WholesaleOS logoWholesaleOS

Privacy Policy

APAI LLC · Effective October 1, 2026 · What we collect, why, how long we keep it, and what you can ask us to do.

The short version

We collect what we need to run a paid software service and keep it secure. We use it to provide the service, bill you, protect your account, and meet our legal obligations.

WE DO NOT SELL YOUR PERSONAL INFORMATION. We do not rent it, and we do not share it for cross-context behavioral advertising or targeted advertising. We do not run third-party advertising or analytics trackers, and we do not use advertising pixels or heat-mapping tools.

We do use a small number of processors to operate the service — payment processing, hosting, data providers, and IP geolocation. They are listed on our Sub-processors page and are bound to use your information only to provide their service to us.

Because we do not sell or share personal information as those terms are defined by US state privacy laws, we do not post a "Do Not Sell or Share My Personal Information" link. Posting one would state something untrue about our practices. If that ever changes, this policy and the site will change with it.

1. Who we are

APAI LLC, 1942 W Gray St, Houston, TX 77019, is the business responsible for the personal information described in this policy. Contact us about privacy at support@wholesaleos.shop.

This policy covers wholesaleos.shop and the WholesaleOS application. It does not cover third-party sites we link to.

2. Information we collect

2.1 Information you give us

  • Account: your email address, a password (stored only as a salted hash — we never store your password itself), your name or business name if you provide it, and your plan.
  • Billing: handled by Stripe. We receive a customer identifier, your billing name, address, email, the last four digits and brand of the card, and whether a payment succeeded. We never receive or store your full card number or CVC.
  • Content you create: property lists, notes, documents, uploaded files, and websites you build.
  • Support: the contents of messages you send us.

2.2 Information collected automatically

  • IP address, and the IP address of the connection we see after our proxy (we record both so we can detect spoofed headers).
  • Approximate location derived from your IP address (city/region/country and, where the provider returns it, an approximate latitude and longitude). This is NOT precise GPS location.
  • Device and browser information collected at sign-in and at checkout: browser, operating system, device type, screen size, timezone, language, CPU core count, and a device fingerprint — a hash derived from those properties that lets us recognize the same device again. It does not read files, contacts, or anything outside the browser.
  • Activity: pages viewed, features used, skip traces performed, sign-in times, and security events. This is kept in an audit log.
  • Cookies: one session cookie. See our Cookie Notice.

2.3 Information about other people (skip-trace data)

The service lets you look up property owners' names, mailing addresses, phone numbers, and email addresses, supplied by licensed data providers. That information is about third parties, not about our customers.

We hold it in your account to provide the service to you. We do not sell it, and we do not use it for our own marketing. You are responsible for using it lawfully — see our Acceptable Use Policy.

2.4 Sensitive personal information

Some privacy laws treat precise geolocation, government identifiers, and certain other categories as "sensitive". The only category we handle is approximate geolocation derived from your IP address, as described above.

We use it to secure your session (an account is locked to the IP it signed in from), to detect fraud, and to display the app in your region. We do not use it to infer characteristics about you, and we do not sell it. We do not knowingly collect government identifiers, biometric data, health data, or information about children.

3. Why we use it and what our legal basis is

  • To provide the service — create your account, deliver the features you asked for, keep your data available. (Performance of our contract with you.)
  • To bill you and manage subscriptions, renewals, refunds, and chargebacks. (Contract, and our legitimate interest in being paid.)
  • To secure the service — detect credential sharing, fraud, and unauthorized access; lock a session to its IP; investigate incidents. (Legitimate interest, and our legal obligations.)
  • To meet legal obligations — tax and accounting records, responding to valid legal process, and handling disputes. (Legal obligation.)
  • To improve the service — aggregate, de-identified statistics about how features are used. (Legitimate interest.)
  • To contact you — service messages, security alerts, and renewal reminders. These are part of the service. We do not send marketing email to people who have not asked for it, and every marketing message has a working unsubscribe link. (Contract, or consent where required.)

4. How long we keep it

We keep information only as long as we need it for the purpose we collected it, and then delete or de-identify it. Concretely:

  • Account and content — while your account is open, then deleted within 90 days of closure, except as noted below.
  • Billing and transaction records — 7 years after the transaction, because tax and accounting law requires it.
  • Security and audit logs, and device fingerprints — 24 months, so that we can investigate an incident or defend a legal claim that arises later.
  • Skip-trace lookups and the contact data they returned — while your account is open, then deleted with the account. Cached public property records are retained separately from personal contact data.
  • Sales records visible to our sales team (account UID, plan, amount, region) — for as long as we need them to calculate and evidence commission payments, and for 7 years where they form part of our financial records.
  • Privacy rights requests — records of requests and our responses for 24 months, as the regulations require.
  • Chargeback and dispute files — for as long as the dispute and any related legal claim can be brought, plus the accounting retention period.
  • Backups — deleted data may persist in encrypted backups for up to 35 days before being overwritten.

5. Who we share it with

We share personal information only with the processors that run the service, and only as needed. They are listed, with what each one does, on our Sub-processors page. In outline:

  • Stripe — payment processing and subscription billing.
  • Our hosting provider — the servers the application and database run on.
  • Skip-trace and property-data providers — we send them the property or address you ask us to trace, and they return contact information. We do not send them your customers' data.
  • IP geolocation providers — we send the IP address we are looking up; they return an approximate location.
  • CARTO — serves the map images on our map and lead pages. It receives the IP address and browser details of anyone viewing a page with a map, in order to return the image, and nothing else about the account or the data being viewed.

6. When else we may disclose information

  • To comply with law, a valid subpoena, court order, or a lawful request from a regulator or law-enforcement agency.
  • To enforce our Terms or Acceptable Use Policy, or to investigate suspected unlawful use of the service.
  • To protect the rights, property, or safety of us, our customers, or the public.
  • In connection with a merger, acquisition, financing, or sale of assets, in which case the recipient is bound by this policy until it is updated, and we will tell you if the terms change.
  • With your direction or consent.
We do not sell personal information, and we do not disclose it to advertising networks, data brokers, or list vendors.

7. Your privacy rights

Depending on where you live, you may have some or all of the rights below. We extend the same core rights to everyone who asks, wherever you live, because it is simpler and fairer. To exercise any of them, use the contact details in section 8.

  • Know and access — confirm whether we process your personal information and get a copy of it.
  • Correct — fix information that is inaccurate.
  • Delete — delete personal information we collected from you, subject to legal retention obligations.
  • Portability — receive a copy in a portable, readily usable format.
  • Opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of. We state that here because the law asks us to tell you.
  • Limit the use of sensitive personal information — we use the one sensitive category (approximate IP geolocation) only to secure and operate your account, which is a purpose for which no limitation right applies. We do not use it for anything else.
  • Non-discrimination — we will not deny you service, charge you more, or give you a worse experience because you exercised a privacy right.
  • Appeal — if we refuse a request, you may appeal by replying to our decision. We will respond to an appeal within 45 days, and if we uphold the refusal we will tell you how to contact your state Attorney General.
We do not use automated decision-making that produces legal or similarly significant effects about you. Our deal-analysis scores are calculations you run on property data for your own business — they are not decisions we make about you as a consumer. If that ever changes, we will disclose it here before the change takes effect.

8. How to make a request

Use any of these methods — you do not need an account to ask:

  • Email support@wholesaleos.shop with the subject line "Privacy Request". This is the fastest route and our preferred one.
  • Write to APAI LLC, Attn: Privacy, 1942 W Gray St, Houston, TX 77019.
  • From inside the app: Settings → Privacy, which uses the same request process.

What happens next

  • We acknowledge your request within 10 business days.
  • We substantively respond within 45 calendar days. If we need longer we will tell you why, and we may take up to 90 additional days.
  • We may ask for information to verify your identity — we will ask for the minimum needed and we will not use it for anything else.
  • An authorized agent may submit a request on your behalf with written permission.

9. Cookies and tracking

We set one cookie of our own — the session cookie that keeps you signed in. Loading our pricing page also causes Stripe to set two of its own cookies on our domain (__stripe_mid and __stripe_sid), which it uses for fraud prevention when a payment is started. Maps load images from CARTO's tile service, which receives your IP address to return the image.

We do not use advertising cookies, analytics cookies, heat-mapping or session-recording tools, or third-party tracking pixels, and we do not track you across other websites or build advertising profiles. Full detail, including cookie names and lifetimes, is in our Cookie Notice.

10. Security

We protect your information with measures that include: passwords stored as salted hashes; encrypted session tokens; sessions bound to the IP address they were created from, with automatic holds on unexpected location changes; encryption of stored data-encryption keys and secrets; access restricted to a single administrator account with key-based server access; full-disk and database backups kept off the application host; an audit log of security-relevant events; and dependency and platform patching.

No system is perfectly secure. If we become aware of a breach that affects your personal information, we will notify you and the relevant authorities as required by applicable law.

You can help: use a unique password, do not share your login, and tell us straight away if you suspect your account has been accessed.

11. Children

The service is for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.

12. Where your information is processed

We are based in the United States and process information there. Our processors may process it in the United States and, for some services such as payment processing, in other countries. Where personal information protected by the GDPR or UK GDPR is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

13. Do Not Track and Global Privacy Control

We do not track visitors across third-party websites, and we do not engage in the sale or sharing of personal information for cross-context behavioral advertising, so there is no cross-site tracking for a browser signal to switch off. If we ever introduce advertising or third-party analytics, we will honour Global Privacy Control signals as an opt-out of sale and sharing, and we will update this policy first.

14. Changes to this policy

If we change this policy we will update the effective date at the top and, for a material change, tell you by email or in the app before it takes effect.

15. Contact

APAI LLC, Attn: Privacy, 1942 W Gray St, Houston, TX 77019. Email: support@wholesaleos.shop.

APAI LLC
1942 W Gray St, Houston, TX 77019
support@wholesaleos.shop
This document is part of the agreement governing your use of WholesaleOS. See also our Terms of Service, Privacy Policy and Refund & Cancellation Policy.

Home·Pricing·All legal documents