Privacy Policy
Last updated: October 8, 2026
Past Clients by Pareto ("we," "our," or "us") is operated by Pareto. This Privacy Policy describes how we collect, use, and protect your information when you use our application at pastclients.bypareto.com.
What Data We Collect
- Signup and site usage data: When you fill in the signup form we store the name, email address and phone number you enter, before you sign in with Google. When you visit the site our servers record the page you opened, the link you arrived from and its campaign parameters, the referring website, your browser type and whether you are on a phone or a computer. We do not store your IP address in our own application records; our hosting providers keep standard server logs for their own operational periods. We also use Vercel Web Analytics, which counts page views without cookies and without personal data.
- Google account information: Your name, email address, and profile picture, provided through Google OAuth sign-in.
- Gmail message content: We read transaction-related emails (closing confirmations, title documents, and settlement statements) to extract past client information. We access your Gmail using the
gmail.readonlyscope, which provides read-only access. We never send, modify, or delete any of your emails. - Extracted client data: Names, email addresses, phone numbers, property addresses, closing dates, and transaction roles (buyer/seller) extracted from your emails.
How We Use Your Data
- To scan your Gmail for real estate transaction emails and extract past client information.
- To display extracted client data in your dashboard and allow you to export it as a CSV file.
- To authenticate your identity via Google OAuth.
- Weekly closing check-ins: for as long as your Gmail stays connected, once a week we read only the email that is new since our last look and note whether a deal has closed. We use this to keep your figures current and so Pareto can congratulate you on a closing. It does not add to or change your list. It stops the moment you disconnect your Google account, and you can ask us to stop it at any time at hey@bypareto.com.
- Ongoing monitoring: unlocking your full list turns on a monthly check, which you can switch off at any time in Settings. Each check reads only the email that is new since the last one, looks for new transactions and changes to existing ones, and surfaces them for you to confirm before anything joins your list.
- If you ask for assisted setup: to let a Pareto team member review your extracted client list and add it to your Pareto account, so you can start keeping in touch with those clients. See “Assisted Setup” below.
We do not sell, rent, or share your personal data or extracted client data with any third parties for marketing purposes.
Gmail Access & Limited Use
Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
- We request only
gmail.readonlyaccess — we cannot send, modify, or delete your emails. - Gmail data is used solely to extract past client information from your transaction emails.
- We do not use Gmail data for advertising, market research, or any purpose unrelated to providing you with your past client list.
- We do not allow humans to read your emails unless you provide affirmative consent, it is necessary for security purposes, or it is required by law.
Ongoing Monitoring (Optional)
By default, we read your mailbox only when you start an extraction and are watching it happen. If you choose to enable ongoing monitoring, we check your mailbox on a recurring schedule so that transactions closing after your first extraction are added to your list.
- It is opt-in. Monitoring is off unless you turn it on, and you can turn it off at any time from your dashboard.
- It runs while you are away. These checks happen on a schedule without you present, using the same read-only Gmail permission you already granted. We do not request any additional permission for it.
- It reads the same thing. Monitoring looks at real estate transaction correspondence, exactly as the initial extraction does, and stores the same fields.
- Nothing is added without you. A newly detected transaction is shown to you for confirmation before it joins your client list.
- Stopping it stops the checks. Turning monitoring off, or revoking Gmail access from your Google account permissions, ends them immediately.
Assisted Setup (Optional)
Pareto also makes a product that helps agents keep in touch with their past clients. If you would like the client list this app builds to go into your Pareto account, you can ask us to do that for you. This is the one case in which a person at Pareto looks at data that came from your mailbox, so here is exactly what it involves.
- Only at your request. Assisted setup happens only when you ask for it and give your explicit consent. We record when you did. It is never on by default, and using this app does not enrol you in it.
- Only your extracted list. The team member sees the same table you see in your dashboard: names, contact details, property addresses, closing dates and transaction roles. They do not see your emails. Nothing in this process gives a person access to your mailbox.
- Only for your account. The list is added to your own Pareto account, for you to use. It is not shared with other agents, combined with other agents’ data, or used for any other purpose.
- Under the same rules. Data handled this way remains subject to the Google API Services User Data Policy, including its Limited Use requirements, and to everything else in this policy.
- You can withdraw. Tell us at any time and we will stop. Data already added to your Pareto account is yours and can be deleted from there, or by asking us as described under “Data Deletion”.
Third-Party Services
We use the following third-party services to operate the application:
- Google OAuth: For user authentication. Google receives your sign-in information per their own privacy policy.
- Anthropic (Claude AI): Email content is processed by Anthropic's Claude AI to extract client information. Anthropic processes this data according to their privacy policy. Data sent to the API is not used to train their models.
- Railway (Postgres): Your account data and extracted client information are stored in a PostgreSQL database hosted on Railway.
- Meta Pixel: Our website uses the Meta (Facebook) Pixel so we can measure whether our advertising brings agents to Past Clients. It records that a page was viewed, that the signup form was completed, that Gmail was connected, and that a first extraction finished along with the number of deals it found. It never receives your name, email address, phone number, the contents of any email, or any client data. Meta processes this according to its own privacy policy. You can opt out of Meta's ad personalisation in your Facebook settings or with a browser tracking blocker.
- United States Census Bureau: Property addresses are checked against the Census geocoding service to confirm the correct city, state and ZIP code. Only the property address is sent. No client name, email address or phone number is included.
Data Storage & Security
- Your data is stored in a secured PostgreSQL database hosted on Railway with encrypted connections.
- Google OAuth tokens are encrypted at rest before being written to the database, and are used only to access your Gmail on your behalf.
- We use HTTPS for all data transmission between your browser and our servers.
Your Rights
- Access: You can view all data we have extracted from your emails through your dashboard.
- Export: You can export your extracted client data as a CSV file at any time.
- Revoke access: You can revoke our Gmail access at any time through your Google account permissions.
- Deletion: You can request complete deletion of your account and all associated data by contacting us at the email below.
Data Deletion
To request deletion of your account and all associated data, email us at christian@bypareto.com. We will delete your data within 30 days of receiving your request. When your account is deleted, we remove your Google OAuth tokens, extracted client data, and all other information associated with your account.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date at the top of this page. Your continued use of the application after changes are posted constitutes your acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or your data, contact us at christian@bypareto.com.