Privacy
The REI Calc Privacy Policy
Effective August 31, 2026
The REI Calc is developed and published by Valtryn Technologies. This Policy explains how The REI Calc web application and public website process information. The Service does not use analytics, advertising trackers, or ad-personalization features.
Scope
This Policy applies to The REI Calc web application and the public pages at thereicalc.com. It describes the implemented product and its current service providers. It does not claim a legal-compliance certification.
Data we process
- Account and profile: email address, first and last name, a service-assigned account identifier, account-creation information, and email-verification status. We use these to authenticate you, maintain your profile, and associate private data with its owner.
- Calculator, report, sharing, and quota data: financial and property assumptions you enter, calculated outputs, saved Mortgage and Rental reports, report identifiers, timestamps, temporary owner-authorized sharing snapshots, and pooled and informational usage counts. We use these to calculate, save, edit, display, share at your direction, and enforce report limits.
- Property images: images you choose to attach to saved reports plus owner/report metadata. Images are stored privately and are not given persistent public download links.
- Billing and subscription metadata: if you purchase or manage a subscription, we may process customer and account associations, plan and billing cadence, subscription and invoice identifiers, status and period information, checkout status, and entitlement status. Our payment processor may receive your account email and a pseudonymous account association to process the transaction and manage the subscription. We do not store full payment-card details.
- Contact submissions: name, email, reason, subject, message, optional signed-in account association, submission time, support status, and notification state. We use these to operate support.
- Security and diagnostics: authentication and abuse-prevention signals, bounded failure categories, short support references, critical client-error records, and short-lived pseudonymous abuse counters. Product logs are designed not to include calculator payloads, Contact message bodies, secrets, or authentication tokens.
- Provider technical data: our cloud, payment, mapping, security, font and icon, and website-delivery providers may process ordinary request information such as IP address, user agent, timestamps, security signals, and service-request metadata under their own operational policies.
- Maps and abuse-prevention signals: when you use Rental address suggestions, the query you type is sent to Google Maps/Places. Automated abuse-prevention services process browser and risk signals to distinguish legitimate app traffic from abuse.
Browser and cloud storage
On your device: authentication persistence and other features may use browser storage. The Service stores calculator drafts, display preferences, short-lived subscription intent, navigation recovery information, and cached resources for offline operation in your browser. These are not the same as saved cloud reports. You can remove them by clearing site data; local anonymous drafts are not deleted by cloud account deletion.
In our cloud services: we store sign-in information, profiles, saved reports and sharing snapshots, usage and quota information, Contact records, billing status, bounded diagnostic and operational records, deletion-safety information, and private report images. Server-side cloud processing supports account, report, support, security, and billing operations. Provider cookies or browser storage may be used for authentication and security. We do not claim that the Service uses no cookies.
Service providers
- Google: cloud services for authentication, hosting, private application data and images, server-side processing, security, monitoring, and recovery; Google Maps/Places for address suggestions and place details when you use that field online; and font and icon resources requested by your browser.
- Stripe: if paid features are used, Stripe may process checkout, billing-management, subscription, invoice, and billing-recovery information.
- Website and content-delivery providers: delivery and protection of the public website and feature-triggered delivery of browser resources. Calculator and report content is processed in your browser rather than intentionally sent to a content-delivery provider.
Retention and account deletion
- Active profile, saved report, sharing, quota, image, notification, and billing data is kept while needed to provide the account, until you delete an item or the account. Temporary shares also expire under their applicable expiry schedule.
- Contact submissions expire 90 days after receipt. Acknowledgement and resolution information may be used during that period.
- Pseudonymous Contact abuse-prevention counters expire after 48 hours; bounded critical client-error records expire after 14 days; incomplete checkout records expire after 30 days.
- Account deletion removes active user-owned application data, shares, reports, private report images, billing-related application records, and sign-in information. It also terminates the associated subscription and payment-provider relationship where applicable. The sign-in account is removed after associated application data has been cleaned up.
- A limited pseudonymous deletion-safety record remains for 30 days to prevent delayed system events from recreating deleted account data.
- Limited system recovery copies may retain deleted cloud data for up to seven days. Those copies are not available through the product and cannot be selectively erased early. Deleted account data is not restored into active use except as part of legitimate disaster recovery, with deletion status reapplied where feasible, and the copies expire at the end of the applicable window.
- Payment and infrastructure providers may retain transaction, security, request, and audit records under their own policies or applicable obligations. The REI Calc does not use provider request logs as an advertising profile.
See Account Deletion for the current in-app steps and the external request path.
Security and choices
We use access controls, authenticated requests, abuse-prevention measures, restricted credentials, validation, rate limits, encryption, monitoring, and provider-managed security controls designed to protect account and application data. No internet service can promise absolute security or availability.
You can edit supported profile preferences, revoke shares, delete individual reports and images, clear local browser data, cancel your subscription, or delete the account from the Account menu after password reauthentication. For a privacy or support question, email support@thereicalc.com and provide enough information for us to identify the request. We may need to verify account ownership before disclosing or changing account data.
The Service is intended for adults. Do not submit another person's personal or property information unless you have permission to do so.
Changes and contact
We may update this Policy as the Service and its processors change. The effective date will be updated, and material changes will be communicated in the Service when practical.
Privacy questions and support requests can be sent to support@thereicalc.com. You can also visit the public Support page.