Privacy and data access
Your data stays your business.
Last updated August 21, 2026
GlidePath CRM provides private real estate CRM workspaces. We do not sell broker lead data, use it for our own prospecting, or use advertising trackers. This policy explains what data the service handles and why.
Information GlidePath CRM handles
GlidePath CRM handles information you provide when you create an account, configure a workspace, import leads, submit the Contact form, or use CRM features. This may include:
- Account and contact information such as your name, email address, business name, authentication records, support topic, and message.
- Workspace branding, settings, custom fields, team invitations, and assigned permissions.
- Lead and contact information, including names, contact details, property information, notes, tags, reminders, communication history, and status.
- Service records needed for security, troubleshooting, abuse prevention, and feature operation.
How information is used
Information is used to authenticate users, provide requested CRM functions, preserve workspace settings, support imports and exports, enable authorized collaboration, prevent misuse, troubleshoot problems, and protect the service.
GlidePath CRM administrators do not use broker leads for prospecting. GlidePath CRM does not sell broker lead data or share it with data brokers.
Workspace isolation and access
Each broker workspace is isolated from other broker workspaces through database authorization controls. Team members receive only the permissions assigned to their verified account.
Supabase project administrators retain technical operational access to the database. Administrative access is limited to people who operate, secure, troubleshoot, and support GlidePath CRM, and is used only when needed to provide or protect the service.
Connected services and providers
GlidePath CRM relies on service providers to operate the product, including Cloudflare for site delivery, Supabase for authentication and database services, Google Workspace to deliver Contact form messages to support, and Esri plus Photon with OpenStreetMap data to return address suggestions when a user types in the address field. Those providers process information as needed to provide their infrastructure services and requested features.
Optional connected services are activated by the user:
- Gmail access is requested directly from each broker with the minimum compose permission used by GlidePath CRM. Drafts are reviewed before sending and messages are sent individually, not by BCC.
- When AI drafting is enabled, the authorized lead context needed for a draft is sent through a server-side OpenAI integration with response storage disabled.
- Local companion features may connect to software on the user's own device when explicitly configured.
Retention and account deletion
Workspace data is retained while an account is active so GlidePath CRM can provide the CRM. When a GlidePath CRM account is deleted, its leads, settings, custom fields, invitations, memberships, and service rate-limit records are deleted with the account.
Backup copies held by infrastructure providers may remain temporarily until their normal backup-retention periods expire.
Security
GlidePath CRM uses authentication, database authorization policies, secure transport, restrictive browser security headers, and purpose-limited administrative access to protect information. No system is completely secure, and users are responsible for protecting their account credentials and devices.
Your choices
You may export workspace data through GlidePath CRM, update account and workspace information, disconnect optional integrations, or request account deletion. Messages submitted through the Contact page are emailed to GlidePath CRM support so we can respond. For access, correction, deletion, or privacy questions, use the Contact page or email [email protected].
Policy changes
This policy may be updated as GlidePath CRM changes. The updated date at the top of this page will show when the policy was revised. Material changes may also be communicated within the service.