1. Introduction
AptAlert NYC ("we," "us," or "our"), operated by SA Consulting AEP LLC, provides an apartment listing alert service for Manhattan, Brooklyn, Queens, and the Bronx. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services at aptalertnyc.com (the "Service"). This policy is designed to comply with applicable U.S. privacy laws including the California Consumer Privacy Act (CCPA) and the CAN-SPAM Act.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name and email address when you create an account, or profile data from Google sign-in. Passwords are handled by Firebase Authentication.
- Search Preferences: Boroughs, neighborhoods, price ranges, bedroom counts, transit preferences, and other apartment search criteria you configure.
- Payment Information: Billing details processed securely by Stripe. We do not store credit card numbers on our servers.
- Communication Data: Telegram chat ID (for Telegram alerts) and email address (for email alerts). We do not currently offer SMS alerts.
- Optional Discovery Summary: If you choose to share a brief summary of the apartment-alert problem you were trying to solve, we store it with your account to improve our service information. Please do not submit a full chat or personal details. We cannot read your ChatGPT conversation or question from a referral link.
- Support Communications: Any messages you send to us via email.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, alert history, and interaction timestamps. With analytics consent, we also store a sanitized referral source and landing page path with your account to measure signup and payment sources.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Analytics Data: We use Google Analytics 4 (measurement ID G-WNBG8MVSHD) to collect anonymized usage data including page views, session duration, and feature interactions. Google may set cookies such as
_ga, _gid, and _gat. - Cookies and Similar Technologies: We use cookies for authentication, preferences, and analytics. See our Cookie Policy for details.
- Log Data: IP address, access times, and referring URLs.
- Referral Program Data: A random public referral code, the relationship between the referring and referred accounts, claim and reward status, relevant Stripe invoice/payment/balance identifiers, and dates needed to operate and audit the program. For the 24-hour abuse check, the request IP is stored only as a keyed cryptographic hash, not as plaintext in referral records.
- One-Time Offer Data: If you accept optional cookies and trigger an exit offer, we record an opaque browser token, when the offer opportunity occurred and expires, and whether it led to checkout or a subscription. A random 10% of eligible visitors see the regular price so we can compare paid conversion and revenue; the other 90% may see the offer. If you are signed in, we link the assignment to your account when shown; otherwise we link it if you begin checkout. To limit automated repeat offers, we use a keyed hash of the request IP for a daily abuse ceiling; the offer record does not store the raw IP address. Your browsing action is used to decide when this promotion is considered.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To send apartment alerts matching your search criteria via email or Telegram
- To understand which service questions led visitors here, when they voluntarily submit an answer
- To process payments and manage subscriptions
- To communicate with you about your account, updates, and support requests
- To detect, prevent, and address fraud, abuse, or technical issues
- To attribute member referrals, determine credit eligibility, apply or reverse invoice credits, enforce program limits, and provide referral history to the participating accounts
- To show and enforce a one-time promotional price, prevent repeated claims, and compare checkout and paid revenue between eligible offer and regular-price visitors
- To analyze usage patterns and improve user experience
- To comply with legal obligations
4. Information Sharing and Disclosure
We do not sell your personal information. We may share information with:
- Service Providers: Stripe (payments), Brevo and SendGrid (email delivery), Telegram Bot API (Telegram alerts), Firebase/Google Cloud (hosting and authentication), Upstash Redis (search result caching), and Google Analytics (usage analytics). Each provider processes data solely for the purpose of providing their respective service.
- Legal Requirements: When required by law, subpoena, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
- With Your Consent: When you explicitly authorize sharing.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Alert history is retained for 90 days. Listing data is cached for 7 days. When you delete your account, we delete operational personal data within 30 days. We may retain limited payment, referral, fraud-prevention, and legal records where required, and a one-way email hash solely to preserve a marketing opt-out. The opt-out record is not used to contact you. One-time offer records are scheduled for deletion after 90 days; keyed-IP abuse counters are scheduled for deletion after two days. Firestore may take up to an additional day to remove records after those deadlines. The account marker is kept while the account exists and removed by the account-deletion process.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including encryption in transit (TLS/SSL), encrypted data storage, secure authentication via Firebase Auth, and PCI-compliant payment processing through Stripe. However, no method of transmission or storage is 100% secure.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal information
- Object to or restrict processing of your data
- Data portability (receive your data in a structured format)
- Withdraw consent at any time
- Opt out of marketing communications
To exercise these rights, contact us at sa.consultingaepllc@gmail.com.
8. California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purpose, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
- Right to Opt Out of Sale: We do not sell personal information. If this changes, we will provide a "Do Not Sell My Personal Information" link.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise these rights, email us at sa.consultingaepllc@gmail.com with the subject line "CCPA Request." We will verify your identity and respond within 45 days.
9. CAN-SPAM Compliance
We comply with the CAN-SPAM Act for all commercial email communications:
- All emails clearly identify AptAlert NYC as the sender.
- All emails include a valid physical mailing address or registered agent address.
- All marketing emails include a clear unsubscribe mechanism.
- Unsubscribe requests are honored within 10 business days.
- We do not use deceptive subject lines or false header information.
- Transactional emails (alerts matching your search criteria) may be sent without an unsubscribe option, as they are essential to the Service you requested.
You can manage your email preferences from your account settings or by clicking "Unsubscribe" in any marketing email.
10. Alert Channels
Apartment-match alerts are currently available by email or Telegram, according to the channels you configure in your account. We do not currently offer SMS alerts.
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
12. Third-Party Links
The Service may contain links to third-party websites (e.g., Craigslist, StreetEasy, LeaseBreak listings). We are not responsible for the privacy practices of these sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.
14. Contact Us
If you have questions about this Privacy Policy, contact us at: