Version 2.0 · Last updated: July 2026
We collect the following categories of information:
Account information: Name, email address, company name, phone number, and other information you provide when creating an account or updating your profile.
Payment information: Card, bank account, and billing details are processed by our payment processor, Stripe. We do not store your full payment credentials on our servers.
Usage data: Information about how you use the Service, including searches performed, communications sent (SMS, calls, emails), features used, and interactions with the platform.
Property and contact data: When you use our prospecting tools, the Service accesses property records and contact information collected from public records (such as county assessor, recorder, deed, tax, and court records), other publicly available sources, and licensed third-party data providers. This data may include personal information about individuals who are not Covent users — see Section 4.5 below.
Device and technical data: IP address, browser type, operating system, device identifiers, and similar technical information collected automatically when you access the Service.
Compliance and verification materials: Documents and business information you provide for A2P registration, carrier vetting, or identity verification, including IRS EIN letters, extracted document fields, and related registration materials.
Authentication and account verification information: Phone numbers and related metadata used to send one-time passcodes, account verification codes, login alerts, and other account access notifications.
When you access our free tools and lead magnets (such as the Contract Builder, Creative Finance Analyzer, and other downloadable resources), we collect the following information:
Contact information: Name, email address, and phone number provided through our opt-in forms.
How we use this data: We use the information you provide to (a) deliver the requested free tool or resource, (b) send you the resource via email, and (c) send marketing communications if you have separately consented to receive them (e.g., by opting in to SMS updates).
Retention: Lead magnet submission data is retained for as long as you remain on our mailing list or have an active account. If you unsubscribe from all communications and do not have an active account, your lead magnet data is deleted within ninety (90) days of your unsubscribe request.
We use your information to: (a) provide, maintain, and improve the Service; (b) process transactions and send related information; (c) send service-related communications, including one-time passcodes, account verification codes, login alerts, account notifications, and security alerts; (d) respond to your requests and support inquiries; (e) monitor and analyze usage trends to improve the Service; (f) enforce our Terms of Service and protect against fraud or abuse; (g) complete business verification, A2P registration, and related compliance workflows; (h) generate or host registration-related materials such as policy pages or business identity pages; (i) comply with legal obligations.
We do not use your information to send unsolicited marketing communications unless you have opted in to receive them.
We share your information with the following categories of service providers:
Payment processing: Stripe processes your payment information. Their privacy policy governs their use of your data.
Communications infrastructure: Twilio and related providers facilitate SMS, voice calls, and related communication features. Message content and metadata are processed through their systems.
Registration and vetting providers: When you use SMS registration or related compliance features, we may share business information, uploaded verification documents, extracted document data, and generated registration materials with Twilio, The Campaign Registry, mobile carriers, vetting providers, and related service providers to complete, support, or maintain your registration.
Cloud infrastructure: We use cloud hosting providers to store and process data.
AI and automated processing: Certain features of the Service use third-party artificial intelligence and machine learning services, such as OpenAI and Anthropic, to generate content, analyze data, and provide automated assistance. When you use these features, your inputs (such as property data, message content, or uploaded documents) are processed by these services to generate responses. We do not use your data to train third-party AI models.
Product analytics and performance tools: We use analytics and performance tools, such as Mixpanel, Vercel Analytics, and Vercel Speed Insights, to understand how the Service is used, measure page performance, and improve the user experience.
Error monitoring and limited session replay: We use error monitoring tools, such as Sentry, to diagnose crashes and technical issues. On a limited sample of sessions, we may collect session replay data such as clicks, page navigation, viewport details, URLs, browser information, and related technical context. Session recordings do not capture passwords or payment information.
In-app support and feedback: We use support and feedback tools, such as Gleap, to provide in-app support, collect feedback, and troubleshoot issues. These tools may receive account and contact information such as your name, email address, phone number, company, avatar, and related support context.
Interactive maps: We use map providers, such as Mapbox, to display maps and map-based property information. Map providers may receive map request data, location-related map context, device information, and similar technical information when map features load.
Push notifications: We use push notification providers, such as OneSignal, to deliver notifications you enable. These providers may receive user identifiers, subscription identifiers, device information, and notification delivery metadata.
Media and document hosting: We use media and document hosting providers, such as Cloudinary, to upload, store, transform, and deliver listing photos, videos, documents, and related media files.
We do not sell your personal information to third parties. We do not sell, rent, or share your phone number or SMS opt-in/opt-out information with third parties for their marketing purposes. SMS consent is not shared with third parties or affiliates for marketing or promotional purposes. We may disclose your information if required by law, subpoena, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Storefront listing pages may also load Google Maps or Street View embeds to display a property location. When those embeds load, the property location and related technical request information may be transmitted to Google.
The Service provides access to property records and contact information sourced from public records databases and licensed third-party data providers. This data is provided “as-is” and we do not guarantee its accuracy, completeness, or currency.
Contact information may be inferred, enriched, skip traced, appended, matched, or updated using automated systems and third-party data sources. These processes can produce incorrect, outdated, incomplete, or mismatched results, including phone numbers or email addresses that no longer belong to the listed person.
You are responsible for: (a) verifying the accuracy of data before using it for outreach; (b) ensuring you have the legal right to contact any individual; (c) complying with all applicable privacy and telemarketing laws; (d) maintaining appropriate records of your data usage and communications.
When you upload, import, sync, or otherwise provide contact data to the Service, you are responsible for the source, accuracy, permissions, consent status, opt-out status, and lawful use of that data. We process that data to provide the Service at your direction.
When customers use communication features, they decide who is contacted, what is sent, and when communications are sent. Covent processes communication data as a technology provider acting on customer instructions, not as the independent sender of customer campaigns.
Not a consumer reporting agency: Covent is not a consumer reporting agency, and information available through the Service may not be used to evaluate any person’s eligibility for credit, insurance, employment, housing, or any other purpose regulated by the Fair Credit Reporting Act (FCRA).
The Service includes personal information about individuals who do not have a Covent account and with whom we have no direct relationship, such as property owners, prospective buyers and investors, and other business contacts (“non-user data subjects”).
Categories of information: Depending on the source, this may include identifiers (name, mailing address, phone number, email address), property ownership and transaction records, mortgage and lien information, business and professional information (such as entity affiliations and investment activity), and inferences derived from that information (such as likely purchase criteria).
Sources: We collect this information from public government records (county assessor, recorder, deed, tax, and court records), other publicly available sources, licensed third-party data providers, and data our customers upload or import.
Purposes and disclosure: We process this information to provide property research, prospecting, deal-marketing, and buyer-matching tools to our customers. It is made available to customers for their own business use, subject to our Terms of Service. Customers are independently responsible for how they use this information, including their own compliance with privacy and telemarketing laws when they choose to contact anyone.
Your choices if you are a non-user data subject: If your information appears in the Service, you may contact us at help@getcovent.com to: (a) request disclosure of the personal information we maintain about you; (b) request correction of inaccurate information; (c) request deletion of your information; or (d) opt out of your information being made available to our customers, in which case we will suppress your records from our prospecting datasets going forward. We honor these requests as required by applicable state privacy laws, and the rights described in Section 8 apply to non-user data subjects as well as account holders.
Information lawfully made available from federal, state, or local government records, or that is otherwise “publicly available” as defined by applicable state privacy laws, may be exempt from some of these rights. Where an exemption applies, we will still review suppression requests in good faith.
When you use the Service’s communication features:
Transactional and security SMS: We may use your phone number to send transactional and security-related text messages, including one-time passcodes, account verification codes, login alerts, and other account access notifications. These messages are sent when you provide your phone number and request or consent to receive messages through the Service.
SMS messages: Message content and delivery status are logged for your compliance records. Logs are retained per applicable regulatory requirements.
Voice calls: Call metadata (duration, time, participants) is logged. If you enable call recording, recordings are stored and accessible through your account. You are responsible for disclosing call recording to participants as required by applicable state and federal law.
Email: Email content and delivery metrics are logged for your records.
Communication logs are retained for a minimum of five (5) years to support TCPA compliance record-keeping requirements.
Message frequency and rates: Message frequency varies based on your account activity and preferences. Message and data rates may apply.
Opt-out and support: You may opt out of text messages at any time by replying STOP to any message. For help, reply HELP or contact help@getcovent.com.
Carrier disclaimer: Carriers are not liable for delayed or undelivered messages.
Active accounts: We retain your data for as long as your account is active and as needed to provide the Service.
After termination: Upon account termination, your data is retained for ninety (90) days to allow for reactivation or data export. After this period, data is permanently deleted.
Communication logs: Retained for a minimum of five (5) years per regulatory requirements.
Payment records: Retained as required by tax and financial reporting obligations.
Property and prospecting data: Property records and contact information described in Section 4.5 are retained and refreshed for as long as they remain current and relevant to providing the Service. Records suppressed at a data subject’s request are added to a suppression list, which we retain so that suppressed records are not re-added from new data sources.
Aggregated data: We may retain anonymized, aggregated data that cannot be used to identify you for analytical purposes indefinitely.
Retention criteria: For each category of personal information described in Section 1, we determine the retention period based on: (a) how long the information is needed to provide the Service and operate your account; (b) legal, regulatory, tax, and record-keeping obligations; and (c) whether retention is needed to resolve disputes, enforce our agreements, or protect against fraud and abuse.
We implement industry-standard security measures to protect your data, including: encryption in transit (TLS) and at rest (AES-256), access controls and authentication, regular security assessments, and employee access restrictions.
No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
Right to correct: You may request that we correct inaccurate personal information we maintain about you.
Right to delete: You may request deletion of your personal information, subject to certain exceptions.
Right to opt out of sale or sharing: We do not sell personal information for monetary consideration, and we do not share personal information for cross-context behavioral advertising. If our practices ever change, we will provide a clear “Do Not Sell or Share My Personal Information” link in our footer and update this policy before any such activity begins.
Right to limit use of sensitive personal information: You may direct us to limit our use and disclosure of any sensitive personal information we have collected.
Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
Universal opt-out signals (Global Privacy Control / “Do Not Sell or Share”): We honor the Global Privacy Control (GPC) browser signal and any other universal opt-out mechanism recognized by California or other applicable state privacy law. When we detect a recognized signal, we treat your visit as an opt-out of any sale or sharing of personal information and of targeted advertising, and we apply this preference automatically without requiring further action from you.
California residents — no commercial-context exemption: If you are a California resident, you have these rights regardless of whether you are interacting with us in a personal capacity or a business capacity. The California business-to-business exemption expired on January 1, 2023, and we do not rely on it.
Submitting requests and verification: To exercise these rights, contact us at help@getcovent.com. We will verify your request by matching the information you provide against the information we maintain, and we may request additional information where reasonably necessary to confirm your identity. Information provided for verification is used only for that purpose. We will respond to verifiable requests within forty-five (45) days, and may extend that period once by an additional forty-five (45) days where reasonably necessary, in which case we will notify you.
Authorized agents: You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written authorization and may require you to verify your identity directly with us.
Appeals: If we decline to act on your request, we will explain why. You may appeal our decision by replying to our response or by emailing help@getcovent.com with the subject line “Privacy appeal” within a reasonable time after receiving it. We will respond to appeals within the timeframe required by applicable law (generally forty-five (45) to sixty (60) days). If your appeal is denied, you may contact your state attorney general or other supervisory authority to submit a complaint.
Residents of other states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Iowa, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Rhode Island, and Kentucky — may have similar rights, including the rights to access, correct, delete, and opt out described above and the right to appeal. Contact us to submit a request.
We use the following types of cookies and similar technologies:
Essential cookies: Required for authentication, session management, security, and core functionality. These cannot be disabled.
Analytics cookies and session tracking: Help us understand how the Service and our public storefront pages are used, including pages viewed, links clicked, time on page, and session-level interactions. Storefront analytics apply to all visitors, regardless of whether they have been separately vetted by a customer of the Service. You may disable these through your browser settings or by sending a recognized universal opt-out signal as described below.
We do not use third-party advertising cookies or tracking pixels for targeted advertising or cross-context behavioral advertising.
Global Privacy Control (GPC) and similar signals: We honor the Global Privacy Control (GPC) browser signal and any other universal opt-out mechanism recognized by California, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, Nebraska, or other applicable state privacy law. When we detect a recognized signal, we treat your visit as an opt-out of any sale or sharing of personal information and of targeted advertising, and we apply this preference automatically without requiring further action.
You can manage your cookie preferences through your browser settings, by sending a recognized universal opt-out signal, or by contacting us at help@getcovent.com.
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected personal information from a child under 18, we will take steps to delete it promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice in the Service at least thirty (30) days before the changes take effect.
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. If you do not agree to the changes, you should discontinue use of the Service.
This service is operated in and intended for users in the United States, and the property and contact data available through the Service relates to United States properties. If you access the service from outside the US, you do so at your own risk and are responsible for compliance with local laws. The Service is not directed to individuals in the European Economic Area or the United Kingdom, and we do not target or knowingly offer the Service to residents of those regions.
Covent LLC, a Wyoming limited liability company.
For privacy-related questions or requests, contact us at: help@getcovent.com