Privacy Policy
Effective date: August 27, 2026
Last updated: August 27, 2026
Version: 1.0
This Privacy Policy explains how List My Furniture, LLC, a Delaware limited liability company operating as AppraisalSoftware ("we," "us," "our"), collects, uses, discloses, and protects information through the AppraisalSoftware web application, mobile application ("Item Capture"), browser extension ("Comp Capture"), and related services (together, the "Service").
Two categories of data, two roles. AppraisalSoftware is B2B software used by professional appraisers. We are a controller for your account/subscriber data (how you sign up, pay, and use the Service). We are generally a processor/service provider for the data you enter about your own clients, their contacts, and their property ("Customer Data") — you control what goes into the Service and why. Our companion Data Processing Agreement, available to customers on request, governs the processor-side terms. For two specific flows, we are a controller rather than a processor, because we collect personal information directly from individuals who are not our customers: (a) contract e-signature (Section 2.4), where we collect a signer's typed name, company, signature image, IP address, and browser user-agent through our public signing link; and (b) client invoicing (Section 2.11), where we collect your clients' billing contact and payment information and email them directly. In both cases you remain responsible for your engagement and relationship with that individual, but we are accountable for our own collection and use of the information described.
1. Who this applies to
- Appraisers (our direct customers/users). You create an account, subscribe, and use the Service.
- Collaborators. Additional appraisers you invite onto a job (multi-user collaboration).
- Your clients and their contacts. Individuals whose personal information you enter as Customer Data — including, notably: (a) individuals who electronically sign a contract you send them (Section 2.4), and (b) individuals who receive an invoice, receipt, payment confirmation, or past-due notice from you through the Service's built-in client-invoicing feature (Section 2.11). These individuals are not our customers and never created an account, but we receive and directly process some of their personal information (signature image, IP address, and browser user-agent for e-signature; name, email, and billing/payment data for invoicing) and, for invoicing, we email them directly on your behalf. For these two flows we act as a controller rather than a processor, as described above.
2. Information we collect
2.1 Account information (authentication)
When you sign up, we collect email, first name, last name, and company through our managed authentication provider, which manages your password/credentials directly — we never see or store your raw password.
2.2 Profile and business settings
Phone number, business address, company name, signature image, report/contract headers/footers, and billing rate preferences you add to your profile.
2.3 Billing information
We do not collect or store full payment-card numbers. Stripe, our payment processor, handles card data directly; we receive only billing metadata (subscription status, plan, Stripe customer/subscription IDs). A Stripe Customer record is created for every account at signup — before you choose a paid plan — so a 7-day trial can start immediately. Card data never touches our servers.
If you (or your client, via Section 2.11) pay by bank transfer (ACH), Stripe's Financial Connections feature links a bank account directly with Stripe — including read access to account balance data as part of that linking — before any of it reaches us.
2.4 Customer Data you enter or upload
This is the bulk of what the Service stores, and it is data you choose to input about your own business and clients:
- Clients & client contacts — names, addresses, emails, phone numbers, notes.
- Jobs, items, valuations, and comparable-sales research (comps) you create.
- Images and documents — photos of items, source documents, and generated reports — stored and delivered via our cloud infrastructure's file-storage and content-delivery services, with automatic resizing/optimization.
- Contract e-signature data — when your client signs a contract through the Service's public signing link, we capture their typed name, typed company, consent flag, an uploaded signature image, their source IP address, and their browser user-agent string. This data is collected by us directly from the signer rather than entered by you, and we handle it as a controller (see the roles description above).
- Contact categorization ("campaigns") — you may tag client contacts into groups (e.g., "email campaign," "direct mail campaign") for your own organization and CSV export. The Service itself does not send bulk marketing email or mail to these contacts today — it is a labeling/export feature only. We will update this paragraph if and when automated campaign sending ships.
2.5 AI-assisted feature inputs
Several features send data to AWS Bedrock's managed AI service to produce a result:
- Comp Capture (Chrome extension): the extension sends the text content, URL, and title of a web page you are viewing to our backend, which sends it to an AI model hosted within AWS's managed Bedrock environment to extract structured comparable-sale fields. This is a compute-only call — nothing is saved until you choose to create the comp.
- Item field extraction from photos/files: uploaded images/documents can be sent to AI models hosted within AWS's managed Bedrock environment to auto-fill item fields.
- "Tony," the in-app AI assistant: your typed requests and relevant job/item context are sent to Bedrock foundation models to answer questions or perform in-app actions on your behalf.
We do not use your inputs to train general-purpose AI models, and this processing happens inside AWS's managed Bedrock environment rather than being sent to a third-party AI company's own servers or API.
2.6 Document processing (PDF conversion)
Generated appraisal reports, tear sheets, and contracts are converted to PDF by our own self-hosted document engine running inside our AWS environment — the generated document (which may contain your clients' personal information) is not sent to any third-party conversion service. Separately, when you build or import a report template, we use Adobe PDF Services to convert that template between PDF and editable Word formats; that conversion involves your template's layout and placeholder tags, not your clients' appraisal data. See the sub-processor table in Section 4.
2.7 Address autocomplete and travel-distance lookups (Google)
Address autocomplete. Address fields (for example, contract signing pages and job origin addresses) use a Google address-autocomplete service loaded in your browser. As you type, Google receives the text you type and, because the request originates from your browser, your IP address.
Travel-distance calculation. When a job's travel distance or time is calculated, our servers send two address strings to Google's Distance Matrix service: the job's origin address and the job's site address, which is typically your client's property. The address is sent on its own — not accompanied by any name, client identifier, valuation, image, or item data that would tie it to a particular person — and because the request is made server-side, Google does not receive your IP address.
2.8 The mobile app ("Item Capture")
The mobile app is an offline-first field-capture tool. It accesses the device camera and photo library to capture item photos, uses on-device secure storage to cache your auth session and job/item data for offline use, and syncs drafts (new items, new jobs, edits, photos) back to the Service when connectivity returns. Basic device information (e.g., device model/OS) may be available to the app for diagnostics.
2.9 Usage, log, and connection data
Standard operational logs: authenticated user ID, action taken, resource type/ID, changed fields, and duration are logged (structured JSON) for every API call. The "changed fields" recorded in these operational logs are field names only, not the values entered, so these logs do not contain Customer Data. (Separately, we keep a short-lived change-history log that supports undo and audit and *does* record before/after field values; its retention is described in Section 6.) Real-time collaboration features transmit connection metadata (a connection identifier linked to your user ID) to keep multi-user views in sync.
2.10 Cookies and browser storage
The Service does not use analytics, advertising, or tracking-pixel technology, and sets no advertising or cross-site tracking cookies. The only cookies and browser storage the Service relies on are strictly necessary for it to function:
- Authentication. Your sign-in session is managed by our authentication provider using tokens stored in your browser's local storage (not a session cookie we set). These are essential to keep you logged in.
- Payments (Stripe). When you begin a checkout or use client-invoicing, we load Stripe's payment library, which sets its own strictly-necessary cookies (for example
__stripe_midand__stripe_sid) to process payments and detect and prevent fraud. These are governed by Stripe's Cookies Policy. They load only within the payment flow, not on our general marketing pages. - Address autocomplete (Google). When you type into an address field, a Google autocomplete service loaded in your browser receives the text you type (and your IP address) to return suggestions.
Because we set no analytics, advertising, or tracking cookies, no cookie-consent banner is required. If we later add analytics or any non-essential/cookie-based tracking, we will update this section and add a cookie-consent mechanism where required (e.g., for EEA/UK users) before doing so.
2.11 Client billing and invoicing (Stripe Connect)
If you use the Service's client-invoicing feature, we create a Stripe Connected Account for you and use it to bill your clients directly:
- We create and help you onboard a Stripe Connected Account in your name (Stripe Connect's hosted onboarding flow).
- We generate invoices addressed to your clients and process their payments (including ACH, Section 2.3) through Stripe under your connected account — you, not us, are the merchant of record for these transactions (see the Terms of Use, "Payments and invoicing to your clients").
- We email your clients directly (via our email service) on your behalf: the invoice itself with a PDF attachment, payment receipts, paid-confirmation notices, and past-due notices.
This means your clients' name, email address, and billing/invoice data pass through both Stripe (as the connected-account processor) and our own systems (to generate and send the emails above) — even though the client never creates an account with us. See the Stripe sub-processor row in Section 4.
3. How we use information
We use the information above to: operate and secure the Service; authenticate you; generate the reports, tear sheets, contracts, and invoices you request (converted to PDF, Section 2.6); process billing through Stripe, including billing your own clients and emailing them invoices, receipts, paid confirmations, and past-due notices when you use the client-invoicing feature (Section 2.11); provide the AI-assisted features described in Section 2.5, at your direction; send transactional email via our email service (account, billing, contract/e-signature, client-invoicing, and error/notification emails — we do not send bulk marketing email, see Section 2.4); provide customer support; and monitor and troubleshoot the Service via structured logs.
We do not sell or share personal information or Customer Data, and we do not use Customer Data or AI-feature inputs to train general-purpose models.
4. Sub-processors
| Sub-processor | Purpose | What it receives |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: hosting, database, file storage and content delivery, authentication, transactional email, real-time collaboration, and AI inference via Amazon Bedrock | Account data, Customer Data, images/files, usage/log data, AI-feature inputs/outputs |
| Stripe, Inc. | Subscription billing and payment processing for your account; and, via Stripe Connect, onboarding your Connected Account and processing invoice payments (including ACH/bank-transfer via Financial Connections) from your clients | Your name, email, billing metadata; your Connected Account details (business/identity/banking information Stripe requires for payouts); your clients' payment and billing data submitted to pay an invoice, including bank-account linking/balance data for ACH payments; full card data goes directly to Stripe, never to us |
| Adobe (PDF Services) | Report-template conversion between PDF and editable Word formats, during template setup only | Your report template's layout and placeholder tags — not your clients' appraisal data |
| Address autocomplete in address-entry fields; travel-distance and time calculation for a job | Address text typed into autocomplete fields (and your IP address, as the request runs in your browser); a job's origin and site addresses for travel calculation, sent from our servers |
Sub-processor changes. When we add or replace a sub-processor that will process Customer Data, we will update this table and the DPA's sub-processor annex, and notify account owners by email at least 14 days before the change takes effect, with an objection right consistent with Section 6.3 of our Data Processing Agreement.
5. Data location
The Service is hosted on cloud infrastructure located in the United States.
6. Data retention and deletion
- Account status. The app uses a soft-delete pattern (flagging a record inactive) rather than immediately hard-deleting user/collaborator records on removal. Soft deletion applies to ordinary account and collaborator removal. On a verified erasure request under Section 9, we hard-delete the identified records from the live system rather than flagging them inactive, and confirm completion to the requester. Residual copies may persist in rolling backups until those backups are overwritten in the ordinary course.
- Customer Data is retained for as long as your account is active and as needed to provide the Service.
- Post-termination export/retention window: after account termination, you may request export of your Customer Data for 30 days, after which we may delete Customer Data in the ordinary course (see the Terms of Use, "Termination" — this figure matches that section).
- Operational (usage) logs — the structured API-call logs described in Section 2.9, which record field names but not values — are retained for 12 months. Because they contain no Customer Data values, they are not a shadow copy of deleted Customer Data.
- Change-history log — a separate short-lived log that records before/after field *values* to support undo and audit is retained for approximately 90 days and then purged on a rolling schedule; on a verified erasure request we also purge the requester's data from it.
- Backups are retained on a rolling/overwritten basis; residual copies in backups may persist briefly after deletion from the live system.
7. Security
Encryption in transit (HTTPS/TLS) and at rest (database, file storage, and backups) via AWS-managed infrastructure; managed authentication; least-privilege access controls; structured audit logging on every API call (Section 2.9). No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. Data breach notification
If we become aware of a security incident that compromises the confidentiality, integrity, or availability of Customer Data, we will notify affected account owners without undue delay and as required by applicable law, and will provide the information reasonably available to us about the nature of the incident, the data involved, and steps taken in response. Where the incident involves information for which we are a controller — contract e-signature data (Section 2.4) or client-invoicing data (Section 2.11) — we will also notify affected individuals directly where required by applicable law. Our specific processor-to-controller breach-notification commitments are set out in our Data Processing Agreement (available on request).
9. Your rights and choices
You can view/edit most Customer Data directly in the Service. Bulk export today is per-entity CSV (jobs, items, clients, contacts, comps) — there is no single consolidated account-wide export/erasure button yet. For deletion, correction, or export requests beyond what the in-app tools provide, contact us (Section 12); we will action verified requests manually.
If you are a client or contact of one of our appraiser users (i.e., you did not create an account but your information was entered by an appraiser, you signed a contract through the Service, or you received an invoice through the Service's client-invoicing feature), and want to exercise a data right, contact that appraiser first — they control the data; we process it on their instructions. If you signed a contract directly through our public signing link, or received an invoice/receipt/payment notice directly from us (Sections 2.4, 2.11), you may also contact us directly since we collected and/or sent that information ourselves.
9.1 EEA/UK — GDPR
Where the GDPR/UK GDPR applies, we rely on these legal bases for controller-side processing: performance of a contract (providing the Service and billing); legitimate interests (securing, improving, and supporting the Service, and preventing abuse); consent (where required); and legal obligation (e.g., tax and accounting records). For processor-side processing of Customer Data, your instructions and the DPA govern. If applicable to you, you have the standard GDPR rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data-protection supervisory authority.
9.2 California — CCPA/CPRA
We do not currently meet the revenue, volume, or data-sale thresholds that would make us a "business" subject to the CCPA/CPRA. We provide the following disclosures voluntarily, and will comply with the CCPA/CPRA in full if we become subject to it. The categories of personal information we collect, their sources, purposes, and disclosures are set out below (see Sections 2 and 4 for detail):
| Category | Examples | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email, phone, IP address | You; your clients (via Customer Data) | Account operation, security, e-signature, invoicing | AWS, Stripe, (Adobe/Google/AI sub-processors as applicable) |
| Commercial/financial information | Billing metadata, invoice/payment data | You; Stripe; your clients (via invoicing) | Billing, client invoicing | Stripe, AWS |
| Internet/device activity | Log data, connection metadata, usage data | Automatically collected | Security, operation, troubleshooting | AWS |
| Audio/visual information | Item photos, uploaded documents, signature images | You; your clients (e-signature) | Service delivery, report generation | AWS, AI sub-processors (where used) |
| Geolocation/address data | Typed address text; job origin and site addresses | You; your clients | Address autocomplete; travel-distance calculation | |
| Sensitive personal information | Financial account information used for ACH payments (bank account linking and balance data via Stripe Financial Connections) | Your clients; Stripe | Processing invoice payments you initiate | Stripe |
The only sensitive personal information involved in the Service is financial account information used to process ACH payments, which is collected and held by Stripe rather than by us. We do not use or disclose sensitive personal information for any purpose other than performing the payment you or your client initiated, which falls within the exemptions to the right to limit use of sensitive personal information.
We do not sell or share personal information, as those terms are defined under the CCPA/CPRA. You have the CCPA rights to know, delete, correct, opt out of sale/share (not applicable, as we do not sell/share), limit use of sensitive personal information, and non-discrimination for exercising these rights. We do not currently respond to browser Do Not Track or Global Privacy Control signals; because the Service does not use cookies or trackers for cross-context behavioral advertising, this has no practical effect on your data.
10. Children's data
The Service is professional B2B software not directed at children. We do not knowingly collect personal information from anyone under 18.
11. International data transfer
Because appraisers and their clients may be located outside the United States while the Service and its sub-processors run in the U.S. (Section 5), information may be transferred to and processed in the United States. If EEA/UK/Swiss individuals' data is in scope, the Standard Contractual Clauses referenced in Section 11 of our Data Processing Agreement apply to that transfer.
12. Contact us
List My Furniture, LLC
c/o Harvard Business Services, Inc., 16192 Coastal Highway, Lewes, DE 19958
Privacy questions: support@appraisalsoftware.com
13. Changes to this Policy
We may update this Policy. We will post the updated version and revise the "Last updated" date above; for material changes we will provide reasonable notice.