Effective August 21, 2026
1. Scope
This policy covers this website and the FAPG Trust Desk application.
The two are very different in what they collect, so they are described separately below. The website collects essentially nothing; the application, by necessity, collects a great deal.
2. This website collects no personal information
No cookies, no analytics, no third-party scripts
This site sets no cookies, uses no local storage, embeds no third-party content, runs no analytics, and loads no fonts or scripts from another domain. There is no form on it. A Content-Security-Policy served with every page restricts the browser to this origin, which is what makes that claim checkable rather than merely stated.
Our hosting provider records standard server request logs, including IP address, request time, and user agent, for security and reliability purposes. We do not use those logs to build a profile of you and do not combine them with application data.
3. What the application collects
| Category | Examples | Why |
|---|---|---|
| Identifiers | Name, email address, postal address, telephone number | To identify the parties and prepare instruments naming them correctly |
| Sensitive identifiers | Social Security or taxpayer identification number, government identification documents, date of birth | Required for trust tax reporting, identity verification, and to establish that the person signing is the person named on title |
| Financial information | Loan servicer, loan balance, monthly payment, purchase price, cash to seller | To prepare the conveyance and disclosure documents and to compute transfer tax |
| Property information | Address, county, parcel identifiers, occupancy | To apply the correct state and county rules and to describe the property in a recordable instrument |
| Marital and household information | Marital status, spouse name | Homestead and community-property rules require a non-title spouse to join some conveyances |
| Identity verification results | Pass or fail outcome, provider reference, method | To make an electronic signature attributable and defensible |
| Transaction records | What you acknowledged and when, signature events, document hashes | To evidence disclosure and execution |
| Payment information | Handled by our payment processor; we receive a token and the last four digits | To authorize and capture payment |
4. Confidential identifiers are stored so nobody can read them back
Social Security numbers and comparable identifiers are held separately from the rest of your file. No party to the transaction can read them — including you. There is no product reason to display your own SSN back to you, and a value that is never displayed cannot be displayed to the wrong person.
Staff access to those values requires a written reason and creates a permanent, non-editable audit entry naming who accessed the value and why.
5. What the other party can see
Field visibility is an explicit allow-list with default deny. The other party sees only the fields necessary to the transaction, and each of those fields has a recorded reason for being visible.
The counterparty is told that you passed identity verification. They are not told how, and they do not receive the underlying documents or the provider's reference.
6. How we use information
- To prepare, review, and deliver the documents for your transaction
- To verify identity and to make electronic signatures attributable
- To run compliance checks, including jurisdiction and disclosure requirements
- To authorize and capture payment and to reconcile pass-through costs
- To communicate with you about your file
- To keep records we are required to keep, and to detect and prevent fraud and abuse
We do not use your information to train machine-learning models, and we do not use it for behavioural advertising.
7. Who we disclose information to
| Recipient | What they receive | Why |
|---|---|---|
| The other party to your transaction | Only the allow-listed fields described above | The transaction cannot be documented otherwise |
| Supervising counsel | The file, where a state requires attorney review | Legal review of the jurisdiction and documents |
| Payment processor | Payment credentials and amount | To authorize and capture payment |
| Identity verification provider | Identifying information and identity documents | To verify you are who you say you are |
| Notary or remote notarization provider | Identifying information and the documents to be notarized | To notarize recordable instruments |
| County recording office | The recordable instruments themselves | Recording is a public act and recorded documents become public records |
| Hosting and infrastructure providers | Encrypted data at rest and in transit | To operate the service |
We also disclose information where legally required — in response to lawful process, or to protect rights and safety.
Service providers act on our instructions and may not use your information for their own purposes.
8. We do not sell or share your personal information
No sale, no sharing, no cross-context behavioural advertising
We have not sold or shared personal information in the preceding twelve months, and we do not sell or share sensitive personal information. We honour Global Privacy Control signals regardless. See the Do Not Sell or Share page.
9. Recorded documents are public
A deed recorded with a county becomes a public record. That is the point of recording, and it is outside our control once the instrument is filed.
Much of the reason the land trust structure exists is that the trust agreement and the assignment of beneficial interest generally are not recorded. Which documents reach the recorder in your state is set out on that state's page.
10. How long we keep information
Executed documents and the record of their preparation are retained as business records for as long as we are required to keep them. Information collected for a file that is never completed is deleted once it no longer serves the purpose it was collected for.
11. Security
Access to records is enforced at the database level rather than only in application code. Confidential identifiers are held separately as described above. The audit log rejects updates and deletions and each entry commits to the hash of the entry before it, so an altered history stops verifying.
No system is perfectly secure. If you believe you have found a vulnerability, our disclosure policy explains how to report it.
12. Your rights
One limit worth stating plainly
We cannot delete information we are required to retain, and we cannot retract a document that has already been recorded with a county. Recording is public and permanent.
Depending on where you live, you may have the right to know what personal information we hold, to obtain a copy of it, to correct it, to delete it, to limit our use of sensitive personal information, and to opt out of sale or sharing — which, as stated above, we do not do.
You may also have the right to appeal a refusal, and to be free from discrimination for exercising these rights. We do not offer financial incentives in exchange for personal information.
We will verify your identity before acting, because acting on an unverified request about a real estate transaction is itself a risk. An authorized agent may make a request on your behalf with written permission.
13. Global Privacy Control
We treat a Global Privacy Control signal as a valid opt-out request. Because we do not sell or share personal information, the signal does not change our behaviour — but it is honoured rather than ignored.
You can check whether your browser is sending the signal on the Do Not Sell or Share page.
14. Children
The service is not directed to anyone under 18 and we do not knowingly collect information from children.
15. Changes, and how to reach us
We may update this policy. The effective date at the top changes when we do, and material changes are communicated to account holders.
Contact
Privacy enquiries: Eric@FiduciaryAssetProtectionGroupLLC.com
