Back to AcqFlo

Privacy Policy

Version 2026-08-25 · Effective August 25, 2026

1. Introduction

AcqFlo, operated by BrackBox Ventures LLC ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our deal pipeline management application.

2. Information We Collect

Account Information

  • Email address
  • Name (if provided)
  • Profile information from OAuth providers (Microsoft)

Deal Data

  • Property names and addresses
  • Financial information (asking prices, valuations)
  • Notes and documents you upload
  • Deal stage history and activity logs

Organization Data

  • Organization name and settings
  • Team member information
  • Role and permission assignments

Outlook Add-in Data (AcqFlo Send to Pipeline)

When you use the AcqFlo Outlook Add-in and click "Send to AcqFlo," we collect the following data from the email you are currently viewing:

  • Email subject line
  • Sender name and email address
  • Email body (HTML content)
  • File attachments (PDF, Excel, CSV, Word documents only)
  • Internet message ID (for duplicate detection)
  • Date and time the email was received

The add-in uses the ReadItem permission and only accesses the single email you explicitly choose to send. It does not scan, index, or access any other emails in your mailbox.

Custom Skills (Saved Prompts)

When you save a custom skill on the Claude Skills page, we store the prompt title, optional description, and prompt text you provide. These are scoped to your user account within your current organization and are not shared with other users.

Usage Data

  • Log data (IP address, browser type, access times)
  • Device information
  • Feature usage patterns

3. How We Use Your Information

  • To provide and maintain our service
  • To authenticate your identity
  • To enable collaboration with your team members
  • To store and organize your deal pipeline data
  • To send transactional emails (invitations, notifications)
  • To improve our service and develop new features
  • To detect and prevent fraud or abuse

4. Third-Party Services

We integrate with the following third-party services to provide our functionality:

Supabase

We use Supabase for authentication, database, and file storage services. Your data, including documents you upload, is stored securely in Supabase's infrastructure with row-level security policies.

Google Maps

We use the Google Maps API for address autocomplete, geocoding, and map display. Property addresses and coordinates are sent to Google Maps to locate and display your deals. AcqFlo does not integrate with Google Drive.

Microsoft Services

If you connect OneDrive or SharePoint, we request access to store and retrieve files you upload through AcqFlo in your Microsoft cloud storage. The AcqFlo Outlook Add-in reads email content you explicitly submit and transmits it to our servers for deal extraction.

Anthropic (Claude / AI Processing / MCP)

Anthropic processes your data in these ways depending on which features you use:

  • Document extraction: when you use AI-powered field extraction (e.g., extracting deal details from an offering memorandum), the text content of that document is sent to Anthropic's Claude API.
  • Contract extraction: when you extract terms from an LOI or PSA, the document file itself is sent to Anthropic's Claude API.
  • Email ingestion: when you send an email into AcqFlo (for example via the Outlook Add-in), the message, including the sender's name and email address, is sent to Anthropic's Claude API for deal extraction.
  • Model Context Protocol (MCP) integration: if you connect Claude (Desktop, claude.ai, or Claude Code) to AcqFlo via the MCP connector, then any deal, broker, file metadata, or other data Claude reads or modifies through MCP tool calls flows through Anthropic during that session. You authorize this on a per-user basis via OAuth and can revoke the connector at any time from your Claude client's settings. The MCP connector binds to the AcqFlo organization you have selected at approval time; switching organizations later does not move the connection.

AI features run under an API key configured by your organization (or your own personal key), so your organization controls the AI provider relationship. Anthropic's processing of this data is governed by Anthropic's commercial terms, under which API inputs are not used to train Anthropic's models.

Stripe

We use Stripe for subscription billing. Stripe receives your organization name, a billing contact email address, and invoice records. Deal data is not sent to Stripe.

Cloudflare

We use Cloudflare R2 object storage for off-site backups: encrypted database backups, plus a nightly backup copy of the deal documents you upload.

Sentry

We use Sentry for error tracking and performance monitoring. Sentry receives error reports, stack traces, and basic request metadata when errors occur. We scrub these reports of personal data (email addresses, API keys, IP addresses) before they are sent, we do not attach request bodies to error events, we do not intentionally include deal content in them, and we do not use session replay.

Vercel

We use Vercel for hosting and performance analytics. Vercel collects anonymized performance metrics (page load times, web vitals). No personal data or deal content is shared.

Upstash

We use Upstash to rate limit requests to the service. Upstash receives request identifiers, which for unauthenticated requests are IP addresses.

Government Data APIs

Geographic coordinates derived from a property's address are sent to public government APIs (Census, FEMA, EPA, BLS, USGS, etc.) to enrich deal records with demographics, flood zones, and market data. These APIs receive coordinates, not the address itself; the address is sent to Google (see Google Maps above) for geocoding and address autocomplete. No personal information is shared with these services.

OpenStreetMap (Overpass)

Property coordinates are sent to community-operated OpenStreetMap Overpass servers to count nearby self-storage facilities. These servers include a mirror operated by Kumi Systems in Austria, so coordinate queries may be processed outside the United States.

Walk Score

Walk Score is a commercial API that received property addresses to compute walkability scores. We are discontinuing this integration; historical scores may remain stored on your deals.

StorTrack

For organizations that connect their own StorTrack account, property coordinates are sent to StorTrack to retrieve self-storage market data. Nothing is sent to StorTrack unless your organization has connected its own account.

Email Delivery

We use Resend for transactional email delivery, such as team invitations and notifications. Only email addresses and notification content are shared with this provider.

5. Data Storage and Security

Your data is stored in secure cloud infrastructure with encryption at rest and in transit. We implement industry-standard security measures including:

  • SSL/TLS encryption for all data transmission
  • Row-level security policies in our database
  • Secure authentication via OAuth 2.0
  • Regular security audits and updates

To report a security vulnerability, see our Security & Vulnerability Disclosure page or fetch /.well-known/security.txt.

6. Data Sharing

We do not sell your personal information. We may share your data only in these circumstances:

  • With team members in your organization (based on permissions)
  • With service providers who assist in operating our service
  • When required by law or to protect our rights
  • In connection with a merger, acquisition, or sale of assets

7. Your Rights

Depending on your location, you may have the following rights:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data
  • Withdraw consent for optional processing
  • Disconnect third-party integrations

To exercise these rights, email privacy@acqflo.com. We respond within 45 days and will tell you if we need a further 45 days. We will not deny you service, charge you a different price, or give you a lesser experience for making a request.

How this works in practice: deletion of an account and its associated personal data is performed by our team on request; there is no self-service account-deletion control today. When we delete your account, we remove your personal data from our live systems, and copies persist in encrypted backups for a bounded period before those backups age out. You can export your organization's deal pipeline yourself at any time as a CSV or PDF from the deal export page; other data requests are handled through the contact email above.

Residents of US states with comprehensive privacy laws (including California, Colorado, Connecticut, Texas, Utah, and Virginia) have these rights by statute, along with the right to appeal if we refuse a request. To appeal, reply to our decision and we will answer within 60 days; if we deny the appeal you may complain to your state attorney general.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act and the Texas Data Privacy and Security Act. We have not done so in the preceding twelve months. We do not use advertising trackers, and we do not use or disclose sensitive personal information beyond what is necessary to provide the Service.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide services. When we delete your account at your request, we delete your personal data within 30 days, except where retention is required by law.

Some data follows its own retention schedule: a deal you delete stays recoverable for 30 days and is then permanently purged along with its files; operational logs are pruned on a schedule; and backups are retained for a bounded period, after which deleted data ages out of them as well.

9. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies.

10. Children's Privacy

AcqFlo is not intended for use by children under 13. We do not knowingly collect personal information from children under 13.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at: privacy@acqflo.com