NEWMARKET EDGE

Privacy Policy

Last updated: July 2026 · Effective: July 2026

Who we are

Newmarket Edge, Inc. ("Newmarket Edge", "we", "us", or "our") operates the Newmarket Edge agent platform at app.newmarketedge.com, our marketing site at newmarketedge.com, our consumer tools at newmarkethq.com, and the Newmarket Edge mobile apps for licensed California real estate agents and their clients (collectively, the "Services"). This policy explains what we collect, how we use and share it, how long we keep it, and the rights you have. It applies to all of the Services above.

Newmarket Edge is based in California and offers the Services to California real estate professionals and consumers. This policy is written to comply with California law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA/CPRA"), the California Online Privacy Protection Act ("CalOPPA"), the CAN-SPAM Act, and the Telephone Consumer Protection Act ("TCPA").

Notice at Collection (California)

At or before the point we collect your personal information, California law requires that we tell you the following. The full detail is in the sections that follow.

  • What we collect: identifiers (name, email, phone, DRE license number), account and profile details, client information you enter, connected-account data (Gmail/Outlook/calendar), payment status (via Stripe), device and usage data, consumer lead details, and — only if you enroll — voice samples. See "Information we collect."
  • Why: to provide, secure, and improve the Services; match consumers with agents; communicate with you; and meet legal obligations. See "How we use information."
  • Sensitive personal information: we collect limited sensitive information (account log-in credentials and, if you enroll, voice recordings). We use it only to provide the Services and for other purposes the law permits without an option to limit. See "Sensitive personal information."
  • Do we sell or "share" it? No. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months.
  • How long we keep it: for the periods described in "Data retention," and no longer than reasonably necessary for the purpose collected.

Information we collect

We collect the following categories of personal information, from the sources noted, over the preceding 12 months:

Category (CCPA/CPRA)ExamplesSource
IdentifiersName, email, phone, DRE license number, IP address, account/session IDsYou; automatically
Customer recordsContact details, brokerage, billing historyYou; Stripe
Commercial informationSubscription plan, status, transactionsYou; Stripe
Internet / device activityPages visited, features used, timestamps, browser/device infoAutomatically
Geolocation (approximate)Coarse location inferred from IP addressAutomatically
Professional informationLicense status, brokerage affiliationYou
Client information you provideYour clients' names, contact details, notes, journey stage, saved homesYou
Connected-account contentGmail/Outlook messages and calendar events you read or send through us; OAuth tokensGoogle / Microsoft, with your authorization
Consumer lead dataName, email, phone, buy/sell intent, price range, area, timelineYou (consumer)
Audio / sensitiveVoice samples for meeting attribution (only if you enroll); account log-in credentialsYou
InferencesAgent-to-consumer matches and preferences derived from the aboveDerived

Payment card numbers are collected and processed directly by Stripe; we never see or store your full card number.

Sensitive personal information

Under the CPRA, some information is treated as "sensitive." The only sensitive personal information we handle is (a) your account log-in credentials, and (b) if you choose to enroll, voice recordings used to attribute speakers in meeting transcripts.

We use sensitive personal information only to perform the Services you request, to secure your account, to prevent fraud and abuse, and for the other limited purposes permitted by California Civil Code § 1798.121 — never to infer characteristics about you and never for advertising. Because we do not use or disclose sensitive personal information beyond those permitted purposes, the CPRA "right to limit" is honored by default; you may still delete voice samples at any time in Settings → Voice.

How we use information

We use personal information for these business and commercial purposes:

  • Provide and operate the Services — authenticate you, sync your data across web and mobile, and generate AI responses scoped to your account.
  • Match consumer leads with real estate agents who are licensed and in good standing with the California Department of Real Estate.
  • Communicate with you — send transactional messages (verification codes, password resets, receipts, briefing summaries) and, where you have opted in, product news.
  • Secure the Services — detect, investigate, and prevent fraud, abuse, and security incidents, and debug and repair errors.
  • Improve the Services using aggregated or de-identified usage data.
  • Comply with law and enforce our Terms — tax, real estate licensing, anti-fraud, legal process, and dispute resolution.

We will not use personal information for a materially different, unrelated, or incompatible purpose without providing you notice.

How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only in these ways:

  • Service providers / processors who work on our behalf under contract and may use the data only to provide services to us: Supabase (database + hosting, United States), Stripe (payments), Anthropic (AI processing to generate summaries and reply drafts), and our transactional email and SMS delivery providers.
  • Agent matching — when a consumer uses a gated tool or asks to be matched, we share that consumer's lead details only with the licensed California agent they are matched to or have signed up to work with. We do not distribute lead information more broadly.
  • Legal and safety — to comply with law, legal process, or enforceable governmental requests, or to protect the rights, property, or safety of Newmarket Edge, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, with notice to you and subject to this policy.
  • With your direction or consent — for example, when you connect Gmail or Outlook, or otherwise ask us to share.

Categories of personal information disclosed to service providers in the past 12 months include identifiers, customer records, commercial information, device activity, and (for connected accounts) message and calendar content.

Google user data — Limited Use disclosure

When you connect Gmail to Newmarket Edge, we request the following Google API scopes:

  • gmail.readonly — to read messages in your inbox so we can surface them in your Email Intelligence triage view, classify urgency, and identify which clients need a reply.
  • gmail.send — to send replies you author or approve from within Newmarket Edge, on your behalf, from your own email address.
  • userinfo.email — to associate the connected account with your Newmarket Edge agent record.
  • calendar — to read your events (so we don't double-book) and add showings + meetings you schedule from inside Newmarket Edge.

Newmarket Edge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We use Gmail data only to provide and improve the user-facing features of the Email Intelligence module (triage, summarization, reply drafting).
  • We do not transfer Gmail data to third parties except as necessary to provide the service (e.g. our LLM provider, Anthropic, to generate summaries and reply drafts on your behalf), to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  • We do not use Gmail data for advertising. We do not display ads in Newmarket Edge.
  • We do not use Gmail data to train generalized or non-personalized AI/ML models.
  • We do not allow humans to read your Gmail data except: (a) with your explicit consent for a specific message; (b) when necessary for security purposes such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized for our internal operations.
  • You can disconnect Gmail at any time at app.newmarketedge.com → Intelligence → Email, which revokes our access and deletes the stored tokens.

The same posture applies to Microsoft Outlook / Microsoft Graph data when you connect an Outlook account, consistent with Microsoft's API terms.

Text messages and calls (SMS / TCPA)

  • We (or a founder or agent on our behalf) may call or text the phone number you provide only to follow up on a request you made — for example, to talk about joining the waitlist or to connect you with an agent.
  • We obtain your prior express consent before sending any autodialed or marketing text messages, and consent is not a condition of purchasing anything.
  • Message and data rates may apply. Message frequency varies. Reply STOP to opt out of texts at any time, or HELP for help. Opting out of texts does not opt you out of essential transactional email.
  • We do not share phone numbers or SMS opt-in consent with third parties for their own marketing.

Marketing email (CAN-SPAM)

We send marketing email only where permitted. Every marketing email includes a working unsubscribe link and our physical mailing address. You can also opt out by emailing unsubscribe@newmarketedge.com. We honor opt-outs promptly. Transactional messages necessary to operate your account (e.g. verification, receipts) are not marketing.

Storage, encryption, and data retention

  • Account and client data is stored in Supabase (Postgres) within the United States.
  • OAuth tokens for Gmail / Outlook are encrypted with AES-256-GCM before being written to the database. Decryption happens only at request time on our backend.
  • Data in transit is protected with TLS; access to production systems is restricted and logged.

We keep each category of personal information only as long as needed for the purpose it was collected:

  • Account & profile data — for the life of your account, then erased within 30 days of account deletion (except records we must keep by law).
  • Cached email bodies (triage view) — up to 30 days, then purged. Message headers (sender, subject, received time) are kept for the inbox-state timeline.
  • OAuth tokens — until you disconnect the account, then deleted.
  • Voice samples — until you delete them in Settings → Voice.
  • Consumer lead data — for as long as needed to match you with an agent and for a reasonable period thereafter, or until you request deletion.
  • Usage / device logs — typically up to 24 months, then deleted or de-identified.
  • Billing & tax records — retained as required by tax and financial law (generally up to 7 years), primarily via Stripe.

Data security and breach notification

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption at rest and in transit, access controls, and monitoring. No system is perfectly secure, and we cannot guarantee absolute security. If we experience a breach of personal information affecting California residents, we will notify affected users and any regulators as required by California Civil Code § 1798.82 without unreasonable delay.

Your California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know / access — the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it.
  • Delete — the personal information we have collected from you, subject to legal exceptions.
  • Correct — inaccurate personal information we maintain about you.
  • Opt out of sale / sharing — we do not sell or share personal information, so there is nothing to opt out of; we honor opt-out signals regardless (see "Do Not Track / Global Privacy Control").
  • Limit use of sensitive personal information — we already limit our use to permitted purposes only.
  • Non-discrimination — we will not deny you services, charge a different price, or provide a different quality of service because you exercised any of these rights.

How to submit a request. Email privacy@newmarketedge.com, or use in-app account deletion. To protect you, we will verify your request by confirming control of the email or account associated with the information; we may ask for additional information to verify identity for access or deletion requests. You may use an authorized agent to submit a request on your behalf by providing the agent written, signed permission; we may still verify your identity directly.

Our response. We confirm receipt within 10 business days and respond within 45 days, extendable by another 45 days with notice. There is no charge for a verifiable request unless it is excessive or repetitive.

California's "Shine the Light" law (Civil Code § 1798.83): we do not disclose personal information to third parties for their own direct marketing.

Do Not Track / Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) setting and a Global Privacy Control (GPC) signal. Because there is no common industry standard for DNT, our sites do not respond to DNT signals; instead we simply do not track you across third-party websites or serve behavioral ads, and we use no Google Analytics, Facebook Pixel, or third-party trackers. We treat a GPC signal as a valid request to opt out of the sale or sharing of personal information — and since we do not sell or share, no data is affected, but we honor the signal.

Cookies and tracking

We use one HttpOnly session cookie (nme_lead_session) on the marketing site to remember signed-in tool users for 30 days. The agent dashboard uses a JWT in localStorage for the session. We use our own in-house, first-party event tracking to understand feature usage. We do not use third-party advertising cookies or cross-site trackers on newmarketedge.com or newmarkethq.com.

Children

The Services are intended for real estate professionals and adult consumers and are not directed to children under 13. We do not knowingly collect personal information from children under 13, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided us information, contact privacy@newmarketedge.com and we will delete it.

Changes to this policy

We'll post material changes here and update the "Last updated" date above. If a change affects how we handle Gmail / Outlook data, we'll notify connected agents by email at least 30 days before it takes effect.

Contact us

Newmarket Edge · Founded May 2026 · California