At Certihomes, Inc. ("Certihomes," "we," "us," or "our"), we take your privacy seriously. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use the Certihomes financial planning application, website, and related services (collectively, the "Services").
By using our Services, you consent to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
1. What This Privacy Policy Covers
This Privacy Policy covers the collection and use of personal information — information that identifies, relates to, describes, or could reasonably be linked to you — that we gather when you use our Services. This policy does not apply to third-party websites, applications, or services that may be linked from our Services, each of which may have their own privacy policies.
2. Personal Data We Collect
2.1 Categories of Personal Data
We may collect the following categories of personal information:
- Account Data: Name, email address, password, and account preferences when you create an account.
- Profile Data: Additional information you provide such as date of birth, phone number, and profile photo.
- Financial Data: Account balances, transaction history, income information, debt details, investment holdings, and other financial information you provide or that we access through linked financial accounts.
- Payment Data: Credit card number, billing address, and payment method details for subscription purchases (processed securely by our payment processor).
- Device and Usage Data: IP address, browser type, operating system, device identifiers, pages visited, features used, timestamps, and referring URLs.
- Communication Data: Messages, feedback, and support requests you send to us.
- Third-Party Account Data: Financial account information accessed through third-party services such as Plaid, including account numbers (masked), routing numbers, balances, and transaction data.
2.2 Sources of Personal Data
- Directly from you: Information you provide when creating an account, updating your profile, contacting support, or using our Services.
- Automatically: Device and usage data collected through cookies, web beacons, and similar technologies when you interact with our Services.
- Financial account connections: Data retrieved from your linked financial institutions through services like Plaid.
- Third parties: Information from analytics providers, advertising networks, and other service partners.
3. How We Use Your Personal Data
We use your personal information for the following purposes:
3.1 Providing and Improving Services
- Creating and maintaining your account.
- Displaying your financial data, generating reports, charts, and insights.
- Providing mortgage calculations, debt payoff projections, and other financial tools.
- Processing subscription payments.
- Improving, personalizing, and developing new features.
3.2 Communications
- Sending account notifications, security alerts, and service updates.
- Responding to your inquiries and support requests.
- Sending promotional communications (with your consent, where required by law).
3.3 Legal and Security Purposes
- Complying with applicable laws, regulations, and legal processes.
- Detecting, preventing, and addressing fraud, security issues, and technical problems.
- Protecting the rights, property, and safety of Certihomes, our users, and the public.
- Enforcing our Terms of Service and other agreements.
4. How We May Disclose Your Personal Data
We may share your personal information with the following parties:
- Service Providers: Third-party vendors who help us operate and improve the Services, including hosting providers, payment processors, analytics providers, and customer support tools. These providers are contractually obligated to protect your data.
- Financial Data Providers: Services such as Plaid that facilitate connections to your financial institutions. These providers have their own privacy policies governing their use of your data.
- Household Members and Financial Professionals: If you grant access to household members or authorized financial professionals through the Services, they may view your financial data as permitted by your sharing settings.
- Legal and Regulatory: When required by law, subpoena, court order, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as a business asset.
- With Your Consent: We may share your information for other purposes with your explicit consent.
We do not sell your personal information to third parties for their marketing purposes.
5. Cookies and Tracking Technologies
We use the following types of cookies and tracking technologies:
- Essential Cookies: Required for the Services to function properly (e.g., authentication, security).
- Functional Cookies: Remember your preferences and settings to enhance your experience.
- Performance Cookies: Help us understand how you use the Services so we can improve them (e.g., Google Analytics).
- Advertising Cookies: Used to deliver relevant advertisements and measure ad campaign effectiveness.
You can control cookies through your browser settings. Disabling certain cookies may limit your ability to use some features of the Services.
Do Not Track: Some browsers offer a "Do Not Track" signal. We currently do not respond to Do Not Track signals, but we honor opt-out preferences as described in this policy.
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Regular security assessments and vulnerability testing.
- Access controls and authentication mechanisms.
- Employee training on data privacy and security practices.
While we strive to protect your personal information, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Services. We may also retain and use your information as necessary to comply with legal obligations, resolve disputes, enforce our agreements, and for legitimate business purposes. When your data is no longer needed, we will securely delete or anonymize it.
8. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at privacy@certihomes.com.
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right to Access: Request a copy of the personal information we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete personal information.
- Right to Deletion: Request deletion of your personal information, subject to certain legal exceptions.
- Right to Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
- Right to Opt-Out: Opt out of the sale or sharing of your personal information, targeted advertising, or profiling.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
State-Specific Rights
If you are a resident of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or other states with comprehensive privacy laws, you may have additional rights. Please contact us to exercise your rights.
10. Exercising Your Rights
To exercise any of your privacy rights, you may:
- Email us at privacy@certihomes.com
- Use the privacy settings available in your account
- Write to us at the address listed in the Contact section below
We will verify your identity before fulfilling any request. We will respond to valid requests within the timeframe required by applicable law (typically 30-45 days). If we deny your request, you may appeal the decision by contacting us.
11. International Data Transfers
Your personal information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from your country. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you through the Services, via email, or by other appropriate means. Your continued use of the Services after any changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: