RealPortal ("we", "us", "RealPortal") operates realportal.ae and the branded property portals we host for individual real estate agencies (each agency's own subdomain, e.g. youragency.realportal.ae). This policy explains what personal data we collect, why we collect it, who it's shared with, and how it's protected — written to describe what this platform actually does, not generic boilerplate.
If you're a home buyer or renter talking to our AI concierge or browsing the demand board, the sections on buyer data apply to you. If you're an agency admin or agent using RealPortal's CRM, the sections on agency accounts and CRM data apply to you — and if your own agency's clients are the ones whose data is involved, the multi-tenant isolation section below is the one that matters most.
1. Information we collect
If you're a buyer or renter
When you use the AI concierge on realportal.ae or an agency's own site, or respond to a message from an agency, we collect:
- Phone number and email address — used to create your account and verify it's really you (see Verification below).
- Your name, as you give it in conversation.
- Conversation history with our AI concierge — everything you tell it about what you're looking for (budget, areas, property type, timeline, and anything else you share), stored so the conversation can continue where you left off and so the summary we pass to agencies is accurate.
- Verification codes — short-lived one-time codes sent to confirm you control the phone number or email you gave us. These are generated and checked by our verification provider (Twilio) and are not something we store or compare ourselves.
- Property preferences captured from the conversation — budget range, areas, bedrooms, property type, purpose (buy vs. rent), timeline.
- Basic technical data — a session cookie that keeps you signed in (see Cookies below), and standard web server logs (IP address, browser type).
Until you choose to share your phone number with a specific agency (a deliberate, one-click action you take, never automatic), agencies see only your requirement — the budget, area, and property details — never your name or contact details. This is explained further in the isolation section below.
If you're an agency admin or agent
Creating a staff account on RealPortal (as an agency admin or agent) collects:
- Name, email address, and phone number.
- A securely hashed password (we never store your actual password — only a one-way cryptographic hash of it).
- Your role at the agency (agent, agency admin, or — for RealPortal's own staff — platform administrator).
Data agencies store about their own clients
RealPortal's CRM lets an agency manage its own business — property owners, leads, tenancy/lease records, and related financial records like rent cheques. Agencies enter and store this data themselves as part of running their business on our platform. We host it; the agency controls it. See the isolation section below for how this data is kept separate between agencies.
2. How we use it
- AI-driven qualification conversations — our AI concierge (built on Anthropic's Claude models) asks follow-up questions to understand what you're actually looking for, so the requirement we pass on is useful, not a guess.
- Connecting buyers with agencies — your requirement (not your identity) is shown to relevant agencies on the demand board; an agency that thinks it can help responds with a real listing, and you decide whether to continue the conversation and, eventually, share your contact details.
- CRM functionality for agencies — storing and organizing an agency's own leads, clients, listings, and related records so their team can work from one place.
- Lead re-engagement outreach — if you've contacted an agency and gone quiet, we may send a small number of follow-up messages (by email, and where an agency has that enabled, other channels) with a link back into the same conversation, so you don't have to start over.
- Verification and fraud prevention — confirming a phone number or email actually belongs to the person signing up, and basic checks to keep the demand board genuine (for example, an agency cannot use its own staff's phone number to seed fake buyer demand).
- Market context — we reference public Dubai Land Department transaction data (median prices, rents) to ground the AI's answers in real numbers. This is public market data, not personal data, and isn't collected about you.
3. Third-party services
We use a small number of specialist providers to run the platform. Each only receives the data it needs to do its specific job:
- Twilio — sends and checks phone verification codes (OTP). Twilio receives your phone number for this purpose.
- Postmark — delivers all of our transactional and outreach email (verification codes, agency notifications, re-engagement messages). Postmark receives the recipient's email address and message content.
- Anthropic — powers the AI concierge. Your conversation messages are sent to Anthropic's Claude models to generate a response; Anthropic processes this as our AI provider, under their own data-handling terms for API customers.
- Google Places API — used to show real photos of a community or building the AI is discussing (e.g. "Dubai Marina"). We send a place name, not personal data, and receive photos back.
- Meta (Facebook/Instagram) — for agencies that choose to connect their own Meta advertising account, we create ad campaigns on their behalf and may report campaign outcomes back to Meta to measure performance. Any contact details used for this (email/phone) are cryptographically hashed before being sent — Meta never receives raw contact information from us. This only applies to agencies that explicitly connect a Meta account; it has no effect on agencies that don't.
- Dubai Land Department — the source of the public transaction data referenced above. We query DLD's published records; we don't send DLD any personal data.
4. Multi-tenant data isolation
Agencies cannot see each other's leads, clients, or financial data. This isn't a policy promise layered on top — it's how the system is built. Every piece of agency data in our database is tagged with which agency it belongs to, and every query an agency's staff can run is automatically scoped to their own agency's records only. An agent at Agency A has no path — through the CRM, an API call, or otherwise — to read Agency B's clients, tenancies, financial records, or buyer conversations.
The one place data is deliberately visible across agencies is the public demand board — and even there, only the anonymized requirement is shown (budget, area, property type), never a buyer's name or contact details, until the buyer themselves chooses to share them with one specific agency.
RealPortal's own platform administrators can access agency data only for legitimate support and platform-operation purposes, and any such access is logged.
5. Data retention & deletion
- Verification codes expire automatically within minutes and are never stored by us in readable form.
- Buyer accounts and conversations are kept for as long as your account is active, so you can pick up a conversation where you left off.
- Unclaimed demand-board requests — a request that sits on the board for 10 days with no agency response is automatically removed. This is a real, permanent, ongoing policy, not a one-time cleanup.
- Agency accounts can be suspended (fully reversible — the agency's site and data are simply paused) or permanently deleted by RealPortal at the agency's request, which is a genuine, irreversible deletion of that agency's data, verified by a one-time code before it happens.
- Session cookies expire automatically after 30 days, or immediately when you log out.
We don't currently offer a self-service "delete my account" button for buyers. If you want your data deleted or want to know what we hold about you, email us at admin@realportal.ae and we'll handle it directly — this is a genuine commitment, not a formality.
6. Cookies & sessions
We use one first-party session cookie to keep you signed in after you verify your phone or email, so you don't have to re-verify on every visit. It's stored server-side (we don't put your data in the cookie itself, just an identifier), lasts up to 30 days, and is cleared when you log out. We don't use third-party advertising or tracking cookies of our own on realportal.ae.
7. Security
- All traffic to realportal.ae and every agency subdomain is encrypted (HTTPS).
- Passwords are stored as one-way cryptographic hashes, never in plain text.
- Sensitive credentials an agency connects to us — like a Meta advertising account's access token — are encrypted at rest, not stored in plain text.
- Contact details shared with Meta for ad performance reporting are cryptographically hashed before they leave our servers, as described above.
8. Children's privacy
RealPortal is a real estate platform intended for adults arranging property purchases or rentals. It is not directed at children, and we don't knowingly collect data from anyone under 18.
9. Changes to this policy
If we materially change what data we collect or how we use it, we'll update this page and the "last updated" date at the top. We'd encourage checking back occasionally, particularly before sharing sensitive information.
10. Contact us
Questions about this policy, or a request about your own data — reach us at admin@realportal.ae.