What we collect, what leaves your computer, and who can see it.
This policy covers the Excel add-ins CRE Data Bridge for Excel and Alpha Data Bridge, the Deal Command portal, this website, Alpha CRE Apprenticeship, and Alpha's consulting work. It is written to be read, not to be survived.
01What this policy covers
Alpha CRE Solutions LLC ("Alpha", "we", "us") builds deal infrastructure for commercial real estate firms and teaches people to build it. This policy describes what personal information the products and services below collect, what we do with it, who else handles it, and how to have it removed. It applies to all of them.
CRE Data Bridge for Excel
The Microsoft Excel add-in listed on Microsoft AppSource. It is the Alpha CRE build, used by students of the course, and it connects to Alpha's teaching sandbox database. That dataset is entirely synthetic.
Alpha Data Bridge
The production build of the same Excel add-in, deployed to Alpha's consulting clients and connected to Alpha's production database. Same mechanics, different database and different accounts.
The Deal Command portal
The browser view of deals that have already been pushed. It signs in against the same accounts and is limited by the same rules as the add-in.
alphacre.io
This website, including the Alpha CRE pages and the newsletter.
Consulting engagements
Work Alpha performs for a client firm under a written agreement, including underwriting, data infrastructure, and reporting.
This document is the privacy policy, and only that
It is not the terms of use, and it is not an end user license agreement. Those are separate documents and nothing in this one replaces them.
02The Excel add-in and the portal
This section describes CRE Data Bridge for Excel and Alpha Data Bridge, the two builds of the Alpha Excel add-in, and the Deal Command portal that reads the same records in a browser. Everything below describes how the software behaves today.
What the add-in reads from your workbook
The add-in is a task pane that runs inside Excel. Excel grants it read and write access to the workbook you have open, which is what lets it write a pulled version back into your model. What it actually reads is narrower than what Excel permits, and the workbook itself decides the boundary:
- The contract sheet, a worksheet named 99_Data_Backend, and the mapping tables on it. Those tables declare, by name, every field and every table the add-in is allowed to move.
- The worksheet tables that those mappings declare, such as a rent table, a capital budget, or an operating pro forma. They can live on other worksheets, but only because the contract sheet names them.
- A short fixed list of named ranges for deal identity and version stamping: property name, address, city and state, unit count, rentable area, year built, deal type, close date, analyst name, and similar.
It does not read worksheets the contract sheet does not declare, it does not read other workbooks, and it has no access to your file system, your email, or your contacts. If you run the Backend Setup Wizard, it lists the defined names and tables already in your open workbook so you can map them. That inspection happens inside Excel on your computer, and nothing from it is transmitted.
What leaves your computer
When you press Push, the add-in sends the values of the declared fields and tables above, as a structured snapshot, together with your sign-in token, over HTTPS on port 443 to Alpha's database. Nothing else is read from the machine and nothing else is sent. Reading in the other direction, such as your deal list, a version history, or a stored version loaded back into the model, is the same kind of HTTPS request for records your account already owns.
The task pane itself is served over HTTPS from a host Alpha operates, and Excel loads Microsoft's own Office runtime from Microsoft. Those are the only hosts involved.
What is stored on your device
- Your password is never stored. Signing in exchanges it for tokens and the password is not kept anywhere on the machine.
- The short-lived access token stays in memory only and is gone when the pane closes.
- One refresh token is stored in the add-in's own storage provided by Office, under the key adb.refresh_token, so you are not asked to sign in every time you open the model. It is replaced each time it is used, and signing out deletes it.
- The identifier of the active deal is written into the workbook itself, in a cell on the contract sheet. It travels with the file if you send the file to someone.
Where it goes, and who can see it
Pushed records are stored in PostgreSQL databases that Alpha owns, hosted on Supabase. The production database used by consulting clients and the Apprenticeship teaching sandbox are separate projects with separate databases and separate accounts. Nothing moves between them.
Isolation is enforced in the database itself. PostgreSQL row-level security is keyed to the token you signed in with, so an account can read and write only its own firm's rows. The one credential that can bypass those rules exists only inside a server-side function that performs the transactional write; it is never present in the code that runs on your machine. Alpha staff who operate and support the service can access stored records; access is limited to the people who need it to do that work.
Every push writes a new version and never overwrites an earlier one. That immutability is the product's purpose, and it is also a retention fact worth knowing: correcting a mistake means pushing a new version, and removing a record means asking us. See section 7.
The Apprenticeship teaching sandbox
The database behind CRE Data Bridge for Excel is a teaching sandbox. Its dataset is 100 percent synthetic, a fictional multifamily portfolio supplied with the course, and students are instructed not to enter their firm's data or any real deal data into it. The only real personal information in that environment is the student's own account: name, email address, and password.
What the add-in does not do
- No advertising, and no advertising identifiers.
- No analytics or telemetry library inside the task pane. The add-in reports nothing about your usage to us or to anyone else.
- No sale of personal information, and no sharing of it for cross-context behavioral advertising.
- No access to your file system, your other workbooks, your email, or your contacts.
- No service credentials in the code that runs on your machine. The key that can bypass row-level security exists only on the server.
03Information we collect
Across all of the products in section 1, this is the whole list.
Account information
Your name, work email address, the firm you belong to, and your role. Your password is handled by our authentication provider and stored as a hash; Alpha cannot read it and never sees it after sign-in.
Deal content you push
The values your workbook declares for a deal: property details, rents, capital costs, operating lines, and the figures your model produces. If you type a person's name, email address, or a note about a broker, tenant, or counterparty into a field that the contract sheet declares, that text is pushed with the rest and stored as part of the deal record.
Deal record activity
Which account pushed which version, when, and any label you gave it. This is the audit trail the product exists to produce.
Support correspondence
What you send us when you ask for help: your message, your address, and any screenshot you attach. We ask you not to send deal data or rent rolls with a support request.
Website usage
Pages viewed, referring link, approximate location derived from your IP address, device and browser type, and a recording of your interactions with the page. See section 4.
Things you submit on the website
Your email address if you subscribe to the newsletter, and your name, email address, and any note you type if you book a call.
Consulting engagements are the one place where Alpha may also receive documents directly from a client, such as rent rolls, operating statements, and leases, which can contain personal information about tenants and counterparties. Alpha handles those under the engagement agreement with that firm, uses them only to perform the work, and returns or deletes them on request.
04This website
alphacre.io uses two measurement tools, both of which set cookies and both of which can be turned off.
- Google Analytics records which pages are viewed, where the visit came from, the device and browser, and an approximate location derived from the IP address.
- Microsoft Clarity records heatmaps and session replays of how pages are used. Text typed into any input field or dropdown is masked by Clarity in every mode and cannot be unmasked, and our forms carry an additional masking attribute on top of that. We use it to see which parts of a page are read and where people get stuck.
Pages that offer a call embed Calendly, and the site loads MailerLite's script for newsletter forms. Both are third parties with their own privacy policies, and both see the information you type into them.
The firm parameter in our email links
Links we send in outreach email sometimes carry a ?firm= parameter naming the company we sent it to. The site remembers it for that browser tab and keeps it on the address bar as you move between pages, so our analytics can attribute the visit to the company. It identifies an organization, not a person, and it is gone when the tab closes.
How to turn measurement off
Visit any page on this site with ?me=1 on the end of the address, for example https://alphacre.io/?me=1. That sets a cookie on that device which stops both Google Analytics and Microsoft Clarity from loading on this site for a year. Clearing your cookies clears the opt-out too, so it has to be set again. Blocking cookies or using your browser's tracking protection works as well, and nothing on this site requires either tool to function.
05How we use information
- To run the products above: sign you in, store the versions you push, and show you your own records.
- To answer support requests and fix what is broken.
- To keep the service secure, including detecting abuse and diagnosing failures.
- To deliver work under a consulting agreement, on the client firm's instructions.
- To understand which pages of this website are useful, in aggregate.
- To send the newsletter, to the people who asked for it, until they unsubscribe.
We do not use your deal content to train machine learning models, we do not use it to build products for other firms, and we do not use it for advertising.
06Who else handles it
Alpha uses a small number of service providers to run the products. Each one only handles what its job requires, and each is bound by its own agreement with us.
Supabase
Managed PostgreSQL and authentication. Holds the deal records, the accounts, and the newsletter list. Alpha owns the projects.
Cloudflare
Serves this website and the add-in task pane, and handles the traffic in front of them.
Microsoft
The Office add-in platform the add-in runs inside; Microsoft Clarity for website session analytics; and Microsoft 365 for Alpha's own email and document storage.
Google
Google Analytics for website measurement.
MailerLite
Sends the newsletter to people who subscribed to it.
Calendly
Schedules calls booked from this website.
FreshLearn
Hosts the Alpha CRE course platform and its student accounts.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. Beyond the providers above, we disclose information only when the law requires it, when we need to protect the service or someone's safety, or as part of a merger or acquisition, in which case this policy continues to apply to the information transferred.
07Retention and deletion
Deal records are kept for as long as the account or the engagement is active, because an audit trail with holes in it is not an audit trail. Pushed versions are immutable by design and are not deleted in the normal course of using the product.
Write to support@alphacre.io and we will delete your account and the records it owns within 30 days, except where we have to keep something for a legal, tax, or contractual reason, and except for routine backups, which expire on their own schedule. For a consulting engagement, the agreement with your firm governs, and we return or delete engagement materials on request when the work ends. Newsletter subscribers can leave using the unsubscribe link in any email, or by writing to us.
08Security
- All traffic runs over HTTPS. There are no open database ports, and the products require no VPN, tunnel, or local certificate.
- Isolation between accounts is enforced by the database with row-level security, not by the application, so a bug in the client cannot hand one firm another firm's rows.
- The credential that can bypass row-level security is held only in a server-side function. It is not in the add-in, the portal, or this website.
- Passwords are never stored by our software; sign-in uses tokens that expire and rotate.
No system is perfectly secure. If you find a weakness, email support@alphacre.io with "Security" in the subject line, as described on our support page. We will confirm receipt and tell you what we are doing about it.
09Your choices
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to support@alphacre.io with "Privacy" in the subject line. We will not treat you differently for asking.
Depending on where you live, you may have additional rights under your state or national privacy law. Tell us which right you are exercising and we will honor it on the timeline that law requires.
One thing to know if you use the add-in through your employer: the deal records belong to your firm's account, not to you personally. If you want a firm's records changed or removed, that request has to come from the firm. Ask your firm's Alpha contact, and we will work with them.
10Children
These are professional products for people doing commercial real estate work. They are not directed at children, we do not knowingly collect personal information from anyone under 18, and if we learn that we have, we delete it.
11Where we operate
Alpha CRE Solutions LLC is a United States company and operates these products from the United States. If you use them from somewhere else, your information is transferred to and processed in the United States. If you need the specific hosting region of a database for a compliance review, ask us and we will tell you.
12Changes to this policy
When this policy changes we post the new version at this address and change the date at the top. If a change materially affects how we handle information for people with accounts, we will also tell those account holders by email. This address does not change, so a link to it always points at the current policy.
13How to reach us
Privacy questions, data requests, and anything about this page go to support@alphacre.io with "Privacy" in the subject line. Product help goes to the same address; our support page explains what to include. New work and pricing go to contact@alphacre.io.
Alpha CRE Solutions LLC. Effective August 6, 2026.
