1. Scope
This draft describes the intended privacy practices of [LEGAL ENTITY NAME] for the VBN + OMS website, Buyer Passport experience, seller workspace, and marketplace services. The current product remains pre-production and includes a mix of working account workflows, private data handling, and clearly labeled sample data.
2. Information users may provide
Future users may provide account, profile, organization, acquisition, property, verification, communication, and preference information. Production collection will depend on the services actually launched.
- Name and contact details
- Organization and authorization details
- Account and communication preferences
- Consent and disclosure choices
3. Buyer Passport information
Buyer Passport data may include acquisition criteria, markets, property types, purchase ranges, transaction history, funding posture, timeline, and sharing preferences. Self-reported information should remain labeled as such.
4. Seller and property information
Seller services may collect seller identity, property location, ownership or authorization context, property facts, pricing guidance, occupancy, condition, diligence availability, and disclosure rules. Public seller-preview pages do not collect property submissions; authenticated workspace behavior should be described according to the specific workflow in use.
5. Identity and verification information
A configured verification workflow may receive status, provider references, review dates, and failure reasons. Sellers should see only permitted verification results and freshness—not identity documents. A provider result should never be inferred unless the applicable workflow was completed.
6. Financial-readiness information
Buyers may submit stated capacity, funding posture, proof-of-funds status, or preapproval status through available workflows. Account balances and raw financial documents must remain protected from sellers. A readiness status does not guarantee funding or ability to close.
7. Documents
Document workflows require private storage, strict access control, retention and deletion rules, and clear status labels. Raw identity and financial files must remain separate from seller-visible status, and users should upload only documents they are authorized to provide.
8. Messaging and communications
Future services may process messages between buyers, sellers, and platform review teams, together with delivery and read status. Prototype messages are fictional and remain in memory.
9. Usage and device information
A future production service may collect security logs, device and browser information, IP address, timestamps, navigation events, and diagnostic data. This draft does not promise a specific analytics implementation.
10. Cookies and local browser technologies
The prototype may use framework-required browser behavior and a narrowly scoped service worker for public assets. Sensitive Passport, document, message, assistant, and authenticated response data are not intentionally stored in localStorage, sessionStorage, IndexedDB, or service-worker caches. Future cookie choices will be disclosed when implemented.
11. How information may be used
Information may eventually be used to operate accounts, structure profiles and opportunities, explain relevance, apply disclosure choices, facilitate communication, prevent abuse, support users, and improve the product. New uses should be disclosed before production collection.
12. Criteria matching and information prioritization
Future matching may compare buyer criteria with opportunity attributes and permitted readiness context. The system should explain the relevant overlap and preserve human judgment. It is not an eligibility, underwriting, appraisal, or suitability decision and does not guarantee financing or closing.
14. Service providers
Didit is integrated for buyer identity verification when configured. The consent dialog explains the provider workflow and links to Didit’s verification privacy notice. VBN stores session references, consent records, verification status, and dates; Didit’s raw identity documents and biometric results are not stored by this integration. Other provider services depend on the workflows configured in the application.
Legal review pending: finalize provider agreements, biometric consent, retention, deletion, and jurisdiction-specific privacy disclosures before public launch.
15. Seller and buyer disclosure controls
Buyers should control Passport visibility by field and stage. Sellers should control property, identity, address, diligence, and contact release. Some processing may be required to provide the requested service even when optional sharing is disabled.
16. Data retention
Retention periods have not been finalized. Production periods must be based on operational, legal, security, and user-choice requirements. Until those periods and deletion workflows are approved, users should not assume that information is removed on a particular schedule.
17. Security limitations
No system is secure beyond doubt. Safeguards, encryption choices, incident response, access controls, and vendor configuration require continuing security review. Users should provide sensitive information only through the designated private workflow and only when authorized to do so.
18. User rights and choices
Depending on location and applicable law, users may have rights to access, correct, delete, restrict, or obtain certain information, and to appeal or opt out of specific processing. Procedures and identity-verification requirements will be finalized before production launch.
19. Children’s privacy
The intended marketplace is not directed to children. Production eligibility and age-verification decisions require legal review. The prototype should not be used to submit information about children.
20. Interstate and state-specific considerations
Property activity, privacy rights, record obligations, and marketplace rules may vary by state. State-specific notices and choices will be added after qualified legal review and a confirmed operating footprint.
21. Changes to this policy
Material changes should be posted with a revised effective date and, where required, additional notice or consent. This draft may change substantially before launch.
22. Contact
Privacy questions: support@offmarketsolutions.com. Legal entity: [LEGAL ENTITY NAME]. Mailing address: [MAILING ADDRESS TO BE DETERMINED]. Do not send sensitive documents by email.
