Privacy Policy

Riddle, LLC · Maryland limited liability company · SDAT Department ID W27515154 · 7608 Genevieve Blvd, Laurel, MD 20723 · privacy@riddledevs.com

This Privacy Policy describes how Riddle, LLC (“Riddle,” “we,” “us”) collects, uses, discloses, and protects personal information on riddledevs.com, at Stripe Checkout, and inside Riddle CRM and later Modules. Capitalized terms not defined here have the meaning in the Terms of Service.

This Policy is part of the agreement described in the Terms. If a signed Data Processing Addendum later exists, it controls processing of Customer Data to the extent of conflict with this Policy. The Subscription Agreement controls fees and cancellation.

1. Who we are; two different roles

Riddle is a Maryland company that sells business software to real-estate agents, brokerages, and property managers in the United States. We play two different roles, and this Policy treats them separately:

Controller (or “business”) for information we collect about you as a visitor, demo requester, billing contact, or Authorized User — for example your name, email, plan, and site analytics. We decide why that information is processed.

Processor (or “service provider”) for Customer Data that a Customer uploads into a Tenant (contacts, journeys, documents, messages, listing files, and personal information of that Customer’s clients). The Customer decides what to put in and is responsible for it. We process it only to provide the Platform, on the Customer’s instructions (the Terms, this Policy, and in-product settings).

The Maryland Online Data Privacy Act, Md. Code, Com. Law § 14-4701 et seq. (“MODPA”), defines “consumer” as a Maryland resident and excludes an individual acting in a commercial or employment context. Most Authorized Users and billing contacts are acting commercially. Marketing-site visitors who are Maryland residents and are not yet acting for a business may still be “consumers.” We do not currently meet MODPA’s volume thresholds (generally 35,000 consumers, excluding payment-only data, or 10,000 consumers plus more than 20% of revenue from sales of personal data). We still apply this Policy’s operational promises — no sale, no targeted advertising, tenant isolation, no default AI training — to everyone.

Other U.S. state privacy laws (including the California Consumer Privacy Act as amended, “CCPA”) have their own thresholds. At launch we do not meet typical CCPA thresholds (for example $25 million gross revenue, or 100,000 consumers/households). We will honor the requests in Section 16 even when a statute does not yet require it.

2. Scope; who this Policy covers; who it does not

This Policy covers: (a) the marketing and legal pages on riddledevs.com; (b) demo requests; (c) Stripe Checkout and the billing relationship; (d) Entra sign-in; (e) use of the Platform by Authorized Users; and (f) Customer Data we host.

It does not cover: third-party sites we link to; Google, Microsoft, Stripe, or Twilio acting under their privacy policies when you deal with them directly; or a Customer’s own privacy practices toward that Customer’s clients. If you are a home buyer, seller, or tenant whose agent uses Riddle, the agent (our Customer) is the party to contact first about your information.

The Platform is offered only in the United States to users 18 or older for commercial use. We do not offer the service in the EU, UK, or Canada at launch and do not intend to process personal data as a GDPR/UK GDPR “controller” or under PIPEDA/Quebec Law 25 until we publish a territorial addendum.

3. Categories of personal information we collect

Depending on how you interact with us, we may collect:

  • Identity and contact: name, email address, phone number, company or brokerage name, role, mailing or billing address if you give it.
  • Account and authentication: Entra External ID identifiers, username, hashed credentials or federated tokens, MFA status, session metadata.
  • Commercial and billing: plan (monthly or yearly), trial status, Stripe customer id, subscription id, invoice ids, tax metadata, last four of a card and card brand as Stripe returns them. We do not collect or store full payment-card PAN or CVV; Stripe does.
  • Customer Data (processor): whatever the Customer puts in the Tenant — client names and contact details, journey stages (buying, selling, leasing), notes, listing photographs, contracts, identification documents, wire instructions, Social Security numbers or other government IDs if the Customer uploads them, messages the Customer sends, calendar and contact data if the Customer connects Google or Microsoft, and similar professional-file content.
  • Communications content: email and SMS bodies Customer initiates or schedules through Twilio, Microsoft, or Google; demo-request text; support emails you send us.
  • Device and site: IP address, browser type, pages viewed, referring URL, approximate region derived from IP, and essential cookie identifiers.
  • Telemetry (product analytics): feature flags, counts (how many contacts, documents, journeys), document sizes, error traces, performance timings. Application logs are designed not to include personal information of clients. Aggregate numbers may be used to operate and improve the Platform.
  • Inferences: we do not build advertising profiles. We may infer coarse product-usage segments (for example “used Communications this week”) solely to run and improve the service.

We do not intentionally collect biometric identifiers, precise geolocation, consumer health data, genetic data, or information we know is about a child, as a controller. A Customer might upload a document that happens to contain those categories; that is Customer Data under Section 7.

4. Sources

  • You, when you browse, request a demo, check out, create an account, or email us.
  • Your Administrator, if they invite you as an Authorized User (when seats exist).
  • Stripe, which returns payment status and identifiers.
  • Microsoft Entra, which returns authentication events.
  • Google or Microsoft, if you connect those accounts (contacts, mail, calendar tokens and the data you authorize).
  • Twilio, delivery receipts for SMS you send.
  • Automatic collection from your browser and the application (cookies, logs, telemetry).

We do not buy personal information from data brokers.

5. How we use information (purposes)

We use personal information only for:

  • Providing, hosting, securing, and supporting the Platform and sites;
  • Creating, billing, converting, pausing, disabling, and re-enabling subscriptions and Entra accounts from Stripe events;
  • Responding to demo requests and support;
  • Sending transactional mail (receipts, trial-end, renewal, security alerts). Marketing mail, if we ever send it, will include an unsubscribe;
  • Debugging, security monitoring, fraud prevention, and product analytics described above;
  • Enforcing the Terms, protecting the Platform, and establishing legal claims;
  • Tax, accounting, and other legal duties (including Maryland sales-and-use tax on qualifying SaaS when we collect it);
  • De-identified, aggregate metrics that cannot reasonably identify you or a client, to improve the Platform.

We do not: sell personal information; share it for cross-context behavioral or targeted advertising; use it to train generalized or third-party foundation models; mix one Tenant’s Customer Data into another Tenant or Module except as that Customer configures RBAC; or use Customer Data for our own marketing to that Customer’s clients.

6. Sensitive information and Maryland PIPA “personal information”

MODPA sensitive data (racial or ethnic origin, religious beliefs, consumer health data, sex life or orientation, transgender or nonbinary status, national origin, citizenship or immigration status, genetic or biometric data, personal data of a child, precise geolocation) is not something we collect as a controller. We will not sell sensitive data, which MODPA forbids even with consent. We will not process it as a controller unless it is strictly necessary to a product you requested — which, at launch, it is not.

PIPA personal information (Md. Code, Com. Law § 14-3501) is different. It includes an individual’s name in combination with SSN, taxpayer ID, passport, driver’s license, financial account number plus access code, certain health identifiers, or biometric data, when not encrypted or otherwise unreadable. Customer Data may include those elements if a Customer uploads IDs, contracts, or wire instructions. We encrypt Customer Data at rest and in transit. Encryption does not transfer legal responsibility: the Customer decides whether to upload that material and remains the controller of it. See Terms § 7.

Do not email Social Security numbers or wire instructions to privacy@ or legal@ mailboxes.

7. Customer Data in the Platform (Riddle as processor)

For Customer Data, Riddle:

  • Processes only to provide the Platform, secure it, bill it, prevent abuse, and create de-identified telemetry;
  • Does not sell it or use it for advertising;
  • Does not access it for personnel use except as needed for support, security, or legal process, under access controls;
  • Does not train personalized AI on it at launch (Section 11);
  • Keeps it logically isolated by Tenant; later Modules share infrastructure, not data;
  • Deletes or de-identifies it on the schedule in Section 13 after the Tenant ends, except legal holds and tax records.

If you are a client of an agent who uses Riddle, send access, correction, or deletion requests to that agent. We will assist the Customer in responding where the law requires a processor to help. We will not honor a third-party request that would let us look through a Tenant without the Customer’s instruction or a binding legal demand.

8. Communications: Twilio, Microsoft, Google

If Customer uses Communications, Riddle forwards Customer-generated email or SMS (including scheduled templates). Customer is the sender. Twilio, Microsoft, and Google process message content and addressees as needed to deliver. Delivery logs (status, timestamp, destination number or address) may be stored to debug sending. We do not harvest Customer’s client lists to market Riddle.

Connecting Google or Microsoft is optional and Customer-directed. Tokens are stored to maintain the connection you enabled. You may disconnect in-product or by revoking access at the provider. Those providers’ privacy policies apply to their processing.

9. Cookies and similar technologies

At launch the marketing site is designed to use essential cookies and local storage only: session, load balancing, security, and the clickwrap/acceptance log. Stripe Checkout is hosted by Stripe and will set Stripe’s cookies under Stripe’s policy.

We do not currently operate advertising pixels or cross-site tracking. If we later add a product-analytics cookie on the marketing site (for example a first-party analytics tool), we will update this Section and, where required, provide a non-essential opt-out. We honor a Global Privacy Control (GPC) signal as an opt-out of sale/sharing to the extent we ever engage in activity those laws treat as a sale or share; today we do not sell or share for ads, so GPC does not change a default we already apply.

The logged-in Platform may use essential cookies or tokens to keep you signed in and to remember UI settings.

10. Subprocessors and other disclosures

We disclose personal information to:

  • Stripe, Inc. — payments, invoices, customer portal, tax calculation if enabled. Categories: identity, contact, commercial/billing. Role: processor / payment institution.
  • Microsoft — Azure hosting in the United States (currently East US 2 for regional resources, geo-redundant storage where configured), Entra External ID, and optional Outlook/Graph if Customer connects it. Categories: account, Customer Data, telemetry.
  • Google — optional Gmail, Calendar, Contacts if Customer connects them.
  • Twilio, Inc. — SMS Customer initiates or schedules.
  • Professional advisors (counsel, accountants, insurers) under confidentiality, as needed to run the company.
  • Authorities when we believe in good faith we must, to comply with law, a valid legal process, or to protect Riddle, Customers, or the public.
  • A buyer in a merger, financing, or sale of assets, under a duty to use the information consistent with this Policy, with notice if the law requires it. That transfer is excluded from MODPA’s definition of “sale.”

We do not disclose personal information to data brokers or advertising networks. We may change Subprocessors; material changes will be posted here or emailed to the billing contact. Stripe, Microsoft, Google, and Twilio have their own terms and infrastructure; we remain responsible to the Customer for their processing of Customer Data as described in the Terms, to the extent the law allows.

11. Artificial intelligence

Riddle CRM at launch does not include personalized-AI features and does not train models on Customer Data. Telemetry described in Section 3 is not model training on Tenant content.

If we later offer features that learn from or personalize using Tenant content, they will be: (a) off by default; (b) described in-product; (c) subject to a separate upgraded data agreement and an affirmative opt-in; and (d) limited to internal platform improvement, not sale and not training of third-party foundation models, unless that addendum clearly says otherwise. You may stay on this Policy by never opting in.

We do not use automated decision-making that produces legal or similarly significant effects about a consumer without human involvement.

12. Sale, sharing, and targeted advertising

We do not sell personal information as MODPA, the CCPA, and similar state laws define “sale.” We do not share personal information for cross-context behavioral or targeted advertising. We do not sell sensitive data. Because those activities are not on, “Do Not Sell or Share My Personal Information” is already the operational default. If that ever changes, we will update this Policy, provide a conspicuous opt-out link, and honor GPC.

Paying Stripe, Microsoft, Google, or Twilio to host or deliver the service is processing, not a sale.

13. Retention

  • Marketing and demo records: as long as needed to respond and for a reasonable follow-up, then delete or de-identify, unless you become a Customer (then they join the billing file).
  • Account, billing, and tax: for the life of the account plus the period Maryland and federal tax and accounting rules require (often seven years for some records).
  • Customer Data in an active Tenant: until the Customer deletes it or the Tenant ends.
  • After disable or cancellation: interactive access ends at the close of the last paid period. Customer Data remains available for export or resubscribe for thirty (30) days. Rolling backups expire on a cycle not to exceed ninety (90) days. We then delete or de-identify Customer Data from production systems except legal holds and records we must keep.
  • Entra accounts disabled for non-payment may remain disabled (not immediately deleted) so a later payment can re-enable them.
  • Security and server logs: typically 90 days or less unless an investigation requires longer.
  • Clickwrap logs (timestamp, email, document versions): for the life of the contract plus any limitations period.

When we destroy records containing PIPA personal information, we take reasonable steps to make them unreadable, as PIPA § 14-3502 requires.

14. Security

We implement and maintain commercially reasonable administrative, technical, and physical safeguards appropriate to the nature of the information and the size of the business, consistent with PIPA § 14-3503, including encryption in transit and at rest, Tenant isolation, RBAC, least-privilege access, and logging. We do not claim SOC 2, ISO 27001, or a completed penetration test in this Policy. No method of transmission or storage is perfectly secure.

You must protect your credentials, use a unique password, and tell us if you suspect unauthorized access.

15. Security Incidents

If Riddle discovers a Security Incident affecting Customer Data, we will investigate, contain, and:

  1. Notify the Customer without unreasonable delay and, because we typically maintain Customer Data on the Customer’s behalf, no later than ten (10) days after discovery, so the Customer can notify individuals (PIPA § 14-3504);
  2. Where we ourselves own or license personal information of Maryland residents, notify affected individuals as soon as reasonably practicable and not later than forty-five (45) days after discovery, unless a permitted law-enforcement delay applies; and
  3. Notify the Maryland Attorney General when PIPA requires it, and consumer reporting agencies when the number of Maryland residents requires it.

Report suspected incidents on your side to privacy@riddledevs.com and legal@riddledevs.com.

16. Your choices and rights

Everyone. You may request access to, correction of, or deletion of marketing-site and account information we hold as a controller by emailing privacy@riddledevs.com. You may close your account by canceling under the Subscription Agreement. You may manage cards in the Stripe customer portal. You may disconnect Google or Microsoft. You may decline any future AI addendum.

Authorized Users. Your Administrator controls Tenant permissions. MVP is one Authorized User per Tenant.

Customers as controllers of client data. Use in-product tools to access, correct, or delete Customer Data. We will assist with export during the 30-day window in Section 13.

State privacy rights. If you are a “consumer” under MODPA or a similar state law and that law applies to us, you may have the right to: confirm whether we process your personal data; access it; correct inaccuracies; delete it; obtain a portable copy; opt out of sale, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects; and appeal a refused request. We will not sell or use targeted advertising regardless. We will not discriminate against you for exercising a privacy right.

How to submit. Email privacy@riddledevs.com from the address we have on file, with “Privacy request” in the subject, and tell us which right you want to exercise. We will verify you (for example by email challenge) before disclosing or deleting. We will respond within the time the applicable statute sets (MODPA generally 45 days, extendable once). If we deny a request that a statute covers, you may appeal by replying to our decision; we will inform you of the Maryland Attorney General complaint process if required.

Authorized agents. You may use an authorized agent where a statute allows it. We will require proof of authority and still verify you.

We may decline a request that is unfounded, excessive, conflicts with a legal hold, or would require us to violate another Customer’s Tenant isolation.

17. Children

The sites and Platform are business services, not directed to children under 18, and we do not knowingly collect personal information from children as a controller. If you believe we have, email privacy@riddledevs.com and we will delete it. Customer Data may include a client household with minors (for example a lease with a parent and child). That is the Customer’s file; the Customer must have a lawful basis to hold it. We do not use that information except to host the Tenant.

18. U.S. hosting; no international product offering

Customer Data is hosted on Microsoft Azure in the United States. We do not freeze a single region in this Policy (currently East US 2 for many regional resources). We will not transfer Customer Data outside the United States as part of a standard offering without notice. We do not currently offer the Platform to EU/UK/Canadian customers and do not rely on GDPR Standard Contractual Clauses or PIPEDA adequacy because we are not offering those territories.

19. Third-party links

The sites may link to third parties (for example Stripe Checkout, a scheduling tool, Microsoft, Google). Their privacy practices govern their pages. We are not responsible for them.

20. Changes

We will post updates here with a new “Last revised” date. If we materially expand how we use personal information as a controller (for example adding advertising cookies or AI training), we will email the billing contact at least thirty (30) days before that use begins, except where the law requires or allows faster change. Continued use after the effective date is acceptance of the updated Policy for controller data. For Customer Data, a material change that is not required to provide the existing service will not apply to that Tenant without the Customer’s instruction or a Terms change process.

21. Contact

Privacy requests and questions: privacy@riddledevs.com · Legal: legal@riddledevs.com · Billing: billing@riddledevs.com · Riddle, LLC · 7608 Genevieve Blvd, Laurel, MD 20723 · Attn: Privacy / Resident Agent

Do not send Social Security numbers or wire instructions to these mailboxes.