Legal
Privacy policy
What we collect, why, on what basis, who processes it for us, where it is held, how long we keep it, and how to see it, correct it or have it deleted.
Version 3.0, effective . Last updated .
Who we are
YieldPulse is owned and operated by Constructive FZE LLC, which decides why and how your personal data is used (the “controller”).
- Legal name: Constructive FZE LLC
- Registered address: Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
- Tax registration number: 105346773200001
- Privacy contact: hello@yieldpulse.io, with “Privacy request” in the subject
1. This policy and the law
This policy covers the website at yieldpulse.io and everything it does: the calculator, the results, saved analyses, reports, accounts, payments, messages and the mortgage-broker directory. The law that governs how we handle personal data is the United Arab Emirates’ Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. This policy sets out what that law asks us to tell you.
We do not sell personal data. We do not use it to make decisions about you that have legal or similar effects.
2. What we collect
| What | What it includes | When and from whom |
|---|---|---|
| The property you describe | Price, rent, size, area or building, type, bedrooms, deposit, rate and the other figures in the calculator; a listing link if you paste one. | From you. It stays in your browser until you save an analysis, give your email, or open or buy a report; then it is sent to us with that request. |
| Your email, with your figures | Your email address, the figures above and the headline results worked from them, and the campaign you arrived from if you agreed to analytics. | When you ask for a link to your results, the one-page summary or the full report. |
| Your account | Your name, your email address and your password. The password is stored by our sign-in provider in a form we cannot read. | When you make an account. |
| Saved analyses and reports | Each analysis you save and each report you open or buy, with the figures and the snapshot of the report as it was made. | From you, through your use of the site. |
| Purchases | The amount, the date, the report it was for, Stripe’s references for the payment, and any referral or promotion code used. Never your card number. | From Stripe and from you when you buy a report. |
| Messages | What you write in the contact form or a support request, and our replies. | From you. |
| Broker applications | For a mortgage broker who applies to be listed: the firm’s details, licence and registration references, and the name, role and business email of a contact at the firm. | From the broker, on the application form. |
| Technical data | The IP address of each request to our server, kept briefly to limit abuse; the ordinary request records our hosts keep (address, browser, the page asked for, the time). | From your browser, automatically. |
| Analytics and advertising data | Pages visited and steps taken, with the identifiers those services set; for a purchase, the amount and (to Meta) your email address in hashed form. Only with your consent (section 9). | From your browser and, for a purchase reported to Meta, from our server. |
The property you describe
- What it includes
- Price, rent, size, area or building, type, bedrooms, deposit, rate and the other figures in the calculator; a listing link if you paste one.
- When and from whom
- From you. It stays in your browser until you save an analysis, give your email, or open or buy a report; then it is sent to us with that request.
Your email, with your figures
- What it includes
- Your email address, the figures above and the headline results worked from them, and the campaign you arrived from if you agreed to analytics.
- When and from whom
- When you ask for a link to your results, the one-page summary or the full report.
Your account
- What it includes
- Your name, your email address and your password. The password is stored by our sign-in provider in a form we cannot read.
- When and from whom
- When you make an account.
Saved analyses and reports
- What it includes
- Each analysis you save and each report you open or buy, with the figures and the snapshot of the report as it was made.
- When and from whom
- From you, through your use of the site.
Purchases
- What it includes
- The amount, the date, the report it was for, Stripe’s references for the payment, and any referral or promotion code used. Never your card number.
- When and from whom
- From Stripe and from you when you buy a report.
Messages
- What it includes
- What you write in the contact form or a support request, and our replies.
- When and from whom
- From you.
Broker applications
- What it includes
- For a mortgage broker who applies to be listed: the firm’s details, licence and registration references, and the name, role and business email of a contact at the firm.
- When and from whom
- From the broker, on the application form.
Technical data
- What it includes
- The IP address of each request to our server, kept briefly to limit abuse; the ordinary request records our hosts keep (address, browser, the page asked for, the time).
- When and from whom
- From your browser, automatically.
Analytics and advertising data
- What it includes
- Pages visited and steps taken, with the identifiers those services set; for a purchase, the amount and (to Meta) your email address in hashed form. Only with your consent (section 9).
- When and from whom
- From your browser and, for a purchase reported to Meta, from our server.
We do not ask for your telephone number, your nationality, your income or anything about your health or beliefs. Please do not put such things in a message.
The registered sales, tenancies and service charges a report uses are public records about properties, not about you. Contains information originated by the Dubai Land Department and the Dubai Data and Statistics Establishment, obtained from Data Dubai (https://data.dubai) under its Open Data Licence. Every figure is YieldPulse's own calculation from that information.
3. Why we use it, and on what basis
| Purpose | The data | Basis |
|---|---|---|
| Working out your results and your report, saving them and showing them again | Your figures, your account, saved analyses and reports | Doing what you asked: providing the service you requested |
| Taking payment, refunding, and keeping the records the law requires | Purchases, your email | Performing the contract with you, and our legal obligations on tax and accounts |
| Sending the link, the summary or the report you asked for, and emails about your account | Your email, your figures | Doing what you asked: providing the service you requested |
| Up to five follow-up emails about the property you looked at, over about two weeks after you give your email | Your email, your figures | Your consent, given when you enter your email under the notice that says so. Every email has a link to stop them, and stopping them changes nothing else |
| Answering your messages | Messages, your email | Doing what you asked |
| Considering and publishing a broker listing, and writing to the broker about it | Broker applications | The broker’s request and consent, given on the application form |
| Keeping the service secure and limiting abuse | Technical data | Protecting the service and its users; our legal obligations |
| Counting visits and steps, to improve the site | Analytics data | Your consent, through the consent banner. You can withdraw it at any time |
| Measuring our advertising | Advertising data | Your consent, through the consent banner. You can withdraw it at any time |
Working out your results and your report, saving them and showing them again
- The data
- Your figures, your account, saved analyses and reports
- Basis
- Doing what you asked: providing the service you requested
Taking payment, refunding, and keeping the records the law requires
- The data
- Purchases, your email
- Basis
- Performing the contract with you, and our legal obligations on tax and accounts
Sending the link, the summary or the report you asked for, and emails about your account
- The data
- Your email, your figures
- Basis
- Doing what you asked: providing the service you requested
Up to five follow-up emails about the property you looked at, over about two weeks after you give your email
- The data
- Your email, your figures
- Basis
- Your consent, given when you enter your email under the notice that says so. Every email has a link to stop them, and stopping them changes nothing else
Answering your messages
- The data
- Messages, your email
- Basis
- Doing what you asked
Considering and publishing a broker listing, and writing to the broker about it
- The data
- Broker applications
- Basis
- The broker’s request and consent, given on the application form
Keeping the service secure and limiting abuse
- The data
- Technical data
- Basis
- Protecting the service and its users; our legal obligations
Counting visits and steps, to improve the site
- The data
- Analytics data
- Basis
- Your consent, through the consent banner. You can withdraw it at any time
Measuring our advertising
- The data
- Advertising data
- Basis
- Your consent, through the consent banner. You can withdraw it at any time
Where a use rests on your consent, you can withdraw it at any time, as easily as you gave it: the follow-up emails by the link in each of them, analytics and advertising from “Cookie choices” at the foot of every page. Withdrawing does not undo what was done before.
4. Who processes it for us
These services process personal data on our behalf, under their own contracts with us, for the purposes above only. The list is as the site stood on .
| Service | What it does for us | What it receives |
|---|---|---|
| Supabase | Holds accounts, saved analyses, reports, purchases, messages and broker applications, and runs the server functions behind the site. | Everything in section 2 except analytics and advertising data. |
| Vercel | Hosts the website, and prints a report to PDF when you ask for the download. | Ordinary request data; for a PDF, the report being printed. |
| Stripe | Takes card payments and makes refunds. | The buyer’s email address, the amount, and our references for the report. Card details are entered on Stripe’s own page and go only to Stripe. |
| Resend | Sends our emails. | The recipient’s email address and name, and the content of the email. |
| Firecrawl | Reads a listing page when you paste a Bayut or Property Finder link into the calculator, to fill in the form. | The listing link you pasted. Not your name or your email address. |
| Cloudinary | Keeps a copy of a pasted listing’s main photo, so that it keeps showing in your saved report. | The address of the listing’s photo, which it fetches. |
| Google Analytics | Counts visits and steps. Only with analytics consent. | The pages visited and the events of a visit (a report opened, a checkout begun, a purchase and its amount), your IP address and browser details, through its own cookies. |
| Google Ads | Measures our Google advertising. Only with advertising consent. | Page and purchase events, and the Google click identifier on the link you arrived by. |
| Meta | Measures our advertising on Facebook and Instagram: the Meta pixel in your browser, and the conversions API from our server for a purchase. Only with advertising consent. | Page views and events with a browser identifier; for a purchase, from our server: the amount and your email address in hashed form. |
| Built in but not switched on at the date of this policy. If it is, it loads only with advertising consent. | Page visits and the events of a checkout begun, a purchase and an account made, with LinkedIn’s browser identifier. |
Supabase
- What it does for us
- Holds accounts, saved analyses, reports, purchases, messages and broker applications, and runs the server functions behind the site.
- What it receives
- Everything in section 2 except analytics and advertising data.
Vercel
- What it does for us
- Hosts the website, and prints a report to PDF when you ask for the download.
- What it receives
- Ordinary request data; for a PDF, the report being printed.
Stripe
- What it does for us
- Takes card payments and makes refunds.
- What it receives
- The buyer’s email address, the amount, and our references for the report. Card details are entered on Stripe’s own page and go only to Stripe.
Resend
- What it does for us
- Sends our emails.
- What it receives
- The recipient’s email address and name, and the content of the email.
Firecrawl
- What it does for us
- Reads a listing page when you paste a Bayut or Property Finder link into the calculator, to fill in the form.
- What it receives
- The listing link you pasted. Not your name or your email address.
Cloudinary
- What it does for us
- Keeps a copy of a pasted listing’s main photo, so that it keeps showing in your saved report.
- What it receives
- The address of the listing’s photo, which it fetches.
Google Analytics
- What it does for us
- Counts visits and steps. Only with analytics consent.
- What it receives
- The pages visited and the events of a visit (a report opened, a checkout begun, a purchase and its amount), your IP address and browser details, through its own cookies.
Google Ads
- What it does for us
- Measures our Google advertising. Only with advertising consent.
- What it receives
- Page and purchase events, and the Google click identifier on the link you arrived by.
Meta
- What it does for us
- Measures our advertising on Facebook and Instagram: the Meta pixel in your browser, and the conversions API from our server for a purchase. Only with advertising consent.
- What it receives
- Page views and events with a browser identifier; for a purchase, from our server: the amount and your email address in hashed form.
- What it does for us
- Built in but not switched on at the date of this policy. If it is, it loads only with advertising consent.
- What it receives
- Page visits and the events of a checkout begun, a purchase and an account made, with LinkedIn’s browser identifier.
Beyond these, we disclose personal data only where the law requires it, to protect our legal rights, or to a buyer of the business, who would be bound by this policy. A report you share is seen by whoever you share its link with.
5. How long we keep it
- Your account, saved analyses and reports: while the account is open. When you ask us to delete the account, we delete it and them within 30 days.
- Your email with your figures, when you have no account: 24 months from the last time you used the site or opened one of our emails, unless you ask us to delete it sooner.
- Purchases and refunds: for as long as UAE tax and company law requires us to keep accounting records, which is at least five years. This is kept even after an account is deleted.
- Messages and support requests: three years, so that we can answer a later question or a complaint about the same thing.
- Broker applications: a listing while it is published and 12 months after it is removed; an application that is not approved, 12 months.
- IP addresses kept to limit abuse: only as long as is needed to enforce a limit on repeated requests.
- Analytics data: no longer than 14 months, the longest Google Analytics allows for event data.
- Copies held in backups are overwritten in the ordinary course, within 90 days.
6. Where it is held
The services in section 4 store and process data outside the United Arab Emirates, mainly in the European Union and the United States. Each is bound by its contract with us to protect the data and use it only for us. Where the law requires a further safeguard for a transfer, we rely on those contracts and, where the law asks for it, on your consent, which you give by using the part of the service that needs the transfer.
7. How it is protected
- Everything between your browser and our servers is encrypted in transit.
- Passwords are handled by our sign-in provider and are never stored in a form we can read.
- Card details go to Stripe and never reach us.
- Access to stored data is limited to our own administrator accounts.
No system is perfectly secure. If a breach puts your personal data at risk, we will tell you and the authorities as the law requires.
8. Your rights
Under the law, you can ask us:
- what personal data we hold about you, why, and who has received it, and for a copy of it;
- to correct it, or complete it;
- to delete it, where we do not have to keep it;
- to restrict how we use it while a question about it is settled;
- to stop using it, including for any email that is not about something you asked for;
- for a copy you can give to someone else, in a common format;
- to withdraw a consent you gave.
Write to hello@yieldpulse.io with “Privacy request” in the subject, from the address we know you by, or say which it is. We may ask you to confirm it is you. We answer within 30 days, and do not charge for it. Some of this you can do yourself: your account and saved analyses are in your dashboard, a report’s PDF is a download, and you can ask for your account to be deleted from Profile and settings.
If you are not satisfied with our answer, you can complain to the UAE Data Office, the authority for this law.
9. Cookies and similar storage
The site stores a few things in your browser. Some it needs in order to work; those are always on. Everything else is in two classes, analytics and advertising, and none of it loads, is set or is sent before you say yes to that class in the consent banner. If you say no, or say nothing, none of it runs.
You can change your choice, or withdraw it, at any time from “Cookie choices” at the foot of every page. Withdrawing removes the cookies those services set on this site; a script already loaded stops sending and is gone at the next page. If your browser sends the Global Privacy Control signal, we treat it as a no to both classes and do not show the banner; advertising then stays off whatever is chosen.
Essential: always on
| Name | Where, and who sets it | What it is for |
|---|---|---|
| sb-…-auth-token | Browser storage (local). Set by YieldPulse (through Supabase). | Keeps you signed in. Removed when you sign out. |
| yp_consent | Browser storage (local). Set by YieldPulse. | Remembers your cookie choices, so that we do not ask on every page. |
| yieldpulse_guest_reports, yieldpulse_current_guest_report_id | Browser storage (local). Set by YieldPulse. | Keeps an analysis you made without an account, so that it is there when you come back or sign up. |
| yieldpulse_guest_purchase | Browser storage (local). Set by YieldPulse. | Finds a report you opened or bought without an account. |
| yp_calc_draft_v1 | Browser storage (session). Set by YieldPulse. | Keeps the figures you typed into the calculator if you leave the page. |
| yp_pricing_v1 | Browser storage (local). Set by YieldPulse. | Remembers the current price and free period for a few minutes, so that pages show it at once. |
| yp_gate_email, yp_lead_id | Browser storage (session). Set by YieldPulse. | Remembers the email you gave in this visit, so that we do not ask for it again. |
| yp_agent_ref, yp_promo_code | Browser storage (local and session). Set by YieldPulse. | Keeps a referral or promotion code you arrived with, so that it applies at checkout. |
| yp:auto_saved_analysis_id, yp:last_sync, yp:admin:…, pendingVerificationEmail | Browser storage (local and session). Set by YieldPulse. | Account housekeeping: saving an analysis once, confirming an email address. |
| yieldpulse_advisor_settings, yp.report.welcomed | Browser storage (local). Set by YieldPulse. | Display preferences, and whether a report’s opening has been played before in this browser. |
sb-…-auth-token
- Where, and who sets it
- Browser storage (local). Set by YieldPulse (through Supabase).
- What it is for
- Keeps you signed in. Removed when you sign out.
yp_consent
- Where, and who sets it
- Browser storage (local). Set by YieldPulse.
- What it is for
- Remembers your cookie choices, so that we do not ask on every page.
yieldpulse_guest_reports, yieldpulse_current_guest_report_id
- Where, and who sets it
- Browser storage (local). Set by YieldPulse.
- What it is for
- Keeps an analysis you made without an account, so that it is there when you come back or sign up.
yieldpulse_guest_purchase
- Where, and who sets it
- Browser storage (local). Set by YieldPulse.
- What it is for
- Finds a report you opened or bought without an account.
yp_calc_draft_v1
- Where, and who sets it
- Browser storage (session). Set by YieldPulse.
- What it is for
- Keeps the figures you typed into the calculator if you leave the page.
yp_pricing_v1
- Where, and who sets it
- Browser storage (local). Set by YieldPulse.
- What it is for
- Remembers the current price and free period for a few minutes, so that pages show it at once.
yp_gate_email, yp_lead_id
- Where, and who sets it
- Browser storage (session). Set by YieldPulse.
- What it is for
- Remembers the email you gave in this visit, so that we do not ask for it again.
yp_agent_ref, yp_promo_code
- Where, and who sets it
- Browser storage (local and session). Set by YieldPulse.
- What it is for
- Keeps a referral or promotion code you arrived with, so that it applies at checkout.
yp:auto_saved_analysis_id, yp:last_sync, yp:admin:…, pendingVerificationEmail
- Where, and who sets it
- Browser storage (local and session). Set by YieldPulse.
- What it is for
- Account housekeeping: saving an analysis once, confirming an email address.
yieldpulse_advisor_settings, yp.report.welcomed
- Where, and who sets it
- Browser storage (local). Set by YieldPulse.
- What it is for
- Display preferences, and whether a report’s opening has been played before in this browser.
Analytics: only with your consent
| Name | Where, and who sets it | What it is for |
|---|---|---|
| _ga, _ga_… | Cookie. Set by Google Analytics. | Tells one visit from another, to count visits and the steps taken. Up to two years. |
| yp_acquisition (campaign fields) | Browser storage (session). Set by YieldPulse. | The campaign a visit came from (utm_source and the like), kept with an analysis you save. |
_ga, _ga_…
- Where, and who sets it
- Cookie. Set by Google Analytics.
- What it is for
- Tells one visit from another, to count visits and the steps taken. Up to two years.
yp_acquisition (campaign fields)
- Where, and who sets it
- Browser storage (session). Set by YieldPulse.
- What it is for
- The campaign a visit came from (utm_source and the like), kept with an analysis you save.
Advertising: only with your consent
| Name | Where, and who sets it | What it is for |
|---|---|---|
| _fbp, _fbc | Cookie. Set by Meta. | Measures whether our advertising on Facebook and Instagram led to a visit or a purchase. About three months. |
| _gcl_au, _gcl_aw | Cookie. Set by Google Ads. | Measures whether our Google advertising led to a purchase. About three months. |
| li_fat_id, lidc, bcookie, li_gc | Cookie. Set by LinkedIn. | Measures our LinkedIn advertising. Up to two years. |
| yp_meta_event_id, yp_acquisition (click identifiers) | Browser storage (session). Set by YieldPulse. | Matches a purchase in your browser with the same purchase reported by our server, so that Meta counts it once. |
_fbp, _fbc
- Where, and who sets it
- Cookie. Set by Meta.
- What it is for
- Measures whether our advertising on Facebook and Instagram led to a visit or a purchase. About three months.
_gcl_au, _gcl_aw
- Where, and who sets it
- Cookie. Set by Google Ads.
- What it is for
- Measures whether our Google advertising led to a purchase. About three months.
li_fat_id, lidc, bcookie, li_gc
- Where, and who sets it
- Cookie. Set by LinkedIn.
- What it is for
- Measures our LinkedIn advertising. Up to two years.
yp_meta_event_id, yp_acquisition (click identifiers)
- Where, and who sets it
- Browser storage (session). Set by YieldPulse.
- What it is for
- Matches a purchase in your browser with the same purchase reported by our server, so that Meta counts it once.
The names and lifetimes of other companies’ cookies are theirs and can change; these are the ones they documented when this policy was written.
10. Children
The service is for adults buying property. We do not knowingly collect personal data from anyone under 18. If you think we have, write to us and we will delete it.
11. Other sites and the broker directory
A link to another site, including a broker’s website in the mortgage-broker directory, takes you to a site with its own privacy policy. We do not tell a broker who looked at their listing or clicked their link, and we do not pass your details or your figures to any broker. If you contact a broker, what you tell them is between you and the broker.
12. Changes to this policy
When we change this policy we change the date at the top. If a change affects how we use data we already hold, we say so on the site before it takes effect and, if you have an account, by email. Where a change needs your consent, we ask for it.
13. Contact
Constructive FZE LLC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Email hello@yieldpulse.io, or use the contact page.