Back to Maraboard

Privacy Policy

Effective date: August 12, 2026

1. Who We Are and Scope

Maraboard is a property diligence product and service operated by Insyterra LLC at maraboard.com. In this policy, “Maraboard” refers to the product and service, while “we,” “us,” and “our” refer to Insyterra LLC when operating Maraboard. Insyterra LLC is responsible for the privacy practices described in this policy.

This policy explains how we handle personal information when you browse public property opportunities, create or use an account, save listings, set buyer preferences, submit an inquiry, purchase Premium Review access, receive communications, or contact support.

Questions or privacy requests may be sent to support@maraboard.com or through the Maraboard contact page.

2. Information We Handle

Account and profile information

We handle the email address and authentication information needed to create and secure your account. If you use Google sign-in, Google and Supabase support that authentication flow. We may also handle your name, buyer-profile completion status, preferred property market, purchase timeline, notification preferences, and account email-change or password-recovery activity.

We do not receive your Google password. Password credentials and authentication sessions are handled through Supabase Auth.

Saved activity and diligence access

When you use account features, we may keep records of saved listings, project interests, Premium Review purchases and entitlements, notification preferences, and the project trust content you are authorized to access. These records support your account experience and enforce product access; analytics is not used as an entitlement source of truth.

Inquiries and support

Contact submissions may include your name, email address, inquiry reason, and message. Developer inquiries may also include company name, country, project location, website, and message. The inquiry flow uses timing, a hidden anti-spam field, a submission identifier, Cloudflare Turnstile evidence, and available network information such as an IP address to validate the submission.

Validated public inquiries are delivered through Resend to a configured Maraboard inbox. They are not added to the normal application email outbox and do not trigger an automatic visitor email.

Payments and entitlements

Stripe hosts checkout and processes payment-card information. We do not store full card numbers or card security codes. We receive and retain transaction information needed to reconcile payment and access, such as the buyer and project identifiers, amount, currency, payment status, Stripe Checkout and PaymentIntent references, refund state, and verified Stripe event history.

A successful checkout redirect does not grant access. Verified Stripe webhook processing updates Maraboard's payment ledger and grants the relevant Premium Review entitlement.

Communications

We handle your email address, message category, preferences, suppression status, delivery state, and provider identifiers to send and administer authentication, payment, trust-update, saved-listing, and optional digest communications. Resend is the current email delivery provider. Open and click tracking are disabled for Maraboard application email.

Optional messages include category-specific unsubscribe controls. Required authentication, payment, security, and service messages may still be sent when necessary to operate your account or deliver a purchase.

Analytics and error information

Cookiebot manages browser consent. Maraboard initializes browser PostHog analytics, identification, session replay, and browser exception capture only when Cookiebot reports Statistics consent. Before that consent, browser events are dropped rather than queued. Withdrawing Statistics consent opts the browser out and resets the active PostHog identity.

With consent, PostHog may receive a pseudonymous or authenticated user identifier, page and product events, limited event properties, device/browser information, and replay or browser-error context. Maraboard disables general browser autocapture and does not intentionally send personal documents, payment-card data, free-form inquiry messages, secrets, or raw Stripe objects to PostHog.

Selected server-side payment events and sanitized exceptions may be sent to PostHog for transaction integrity and operational monitoring. This server-side safety telemetry is separate from optional browser analytics and is designed to exclude card data, secrets, checkout URLs, receipt URLs, and raw provider payloads.

Website and third-party feature information

Our hosting, security, content, and map services may process ordinary request information such as IP address, browser/device information, requested URL, timestamps, and security signals. Google Maps loads on the project browse experience; Sanity supplies public editorial content; Cloudflare Turnstile protects public forms; Cookiebot stores consent choices.

3. How We Use Information

We use personal information to:

  • provide, secure, and support accounts and authentication;
  • show public opportunities and buyer-authorized diligence content;
  • remember saved activity and buyer preferences;
  • process and reconcile payments, refunds, and entitlements;
  • answer contact, developer, and support inquiries;
  • send required service messages and optional communications you have not disabled;
  • prevent spam, abuse, unauthorized access, and payment or delivery fraud;
  • diagnose failures, preserve audit records, and maintain service reliability;
  • understand and improve the service when browser analytics consent is present; and
  • comply with legal obligations and enforce our terms.

We do not sell personal information. We do not use PostHog, Stripe, or email-delivery state as a substitute for Maraboard's account or entitlement authorization controls.

4. Service Providers and Disclosures

We disclose information only as needed to operate the service, fulfill a request, protect Maraboard and its users, or comply with law. Current service categories include:

  • Supabase for database, storage, authentication, and server functions;
  • Stripe for checkout, payment processing, refunds, and verified payment events;
  • Resend for authentication, application, support, and inquiry email delivery;
  • Vercel for the web application and Render for the email worker and scheduled digest job;
  • Cloudflare for domain/security services and Turnstile form verification;
  • PostHog for consent-gated browser analytics, session replay, and error tracking, plus limited server-side operational telemetry;
  • Cookiebot for consent management;
  • Google Maps for the project browse map; and
  • Sanity for public editorial content.

We may also disclose limited information to professional advisers, diligence or verification partners involved in a requested service, payment or fraud specialists, regulators, courts, or law enforcement where appropriate and lawful. Property developers and other third parties receive information only when needed for the interaction or service you request; we do not provide them unrestricted access to buyer account data.

5. Cookies and Similar Technologies

Necessary technologies support authentication, security, consent storage, checkout, form protection, and requested site features. Optional PostHog browser analytics requires Cookiebot Statistics consent. Google Maps may use Google technologies when its map is loaded on /projects.

See the Cookie Policy for the current categories and controls. You can reopen Cookiebot from the footer's Cookie preferences action.

6. Retention

We keep information only for as long as reasonably needed for the purpose collected, including account operation, purchased-content access, payment and refund records, security, suppression safety, dispute handling, and legal obligations.

Retention varies by record:

  • account, buyer preference, saved activity, and entitlement records are kept while needed to provide the account and document access;
  • payment, refund, webhook, and audit records may be kept longer for financial reconciliation, fraud prevention, disputes, and legal recordkeeping;
  • authentication delivery records have a twelve-month operational retention requirement, while permanent email-safety suppressions may remain until safely resolved;
  • inquiries and support correspondence are retained only as long as needed to respond, maintain appropriate business records, or address a dispute; and
  • Cookiebot, PostHog, Stripe, Resend, hosting, and security-provider information is subject to Maraboard's configured settings and the provider's processing obligations.

Deletion or account closure may not remove information that must be retained for payment, security, audit, suppression, dispute, or legal reasons. Where feasible, records may be deleted, de-identified, or access-restricted when no longer needed.

7. Security

We use access controls, row-level database security, trusted server-side mutation boundaries, signed provider webhooks, private storage with short-lived download links where applicable, and environment-separated credentials to protect Maraboard. No online service can guarantee absolute security. Do not send card details, passwords, private legal documents, or other unnecessary sensitive information through public inquiry forms or ordinary email.

8. International Processing

Maraboard serves diaspora buyers and uses providers that may process information in countries other than your own. We use contractual and technical safeguards appropriate to the service and provider. Local privacy and consumer-protection rights continue to apply where they cannot lawfully be waived.

9. Your Choices and Rights

Depending on applicable law, you may ask to access, correct, delete, or restrict certain personal information, or object to certain processing. You may:

  • update available account and notification preferences;
  • unsubscribe from an optional email category through its one-click link;
  • reopen Cookiebot to grant or withdraw Statistics consent; and
  • contact support@maraboard.com for an account or privacy request.

We may need to verify your identity before completing a request. Some requests may be limited by payment, fraud-prevention, security, audit, or legal-retention obligations.

10. Changes to This Policy

We may update this policy when the service, providers, or legal requirements change. We will publish the revised policy with a new effective date and provide additional notice when appropriate.

11. Contact

Email support@maraboard.com or use the Maraboard contact page. Include enough information for us to identify the account or request, but do not send passwords or full payment-card details.