privateproperty.mt Logo

Privacy Policy

Last Updated: October 17, 2025

1. Introduction

PrivateProperty.mt ("we," "us," or "our") operated by Private Property Malta is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Platform.

We are the data controller for the personal information we collect through the Platform. We are committed to complying with the General Data Protection Regulation (GDPR) and Malta Data Protection Act.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name (first and last name)
  • Email address
  • Password (encrypted and securely hashed)
  • Phone number (optional)
  • Account type (landlord, tenant, agent, sub-agent, or advertiser)
  • Profile photo/avatar (optional)
  • Registration date and IP address
  • Registration country (from IP geolocation)

2.2 Landlord Information

For landlords, we additionally collect:

  • Property ownership documentation (optional, for verification)
  • Property listing details (address, description, photos, pricing)
  • Credit purchase history and boost usage
  • Property analytics and views data
  • Languages spoken
  • Auto-reply message templates

2.3 Tenant Information

For tenants, we collect comprehensive profile data to help landlords and agents assess applications:

  • Basic Info: Name, email, phone, nationality, country, current location
  • User Intent: Long-term rental, short-term rental, buying, investment
  • Account Type: Individual, family, corporate, student, relocating
  • Financial Info: Employment status, employer, occupation, income range, credit score range
  • Buyer Info: Buyer status, financing status, mortgage preapproval amount, ready to purchase timeline
  • Rental Preferences: Budget range, rental duration, move-in date, number of occupants
  • Lifestyle: Pet ownership, smoking preference, guarantor information
  • Location Preferences: Preferred islands, regions, towns, commute location
  • Verification Documents: ID documents, proof of income, landlord references (optional)
  • Social Links: LinkedIn, Facebook, professional website (optional)
  • Activity Data: Properties viewed, inquiries sent, viewings attended
  • Trust Score: Calculated score (0-100) based on profile completion and verifications

2.4 Real Estate Agent Information

For real estate agencies, we collect:

  • Agency name, business type, and registration details
  • Business registration number and VAT number
  • License number and license documentation
  • Business certificate and ID documents
  • Contact person name and details
  • Agency logo and branding materials
  • Subscription billing information and payment history
  • Credit purchase and boost usage history
  • Tenant leads and lead management data
  • Sole mandate documentation for exclusive listings
  • Sub-agent account information
  • Agency performance analytics

2.5 Third-Party Advertiser Information

For advertisers, we collect:

  • Business name and contact person details
  • Email address and phone number
  • Country and business information
  • Campaign content (images, headlines, descriptions)
  • Target audience specifications
  • Credit purchase history
  • Campaign performance analytics

2.6 Communication Data

  • Messages sent through in-app messaging system
  • Message timestamps and read receipts
  • Conversation history and status
  • User reports and flagged content
  • Support ticket communications

2.7 Payment Information

  • Payment details are processed by Stripe (we do not store credit card numbers)
  • Transaction history for subscriptions, boost credits, and advertiser campaigns
  • Bank transfer references and proof documents (for bank transfer payments)
  • Stripe customer IDs for subscription management
  • Billing addresses and tax information

2.8 Usage Information & Analytics

  • Pages visited and time spent on Platform
  • Property searches and filters used
  • Listing views with IP address and session data
  • Click tracking for boost performance
  • Browser type and device information
  • Referrer URLs and traffic sources
  • Feature usage and interaction patterns
  • Last active timestamps and login history

3. How We Use Your Information

We use your personal information for the following purposes:

  • Platform Services: To provide and improve Platform functionality, property listings, search, and messaging
  • User Matching: To facilitate connections between landlords, tenants, and agents
  • Communication: To enable messaging between users and send notification emails
  • Payment Processing: To process subscription payments, credit purchases, and billing
  • Account Management: To create and manage user accounts, authentication, and access control
  • Verification: To verify user identities, property ownership, and business licenses
  • Lead Management: To capture and manage tenant leads for agents
  • Analytics: To track property views, boost performance, and platform usage
  • Fraud Prevention: To detect and prevent fraudulent activity, scams, and abuse
  • Legal Compliance: To comply with legal obligations and respond to legal requests
  • Marketing: To send marketing communications (with your consent)
  • Support: To provide customer support and respond to inquiries

4. How We Share Your Information

4.1 With Other Users

When you use the Platform, certain information is visible to other users:

  • Landlords & Agents: Your name, profile information, verification badges, and messages you send are visible to tenants who inquire
  • Tenants: Your profile, verification badges, and search preferences may be visible to landlords and agents when you inquire about properties
  • Property Listings: Property information posted by landlords and agents is publicly visible on the Platform
  • Lead Data: When tenants inquire about agent listings, their profile information is shared with the agent as a lead
  • Agency Profiles: Agency information, branding, and public profiles are visible to all users

4.2 With Service Providers

We share information with trusted third-party service providers:

  • Stripe: Payment processing, subscription billing, and transaction management
  • Supabase: Database hosting, file storage, and data management
  • Brevo: Transactional emails, message notifications, and email delivery
  • Google Maps: Location services, geocoding, and map display
  • Cloudflare Turnstile: Security verification and bot protection
  • Netlify: Platform hosting, CDN, and edge functions

These service providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.3 For Legal Requirements

We may disclose information if required to:

  • Comply with legal obligations, court orders, or subpoenas
  • Enforce our Terms of Service and policies
  • Protect our rights, property, and safety
  • Protect the rights, property, and safety of our users
  • Investigate and prevent fraud, security issues, or illegal activity
  • Cooperate with law enforcement or regulatory authorities

4.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your personal information may be transferred. We will notify you of any such change and provide choices regarding your information.

4.5 With Your Consent

We may share your information for other purposes with your explicit consent.

5. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data transmission uses HTTPS/TLS encryption
  • Password Security: Passwords are hashed using bcrypt with 12 rounds
  • Database Security: Secure PostgreSQL database hosted by Supabase with Row Level Security (RLS)
  • Payment Security: PCI-compliant payment processing through Stripe
  • Access Controls: Role-based access control and authentication for all user types
  • Audit Trails: Comprehensive logging for listing views, message access, and sensitive operations
  • Session Management: HTTP-only cookies for authentication tokens
  • Security Verification: Cloudflare Turnstile for bot protection
  • Regular Updates: Security patches and updates applied regularly

While we strive to protect your personal information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of Access: Request a copy of your personal data we hold
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing of your data for specific purposes
  • Right to Restriction: Request limitation of data processing
  • Right to Withdraw Consent: Withdraw consent for data processing at any time
  • Right to Lodge a Complaint: File a complaint with a supervisory authority

To exercise these rights, please contact us through our contact page. We will respond within one month of your request.

7. Data Retention

We retain your personal information for as long as necessary to provide services and comply with legal obligations:

  • Account Data: Retained while your account is active and for 90 days after account deletion
  • Property Listings: Retained while active; archived listings kept for 1 year
  • Messages: Retained for 1 year after last activity in conversation
  • Transaction Records: Retained for 7 years (Malta legal requirement for financial records)
  • Verification Documents: Retained for 2 years after account closure for audit purposes
  • Lead Data: Retained by agents; deleted if agent account is terminated or tenant requests deletion
  • Analytics Data: Aggregated and anonymized analytics retained indefinitely
  • Legal Records: Records related to legal matters retained as required by law

8. Cookies and Tracking Technologies

We use cookies and similar technologies to provide and improve our services. See our Cookie Policy for detailed information about:

  • Authentication cookies for all 6 user types
  • Session management cookies
  • Analytics and performance cookies
  • Third-party service cookies (Stripe, Google Maps, Turnstile)
  • How to manage and opt-out of cookies

9. Children's Privacy

Our Platform is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we discover that we have collected information from a child under 18, we will delete it immediately.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

10. International Data Transfers

Your personal information may be transferred to and processed in countries outside Malta and the European Union, including the United States where our service providers (Stripe, Supabase, Netlify) operate.

We ensure appropriate safeguards are in place for such transfers, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Privacy Shield certification (where applicable)
  • Adequate data protection agreements with service providers
  • Compliance with GDPR requirements for international transfers

11. Marketing Communications

With your consent, we may send you marketing communications about:

  • New property listings matching your preferences
  • Platform updates and new features
  • Special offers and promotions
  • Property market insights and guides

You can opt-out of marketing communications at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Updating your notification preferences in account settings
  • Contacting us to request removal from marketing lists

Note: You cannot opt-out of transactional emails (account notifications, message alerts, payment confirmations) as these are essential for Platform functionality.

12. Changes to Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make significant changes:

  • We will notify you via email to your registered email address
  • We will post a notice on the Platform
  • We will update the "Last Updated" date at the top of this policy
  • Material changes will have a 30-day notice period before taking effect

Continued use of the Platform after changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

Data Controller: Private Property Malta
Registered in: Malta
Platform: PrivateProperty.mt

For privacy-related questions, to exercise your rights, or to report privacy concerns:

We will respond to your privacy requests within one month.