Your data. Your rules.
We built VOLUME to earn back the trust that Big Real Estate software has burned. That means fewer cookies, clearer data handling, plain-language legal, and the ability to walk away with everything you paid us to make — anytime.
How we handle the stuff you send us.
Encryption at rest + in transit
Every byte you send us is TLS 1.3 in transit. Postgres, storage, and backups are encrypted at rest via industry-standard AES-256. Secrets live in Vercel's environment vault — never in the repo.
Least-privileged access
Row-level security policies are the primary access control. Even a stolen anon key can't read another workspace's tours. Service-role access is limited to a small set of vetted server-side routes.
Password hygiene
We enforce a 10+ character minimum with mixed case, digits, and symbols. Every password is checked against the haveibeenpwned breach corpus at sign-up — via k-anonymity, so your password never leaves your browser.
Audit trail
Every workspace-level action (invite, role change, tour publish, tour delete) is logged. Owners can request a full export for the last 12 months of activity.
Right to portability
You can download every tour as a .ply file at any time — no export button hidden behind a Pro plan, no proprietary format lock-in. If you leave, you leave with your data.
Right to be forgotten
Delete your account and every associated tour, lead, and analytics event is permanently removed within 30 days. We keep audit logs for 12 months for security review, then those are purged too.
Every third party that touches your data.
These are the vendors we've chosen to run VOLUME on. If we ever add or remove one, we'll update this list and notify subscribed customers 30 days in advance.
| Vendor | Role | Data location | Privacy |
|---|---|---|---|
| Vercel | Edge network + serverless functions | USA / global | Policy → |
| Supabase | Postgres, auth, storage | USA (AWS us-east-1) | Policy → |
| Cloudflare | R2 object storage for splat files | Global | Policy → |
| MakeSplat | Gaussian-splat reconstruction | USA | Policy → |
| Stripe | Payments + subscription billing | USA / Ireland | Policy → |
| Sentry | Error + performance telemetry | USA | Policy → |
| Resend | Transactional email delivery | USA / EU | Policy → |
If we don't need it, we don't collect it.
Where we are, where we're going.
GDPR + CCPA aligned
Cookie consent center, right to portability, right to be forgotten, data-processing addendum available on request. We treat every user like a GDPR user by default — no matter their jurisdiction.
Cookie & tracker transparency
We use essential cookies for auth + Vercel Analytics for page-view stats + Sentry for errors. No ad-tech, no marketing pixels, no third-party trackers. You can toggle any category at any time.
SOC 2 Type II
Type I readiness audit scheduled Q1 2027. Full Type II observation window Q2–Q4 2027. If you need a signed security questionnaire before, we can walk through it call-first.
Data residency options
Currently US (Supabase us-east-1 + Cloudflare R2). EU-region availability targeted mid-2027 for customers who require it.
Find a bug? Tell us first.
Security researchers who report vulnerabilities in scope get credit on this page and a personal thank-you from the team. Send findings to security@volumevirtual.com — include a repro, expected vs actual, and (if relevant) a PoC. We reply within 3 business days.
Our security.txt has the machine-readable version.
Need a DPA or security questionnaire?
Real signature, real turnaround. If you're procuring VOLUME for a team of 10+, we'll get you what you need to close.