Privacy Policy
1. Who we are
smartimoti ("we", "us") operates the property search and marketing platform at smartimoti.com. This policy explains what personal data we process, why, and what rights you have. For any privacy question or request, contact hello@smartimoti.com.
2. Data we collect
- Account data — username, email address, password (stored as a salted hash), optional company name and logo.
- Billing data — credit balance, purchase and usage history. Card payments are handled entirely by Stripe; we never see or store full card numbers.
- Connected platform credentials — when you link a Facebook, Google, YouTube or TikTok account, we store the access and refresh tokens those platforms issue, the account or channel name, and its identifier. We never see your passwords for those platforms.
- Content you upload — photos, videos and ad text you add to campaigns, and images you submit to image search.
- Alert settings — saved search criteria and the email address or Telegram chat ID you choose for notifications.
- Usage data — search queries, feature usage and technical logs (IP address, browser type) needed to run and secure the Service.
3. How we use your data
- To provide the Service: search, alerts, analytics, campaign drafting and publishing.
- To publish content to third-party platforms — only when you explicitly trigger or schedule publishing, and only to the accounts you connected.
- To process payments and maintain your credit balance.
- To send service messages (alerts you configured, billing confirmations, important account notices). We do not sell your data and we do not send third-party marketing.
- To protect the Service against abuse and fraud.
4. AI processing
Some features send data to AI providers to generate output: ad text and translations (campaign and listing details), image search (the image you upload), summaries and market insights (listing data). These requests are processed by our AI providers (Google Cloud Vertex AI and OpenAI) under their respective data-processing terms and are not used by us to train models.
5. Third-party processors
- Stripe — payment processing.
- Google Cloud / OpenAI — AI features.
- Meta, Google, YouTube, TikTok — when you connect accounts and publish content. Each platform processes that data under its own privacy policy.
- Hosting and email providers — to run the Service and deliver notifications.
6. Connected accounts and revoking access
Stored platform tokens are used solely to perform the actions you request (publishing posts, reading basic account info, campaign statistics). Clicking Disconnect in the app deletes the stored tokens immediately. You can also revoke our access from the platform's own security settings (e.g. Google Account permissions, TikTok app authorisations), which invalidates the tokens on their side.
7. Retention
- Account data is kept while your account exists and deleted or anonymised after account deletion, except records we must keep for accounting and legal compliance.
- Connected-platform tokens are deleted on disconnect or account deletion.
- Uploaded campaign media is deleted when you delete the campaign or your account.
8. Your rights (GDPR)
If you are in the EU/EEA you have the right to access, correct, export, restrict or delete your personal data, and to object to processing based on legitimate interest. Write to hello@smartimoti.com and we will respond within 30 days. You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP).
9. Security
Passwords are hashed, platform tokens are stored server-side only and never exposed to the browser, access to production systems is restricted, and payments are delegated to Stripe. No system is perfectly secure — if a breach affecting your data occurs, we will notify you as required by law.
10. Cookies and local storage
We ask for your consent before setting anything beyond what's strictly necessary, via the cookie banner shown on your first visit. You can change your choice at any time using the "Cookie settings" link in the footer (or the floating button in the app).
- Necessary (always on, no consent required) —
mdg_auth_token, which keeps you signed in, andcookie_consent, which remembers your cookie choice for one year. Neither is used for tracking or advertising. - Analytics (optional, off by default) — not currently used. If we add analytics in the future, the corresponding script will only load after you accept this category.
- Marketing (optional, off by default) — not currently used. If we add ad-measurement/marketing tools in the future, they will only load after you accept this category.
We also keep a record of each consent decision (timestamp, categories chosen, policy version, and a truncated IP address with the last octet removed) to demonstrate compliance as required by GDPR Article 7(1). This record is kept for as long as the corresponding cookie choice is active.
Separately, the app also uses browser local storage (not cookies) to hold your session token and interface preferences (language, saved filters). Like the necessary cookies above, this is strictly necessary for the Service to function and doesn't require consent — it isn't used for advertising or cross-site tracking, and nothing in local storage is sent to third parties.
11. Changes
We may update this policy as the Service evolves. Material changes will be announced in the app or by email, with the "last updated" date above revised.