- Who We Are
- Information We Collect
- Identity Verification & KYC Data
- Financial Data & GLBA Disclosure
- How We Use Your Information
- How We Disclose Your Information
- Platform-Specific Data Practices (app.lapisglobal.us)
- Cookies & Tracking Technologies
- Data Retention
- Security
- California Privacy Rights (CCPA / CPRA)
- Do Not Sell or Share My Personal Information
- Other U.S. State Privacy Rights
- International Data Transfers & Mexican Law (LFPDPPP)
- Children's Privacy
- Third-Party Links
- Changes to This Policy
- Contact & Data Requests
Who We Are
LAPIS Global LLC ("LAPIS," "we," "our," or "us") is a Wyoming limited liability company (Registration No. 2026-001860036) operating a technology platform for real estate project management and coordination. Our principal services are accessible at lapisglobal.us (marketing website) and app.lapisglobal.us (the "Platform").
This Privacy Policy describes how LAPIS collects, uses, discloses, and protects personal information about Users of our website and Platform. By accessing or using our services, you agree to the practices described in this Policy. If you do not agree, please do not use our services.
For privacy-related inquiries, contact our Data Protection contact at: privacy@lapisglobal.us
Information We Collect
We collect information in several ways depending on how you interact with our website and Platform:
A. Information You Provide Directly
- Account Registration: Name, email address, phone number, password, and role (investor, broker, project owner, contractor).
- Profile Information: Professional credentials, company name, jurisdiction, years of experience.
- Project Data: Property addresses, project descriptions, budget information, timelines, uploaded documents and plans.
- Communications: Messages sent through the Platform, support requests, and feedback.
B. Automatically Collected Information
- IP address, browser type, device identifiers, operating system;
- Pages viewed, features accessed, session duration, click-stream data;
- Cookies and similar tracking technologies (see Section 8);
- Log data including access times and error logs.
C. Information from Third Parties
- Identity verification data from KYC/AML service providers;
- Credit or background screening data where permitted by law;
- Data from financial institutions regarding escrow account status;
- Publicly available information to verify identity or credentials.
Identity Verification & KYC Data
The Platform (app.lapisglobal.us) requires identity verification for all registered users. As part of our Know Your Customer (KYC) and Anti-Money Laundering (AML) compliance obligations, we collect sensitive personal information including government-issued identification.
Specifically, the Platform collects and processes the following sensitive personal information as required for KYC compliance:
- Government-Issued Photo ID: Passport, driver's license, national identity card, or equivalent document (front and back images).
- Social Security Number (SSN) for U.S. individual users;
- Employer Identification Number (EIN) for U.S. business entities;
- Foreign Tax Identification Number (TIN) for non-U.S. persons;
- Date of Birth;
- Proof of Address (utility bill, bank statement, or government document);
- Entity Formation Documents for business users (articles of organization, operating agreement, certificate of good standing);
- Beneficial Ownership Certification for entities with 25%+ owners, as required under FinCEN rules;
- Source of Funds Declaration.
This information is collected under legal obligation (AML/BSA compliance, FinCEN regulations) and is necessary to provide Platform services. We cannot offer Platform access without completing identity verification.
Document Image Processing: Government ID images are processed using automated identity verification technology that may involve biometric processing (facial recognition, liveness detection) to confirm document authenticity. If you are a resident of a state with biometric privacy laws (including Illinois under the Biometric Information Privacy Act ("BIPA"), Texas, Washington, or others), you will be presented with a specific biometric consent disclosure prior to any biometric data processing. You may contact us at privacy@lapisglobal.us to inquire about biometric data handling.
KYC data is shared with our identity verification service provider(s) and retained in accordance with our legal obligations (see Section 9). We do not sell KYC or government identification data to any third party.
Financial Data & GLBA Disclosure
As a technology platform facilitating real estate investment transactions, LAPIS may collect and process financial information from Platform users, including:
- Bank Account Information: ACH routing numbers and bank account numbers provided for funding escrow accounts or receiving distributions;
- Wire Transfer Information: Beneficiary account details for project-related wire transfers;
- Wallet Transaction History: Records of Platform wallet activity, including escrow funding, fee deductions, and balance history;
- Investment Amounts: Capital commitment amounts, funding dates, and project participation records;
- Tax Information: W-9 or W-8BEN forms, TIN certifications.
Gramm-Leach-Bliley Act (GLBA) Notice. To the extent LAPIS is subject to the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) as a financial institution, we are required to inform you of our information-sharing practices with respect to nonpublic personal financial information ("NPI"). We do not sell your NPI to third parties. We share NPI only as described in this Policy — with service providers acting on our behalf, with financial institutions administering escrow accounts, and as required by law. You may have rights under your state's financial privacy laws in addition to GLBA.
Financial data is transmitted and stored using industry-standard encryption (TLS in transit, AES-256 at rest). ACH and banking information is used solely for the purpose for which it was provided and is not retained longer than necessary for that purpose.
How We Use Your Information
We use the information we collect for the following purposes:
- Platform Services: To create and manage your account, provide project management tools, process transactions, and deliver the services you request.
- KYC / AML Compliance: To verify your identity, comply with anti-money laundering laws, screen against OFAC sanctions lists, and fulfill FinCEN reporting obligations.
- Financial Operations: To facilitate escrow account setup, process wallet transactions, and coordinate with financial institutions on your behalf.
- Tax Compliance & Reporting: To collect and report TINs and other information required by the IRS, FinCEN, or other tax authorities.
- Communications: To send transactional emails, platform notifications, and service-related updates. With your consent, to send marketing communications.
- Safety & Security: To detect fraud, prevent unauthorized access, and protect the integrity of the Platform.
- Legal Compliance: To comply with applicable laws, respond to legal process, and enforce our Terms & Conditions.
- Analytics & Improvement: To analyze usage patterns, improve Platform features, and develop new services. We use aggregated, de-identified data for these purposes where possible.
- Dispute Resolution: To investigate and resolve disputes between users and Contractors.
Legal Basis (for GDPR / international reference): Processing is based on contract performance (to provide services), legal obligation (KYC/AML compliance), legitimate interest (security and fraud prevention), and consent (marketing).
How We Disclose Your Information
We do not sell your personal information to third parties for their own marketing purposes. We may share your information in the following circumstances:
- Service Providers: With vendors and contractors who assist us in operating the Platform, including identity verification providers (KYC), cloud infrastructure (Supabase, Vercel), email delivery, analytics, and customer support. These providers are contractually obligated to protect your information and use it only for the services they provide to us.
- Financial Institutions: With banks, escrow agents, and payment processors necessary to establish and operate your escrow account and process transactions.
- Other Platform Users: Limited profile information (name, role, project affiliation) is visible to other users within shared projects. You control what project information is shared through the Platform's access permissions.
- Contractors: If you engage a Contractor through the marketplace, relevant contact and project information is shared with that Contractor to facilitate the engagement.
- Legal & Regulatory Authorities: When required by law, court order, subpoena, or government demand, including FinCEN (SAR filings), the IRS (information reporting), and OFAC (sanctions compliance). We may also disclose information to prevent or investigate fraud, protect safety, or enforce our Terms.
- Business Transfers: In connection with a merger, acquisition, financing, or sale of LAPIS assets, personal information may be transferred to the acquiring entity, subject to the same protections described in this Policy.
- With Your Consent: For any other purpose with your explicit consent.
Platform-Specific Data Practices (app.lapisglobal.us)
The LAPIS Platform at app.lapisglobal.us is a separate application from our marketing website (lapisglobal.us) and involves more extensive data collection due to the nature of the services provided. The following data practices apply specifically to Platform users:
Database Infrastructure: Platform data (user profiles, project records, documents, wallet transactions) is stored in Supabase, a cloud database platform hosted on Amazon Web Services (AWS) infrastructure. Data may be stored in data centers located in the United States. Supabase is a sub-processor acting under contract with LAPIS.
Document Storage: Project documents, engineering plans, permit filings, and identity documents uploaded to the Platform are stored in encrypted cloud storage. Access is controlled by Platform authentication and role-based permissions.
Activity Logs: The Platform maintains detailed audit logs of user actions (document uploads, approvals, payments, status changes) for compliance, dispute resolution, and security purposes. These logs are retained for a minimum of 5 years.
Session Data: The Platform collects session tokens, authentication timestamps, and device fingerprints to maintain secure sessions and detect unauthorized access.
Project Collaboration Data: When multiple users collaborate on a project (e.g., investor, broker, and project owner), the Platform enables data sharing among those parties within the scope of the project. Each user can view project data consistent with their assigned role and permissions.
Wallet & Transaction Data: All Wallet activity — including funding amounts, service fee deductions, and transaction history — is logged and retained as required for financial recordkeeping and tax reporting compliance.
Cookies & Tracking Technologies
Our website (lapisglobal.us) uses cookies and similar technologies to enhance user experience and analyze site performance. Our Platform (app.lapisglobal.us) uses session cookies and authentication tokens that are strictly necessary for Platform operation.
Types of cookies we use:
- Essential / Strictly Necessary: Authentication tokens, session management, CSRF protection. These cannot be disabled without breaking Platform functionality.
- Analytics: We may use analytics tools (such as Google Analytics or similar) on our marketing website to understand traffic patterns. These tools may set cookies or use pixel tags. Analytics data is aggregated and de-identified where possible.
- Marketing / Advertising: Our marketing website may use tracking pixels (including Meta Pixel for Facebook/Instagram advertising) to measure ad effectiveness and enable audience targeting. These are used only on lapisglobal.us, not within the authenticated Platform.
Your Choices: You may control cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing cookies. Note that disabling essential cookies will impair Platform functionality. For California residents and other state residents with opt-out rights, see Sections 11–13.
We do not use cookies or tracking technologies to build profiles for purposes unrelated to our services.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
- Account and Profile Data: Retained for the duration of your account plus 3 years after closure, unless a longer period is required by law.
- KYC / Identity Verification Data: Retained for a minimum of 5 years after the end of the customer relationship, as required by BSA/AML regulations (31 C.F.R. § 1020.220).
- Financial Records & Transaction Data: Retained for a minimum of 5–7 years as required by IRS regulations and FinCEN rules.
- Project Documents: Retained for the duration of the project plus 7 years, or longer if required by applicable law or ongoing litigation.
- Audit Logs & Activity Records: Retained for a minimum of 5 years for compliance and dispute resolution purposes.
- Marketing Communications Data: Retained until you opt out, plus a reasonable period to process opt-out requests.
When data is no longer needed, we delete or anonymize it using secure methods. Some information may be retained in anonymized or aggregated form for analytics purposes after deletion of personal identifiers.
Security
LAPIS implements technical, administrative, and organizational security measures designed to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include:
- TLS encryption for all data transmitted between your browser and our servers;
- AES-256 encryption for data stored at rest in our database infrastructure;
- Row-level security (RLS) in our database to ensure users can only access data within their authorized scope;
- Multi-factor authentication options for Platform accounts;
- Regular security assessments and penetration testing;
- Access controls limiting employee and service provider access to personal data on a need-to-know basis;
- Incident response procedures for data breach detection and notification.
No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you as required by applicable state breach notification laws, including Wyoming's data breach notification statute (Wyo. Stat. § 40-12-501 et seq.) and the laws of states where affected users reside.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information:
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions (e.g., information we are required to retain by law, including KYC/AML records).
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: You have the right to opt out of the "sale" or "sharing" of your personal information. See Section 12 for how to exercise this right.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use of sensitive personal information (including SSN, government ID, financial account information, and biometric data) to purposes necessary to provide the services you requested.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise your California privacy rights, submit a verifiable consumer request to privacy@lapisglobal.us or by written request to our address in Section 18. We will respond within 45 days of receipt of a verifiable request (extendable by an additional 45 days with notice).
Sensitive Personal Information We Collect: As disclosed in Sections 3 and 4, we collect sensitive personal information including government-issued ID numbers (SSN, EIN, passport number), financial account information (ACH routing and account numbers), and biometric data for identity verification. This information is collected solely to provide our services and fulfill legal obligations and is not used for purposes beyond those disclosed.
California Shine the Light: California Civil Code § 1798.83 permits California residents to request a list of third parties to whom we have disclosed personal information for direct marketing purposes in the preceding year. We do not share personal information with third parties for their direct marketing purposes.
Do Not Sell or Share My Personal Information
Your Opt-Out Right
Under CCPA/CPRA and similar state laws, you have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising.
Submit Do Not Sell / Share RequestLAPIS does not sell personal information in exchange for monetary consideration. However, our marketing website (lapisglobal.us) uses advertising pixels (including Meta Pixel) that may constitute "sharing" of personal information under CCPA/CPRA for cross-context behavioral advertising purposes.
If you wish to opt out of the sharing of your information for cross-context behavioral advertising, you may:
- Email us at privacy@lapisglobal.us with the subject line "Do Not Sell or Share My Personal Information";
- Use the Global Privacy Control (GPC) browser signal, which we honor for California residents;
- Opt out directly through your ad settings on platforms such as Meta (Facebook/Instagram).
Opt-out requests from authenticated Platform users (app.lapisglobal.us) are handled separately — within the authenticated Platform we do not use marketing pixels or engage in cross-context behavioral advertising.
We will process your opt-out request within 15 business days and confirm completion by email.
Other U.S. State Privacy Rights
Residents of the following states have privacy rights similar to those described for California residents under their respective state laws:
- Virginia (VCDPA): Rights to access, correct, delete, port, and opt out of targeted advertising and profiling.
- Colorado (CPA): Rights to access, correct, delete, port, and opt out of targeted advertising, profiling, and sale of personal data.
- Connecticut (CTDPA): Similar rights to access, correct, delete, port, and opt out.
- Texas (TDPSA): Rights to access, correct, delete, port, and opt out of sale or processing for targeted advertising.
- Nevada (NRS 603A): Right to opt out of the sale of covered information.
- Other States: As new state privacy laws take effect, LAPIS will update this Policy and honor applicable rights.
To exercise any state privacy right, please contact us at privacy@lapisglobal.us with your name, state of residence, and a description of your request. We will respond within the timeframe required by applicable state law. We will not discriminate against you for exercising any privacy right.
Where permitted, we may require verification of your identity before processing a request. We will use the information you provide solely for identity verification and will not retain it for other purposes.
International Data Transfers & Mexican Law (LFPDPPP)
LAPIS Global LLC is a U.S. company operating a platform that facilitates real estate projects located in Mexico. As a result, personal information flows between the United States and Mexico in the course of our operations.
Mexico — LFPDPPP Compliance. To the extent that LAPIS processes personal data of individuals located in Mexico (including Mexican project partners, contractors, or brokers using the Platform), LAPIS acknowledges the applicability of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) and its regulations. Such individuals have the right to Access, Rectification, Cancellation, and Opposition ("ARCO Rights") with respect to their personal data processed by LAPIS. ARCO Rights requests may be submitted to privacy@lapisglobal.us.
Cross-Border Data Transfers. Personal data collected in Mexico may be transferred to and stored on servers located in the United States. Such transfers are made pursuant to an international transfer agreement or other legal mechanism that ensures an adequate level of protection for personal data as required by LFPDPPP Article 37.
U.S. Data Storage. All Platform data is primarily stored in cloud infrastructure (Supabase / AWS) in the United States. By using the Platform, non-U.S. users consent to the transfer of their personal information to the United States, where privacy laws may differ from those in their home country.
GDPR / International Users. LAPIS does not currently target EU residents. If EU residents use the Platform, we will apply appropriate data protection measures consistent with GDPR principles, including data processing agreements with service providers and applying data subject rights upon request.
Children's Privacy
The Platform and website are not directed to, and are not intended for use by, individuals under the age of 18. We do not knowingly collect personal information from minors under 18. If we become aware that we have inadvertently collected personal information from a minor under 18, we will promptly delete such information.
If you believe we have collected information from a minor, please contact us immediately at privacy@lapisglobal.us.
Third-Party Links
Our website and Platform may contain links to third-party websites or services that are not operated by LAPIS. We are not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party site you visit through links from our Platform.
Key third-party services integrated into the Platform include: Supabase (database and auth infrastructure), Vercel (web hosting), Google Fonts (typography), and Meta Business Tools (marketing analytics on marketing website only). Each of these providers operates under its own privacy policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on this page and update the "Last Updated" date at the top.
For material changes — particularly those affecting how we handle sensitive personal information or financial data — we will provide additional notice via email to registered Platform users at least 30 days before the change takes effect, where feasible.
Your continued use of the Platform after the effective date of any updated Policy constitutes acceptance of the new terms. If you object to any change, you may close your account by contacting us at support@lapisglobal.us.
Contact & Data Requests
For privacy inquiries, to exercise your data rights, or to submit a data deletion, correction, or access request, please contact us:
LAPIS Global LLC — Privacy / Data Protection
30 N Gould St, Ste R, Sheridan, Wyoming 82801, USA
Email: privacy@lapisglobal.us
Subject line for data requests: "Privacy Request — [Your Name] — [Type of Request]"
To protect your information and comply with verification requirements, we may ask you to verify your identity before processing certain requests. We will respond within the timeframe required by applicable law (typically 45 days for CCPA; 30–45 days for other state laws).
This Privacy Policy was last reviewed and updated on June 26, 2026. It supersedes all prior versions of LAPIS Global LLC's Privacy Policy.