Privacy Policy
Last updated: September 19, 2026
Adapted from the CertPilot terms for the EstoppelPilot service; under counsel review. Your signed service agreement controls where the two differ.
EstoppelPilot is a service of Taro Ventures, LLC (“we”, “us”) that helps community-association management companies draft Florida estoppel certificates from their own inbox and records. This policy explains what information we handle, why, and the rules we hold ourselves to. The short version: your data is yours, we touch only what the service needs, we never sell it, and you can revoke our access at any time.
Information we handle
- Account information — the name and email address of each dashboard user, and login credentials (passwords are stored only as secure hashes by our authentication provider).
- Firm details and fees — the business information you enter (name, address, phone, estoppel desk email, the licensed manager who signs, your fee schedule), printed on certificates.
- Associations and parcel ledgers — the association, parcel, owner, and balance records your company uploads. This is your data; we store it solely to fill certificates from it.
- Estoppel request emails — when a certificate request arrives in the mailbox you connect, EstoppelPilot reads that message to identify the insured, the requesting party, and any requested wording, and records this activity (requester, association and parcel, requesting party, outcome, timing) in your activity log. To do this, the email content is sent to our AI service provider (Anthropic) solely to extract the requested information — see “Where your data goes” below. That data is not used to train AI models.
- Technical records — service logs and monitoring signals needed to keep the service running and secure.
Your book of business and third-party contacts
Your book of business may include the names, business addresses, and contact information of your insured clients and the requesting parties they interact with. You control what you upload and are responsible for ensuring you're authorized to share it with us — including, where applicable, your own notices to those contacts about how their information is used. We process this information only on your instructions, solely to provide the Service (matching requests, filling certificates, and maintaining your activity log); we don't use it for any other purpose.
How we access your mailbox
Access is granted by you and scoped to the single estoppel mailbox you designate — for Google Workspace, through domain-wide delegation authorized by your administrator; for Microsoft 365 or Outlook, through a sign-in you complete as the mailbox owner. EstoppelPilot reads incoming estoppel requests received after your go-live date and saves draft replies. It never sends email — every certificate leaves your company only when a person on your team clicks send. You can revoke this access at any time (Google Admin console, or the mailbox account's Microsoft security settings), which immediately ends our ability to read the mailbox. We never access mail that arrived before you went live.
How we use information
- To operate the service: matching requests to your associations and parcels, filling certificate PDFs, saving reply drafts, and showing your activity dashboard.
- To count monthly usage for billing under your service agreement.
- To monitor reliability and investigate problems you report.
We do not sell or rent your information, use it for advertising, or use your data to train AI models. Our website uses only the cookies strictly necessary to sign you in — no analytics or advertising cookies.
Where your data goes
We use a small set of infrastructure providers to deliver the service, each receiving only what their role requires:
- Google Cloud — the service accounts and APIs through which Google Workspace mailbox access operates.
- Microsoft — the identity and Graph APIs through which Microsoft 365/Outlook mailbox access operates.
- Supabase — our database, where your company details, book of business, and activity log are stored (United States,
us-east-1). - Railway — hosting for your dedicated processing instance and this dashboard (United States).
- Anthropic — the AI service that reads estoppel request emails to extract what is being asked. Data sent through this API is not used to train models.
- Healthchecks.io — uptime monitoring (receives only service-alive signals, never your data).
- Stripe — payment processing (United States) for invoices and subscriptions (receives billing contact and payment details you provide to it directly).
This list is kept current. If we add or replace a provider that processes your data, we will notify account holders by email before the change takes effect. If your company needs a signed data processing addendum for its own compliance program, contact us — we'll put one in place alongside your service agreement.
Retention and deletion
We keep your information while your account is active. We do not store your email. A certificate request is read as it is processed and what we keep is the extracted record — requester, insured, requesting party, outcome, timing, and a reference to the message in your own mailbox. The message itself, its attachments, and the certificate PDFs we generate stay in your mailbox; our processing copies are temporary. Email content is sent to our AI provider only to extract the certificate details for that message; that provider may briefly retain API data under its own policies for abuse monitoring, does not use it to train models, and does not retain it on our behalf beyond that window.
When your service ends:
- Within one business day — mailbox credentials are destroyed, the service account or token through which we reached your mailbox is deleted, your dedicated processing instance is shut down, and dashboard access ends. Your own revocation of mailbox access completes the separation and is available to you at any time, with or without notice to us.
- Within 10 business days — we provide a machine-readable export of your book of business and your complete activity log, available to you for 30 days.
- At 30 days — your book of business, agency details, credentials, and dashboard accounts are permanently deleted.
- Your activity log is retained for the period stated in your service agreement, then permanently deleted. It is the record evidencing what was prepared, from which request, and that your licensed personnel reviewed and sent it — the documentation your company may need if a certificate is questioned after the fact. It contains no email content. After that period we keep only de-identified monthly volume counts as our own financial records, holding no parcel owner names, requesting parties, or requester addresses.
If you would rather we delete the activity log sooner, ask us in writing and we will do so, and confirm in writing what was deleted and when.
Security
- All data moves over encrypted connections (TLS) and is stored with encryption at rest by our database provider.
- Mailbox credentials are held server-side only and are scoped to your single designated mailbox.
- Dashboard accounts are created by invitation only; there is no self-registration.
- Your processing runs in an instance dedicated to your company, with its own credentials — not a shared pool.
- Mailbox credentials are stored where no dashboard user, of any agency, can read them; only our server-side service can.
- Access to production data on our side is limited to named personnel with a business need.
- If we become aware of a security incident affecting your data, we notify your designated security contact without undue delay and within 72 hours of confirming it, so your company can meet its own reporting obligations, including notice to your insurance regulator where one applies.
Your choices and rights
- Access, correct, or delete your company's records by using the dashboard or contacting us.
- Revoke mailbox access at any time via your Google Admin console or the mailbox account's Microsoft security settings.
- End the service per your agreement, which triggers the deletion described above.
California privacy rights
If you or your contacts are California residents, the CCPA gives you rights to know, delete, and correct personal information we hold, and the right not to be discriminated against for exercising them. We do not sell personal information or share it for cross-context behavioral advertising. To make a request, contact us below; we may need to verify your identity or relationship to the account before responding.
Children
EstoppelPilot is a business tool for licensed community association management companies. It is not directed to children, and we do not knowingly collect information from anyone under 16.
Changes and contact
If we make material changes to this policy we will notify account holders by email at least 30 days before the changes take effect. Questions or requests: [email protected].