 2026
Information we process
Depending on the features you use, we may process your account information, search activity, chat history, preferences, location, and information you provide while using the platform.
Facebook and Instagram data
When an agency administrator connects the agency’s own Meta accounts, we use the authorized permissions to identify the Facebook Pages they manage, display the Page name and linked Instagram Business account, and let the agency publish reviewed real-estate content to those selected accounts.
When messaging functionality is enabled for an agency, we may also process messages received by its Facebook Page or Instagram Business account, and replies sent from the CRM, so the agency can manage enquiries from prospective customers.
We do not use this data to post to accounts not selected by the agency or to send bulk promotional messages.
Meta permissions the application requests
When the person who administers a real estate agency connects the agency's accounts, Facebook shows a consent screen listing the permissions below. Each one is named exactly as Meta names it, together with the specific use the platform makes of it. Connecting is voluntary: an account that never connects produces no processing of Facebook or Instagram data at all.
Permissions required in order to publish
These five permissions are indispensable. If any one of them is declined the connection is not created: a connection that cannot publish would serve no purpose in the product.
- pages_show_list
- Lists the Facebook Pages the authorising person administers, so that the agency can choose one. Only the identifier and the name of the chosen Page are kept.
- pages_read_engagement
- Reads that Page's own fields — its name and whether it has a linked Instagram Business account — so they can be shown in the CRM and so we know whether Instagram is reachable.
- pages_manage_posts
- Publishes to the agency's own Facebook Page the content the agency itself wrote and approved. Nothing goes out without the explicit approval of a member of the agency.
- instagram_basic
- Reads the Instagram Business account linked to that Page: its identifier and its username.
- instagram_content_publish
- Publishes to that Instagram account the feed posts and stories the agency approved.
Optional permissions
These permissions are requested on the same screen and may be declined. If they are declined the connection still works for publishing, and the CRM states in words which function stays switched off.
- read_insights
- Reads the Facebook Page's own metrics for the posts published from the platform: views, reactions and clicks.
- instagram_manage_insights
- Reads the metrics of the Instagram posts and stories published from the platform: reach, views, interactions, likes, comments, shares, saves and replies.
- pages_messaging
- Receives the Messenger messages sent to the agency's Page and sends the replies the agency writes in the CRM.
- instagram_manage_messages
- Does the same for the Instagram direct messages of the linked account.
- pages_manage_metadata
- Subscribes the Page to the application's webhook, which is what makes incoming messages arrive at all. It is used for nothing else.
What data each function produces
A received message creates, in that agency's CRM inbox, one contact and one conversation holding the identifier Meta assigns to the sender for that account, their public name or username when Meta supplies it, the message text, and its date and time. Messages carrying only attachments are recorded with a note saying a file arrived, not with its content. That information is visible only to the receiving agency.
Metrics are aggregate figures about the agency's own posts and contain no data identifying the people who saw them or interacted with them. Each reading is stored alongside the post and refreshed at most once every thirty minutes.
The application does not request the business_management permission, nor the advertising permissions ads_management and ads_read: it does not administer the agency's business portfolio or its ad accounts. Nor does it request WhatsApp permissions over third-party accounts.
Retention and withdrawing the authorisation
Connection credentials are stored encrypted and kept for as long as the connection is active and the account exists.
Disconnecting the channel from the CRM erases the stored credential together with the data of the selected Page and Instagram account. That action does not revoke the authorisation on Meta's side: withdrawing it completely also requires removing the application in Facebook's settings, under “Apps and websites”. Messages already received remain as records in the agency's CRM until their deletion is requested.
Meta issues no renewal credential, so the authorisation expires. The CRM gives notice roughly one week before it does, so the agency can authorise again; if it expires, the channel stops working until that happens.
WhatsApp data
Our WhatsApp features run on Meta’s WhatsApp Business Platform. When you message our WhatsApp number, we process your phone number and the content of your messages (text, images, and voice notes, which may be transcribed automatically) to answer your property enquiry and keep the conversation available to you.
When an agency enables the WhatsApp integration, messages exchanged with its customers are also delivered into the agency’s CRM inbox, together with delivery status, so the assigned agent can follow up. Agents link their own WhatsApp number through an explicit verification step confirmed inside the CRM.
Reply drafts may be prepared with AI assistance, and a draft is only sent to a customer after a member of the agency approves it. We do not use WhatsApp data to send bulk or promotional messages.
WhatsApp features operate on the platform's own WhatsApp Business number. The platform does not connect or administer each agency's WhatsApp Business account, and does not request the Meta API's WhatsApp permissions over third-party accounts.
How we use information
We use information to provide, operate, protect, and improve the Service; respond to requests; maintain accounts; and enable the features you choose to activate, including an agency’s voluntary Meta channel connection.
Legal basis
We process data from Meta platforms (Facebook, Instagram, and WhatsApp) on the basis of the authorization given when the channel is connected or when you choose to message us there; you can withdraw it at any time by disconnecting the channel or removing our access in your Meta settings. We process account and usage data because it is necessary to provide the Service you request, and security and reliability data on the basis of our legitimate interest in keeping the Service safe.
Third parties and data sharing
We share data with service providers only as needed to operate the Service: Meta Platforms (which transmits the content an agency publishes and the messages exchanged through its connected channels, under Meta’s own terms), infrastructure and database providers that host our systems, and AI service providers that process the text or audio you submit (searches, chat, message drafts, transcriptions) to power those features.
We do not sell personal data or Meta platform data, we do not share it with data brokers, and we do not use it for third-party advertising.
Retention and deletion
We retain data only as needed to provide the Service, maintain an account, or meet applicable obligations. You may request deletion of data linked to your account or a Meta connection by following our data deletion instructions.
Contact
For privacy or data-processing questions, contact hello@appsuy.com.