Privacy & security

How Listings Studio handles, protects, and respects your data.

Data we collect and why

Listings Studio is operated by Ricardo Leonardo Raphael Cardoz, an individual. We collect the following categories for the stated purposes:

  • Account and profile data — email address, name, company, phone number, location, tagline, authentication records, and session tokens. We use these to create and secure your account, display the profile details you choose to publish, and provide support.
  • Listing and draft data — property details, rough notes, generated and edited copy, map links, layout choices, uploaded media, and publishing state. We use these to save drafts, generate content, host media, and publish the showcase you request.
  • Service and plan data — plan status, AI usage, listing activity, support messages, and limited error or security logs. We use these to operate features, enforce fair-use and plan limits, troubleshoot issues, prevent abuse, and respond to requests.
  • Contact data — the name, email, topic, and message submitted through the public contact form, plus account references you include in a support request. We use this only to route, investigate, and respond to the message.
  • Marketing-site analytics — on the reviewed marketing and legal pages, Vercel Web Analytics can process the URL path without query strings or fragments, referring source, approximate geography, browser, and device information. We use aggregate results to understand site usage; this analytics script is not loaded directly on account, admin, authentication, public-listing, referral, or design-preview routes.
  • Billing references — Razorpay customer, payment, and subscription identifiers and their status from Test Mode or live checkout. We use these to activate plans, reconcile billing, handle cancellations, and investigate refund requests; we do not receive your full card number, PIN, or OTP.
  • Optional notification data — if you enable web push, the browser push endpoint, device keys, user-agent label, and channel preferences are stored so requested notifications can be delivered. You can disable push in Profile and in your browser settings.

What we avoid

  • We do not read or store WhatsApp conversations. A WhatsApp button opens WhatsApp on the visitor's device, where WhatsApp's own terms and privacy practices apply.
  • We do not request precise GPS location, run advertising pixels, build cross-site advertising profiles, or use browser fingerprinting.
  • Raw visitor IP addresses are not written to Listings Studio's listing-analytics tables. Hosting, network-security, and rate-limiting systems may still process request IP addresses in operational logs.
  • We do not sell or rent personal data or listing content to data brokers or advertising networks.

AI processing

  • When you request generation, the property details, rough notes, and a media summary needed for that request are sent server-side to the configured AI provider (OpenAI by default). The images themselves are not sent for image analysis by the current generation flow.
  • Provider retention and data-use policies apply. We do not claim Zero Data Retention or special provider controls. Avoid including sensitive client information in AI requests.
  • Generated output is validated against strict schemas and content limits before storage or display. Listing copy is rendered as escaped React text; the one trusted inline script used for native-app detection contains no user or AI content.
  • AI output can be inaccurate or overstated. Review and edit every generated statement before publishing it.

Service providers and external services

  • Supabase provides account authentication, database hosting, and file storage for account and listing data.
  • Vercel hosts the application and provides network delivery and security. Vercel Web Analytics is enabled only on the reviewed marketing and legal pages; it is blocked on account, admin, authentication, public-listing, referral, and design-preview routes, and allowed events exclude query strings and fragments.
  • The configured AI provider processes the inputs needed for generation. Luna support chat uses OpenAI and sends recent chat messages plus a limited billing summary. Chat text stays in page memory and is not saved to our database or browser storage; reload or clear the chat to remove it. Account-linked request time, model, status and token/cost metadata remain until account deletion. OpenAI retention policies apply independently.
  • Razorpay processes checkout details, contact information and subscription activity. Live checkout collects real payments; checkouts explicitly marked Test Mode do not create a real charge.
  • A browser push service processes the endpoint needed to deliver notifications only if you opt in. WhatsApp processes data when a visitor chooses to open a WhatsApp link.

Published listings

  • A published /p/your-slug page can be opened by anyone who has the link. We send noindex and nofollow directives and omit listing URLs from the sitemap, but third parties can still share, copy, or capture a page.
  • The page shows the property, media, and contact fields you chose to publish. Review the public preview before sharing it.
  • Unpublishing closes the listing page immediately and stops new private-media links from being issued. A signed media link already loaded or copied can remain valid for up to five minutes, and third-party screenshots, downloads, or caches cannot be recalled. Deleting also starts removal of stored records and media as described below.

Visitor analytics on public listings

On a real published listing, we record limited first-party engagement signals so its owner can understand performance and protect the service from abuse:

  • Signals can include page views, WhatsApp-button taps, save toggles, scroll milestones, gallery positions viewed, section dwell time, device and operating-system family, city and country inferred from network headers, UTM tags, and referring-site hostname.
  • A random ls-visitor cookie helps distinguish returning browsers. It is HttpOnly, lasts up to 90 days, and is not a name, email address, phone number, or cross-site advertising identifier. The page still works if cookies are blocked.
  • Short-lived per-listing cookies record only whether a view, WhatsApp tap, or enquiry alert was already counted. They expire after one to six hours and prevent duplicate counters or notifications.
  • Saved-heart state is also kept in that browser's local storage. Listing owners see aggregate and pseudonymous performance signals, not a visitor's WhatsApp messages or identity.
  • Engagement records are retained while the related listing and account remain active so the owner can compare performance. Deleting the listing or account removes the active database records; provider backups and security logs follow the providers' retention and legal requirements.

Cookies and device storage

  • Supabase authentication cookies keep signed-in users authenticated and are refreshed as needed. Signing out clears the active session cookies.
  • An ls-referrer cookie may be set for up to 30 days after a referral link is opened. It contains a signed inviter identifier used only to attribute a later signup and is cleared when consumed.
  • In-progress create-flow fields are stored on that device for up to seven days, bound to your account, and cleared when you sign out, delete your account or switch accounts. Theme and notification preferences and public-listing save markers may also be stored locally. A draft's media can also be uploaded and held server-side during the draft flow so a transfer can safely resume.
  • Clearing site data removes device-only preferences and markers. Server-side account, published-listing, uploaded-media, and push-subscription records require the relevant in-product delete or unsubscribe action.

Retention and deletion

  • Account, listing, media, plan, and activity records are kept while needed to provide the service and while the account or listing remains active.
  • Contact-form and human email support messages are kept while needed to respond, investigate the issue, and maintain necessary support history; you may ask us to delete them unless we need a limited record for security, dispute, or legal reasons.
  • Deleting a listing removes public access and queues its associated storage cleanup. Cleanup is durable and may complete asynchronously so transient storage failures do not silently leave files behind.
  • Account deletion removes the active account profile, listings, media references, analytics, push subscriptions, and other account-scoped product records. Storage and authentication cleanup may continue through a retry queue after the visible account is removed.
  • Limited redacted billing or platform-event records and provider security logs may be retained when needed for fraud prevention, accounting, dispute handling, legal obligations, or system integrity. Residual provider backups age out under each provider's backup policy rather than a fixed 30-day promise from Listings Studio.

Your choices and rights

  • Access and correction — review and edit profile and listing data in the app, or request a copy or correction by email.
  • Deletion — delete an individual listing in its editor or request account deletion from Profile → Account → Delete account.
  • Withdraw consent — where processing is based on consent, use the relevant in-product control or email us to withdraw it. You can also disable push in Profile or browser settings. Withdrawal does not affect processing already completed and may make an optional feature unavailable.
  • Complaint — contact us about a privacy concern or how a request was handled. You may also use any complaint or regulatory remedy available to you under applicable law.

Privacy requests and complaints

Email support@listings-studio.com with “privacy request” or “privacy complaint” in the subject. Signed-in users should write from their registered email and identify the request as access, correction, deletion, consent withdrawal, or complaint. Visitors can include the relevant listing URL and approximate visit time. We may verify a request through the registered email or signed-in account before disclosing or deleting data. We will never ask for your password, OTP, card number, or PIN to verify a privacy request.

Changes to this policy

We may update this page as the product, providers, or legal requirements change. The current version and effective date will remain published here, and material changes will be communicated through an appropriate account channel. Any new consent request will be presented separately where consent is required.

Last updated · August 2026