Privacy Policy
Last updated: March 2025
Who we are
Meydomo is a technology company that operates a flat-fee MLS coordination service. AI is embedded in every client touchpoint—phone, SMS, email, chat, scheduling, and document intake. This policy explains which data we collect, what we do with it, and how we keep it secure inside our own infrastructure.
Data we collect
- Account information. Contact names, phone numbers, email addresses, property details, and billing information supplied during onboarding or through support interactions.
- Conversation transcripts. All phone calls, voicemail, SMS threads, and emails are transcribed and stored in a private database so our AI assistants and human specialists can provide continuous service context.
- Operational metadata. Timestamps, workflow states, task assignments, and audit trails that document how we coordinate listings, showings, and offers.
- Analytics data. We run Google Analytics 4 to understand site usage, campaign performance, and product interest. GA4 collects page views, device characteristics, and approximate geography derived from IP addresses. We do not send raw transcripts or form content to Google Analytics.
- Support evidence. Files you upload (photos, documents, inspection reports) are stored in regionally redundant storage we control. We scan uploads for malware before they are made available to the team.
How we use your data
- Coordinate MLS listings, showing calendars, offer management, and seller communications.
- Train and evaluate the prompts that power our AI concierge (without exposing your raw data outside our control).
- Provide customer support and respond to compliance or legal requests.
- Measure product performance and prioritize improvements based on aggregated analytics.
- Meet our contractual and regulatory obligations, including audit trails and record retention rules.
AI + communications stack
We run proprietary voice, SMS, and email infrastructure on servers we control. We do notexpose SMTP ports or lease third-party telephony accounts. Every outbound message is sent over HTTPS APIs using JSON Web Tokens for authentication. The only external AI partner we use is OpenAI’s GPT-5 family (including GPT-5 Realtime). We transmit de-identified context snippets to those models on a transactional basis, and we do not allow OpenAI to use our data for training.
Conversation transcripts stay in a private Postgres cluster. Access requires hardware security keys, enforced least-privilege roles, and full encryption at rest. Internal systems log every read or export so we can trace misuse.
Cookies & analytics
Google Analytics 4 is the only analytics platform we run. We deploy it to measure aggregate usage, diagnose outages, and improve content. We do not build advertising audiences, share identifiers with ad networks, or sell the resulting data. If you block analytics scripts, the core site continues to function.
Browsers that send a “Do Not Track” signal still receive GA4 because we use it strictly for product metrics. You can opt out by installing the GA opt-out browser add-on or by adjusting cookie controls.
Security approach
- Infrastructure isolation. Communications servers, AI orchestration, and listing workflows run on separate network segments with firewall rules that block lateral movement.
- Encryption everywhere. TLS 1.3 for data in transit, envelope encryption for storage, and hardware security modules for signing outbound email via HTTPS APIs.
- Access governance. Role-based access, hardware security keys, and quarterly access reviews keep human access to a minimum.
- Incident drills. We run tabletop exercises twice a year covering AI prompt misuse, phone fraud, and credential theft scenarios.
Retention & deletion
Listing files and communication transcripts are retained for seven (7) years to satisfy state real estate recordkeeping requirements and to defend against disputes. If you close or cancel your account, we archive transcripts within 30 days and permanently delete them once statutory retention windows expire.
Marketing contacts can unsubscribe at any time. Removing yourself from product communications does not delete transaction records we must retain for compliance.
Your privacy rights
- Request a copy of the personal data we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion when the law allows it (for example, after retention periods expire).
- Restrict certain processing, such as marketing communications.
Email privacy@meydomo.com to submit a request. We verify identity before fulfilling any request.
Sharing & disclosures
We do not sell personal data. We only share information with:
- OpenAI. Real-time model executions for concierge tasks. We send the minimum context required for a response and store the model’s output alongside our transcripts.
- Escrow & closing professionals. When you explicitly instruct us to coordinate with them and provide documentation.
- Regulators and courts. When legal process requires disclosure or when we must enforce our agreements.
Contact
Questions or concerns? Email privacy@meydomo.com or write to Meydomo Privacy, 1337 Market Street, Suite 400, San Francisco, CA 94103.
Policy changes
We update this policy when regulations, infrastructure, or product features change. We post the revision date at the top, email active customers when we make material updates, and archive prior versions for reference.