Skip to content
Lakeside Luxury Realty
All residencesFeatured residence

Privacy Policy

TEMPLATE / DRAFT — NOT LEGAL ADVICE. Authored against the project's documented posture (CLAUDE.md + COMPLIANCE.md). It must be reviewed by a licensed real-estate attorney and confirmed with Stellar MLS / MLS Grid before it is signed, relied on, or published.

Effective date: [EFFECTIVE_DATE] Last updated: [EFFECTIVE_DATE]

This Privacy Policy explains how [COMPANY_LEGAL_NAME] ("we," "us," "our") collects, uses, shares, and protects information in connection with our real-estate marketing and presentation service (the "Service"). The Service builds auto-updating public listing pages for real-estate agents and brokers and generates ready-to-publish email and social media campaign drafts for those agents to review and post themselves.

We are a marketing and presentation layer that sits on top of the Multiple Listing Service (MLS). We are not the system of record for any property listing. The MLS — for our current market, Stellar MLS, accessed through the MLS Grid v2 API — remains the authoritative source for all listing data. Data flows from the MLS to us, for display only; we never write any data back to the MLS.

This policy applies to:

  • Visitors to our public listing pages and any future landing page.
  • Prospective buyers who submit an inquiry through a listing page.
  • Real-estate agents and brokers who hold an account on our agent dashboard.

1. Quick summary

  • We display active MLS listing data sourced read-only from Stellar MLS via MLS Grid. We show this data; we do not sell it.
  • When a buyer submits an inquiry on a public listing page, we capture it internally and route it to the listing's owning agent. We do not forward leads to any external CRM, advertising network, or third-party data buyer.
  • Agent and broker accounts are provisioned by us and authenticated through Supabase. There is currently no self-serve signup.
  • We do not sell personal information, and we do not resell buyer leads.
  • We use a small number of service providers (e.g., authentication, transactional email, hosting) strictly to operate the Service.

This is a draft pending review by a licensed real-estate attorney and confirmation with Stellar MLS / MLS Grid. Specific rights and obligations may change based on that review.


2. The data we handle

We handle three distinct categories of data. They have different sources, purposes, and handling rules.

2.1 MLS listing display data (read-only)

What it is. Property listing information — such as address, price, status, descriptive remarks, listing-agent and listing-office identifiers, and property photos — for active listings.

Where it comes from. We receive this data from Stellar MLS through the MLS Grid v2 API (a RESO Web API, OData v4 feed; source mfrmls). We access the feed using a long-lived authorized credential and synchronize listings on an ongoing basis.

How we handle it.

  • Read-only. Data flows from the MLS to us for display only. We never write back to the MLS.
  • Active listings only. Our feed covers active listings. We do not ingest off-market, sold, or "just sold" data.
  • Display permissions are honored. We filter on the MLS display flag (MlgCanView); if a record may not be displayed, we do not display it. When a listing leaves the feed, we mark it not-viewable and remove it from all reads.
  • Photos are stored locally. We download a local copy of listing media rather than hotlinking the MLS feed's photo URLs, consistent with the feed's terms.

Most MLS listing data describes a property, not a private individual. Where listing data includes a real-estate professional's business contact details (for example, the listing agent), we treat that as business/professional information used for attribution and display in accordance with MLS rules.

This listing data is displayed, not sold or licensed onward. See Section 5.

2.2 Buyer inquiry / lead data (public listing pages)

What it is. When a prospective buyer contacts an agent through a public listing page (for example, to request a tour or ask a question), we collect the information the buyer chooses to provide. This may include:

  • Name
  • Email address
  • Phone number (optional)
  • A free-text message (optional)
  • A preferred tour date and/or time (optional)
  • The intent of the inquiry (e.g., "tour" or "question")
  • The listing the inquiry was made about, and a stored snapshot of that listing's address for the agent's reference

Where it comes from. Directly from the buyer, submitted through the public listing page (our internal POST /leads endpoint). A buyer inquiry is a one-to-one message a person writes about themselves — it is not advertising — so we capture and store it as part of operating the Service.

How we handle it.

  • Internal only. Buyer leads are kept internally. We do not forward them to any external CRM, marketing platform, webhook, or third-party data buyer. There is no external lead resale.
  • Routed to the owning agent. Each lead is best-effort routed to the agent who markets the listing as their own. The lead, and the agent's private working notes and pipeline status for it, are visible only to that owning agent through their dashboard. One agent cannot see another agent's leads.
  • Never dropped. If a lead arrives for a listing we cannot match to an agent, we still capture it (unrouted) rather than discard it, so the buyer's request is not lost.
  • The agent works the lead from their dashboard (for example, moving it through stages such as new, contacted, qualified, tour scheduled, won, lost, or archived) and may export their own leads for their own business use as the listing's representative.

We engage with the buyer through the agent who represents the listing. Buyers should understand that submitting an inquiry shares their message and contact details with that agent so the agent can respond.

2.3 Agent / broker account data

What it is. Account and profile information for the real-estate agents and brokers who use our dashboard, including:

  • Name and email address (used to provision and access the account).
  • A trusted identifier tying the account to the agent's MLS identity (the agent_mls_id claim), used to scope each agent strictly to their own data.
  • The agent's marketing/sender profile used to meet email-marketing requirements (for example, the physical mailing address and sender details required for the CAN-SPAM footer on outbound email campaigns).
  • Content the agent creates or curates in the dashboard — such as generated listing copy and campaign drafts in their review queue, and reusable creative snippets (calls to action, signatures, disclosures, bios, hashtag sets).

Where it comes from. We provision accounts directly. In our current model there is no self-serve signup — an operator onboards the client by hand and issues the login. The agent then receives a "set your password" email and signs in.

How we handle it.

  • Authentication is handled by Supabase Auth, which is the source of truth for logins. Our application backend only verifies the access token and scopes each request to the agent's own data using the trusted agent_mls_id claim carried in the token; it does not issue tokens itself.
  • We use the agent's verified marketing profile to enforce a server-owned, compliant footer on outbound email campaign drafts. This footer is generated by us and is not editable by the agent.

3. How and why we use information

We use the information above only to operate, secure, and improve the Service:

  • To display listings. Render auto-updating public listing pages and broker/agent pages from read-only MLS data.
  • To connect buyers with agents. Capture a buyer's inquiry and route it to the listing's owning agent so the agent can respond.
  • To generate marketing drafts. Produce email and social campaign drafts and listing copy for the agent. Direct-marketing drafts are scoped to the agent's own listings (see Section 4). Every generated asset passes our compliance gate before it reaches the agent's review queue.
  • To authenticate and scope access. Verify each agent's identity and ensure each agent can access only their own listings, campaigns, leads, and settings.
  • To secure and maintain the Service. Detect and prevent abuse, debug issues, and keep the Service running.
  • To meet legal and MLS obligations. Honor MLS display rules and source attribution, and support email-marketing compliance (CAN-SPAM).

We do not auto-send or auto-publish anything. We do not send marketing email or post to social media on an agent's behalf. The agent reviews each draft and publishes it themselves (by copying, downloading, or using a deep link), and self-reports when a draft has been posted.


4. Marketing scope and the compliance gate

Two product rules directly affect personal and business data and are worth stating plainly:

  • Direct advertising is limited to the agent's own listings. We generate direct advertising content only for listings where the signed-up agent is the list agent and the agent's own broker holds the listing side. We do not generate standalone advertisements for another broker's listing without that broker's prior written consent. For other market listings, we generate only "drive to my IDX search page" content that advertises an area, never a specific competing listing.
  • Every generated asset is gate-screened. Before any draft reaches an agent's review queue, it passes a compliance gate covering matters such as Fair Housing, listing-advertising authority, CAN-SPAM, virtual-staging disclosure, IDX display rules, and pricing/status accuracy. This is a hard gate, not a warning; blocked drafts are withheld.

5. How we share information

We share information only as described here. We do not sell personal information, and we do not resell or externally forward buyer leads.

  • MLS source and attribution. Listing data originates from Stellar MLS via MLS Grid and is displayed with the attribution and compliance the MLS requires. Our use of the feed is governed by our agreements with the MLS / MLS Grid.
  • The owning agent. A buyer's inquiry is shared with the agent who represents the listing, so the agent can respond. That agent is the buyer's point of contact.
  • Service providers (processors). We use a limited set of vendors to run the Service, who may process information on our behalf under contract and only as needed to provide their service, including:
    • Supabase — agent/broker authentication and managed database.
    • [EMAIL_PROVIDER, e.g., Resend] — transactional email such as the agent's set-password message and operator notifications.
    • [HOSTING_PROVIDER] — application and database hosting.
    • We do not authorize these providers to use the information for their own marketing.
  • Legal and safety. We may disclose information if required by law, regulation, legal process, or to protect the rights, property, or safety of our users, the public, or us.
  • Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

We do not share data with advertising networks for cross-context behavioral advertising, and we do not sell or rent buyer or agent personal information to data brokers.


6. Legal basis and consent

Depending on the applicable law and the data category:

  • MLS listing display is carried out under our authorization to display Stellar MLS data through MLS Grid and is governed by MLS rules.
  • Buyer inquiries are processed because the buyer has voluntarily submitted them to request contact from the listing's agent (consent / steps taken at the individual's request).
  • Agent/broker account data is processed to perform our agreement with the agent or brokerage and to operate the Service.

Where consent is the basis for processing, an individual may withdraw it (see Section 9). Withdrawing consent does not affect processing already carried out.


7. Cookies and similar technologies

[Describe actual cookie/analytics use here. State whether the public site uses strictly necessary cookies only, and whether any analytics or measurement tools are in use; if so, name them and describe the choices available. If no non-essential cookies/trackers are used, say so. Confirm against the deployed front-end before publishing.] [CONFIRM_BEFORE_PUBLISHING]


8. Data retention

We retain information only as long as needed for the purposes described in this policy or as required by law and MLS rules:

  • MLS listing display data is kept current through ongoing synchronization. When a listing leaves the feed or may no longer be displayed, we stop displaying it and reconcile our local copy accordingly.
  • Buyer leads are retained so the owning agent can work and follow up on the inquiry, and thereafter for a commercially reasonable period or as required by applicable real-estate recordkeeping rules. [RETENTION_PERIOD_LEADS]
  • Agent/broker account data is retained for the life of the account and for a reasonable period afterward to meet legal, tax, and audit obligations. [RETENTION_PERIOD_ACCOUNTS]

Specific retention periods will be finalized in consultation with counsel and the MLS. [CONFIRM_BEFORE_PUBLISHING]


9. Your rights and choices

Subject to applicable law (which may include Florida law and, where relevant, other U.S. state privacy laws), you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Delete your information, subject to legal and MLS retention obligations.
  • Opt out of email marketing. Marketing emails sent by agents through the Service include the legally required unsubscribe mechanism and sender information.
  • Withdraw consent where processing relies on consent.

How to exercise these rights.

  • Buyers: Because your inquiry is handled by the agent who represents the listing, the fastest path is often to contact that agent directly. You may also contact us at [CONTACT_EMAIL] and we will route or action your request.
  • Agents/brokers: Manage your profile and content from your dashboard, or contact us at [CONTACT_EMAIL].

We will verify your identity before acting on a request and will respond within the timeframe required by applicable law. We do not discriminate against you for exercising your rights.

Note: Because the MLS — not us — is the system of record for listing data, requests to change underlying listing facts must be directed to the listing agent/broker and the MLS. We display the MLS's data; we cannot alter it.


10. Data security

We take reasonable technical and organizational measures to protect information, including:

  • Scoped access by verified claim. Each agent can access only their own listings, campaigns, leads, and settings; access is scoped by the verified identity claim in the agent's token, never by a value the caller supplies.
  • Fail-closed access controls. Protected routes reject requests when no valid verifier is configured, and administrative functions are disabled unless explicitly configured.
  • Secret isolation. High-privilege credentials (such as service-role and feed credentials) live only on the server side and are never exposed to the browser.
  • Local media handling and least-exposure storage consistent with our MLS feed obligations.

No system is perfectly secure, and we cannot guarantee absolute security. Please use a strong, unique password and keep your credentials confidential.


11. Children's privacy

The Service is intended for real-estate professionals and adult prospective buyers. It is not directed to children, and we do not knowingly collect personal information from children under [CHILDREN_AGE, e.g., 13]. If you believe a child has provided us personal information, contact us at [CONTACT_EMAIL] and we will delete it.


12. International users

The Service is operated from the United States and is intended for the [STATE_OF_FLORIDA_COUNTY] / Florida market. If you access the Service from outside the United States, you understand your information will be processed in the United States, where data-protection laws may differ from those in your location.


13. Changes to this policy

We may update this policy from time to time. We will post the updated version with a revised "Last updated" date and, where required, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.


14. Contact us

If you have questions about this policy or our data practices, contact:

[COMPANY_LEGAL_NAME] [COMPANY_MAILING_ADDRESS], [STATE_OF_FLORIDA_COUNTY], Florida [ZIP] Email: [CONTACT_EMAIL]


This document is a draft and has not yet been reviewed by legal counsel. It must be reviewed by a licensed real-estate attorney and confirmed with Stellar MLS / MLS Grid before it is published or relied upon. Compliance statements reflect the project's documented posture and published MLS/NAR/Florida guidance, not legal advice.

Lakeside Luxury Realty

Equal Housing Opportunity

Listing data is provided for display only and refreshed from Stellar MLS. Information is deemed reliable but not guaranteed and should be independently verified. Prices and availability are subject to change. Each listing is presented courtesy of its listing brokerage.

© 2026 Lakeside Luxury Realty

Powered by SH Digital Group LLC