Privacy Policy

Effective date: 2026-07-10

Last updated: 2026-07-10

0. Relationship to the Gotlan Terms of Service (Mandatory Companion Document)

This Privacy Policy governs personal-information practices only. It is not the complete legal agreement between you and Gotlan. A separate Terms of Service / Vendor Agreement (the "Terms") governs your contractual relationship with us and must be read together with this Policy.

The Terms carry the items that are not privacy disclosures — including clickwrap and E-SIGN consent, binding arbitration with a class-action waiver, the warranty disclaimer and limitation of liability, mutual indemnification, the Fair Housing covenant, the content license and acceptable-use rules, the DMCA notice-and-takedown process, and the Stripe Connected Account Agreement flow-down and merchant-of-record disclosures.


1. Introduction and Scope

This Privacy Policy explains how Gotlan LLC (a limited liability company formed in Florida), doing business as "Gotlan" ("Gotlan," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you use the Gotlan marketplace, the free Gotlan CRM, our websites (including gotlan.com and public vendor profile pages), and related services (collectively, the "Services").

Gotlan operates a two-sided vertical marketplace and a free customer-relationship-management (CRM) platform that connects:

The marketplace is US-first (initially focused on Texas), and the free CRM is offered nationwide across the United States. We acknowledge that visitors from the European Union/European Economic Area ("EU/EEA"), the United Kingdom ("UK"), and Switzerland may access the Services, and we apply a geo-aware privacy posture described in this Policy.

Our role. Gotlan is a technology platform and marketplace intermediary. When an Agent books a Vendor, the media-services contract is formed solely between the Agent and the Vendor. The Vendor is an independent business and the merchant of record for the media services; Gotlan is not the seller or provider of those services and is not a party to that contract. This distinction matters for privacy because it determines whether Gotlan acts as a controller of your data or merely as a processor/service provider acting on a Vendor's behalf. See Section 12 (Our Role: Controller vs. Processor).

Whom this Policy covers. The Services are intended for businesses and professionals, and the privacy rights and disclosures here apply to all individuals whose personal information we process, including Agents, Vendors and their team members, and individuals whose data appears in the Services (for example, a homeowner whose property is photographed). We treat business-contact information processed through the Services as protected personal information and respond to verified rights requests about it; the precise application of any business-to-business exemption under a given state law is determined by that law.

Notice at collection. Where required (including under the California Consumer Privacy Act, Cal. Civ. Code § 1798.100), we provide a notice at collection at or before the point we collect personal information — for example, at account signup, at checkout, and when you enter a property address — with a link to this Policy.


2. Categories of Personal Information We Collect

We collect the categories of personal information below. Where helpful, we map them to the statutory categories used under the California Consumer Privacy Act, as amended by the CPRA (together, the "CCPA").

Category (plain English)ExamplesCCPA category
Identity & account / authenticationName, email address, and either a password or a Google account identifier (sign-in is handled by our authentication provider, Clerk)Identifiers
Profile & business dataTeam/business name and details, service catalog, pricing, availability, portfolio descriptions, vendor profile and public profile slugIdentifiers; Professional/employment-related information; Commercial information
Booking & transaction dataBookings, orders, order status, amounts, transaction metadata and timestamps, platform-fee records, payout records. We do not store full payment-card numbers (see Payments below)Commercial information
Payment-related dataCard brand, last four digits, expiration, and bank/payout details are handled by Stripe; we store transaction metadata and amounts returned to usCommercial information; Financial information (held primarily by Stripe)
Property & location dataProperty addresses, geocoordinates, and derived solar/weather data obtained via Google Maps / Google Places APIs, used for scheduling, routing, and weather alertsGeolocation data (treated cautiously as potential sensitive data — see Section 4)
Google Calendar integration dataWhere a Vendor connects Google Calendar, the event data Gotlan reads or writes on the Vendor's own calendar (event start/end times, busy/free status, event identifiers, and Gotlan-set extended properties), plus the OAuth access and refresh tokens for that connection (see Section 21)Identifiers; Internet or other electronic network activity information
Content & mediaVendor portfolios, marketplace thumbnails, listing/property content, deliverable metadata, messages, reviews and ratings, and content on token-based homeowner prep pagesAudio, electronic, visual, or similar information
Analytics & usage dataA first-party persistent visitor identifier (`rmm_visitor_id`) and associated `AnalyticsEvent` records (page, referrer, duration); product-analytics profiles via PostHog (person profiles created only for identified/logged-in users; some events may be captured before identification)Internet or other electronic network activity information
Error & diagnostic logsError reports and diagnostic data via Sentry, which may include IP address and technical contextInternet or other electronic network activity information; Identifiers
Communications dataEmail content and delivery metadata (transactional and onboarding sequences via Postmark); SMS opt-in status and delivery data (transactional only, via Twilio); support correspondenceIdentifiers; Commercial information
Device & connection dataIP address, browser/device type, and similar technical signals collected automaticallyIdentifiers; Internet or other electronic network activity information
InferencesLimited inferences such as marketplace scoring/ranking inputs (including a ranking boost for fully onboarded vendors) and aggregate quality scores (see Section 9, Reviews and Ratings)Inferences

We do not intentionally collect government-identifier numbers, biometric data, health data, precise device geolocation of an individual, or children's data through the Services.


3. Sources of Personal Information

We collect personal information from:

Where we obtain personal information indirectly, the controlling user (typically the Vendor) is responsible for ensuring it has the right to provide that information, and Gotlan often acts as a processor/service provider for such data (see Section 12).

Indirect-collection notice (EU/EEA, UK, Switzerland — GDPR Art. 14). Where Gotlan is the controller of personal information obtained indirectly about an EU/EEA, UK, or Swiss individual (for example, certain data we determine the purposes for), we provide the information required by Article 14 — including the categories of data, the source, the purposes, and the recipients — to that individual directly or through the controlling Vendor, generally within one month of obtaining the data or at first communication. Where Gotlan is a processor for indirectly collected data (for example, a Vendor's own CRM client lists or homeowner prep-page data the Vendor controls), the controlling Vendor is responsible for the Article 14 notice, and we support the Vendor in providing it.


4. Sensitive Information and Precise Geolocation

Some privacy laws treat precise geolocation as "sensitive personal information."

Gotlan collects property addresses and geocoordinates via Google Maps/Places to support scheduling, routing, and weather alerts. These coordinates generally describe the location of a property tied to a booking, not the precise location of your own device, and we do not use them to derive an individual user's home location or to profile any individual. We recognize one edge case: for token-based homeowner prep pages, a property address may coincide with an individual homeowner's residence. Even then, Gotlan uses the address only for the operational booking purposes described and does not use it to profile that homeowner.

Out of caution, we disclose property geolocation as potentially sensitive data. We use it only for the operational purposes above, we do not use it to infer characteristics about you, and we do not sell or "share" sensitive personal information. Because we do not sell sensitive personal information, no "NOTICE: We may sell your sensitive personal data" statement is required under the Texas Data Privacy and Security Act ("TDPSA").

Consent to process sensitive data (US opt-in-consent states). Under the Virginia, Colorado, Connecticut, and Utah comprehensive privacy laws, processing sensitive data (including precise geolocation) generally requires the consumer's opt-in consent (Utah requires clear notice and an opportunity to opt out). Where applicable, Gotlan either (a) obtains that consent at or before collection, or (b) relies on the position that a property address tied to a booking is not the individual's own precise geolocation. Where applicable law grants a right to limit the use of sensitive personal information, you may exercise it as described in Section 11.

We do not otherwise intentionally collect special-category data (such as racial or ethnic origin, religious beliefs, health, or biometric data).


5. How We Use Personal Information

We use personal information to:

We do not use personal information for purposes that are materially different from those disclosed here without providing notice and, where required, obtaining consent.


6. Legal Bases for Processing (EU/EEA, UK, and Switzerland)

If you are in the EU/EEA, the UK, or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR (and equivalent principles under the Swiss FADP):

Whether providing data is required. Providing your identity and email (via Clerk) is necessary to create an account and use the Services; a Vendor's Stripe Connect onboarding data is necessary to receive payouts; and a property address is necessary to fulfill a booking. If you do not provide this information, the relevant account, payout, or booking cannot proceed.


7. Payments

Payments are processed by Stripe and Stripe Connect.

When you provide personal data in connection with Gotlan, Stripe receives that personal data and processes it in accordance with Stripe's Privacy Policy (https://stripe.com/privacy). (This same verbatim disclosure must also appear in the Terms — see Section 0.)


8. Cookies, Tracking, and Your Consent Choices

We use cookies and similar technologies and apply a geo-aware consent model:

You can change your choices at any time via "Cookie Settings" in the site footer, which re-opens the consent interface. Withdrawing or changing consent is as easy as giving it, and turning analytics off stops the `rmm_visitor_id` identifier and PostHog capture.

Analytics and "sale"/"share" status. Gotlan does not use advertising or cross-site marketing cookies, does not run ad-network or ad-targeting integrations, and does not disclose personal information to any third party in exchange for monetary or other valuable consideration. Accordingly, Gotlan does not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of consumers we know to be under 16.

Global Privacy Control (GPC). We honor the Global Privacy Control browser signal. For California residents, we treat a valid GPC signal as an opt-out of any "sale"/"share" unconditionally, as CCPA requires. For residents of other US states whose laws recognize an opt-out preference signal, we honor GPC as those laws require.

Cookie table

Cookie / identifierFirst / third partyCategoryPurposeConsent
Consent cookieFirst-partyStrictly necessaryRecords your cookie choicesAlways active
`gotlan_geo_optin`First-partyStrictly necessaryStores your geographic consent postureAlways active
Clerk session cookiesThird-party (Clerk)Strictly necessaryAuthentication / sessionAlways active
Stripe cookiesThird-party (Stripe)Strictly necessaryPayment/fraud-prevention on payment surfacesAlways active
`rmm_visitor_id`First-partyAnalyticsPersistent identifier for first-party page/referrer/duration analytics (`AnalyticsEvent`)Consent required (opt-in EU/EEA/UK/CH; opt-out elsewhere)
PostHog cookiesThird-party (PostHog)AnalyticsProduct analytics (person profiles for identified/logged-in users)Consent required (opt-in EU/EEA/UK/CH; opt-out elsewhere)

We record consent choices (including a timestamp and the categories accepted or rejected) so we can demonstrate your choice.


9. Reviews and Ratings (Bidirectional)

Gotlan operates a two-way rating system, and the two directions are treated differently:

This rating data, including the anonymous agent-quality score, is personal information about the rated individual, and the individual's data-subject/consumer rights (including access) still apply, even though the score is anonymous to other users.

Profiling and automated decisions. Gotlan uses scoring inputs to rank and surface results on the marketplace. These inputs include the aggregate agent-quality score described above and a ranking boost for fully onboarded ("CRM-integrated") vendors. This ranking activity is profiling. We do not use the agent-quality score, by itself, to make decisions that produce legal or similarly significant effects about you, and a human remains responsible for any consequential action such as restricting or removing an account.


10. Email and SMS Communications

We send two categories of messages:

Email is delivered via Postmark. Marketing emails include our physical mailing address (2149 NE 181st Street, North Miami Beach, FL 33162) and an unsubscribe mechanism, consistent with CAN-SPAM. We honor email opt-out requests within 10 business days, and the unsubscribe mechanism remains operational for at least 30 days after a message is sent.

SMS is delivered via Twilio, is opt-in and transactional only, and is sent through a registered A2P 10DLC program. Message frequency varies, and message and data rates may apply. You can opt out by replying STOP (or by any other reasonable means) and get help by replying HELP. We honor SMS opt-out/revocation requests made by any reasonable means within 10 business days, consistent with the FCC's 2025 consent-revocation rule, and we limit post-opt-out messages to a single confirmation. Consent to SMS is not a condition of using the Services.

Vendor-configured marketing automation targets only the Vendor's own direct clients and is not sent to marketplace Agents; marketplace Agents receive promotional content only through Gotlan-mediated channels.

Financial incentives. Gotlan does not offer financial incentives, or price or service differences, in exchange for your personal information. Promotions such as a first-time-client discount, a vendor-imported-client fee exemption, or buyer-protection benefits are based on transaction origin and the fee schedule, not on your consent to marketing or analytics.


11. Your Privacy Rights and How to Exercise Them

You may have the rights described below depending on where you live. To exercise any right, contact us at privacy@gotlan.com. We will verify your request as required by law before responding.

Multi-tenant note. Because Gotlan is multi-tenant, some data you ask about may be controlled by a Vendor (for example, a Vendor's CRM client records, homeowner prep-page data, or listing content the Vendor loaded). For data where the Vendor is the controller and Gotlan acts as a processor/service provider, we will coordinate with the controlling Vendor and respond as required by law. Where Gotlan itself determines the purposes and means of processing (for example, marketplace operation, cross-tenant scoring, review-visibility rules, and Gotlan-mediated marketing), Gotlan acts as a controller/business and responds to your request directly rather than deflecting it to a Vendor. Some data cannot be deleted where we must retain it to meet transaction, payout, tax, or legal-record obligations.

11.1 US state privacy rights (California, Texas, and other states)

If you are a resident of a US state with a comprehensive privacy law (including California, Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, and others as such laws take effect), you may have the rights to:

Sale / share. Gotlan does not sell personal information and does not "share" it for cross-context behavioral advertising. Where the right to limit the use of sensitive personal information applies, you may exercise it using the contacts above.

Appeals. If your state's comprehensive privacy law grants an appeal right (including Texas, Virginia, Colorado, Connecticut, Utah, and other states that provide one), and we decline your request, you may appeal that decision by contacting privacy@gotlan.com. We will respond to an appeal within 60 days of receipt (or the shorter period your state's law requires) and, if we deny the appeal, we will tell you how to contact your state attorney general.

Authorized agents. You may use an authorized agent to submit a request, subject to verification.

Timing. We generally respond to an initial request within the period required by applicable law (typically 45 days, extendable where permitted).

California "Shine the Light" and Do-Not-Track. We do not disclose personal information to third parties for those parties' own direct marketing, so a California "Shine the Light" request would return no such disclosures. Because we do not knowingly track users across third-party websites for advertising, we do not respond to browser Do-Not-Track signals differently than described here, but we do honor GPC as noted in Section 8.

11.2 GDPR / UK GDPR / Swiss FADP rights

If you are in the EU/EEA, the UK, or Switzerland, you have the rights to: access, rectification, erasure, restriction of processing, data portability, object to processing (including processing based on legitimate interests), withdraw consent at any time (without affecting prior lawful processing), and not be subject to a solely automated decision producing legal or similarly significant effects. Subject to the profiling verification in Section 9, we do not make such solely-automated significant decisions about you; if that verification shows the agent-quality score automatically gates access, the Article 22 rights described in Section 9 apply.

You also have the right to lodge a complaint with your supervisory authority (in the EU, your local Data Protection Authority; in the UK, the Information Commissioner's Office) or, where available, to raise an internal complaint with us first at privacy@gotlan.com.


12. Our Role: Controller vs. Processor

Gotlan and Vendors are independent controllers (not joint controllers) with respect to the booking relationship; each decides its own purposes. A vendor-facing data processing addendum (DPA) is available to Vendors.


13. How We Share Personal Information; Subprocessors

We share personal information with service providers (subprocessors) that perform functions on our behalf, and with others as described below. We do not sell your personal information.

We may also disclose personal information:

Where we make a disclosure required by law or to protect rights and safety, our legal basis (for in-scope individuals) is compliance with a legal obligation and/or our legitimate interests in protecting the Services and our users.

A key architectural point: Gotlan does not host bulk media. Vendors connect their own Dropbox or Google Drive accounts at the first-booking-acceptance gate, and bulk deliverables reside in the Vendor's storage under the Vendor's control, not Gotlan's. Because that storage is owned and operated by the Vendor, it is not a Gotlan subprocessor and is listed separately below.

Subprocessors

SubprocessorFunctionData region
ClerkIdentity and authentication (name, email, password or Google OAuth)United States
Stripe / Stripe ConnectPayment and payout processing; handles card and bank data under PCI-DSSUnited States; relies on EU-US Data Privacy Framework and/or SCCs
SupabaseApplication database (PostgreSQL)United States (us-east-1); SCCs / UK addendum
VercelApplication hostingUnited States
UpstashRedis (rate limiting)United States
PostHogProduct analytics (person profiles for identified users; consent-gated)United States; SCCs / DPF where applicable
SentryError and diagnostic monitoringUnited States
PostmarkTransactional and onboarding/welcome emailUnited States; SCCs
TwilioTransactional SMS (opt-in, 10DLC)United States; relies on EU-US/Swiss-US DPF and/or SCCs
Google Maps / Google PlacesGeocoding, routing, and derived solar/weather dataUnited States; SCCs / DPF where applicable

Vendor-controlled third-party storage (not a Gotlan subprocessor): Dropbox / Google Drive — bulk media storage connected by, and under the control of, the Vendor. Gotlan does not host this media or act as its controller; the Vendor's own agreement with the storage provider governs it.

This list may be updated; we maintain it as a separately versioned reference.


14. International Data Transfers

The Services are operated from the United States, and personal information is processed and stored in the United States (our database resides in the us-east-1 region).

If you access the Services from the EU/EEA, the UK, or Switzerland, your personal information is transferred to the United States. For transfers to Gotlan LLC, we rely primarily on the EU Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum / IDTA and, for transfers subject to the Swiss Federal Act on Data Protection ("FADP"), the Swiss addendum to the SCCs, as appropriate. Certain subprocessors (such as Stripe and Twilio) additionally maintain certification under the EU-US Data Privacy Framework (and its UK Extension and Swiss-US counterpart). You may request information about these safeguards at privacy@gotlan.com.

Representatives. Whether Gotlan LLC requires an EU Article 27 representative, a UK representative, and/or a Swiss FADP representative depends on the nature and scale of its processing of in-scope individuals' data; given the currently incidental EU/UK/CH exposure, we believe no such representative is required, and we will name any representative here once designated.


15. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, then delete or de-identify it. In general:

Where no specific period is set, we determine retention based on the nature and sensitivity of the data, the purposes for which it is processed, and applicable legal requirements.


16. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including:

Because Gotlan does not host bulk media (Vendors use their own storage), our data footprint is minimized by design.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach, we will notify affected individuals and regulators as required by applicable law. For EU/EEA, UK, and Swiss personal data, breach notification follows the timelines in GDPR Articles 33–34 and the UK GDPR / FADP equivalents (including, where applicable, notifying the supervisory authority within 72 hours).


17. Children's Privacy

The Services are intended for businesses and professionals and for individuals 18 years of age or older. The Services are not directed to children.

We do not knowingly collect personal information from children. In the United States, we do not knowingly collect personal information from a child under 13 (COPPA). In the EU/EEA, the UK, and Switzerland, we do not knowingly collect personal information from a child under 16 (GDPR Article 8; the applicable national age may be as low as 13). Token-based homeowner prep pages are not directed to children and are designed to surface only property-related operational information, not a minor's personal data. If we learn that we have collected personal information from a child without appropriate consent, we will delete it.


18. Third-Party Links and Services

The Services may link to or integrate third-party websites and services (for example, a Vendor's connected Dropbox or Google Drive, or external sites referenced in content). This Policy does not cover those third parties, and we are not responsible for their privacy practices. Please review their privacy policies, including Stripe's Privacy Policy (https://stripe.com/privacy) for payment processing.


19. Changes to This Policy

We may update this Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide advance notice (for example, by email via Postmark and/or an in-app banner) with a forward-looking effective date. Where required by law, we will obtain your consent before a material change that expands how we use your personal information takes effect. We review this Policy at least every 12 months.

This Privacy Policy is a notice of our practices, not a contract; your contractual agreement with Gotlan is governed by the Terms (see Section 0). Changes to this Policy do not by themselves amend any contract, and we do not treat your continued use of the Services as your "acceptance" of an amended Policy.


20. Contact Us and Data-Controller Identity

The data controller for personal information processed by Gotlan is:

Gotlan LLC (formed in Florida) Mailing address: 2149 NE 181st Street, North Miami Beach, FL 33162 Privacy inquiries and rights requests: privacy@gotlan.com General support: support@gotlan.com

If we designate an EU/EEA, UK, or Swiss representative, that representative's details will be listed here.


21. Google Calendar Integration (Google User Data and Limited Use)

A Vendor may optionally connect their own Google Calendar so that Gotlan can keep shoot appointments in sync. This section describes how Gotlan accesses, uses, transfers, protects, retains, and deletes Google user data obtained through the Google Calendar API, and states our commitment to Google's Limited Use requirements. It supplements the general disclosures above and controls with respect to Google user data if there is any conflict.

21.1 Google data we access

When a Vendor chooses to connect Google Calendar, Gotlan requests the following OAuth scopes and no others:

Gotlan accesses only the specific event fields needed for these features (event start/end times, busy/free status, event identifiers, and extended properties Gotlan itself sets to link an event to a Gotlan order). We do not request access to a Vendor's full calendar, contacts, Gmail, Drive, or any other Google data, and the connection is limited to the individual Vendor account that authorized it. We do not derive aggregated or anonymized products from this data other than what is strictly necessary to render and reconcile the calendar sync.

21.2 How we use Google data

Google Calendar data is used solely to provide the user-facing scheduling features described above: writing Gotlan shoot/appointment events onto the Vendor's calendar and, where inbound sync is enabled, reading existing busy times to prevent scheduling conflicts. We do not use Google user data for advertising, for profiling unrelated to the booking, for credit or lending decisions, or for any purpose other than providing and improving these scheduling features.

21.3 How we share or transfer Google data

We do not sell Google user data and do not transfer it to third parties, data brokers, or advertisers. Google Calendar data flows only between the Vendor's own Google account and the Gotlan systems that operate the sync; it is not disclosed to other users or Vendors. The Vendor's Google Calendar is the Vendor's own connected account (comparable to the Vendor's own Dropbox/Drive described in Section 13) and is not a Gotlan subprocessor.

21.4 AI/ML restrictions

Gotlan does not use Google Workspace API data (including Google Calendar data) to develop, improve, or train generalized artificial-intelligence or machine-learning models, and does not transfer such data to any third-party service that would use it to train its AI/ML models.

21.5 How we protect Google data

The OAuth access and refresh tokens for a Google Calendar connection are stored encrypted at rest, are scoped to the authorizing Vendor under Gotlan's multi-tenant isolation, and are transmitted only over encrypted (TLS) channels. Access to these tokens is restricted to the systems that operate the calendar sync.

21.6 Retention and deletion

Gotlan retains a Vendor's Google Calendar tokens and connection data only for as long as the integration remains connected. When a Vendor disconnects the integration (or deletes their account), Gotlan revokes the token with Google (RFC 7009) and deletes the stored tokens, and stops accessing the Vendor's calendar. Calendar events that Gotlan previously created remain on the Vendor's own Google Calendar under the Vendor's control, where the Vendor can edit or delete them directly. A Vendor may also revoke Gotlan's access at any time from their Google Account permissions page.

Limited Use. Gotlan's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


This Policy is subject to review and revision by Gotlan LLC and its counsel before publication. The governing law, venue, and dispute-resolution terms applicable to your relationship with Gotlan are set out in the Terms (Florida governing law; venue in Miami-Dade County), not in this Privacy Policy.