1. Scope and roles
This Privacy Policy applies to classonebroker.com, app.classonebroker.com, broker workspaces, authorized transaction portals, communications, and support (the “Service”). “Customer” means the brokerage or advisory organization that subscribes to or controls a workspace.
Class One acts as a controller for public-website visitors, contact and sales inquiries, Customer account administrators, security records, and our own billing and service operations. For seller, buyer, referral, advisor, employee, and transaction data submitted by a Customer, the Customer is generally the controller/business and Class One is its processor/service provider. Questions about a specific transaction should first go to the brokerage or advisor managing it.
2. Information we collect
- Account and organization information: name, business email, phone, title, firm, profile, plan, role, permissions, Google basic profile when selected, and authentication or MFA events.
- Contact and inquiry information: information submitted through our contact form, demo requests, support, or other business communications, including optional mobile number and SMS consent.
- Transaction information: contacts, relationships, seller and buyer details, deal notes, messages, tasks, financial records, documents, NDAs, offers, diligence, approvals, and activity.
- Connected-service information: data authorized from Google or another service, such as profile, email, message, calendar, event, attendee, and meeting-link data within the scopes selected.
- AI interaction information: authorized requests, permitted source material, tool actions, outputs, citations, reviews, and model or policy metadata.
- Voice and meeting information: broker command audio and, only where enabled after the required participant disclosure and consent, recordings, transcripts, summaries, and consent evidence.
- Usage and security information: IP address, device and browser data, request identifiers, sign-in/session events, feature activity, audit events, diagnostics, and abuse or incident signals.
3. How we use information
- Provide, personalize, maintain, and support the Service.
- Authenticate users; enforce tenant, deal, role, purpose, consent, and document-access boundaries; and prevent abuse or unauthorized access.
- Process broker-authorized transaction workflows, communications, meetings, documents, financial analysis preparation, and AI requests.
- Respond to business inquiries, provide requested demonstrations, and communicate about a Customer relationship.
- Monitor performance, troubleshoot, audit sensitive actions, improve user-facing features, and satisfy legal obligations.
We do not sell personal information. We do not share Customer Data with other Customers. We do not use confidential transaction data for advertising or to train generalized third-party foundation models.
4. Google user data and Limited Use
If a user chooses Google Sign-In, Class One uses basic profile data such as name, email address, account identifier, and profile image to create, authenticate, and secure the user's Class One account. Google Sign-In is separate from any optional Gmail, Calendar, Drive, or other Workspace authorization.
If a user separately connects Google Workspace features, Class One accesses only the minimum scopes shown in the Google consent flow. Data may include authorized messages and metadata, calendar events, attendees, availability, files selected for a deal, and meeting links. We use it only for prominent user-facing features the user requests, such as attaching authorized messages to a deal, preparing a draft, syncing a meeting, creating an event, or retrieving a selected file.
Class One Broker's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, used to determine creditworthiness, or used to develop, improve, or train generalized or non-personalized AI or machine-learning models.
We transfer Google user data only to service providers needed to deliver the requested user-facing feature, for security, or where required by law, subject to appropriate restrictions. Human access is prohibited except with the user's specific permission for support, where necessary for security or abuse investigation, where required by law, or for appropriately aggregated internal operations. Users may disconnect Google through Class One settings or their Google Account permissions. We delete stored OAuth tokens after disconnection; transaction records already created under Customer control follow the Customer's retention settings and legal obligations.
5. AI processing
AI features receive only the deal-scoped information and tools authorized for the user's request. Source classification, tenant/deal boundaries, and approvals continue to apply. Providers process inputs to generate the requested output under service terms and data-use restrictions. We retain model, policy, citation, review, and audit metadata needed to operate and secure the feature. Google Workspace API data is never used to train generalized or non-personalized AI/ML models.
6. Mobile information, SMS, and OTP privacy
Users may separately opt into Class One Broker Account Security Messages for one-time passcodes, account-security events, and service-related verification. Consent is specific, optional, and recorded with the disclosed text and timestamp. Message frequency varies, generally one message per user request. Standard message and data rates may apply. Reply STOP to opt out or HELP for help.
Mobile numbers and text messaging originator opt-in data and consent will not be sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes.
We may disclose mobile information to communications carriers and service providers such as Twilio only to transmit, secure, troubleshoot, and document the requested program. We do not use OTP consent as consent for marketing, and a Customer may not repurpose it for another messaging campaign.
7. How information is disclosed
We disclose information only as reasonably needed to:
- provide hosting, authentication, storage, security, communications, document, support, and approved AI or integration services through contractually restricted providers;
- follow Customer-authorized deal access and communication instructions;
- protect the Service, users, or another person; investigate abuse; or respond to valid legal process; and
- complete a financing, merger, acquisition, or asset transfer subject to confidentiality, notice, consent where required, and continued policy protection.
8. Security
We use administrative, technical, and organizational controls designed for confidential transaction data, including encrypted transport, private storage, tenant and deal authorization, short-lived access, multi-factor authentication options, session revocation, malware scanning, logging, audit history, least privilege, and protected secrets. No security program can eliminate all risk. Customers must configure roles, permissions, access grants, and connected services appropriately.
9. Retention and deletion
We retain information for the period needed to provide the Service, follow Customer instructions, maintain security and audit history, satisfy the applicable order form, and meet legal obligations. Customers can export or delete records subject to permissions, retention, legal hold, and immutable-audit requirements. After account termination, data is deleted or anonymized on the schedule in the applicable agreement; backups expire in the ordinary cycle. Contact inquiries are retained only as long as needed for the relationship or legal recordkeeping.
10. Privacy rights
Depending on location, a person may have rights to access, correct, delete, receive, restrict, object to, or withdraw consent for personal information. For information tied to a transaction, contact the brokerage or advisor controlling that workspace. For Class One account, website, or contact information, email privacy@classonebroker.com. We verify requests and may preserve data that law, security, legal hold, or immutable audit obligations require.
11. Cookies and analytics
Class One uses strictly necessary cookies or similar storage to maintain sign-in, security, preferences, load balancing, and session integrity. Optional analytics will be described and, where required, activated only after consent. We do not use the Service for third-party behavioral advertising. See the Cookie Notice.
12. International processing
Class One and its providers may process information in countries other than the user's. Regional hosting and transfer safeguards are selected by contract and law. A Customer must not use the Service for information whose transfer is prohibited by applicable law or its own commitments.
13. Children
The Service is a professional business tool, is not directed to children, and may not be used by anyone under 18. We do not knowingly collect personal information from children.
14. Changes and contact
We may update this policy as the Service, providers, and legal requirements change. Material changes will be posted with a new effective date and communicated where required. Contactprivacy@classonebroker.comor use our contact page.