Legal
Privacy notice
Last updated 25 August 2026
Vonta sells personal information about homeowners to licensed mortgage professionals. This notice says so plainly, explains what we hold and where it came from, and tells you exactly how to make us stop.
Before launch: this document is a working draft written to match how Vonta actually operates. It has not been reviewed by counsel. Have a lawyer licensed in your jurisdiction review and adapt it — particularly the liability, indemnity, and dispute-resolution sections — before you rely on it.
The short version
We are a data business. We collect information about homeowners — contact details, property attributes, and modeled loan estimates — and we sell and share it with licensed mortgage lenders, brokers, and loan originators so they can contact you about the mortgage product you inquired about.
Under California, Colorado, Virginia, Connecticut, Texas, Oregon and other state privacy laws, what we do is a “sale” and a “share” of personal information. We are not going to describe it any other way. You can opt out at any time, for free, without an account, and without telling us why.
What we collect
We hold the following categories of personal information:
- Identifiers — name, postal address, telephone number, email address, IP address, and an internal record identifier.
- Property and real-property records — subject property address, property type, occupancy as stated at intake, and information derived from publicly recorded deeds, mortgages and deeds of trust, assessor rolls, and lien filings.
- Modeled commercial inferences — estimated property value, estimated loan balance, estimated available equity, estimated loan-to-value, estimated current interest rate, and lien position. These are statistical estimates, not verified facts, and not sourced from a credit report.
- Recorded mortgage information — the loan type, recording date and original loan amount shown on the publicly recorded mortgage or deed of trust against the property.
- Provenance and suppression records — which sources built the record, when it was last refreshed, and when it was last checked against our opt-out and suppression lists.
What we do not collect
We do not collect or hold credit reports, credit scores, tradelines, credit inquiry history, Social Security numbers, financial account numbers, government identification numbers, precise geolocation, biometric data, or health data. We do not collect or infer race, color, national origin, religion, sex, sexual orientation, gender identity, marital or familial status, disability, age, or receipt of public assistance. We do not knowingly collect information from anyone under 18.
Where it comes from
We did not get any of it from you directly. You never gave us your information and you never asked to hear from anyone, and we are not going to imply otherwise.
- Public records — county recorder filings including mortgages and deeds of trust, assessor rolls, and lien filings.
- Licensed data compilers, for contact-detail appends and telephone attributes matched to the owner of record.
- Our own modeling, which produces the estimated balance, equity, loan-to-value and interest-rate figures described above.
We do not obtain information from consumer reporting agencies, and we do not buy or sell mortgage credit trigger leads.
Why we use it, and who gets it
We use it to build and sell mortgage lead products, to run suppression and fraud checks, to service buyer accounts, and to meet our legal and recordkeeping obligations.
We sell and share it with licensed mortgage lenders, mortgage brokers, and mortgage loan originators whose licenses we verify through NMLS Consumer Access before their first delivery. We also disclose it to service providers who process it on our behalf under contract — hosting, payment processing, email delivery, and suppression-list providers — and to authorities where the law requires it.
We do not sell personal information to data brokers for onward resale, and our buyer agreement prohibits buyers from reselling or redistributing it.
How long we keep it
Suppression and deletion records are retained indefinitely, because keeping a record of your opt-out is the only way to keep honoring it when the same information reaches us again from a public-record refresh. Marketing records are retained no longer than 36 months from collection unless we are required to keep them longer.
Your rights, and how to use them
Wherever you live in the United States, you may ask us to:
- Tell you what personal information we hold about you and where we got it;
- Give you a copy of it in a portable format;
- Correct anything inaccurate;
- Delete it;
- Stop selling or sharing it — permanently;
- Appeal if we refuse any of the above.
We do not charge for this, we do not require you to create an account, and we will not ask why. We respond within 45 days and will tell you if we need a single 45-day extension. If we deny a request you may appeal by replying to our response, and if we deny the appeal we will tell you how to complain to your state attorney general.
Making a request
Email privacy@vonta.ai with the subject line Privacy Request, or use the contact form. Include the name, property address, and phone number the request relates to so we can find the records — we use that information only to process the request.
An authorized agent may submit a request on your behalf with written proof of authority.
Do Not Sell or Share My Personal Information
Your opt-out request stops us selling or sharing your information going forward, and we add you to a permanent suppression list so later data refreshes do not reintroduce you. We also notify buyers who already received your record and require them to suppress it.
We honor Global Privacy Control and other recognised universal opt-out signals automatically, as an opt-out of sale and sharing. You do not need to do anything else.
Opting out here is separate from the FCRA prescreen opt-out at optoutprescreen.com. That one stops credit-based prescreened offers; it does not reach our data, and ours does not reach theirs. It is also separate from the National Do Not Call Registry, which you should register with directly at donotcall.gov.
Stopping calls
Opting out of the sale of your data stops future sales, but a company that already received your record will still have it. To stop calls, tell the company calling you to stop — under FCC rules effective April 2025, a revocation made by any reasonable means must be honored within ten business days. You can also tell us and we will pass the revocation downstream to every buyer who received your record. See our DNC and calling policy.
State-specific disclosures
California
Vonta is a data broker as California defines the term. We register annually with the California Privacy Protection Agency and participate in the DELETE Act’s Delete Request and Opt-Out Platform (DROP), which we check at least every 45 days. Our registration number is published here once issued: [registration number pending]. You have the rights listed above, plus the right to limit the use of sensitive personal information — we do not collect any, so there is nothing to limit. We do not use or disclose personal information for purposes incompatible with those described here, and we will not discriminate against you for exercising any right.
Texas
Vonta is a data broker under Chapter 509 of the Texas Business and Commerce Code. We collect and sell personal data of Texas residents as described in this notice.
Other states
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Utah, Virginia and other states with comprehensive privacy laws have the rights described above, including the right to opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not conduct such profiling.
Security
We maintain an information security program with encryption in transit and at rest, access controls, multi-factor authentication on administrative systems, vendor oversight, and an incident response plan. No system is perfectly secure, and we will not claim otherwise.
Changes
We will update this notice at least every twelve months and post the revised date at the top. Material changes will be announced on this page before they take effect.
Contact
Vonta AI, LLC · privacy@vonta.ai
Questions about this document: compliance@vonta.ai