Privacy Policy
Last updated: July 15, 2026 · Version 1.1
The short version
listdtree gives real estate agents a public link-in-bio page. We collect the information needed to run the service. We don’t use advertising trackers or cross-site tracking, and agents can’t add their own. Our page statistics are designed to be limited and cookieless — they don’t include IP addresses or identifiers that connect a visit to a person — and we honor Do Not Track and Global Privacy Control browser signals. We don’t sell personal information.
1. Who we are
listdtree (“listdtree”, “we”, “us”) is a service at listdtree.com that lets real estate agents publish a public profile page with their listings, links, reviews and contact options. The service is operated by Cayden Harry, a sole proprietor based in California, USA; listdtree is the name of the service, not a separate business entity.
For anything in this policy, contact us at support@listdtree.com.
This policy covers agents who create an account, visitors to agents’ public pages, and visitors to our own website.
2. Where information comes from
The information we handle comes from a few places:
- Directly from account holders — account details and the content you choose to publish (section 3).
- Generated through use of the service — page statistics, service timestamps, and records of the agreements and confirmations you accept.
- From Stripe — if you subscribe, we receive your subscription status and Stripe customer and subscription identifiers. We never receive card numbers.
- From other people — reports submitted through our Report Content page, and messages sent to our support inbox.
- From agents, about other people — content an agent publishes can include other individuals’ information, like a reviewer’s name or people in listing photos. Agents confirm they have permission to publish it; section 8 explains how to request removal of content about you.
3. Information we collect from account holders
If you create an account, we collect:
- Account details — your email address, a password, and the username you choose. Password authentication is handled by our authentication provider (Supabase); we do not receive passwords in readable form.
- Profile content you choose to publish — display name, headline, bio, brokerage, profile photo or banner, contact email/phone, WhatsApp number, Messenger or Instagram handle, social media handles, links, listings and their photos, client reviews you post, and any professional or licensing details you add (license number, NMLS ID, team name, office address). This content is public by design: it appears on your public page for anyone to see, and public pages may be indexed by search engines.
- Billing information — if you subscribe to Pro, payment is processed by Stripe. We store your plan and Stripe customer and subscription identifiers. We never receive or store your card number.
- Agreement and confirmation records — when you accept the Terms of Service or confirm content responsibilities (for example, that a review is genuine), we record which document version you accepted and when.
- Support requests — messages you send through the dashboard’s Support tab or by email.
- Service records — timestamps such as when your account was created, when we sent you a welcome email, and plan-change events.
Please don’t submit information the service isn’t designed to collect — such as passwords or authentication credentials for other services, complete payment-card numbers, Social Security numbers, government identification documents, medical information, or financial-account credentials — whether in your profile content, listings, reviews, or support messages.
4. Page statistics & visitor information
When someone views an agent’s public page or clicks a link on it, we record a limited, cookieless statistics event so the agent can see how their page performs. What listdtree stores for each event:
- the referring website’s hostname (e.g. “instagram.com” — never the full URL),
- a coarse device type (mobile, desktop or tablet),
- the visitor’s approximate country (derived from our hosting provider’s network header),
- a timestamp, and
- which link was clicked, for click events.
Our statistics do not store full IP addresses, names, precise locations, or any persistent identifier that could connect a visit to a person, and we set no cookies for them. If a visitor’s browser sends a Do Not Track or Global Privacy Control signal, we don’t record the view or click at all.
What our providers process: separately from our statistics, the hosting, storage, network, monitoring, and security providers that deliver the service (section 7) process visitor requests — including IP addresses and technical request information — to serve pages, protect against abuse, and troubleshoot problems, and may retain that information for a limited time in operational logs under their own policies. We don’t use those logs to build visitor profiles.
Public pages are built to make no third-party tracking requests: there are no advertising pixels (agents cannot add their own), fonts are served from our own domain, and link icons are fetched through our own server.
If someone submits our Report Content form, we store the report and the reporter’s email address if they choose to provide one, and use it only to handle the report.
6. How we use information
We use the information above to:
- provide the service: publish your page, process subscriptions, show you your page statistics;
- send transactional email: welcome messages, password resets, subscription confirmations;
- respond to support requests and content reports;
- keep records of legal agreements and content confirmations;
- keep the service secure, investigate abuse, and fix errors;
- comply with legal obligations.
We may also use aggregated or de-identified information — like total page views across the service — that doesn’t identify anyone. We don’t attempt to re-identify de-identified information.
We don’t currently send marketing email. If that ever changes, we’ll update this policy first, and you’ll always be able to opt out. We do not use your information for automated decision-making with legal effects, and we do not sell it.
8. Third-party links & communications
Agent profiles link out to third parties: websites, social networks, external listing pages, and contact buttons that open your own email, phone, SMS, WhatsApp, Messenger, or Instagram apps. When you follow a link or contact an agent through one of these, the third-party service (and the agent) receives whatever you send — and that service operates under its own terms and privacy policy, not this one. We don’t control third-party services and aren’t responsible for their privacy practices.
If an agent’s page includes your information and you want it removed, use the Report Content page or email support@listdtree.com — we review reports and remove content that violates our Terms of Service.
9. Retention & account deletion
Account data, published content, uploaded files, and page statistics are kept while your account exists. Deleting your account is self-serve (dashboard → Account tab), and one deletion process handles all of it:
- any active Stripe subscription is canceled first (if that fails, nothing is deleted and you can try again);
- your uploaded files are removed from our active storage;
- your account, published content, and page statistics are deleted from our active database, and your sign-in credentials are removed;
- your public page goes offline.
Some records live outside that process and may remain after deletion:
- Agreement records — a minimal record of your acceptance of our Terms and related attestations (your email address, the document version accepted, and the timestamp) is retained after deletion so we can demonstrate compliance and defend legal claims;
- Billing and tax records held by Stripe, kept as long as tax and accounting rules require;
- Content reports and support correspondence, including emails in our support inbox;
- Security, fraud-prevention, dispute, or legal records where reasonably necessary or legally required;
- Provider logs (section 4), retained for a limited time under each provider’s policy;
- Provider backups, where they exist, persist for a limited period before rolling off. We don’t restore deleted accounts from backups except where a restore is needed to recover the service itself.
10. Where data is processed
listdtree is operated from the United States, is directed to users in the United States, and our service providers store data primarily in the United States. Public pages can be viewed from anywhere; if you use the service from outside the US, your information is transferred to and processed in the US, which may have different data-protection rules than your country.
11. Your privacy rights & requests
Whether or not a particular privacy law applies to a business of our size (California’s CCPA, for example, applies only to businesses meeting certain revenue or data-volume thresholds), we voluntarily offer everyone the core options: you can ask us to access, correct, delete, or provide a copy of your personal information, and we honor the rights your local law actually gives you.
How to make a request: email support@listdtree.com and tell us what you’d like. We’ll usually verify your identity by confirming you control the relevant account email before acting. We may limit or decline a request where we can’t verify identity, where it’s clearly repetitive or unfounded, or where keeping the information is reasonably necessary or legally permitted (for example, billing records or security records — see section 9). Where a law sets a response deadline for us, we’ll meet it; otherwise we respond within a reasonable time.
Account holders can do most of this directly: edit or delete individual content from the dashboard at any time, or permanently delete the entire account from the Account tab. We honor Global Privacy Control signals for page statistics automatically (section 4), and we will never treat you worse for exercising a privacy right.
12. Children
listdtree is for adults: you must be at least 18 to create an account, and we don’t knowingly collect personal information from anyone under 18. Page statistics are collected without identifiers for all visitors regardless of age. If you believe a minor has created an account, contact us and we’ll delete it.
13. Security
We use reasonable safeguards appropriate to a service of this size: connections to the service are encrypted in transit (HTTPS/TLS); password authentication is handled by our authentication provider, which stores passwords only in hashed form — we don’t receive them in readable form; database access is restricted with row-level access controls; payment cards are collected and processed entirely by Stripe and don’t pass through our systems; and error monitoring is configured to reduce unnecessary personal information in error reports. No online service can guarantee absolute security, and we don’t promise it — if we learn of a breach affecting your information, we’ll notify you as applicable law requires.
14. Changes to this policy
If we change this policy, we’ll update the date and version at the top. For material changes we’ll notify account holders by email or a dashboard notice before the change takes effect. The current version always lives at listdtree.com/privacy.
15. Contact us
Questions, requests or complaints: support@listdtree.com.