PANDO/LIVE
Deals closed0Properties vetted20Buy-box criteria11BaseKeokuk, IAImpact ratio15:1Renovation crewsIowa localDeals closed0Properties vetted20Buy-box criteria11BaseKeokuk, IAImpact ratio15:1Renovation crewsIowa local

Privacy policy · v1.0 · effective 2026-04-19

What we collect, how we use it, and what we don't do.

Pando is a small operator. We don't sell data, we don't run ad networks, and we don't share phone numbers with third parties for marketing. This page documents what we do collect, why, and what your rights are.

§1

What we collect

  • Account information — name, email, phone number, state, and for agents, professional credentials (license number, license state, brokerage name).
  • Property data — addresses and property details from public records (county assessors, ATTOM, Beacon, FEMA), plus data and photos agents submit directly through the portal.
  • Usage data — pages visited, Intelligence Console queries, submission activity, reservation history. Used to improve the product and for security auditing.
  • Communication records — emails sent to your account, SMS opt-in consent records with timestamps, support conversations, account notifications.
§2

How we use it

  • Operating the platform — sign-in, submission processing, deal matching, reservations, notifications.
  • Communications — account-related email and (with your consent) SMS messages matching your notification preferences.
  • Product improvement— aggregate analytics (e.g. submission buy-box pass rates, feature adoption). Individual-level analysis only for diagnosing specific problems you've reported.
  • Legal compliance — Iowa HF 2374 records, tax records, SMS opt-in/opt-out logs, security incident forensics.
§3

SMS data handling

Phone numbers and SMS consent are high-sensitivity fields. Here's what we do with them:

  • Collection — phone numbers are collected only with consent. Agents provide their number during the portal sign-up; investors provide theirs during Request Access.
  • Consent logging — when you opt in to SMS, we log the event with a timestamp, the source (UI action or SMS keyword), your IP address, and (for UI actions) your user agent. This creates an audit trail for compliance.
  • Use— phone numbers are used only for notifications you've opted into. We never cold-text.
  • Third-party sharing — phone numbers are not sold, rented, or shared with any third party for marketing or advertising purposes. The only third party that processes your number is Twilio (our SMS delivery provider), under a standard data-processor agreement.
  • Opt-out records— if you opt out via STOP or the preferences UI, we retain the opt-out record indefinitely for compliance. Your number isn't used again for marketing after opt-out.
  • Encryption — phone numbers are encrypted at rest in our database, as is all other PII.
§4

Who we share with

We work with a small set of service providers who act as data processors under standard contracts:

  • Supabase — database, auth, file storage
  • Resend — transactional email delivery
  • Twilio — SMS delivery
  • Vercel — application hosting
  • Anthropic — the Claude models that power our Intelligence Console and admin briefings

Each processes your data only for the purposes we direct, and none of them use Pando user data to train models or build advertising profiles.

We also disclose data when required by legal process (subpoena, court order, valid government request) and in the case of a merger, acquisition, or sale of business — with advance notice to users before any transfer.

§5

How long we retain

  • Account data — while your account is active, plus two years after closure for recovery and audit.
  • Transaction records — seven years (standard regulatory retention period).
  • SMS opt-out records — retained indefinitely to ensure we never re-text someone who has opted out.
  • Marketing email activity — until you unsubscribe or close your account.
  • Usage logs — 24 months, then purged unless required for ongoing investigation.
§6

Your rights

  • Access, correct, or delete your data — subject to legal retention obligations. Email privacy@ownpando.com.
  • Opt out of SMS — reply STOP to any Pando text, or use the Notification preferences page in your portal account. Either path works; both are immediate.
  • Opt out of marketing emails — use the unsubscribe link in any marketing email, or email privacy@ownpando.com.
  • Portability— request a copy of the data you've provided, in a machine-readable format.
§7

Security

Data is encrypted in transit (TLS) and at rest. Supabase service-role keys are restricted to server-side operations only and never exposed to the browser. Admin access is logged; every admin action creates an audit trail.

In the event of a data breach that affects your personal information, we'll notify you per applicable state law — typically within 30 days of confirming scope.

§8

Third-party links

Our admin review surfaces include links to public-record sources (Beacon / Schneider Geospatial, Zillow, county assessor portals). We don't control those sites' privacy practices; when you follow those links, their privacy policies apply.

§9

Children

Pando is not directed at or intended for anyone under 18. We don't knowingly collect data from minors. If you believe we've collected data from someone under 18, email privacy@ownpando.com and we'll delete it.

§10

State-specific rights

Depending on where you live, you have additional rights:

  • California residents (CCPA / CPRA)— right to know what we collect, right to delete, right to opt out of sale. We don't sell personal data. Requests via privacy@ownpando.com.
  • Iowa, Utah, and other states with data-privacy statutes — rights as applicable under state law (access, correction, deletion, portability). Same intake address.
§11

Changes to this policy

Material changes are announced via email to account holders with at least 30 days' notice before taking effect. Minor clarifications update the version and effective date at the top of this page without separate notice.

§12

Contact

Privacy or data-rights questions: privacy@ownpando.com. General contact via /contact.