The product Your state Websites Pricing FAQ Open the live demo

Legal

Privacy Policy

What we collect, who else touches it and where it is kept. Written to be read rather than to be survived.

Last updated September 11, 2026

1. Who we are

Statehouse is a trading name of Software Builders Ltd, a company registered in England and Wales, company number 17431696, registered office 66 Chertsey Road, Windlesham, England, GU20 6HP.

We are a software company. We are not a real estate brokerage, we do not hold a real estate license, and we are not a party to any transaction you run through the product.

2. Two different relationships

This is the most important thing on the page, because the rest of the document turns on it. We handle personal information in two quite different capacities.

We are the controller of information about you: your visit to this website, your account, your billing, and your correspondence with us. We decide why and how that is processed, and this policy governs it.

We are a processor of the information you put into the CRM about your clients: buyers, sellers, leads, their addresses, their phone numbers, their offers and their documents. You, or the brokerage you work for, are the controller of that information. We hold it on your behalf, we act on your instructions, and we do not decide what to do with it. Your own privacy notice, not this one, is what your clients should be reading.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, in the sense those terms are given by the California Consumer Privacy Act. We have never done so. We do not run an advertising business and your client list is not a product we have any interest in.

3. This website

This marketing site sets no cookies. It runs no analytics, no tracking pixels, no session recording, no advertising tags, and no consent banner, because there is nothing to consent to. Nothing is written to local storage. You can verify all of that in your browser's developer tools in about ten seconds, which is rather the point of saying it.

There are two exceptions worth naming honestly.

Web fonts

The page loads its typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). To serve those files Google receives your IP address and your browser's user agent string. That is a request your browser makes directly to Google, and it is governed by Google's own privacy policy rather than ours. It is the only third-party request this site makes.

Server logs

Our web server keeps standard access logs: IP address, timestamp, the page requested, the response code and the user agent. These exist so we can see that the site is up and investigate abuse. They are not joined to any profile and are not used to build one.

4. The live demo

The demo signs you into a shared demonstration account containing entirely fabricated brokerage data. It is the real product, not a video, so anything you type goes into a real database.

Do not put real client information into the demo

The demo account is shared with every other visitor and its contents are reset on a schedule. Anything you enter may be visible to other people trying the product before it is wiped. Type nonsense into it, enthusiastically.

5. Your account

If you become a customer we hold, as controller:

  • your name, work email address, phone number and the name of your brokerage;
  • your license state, because the product's behaviour depends on it;
  • a cryptographic hash of your password, never the password itself;
  • sign-in records: time, IP address and browser, so we can investigate account abuse;
  • your subscription status, plan and seat count;
  • support correspondence you send us.

We use this to give you the service, to bill you, to reach you about the service, and to keep the account secure. We rely on the performance of our contract with you for most of it, and on our legitimate interest in running a secure service for the rest.

Payment details

Subscriptions are billed through Stripe. Card numbers are entered directly into Stripe and never reach our servers. We can see the last four digits, the card brand, the expiry and whether a charge succeeded. That is all we can see, and it is all we want to see.

6. Data you put in the CRM

Contacts, leads, listings, offers, transaction files, notes, tasks, documents and uploaded photographs. You control what goes in. We process it to provide the service, and for nothing else: we do not mine it, we do not aggregate it into market products, and we do not use it to train machine learning models.

The product deliberately does not ask for, and has no field for, the protected characteristics listed on our fair housing page. If you type such information into a free-text note that is your decision and your risk, and we would strongly encourage you not to.

7. Email, texts and calls

When you send email through the product we process the message, the recipient and delivery events such as bounces and opens. When you text or call a contact we process the number, the message body or call metadata, the time, and any consent and opt-out record attached to that contact.

Consent and opt-out records are kept deliberately. If a recipient replies STOP we record that, against both the contact and the phone number, and we keep it after you delete the contact. Deleting a record of someone's refusal in order to message them again is precisely the harm the rule exists to prevent.

If you use the product's handoff mode, the message is composed in Statehouse and sent from your own phone through your own carrier. In that case the content goes to your carrier, not to us or to any messaging provider we use.

8. The AI assistant

If you use the assistant, your question and the records it needs to answer it (for example a property address or a contact's name) are sent to Anthropic, which generates the reply and returns it. This happens only when you use the assistant. It does not run in the background and it does not read your database at rest.

Anthropic processes the request to produce the answer. If you would rather no client information reached a third-party model provider at all, do not use the assistant; every other part of the product works without it.

9. Who else processes it

These are our sub-processors. We keep the list short on purpose.

ProviderWhat it doesWhen
DigitalOcean Servers and database hosting Always
Stripe Subscription billing and card processing If you are a paying customer
Resend Delivering email the product sends When email is sent
Twilio Text messages and calls Only if you enable it, and not in handoff mode
Anthropic Generating assistant replies Only when you use the assistant
Google Fonts Serving typefaces to your browser On the public website

Each is bound by its own contract to process data only on our instructions. We will update this list before adding a new one that touches customer data.

10. Where it is stored

Application data is stored on servers in the United States, in DigitalOcean's New York region. We are a UK company, so information reaching us as controller is also handled under UK law, and transfers between the two are made under the UK's approved transfer mechanisms including the International Data Transfer Addendum where it applies.

11. How long we keep it

  • Your CRM data: for as long as your account is active.
  • After you cancel: you have thirty days to export everything, in full, from inside the product. After that window we delete it.
  • Billing records: six years, because tax law requires it.
  • Opt-out and STOP records: indefinitely, for the reason given in section 7.
  • Server logs: a rolling short period, then overwritten.

12. Your rights

If you are in the United States

Depending on your state, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to delete it, and to not be discriminated against for exercising any of those rights. California residents have these rights under the CCPA as amended by the CPRA; comparable rights exist in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and a growing list of other states.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out for you to exercise on that front. You may use an authorised agent. We will not charge you and we will not ask you to create an account to make a request.

If you are in the UK or the EU

You have the right of access, rectification, erasure, restriction, portability and objection under the UK GDPR. You may complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first and gave us the chance to fix it.

If you are somebody's client rather than our customer

If your details are in a Statehouse CRM it is because an agent or brokerage put them there. They are the controller. Ask them, and if they ask us for help in answering you, we will help them.

13. Security

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Access to production systems is limited to the people who need it. Each brokerage's data is separated from every other brokerage's at the application layer.

No system is perfectly secure and anybody who tells you otherwise is selling something. If you believe you have found a vulnerability, please write to hello@getstatehouse.com and we will take it seriously and will not threaten you for reporting it.

14. Children

Statehouse is a professional tool sold to licensed adults. It is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe we have, tell us and we will delete it.

15. Changes

If we change this policy we will change the date at the top. If a change materially affects how we handle your information we will tell you by email before it takes effect, rather than relying on you to notice.

16. Contact

hello@getstatehouse.com
Software Builders Ltd, 66 Chertsey Road, Windlesham, England, GU20 6HP

See also our Terms of Service and our fair housing commitment.