Privacy policy
The short version
Nobody reads privacy policies. So here is the whole thing in nine lines, and the full version below it.
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone, ever. We also do not share it for advertising.
- We collect the minimum. Your name, email, phone number, and whatever you write in the contact form. If you enroll, we collect what we need to run your program and file our taxes.
- No tracking on the public site. No analytics, no advertising pixels, no third-party cookies, and no cookie banner, because there is nothing to consent to.
- Marketing messages are opt-in. Leave the checkbox unchecked and you will never hear from us that way. Consent is not required to contact us or to enroll.
- Your coursework is not training data. We do not feed your assignments, forum posts, or coaching conversations to any AI or machine-learning system.
- We name the providers who matter. Stripe handles cards. A short list of others handles hosting, message delivery, and contract storage.
- No biometrics. No fingerprints, no face scans, no voice prints. Illinois has a strict law about this and we stay well clear of it.
- You can get your data out, or have it deleted. Email us and we will do it, minus what tax law makes us keep.
- Questions: [email protected]. A real person answers.
Who we are and how to reach us
This policy is issued by Real Estate and Wealth Building Institute LLC ("REWBI", "we", "us", "our"), an Illinois limited liability company.
For any privacy question, request, or complaint, email [email protected] or write to us at [Registered mailing address to be added]. We respond within 30 days, or sooner if the law requires.
When this policy applies
This policy covers personal information we collect through the public website at rewbihub.com and its subdomains, the contact form, marketing emails and text messages sent to people who opted in, the student portal and coursework provided to enrolled clients, and the e-signature flow used for enrollment.
It does not cover third-party websites you reach through a link from ours. Their privacy practices are their own. For rules about using our services, see the Terms of Service.
What we collect
If you only browse the site. Basic web-server logs: your IP address, the pages you request, your browser and device type, and the time of the request. We keep them to run the site and to spot abuse. There are no analytics, no tracking pixels, and no advertising cookies, so we are not building a profile of your browsing.
If you submit the contact form. Your name, email address, phone number, and the details of your inquiry. If you check the marketing consent box, we also record that consent: the fact of the checkbox, the timestamp, and the version of the terms you agreed to. We use all of this to reply to you, route your inquiry internally, keep a record of the exchange, and, if you opted in, add you to our marketing list.
If you are on our marketing list. Your email address, phone number, name, consent record, and delivery history: opens, clicks, bounces, and unsubscribes. That last part exists so we can honor your preferences and keep our messages out of spam folders.
If you enroll in a program. More, because we have a program to run and taxes to file:
- Identity and contact information: legal name, email, phone, mailing address, and, if you enroll on behalf of a company, your role and the entity details.
- Contract records: the signed Client Service Agreement, any addenda, and the metadata that comes with signing it (signer identity, timestamp, IP address, signed PDF).
- Payment records: amount, date, method, and payer identity. Card payments go through Stripe, and we receive a confirmation, the amount, and the last four digits. Bank transfers happen between your bank and ours, so we record only the amount, date, and payer. Cash is recorded by hand.
- Portal account data: username, email, password hash, multi-factor settings, session logs, and login history.
- Coursework and portal activity: modules completed, quiz responses, assignments, forum posts and comments, messages to your coach or other students, and files you upload.
- Coaching and session records: attendance, notes, and, only where you have given prior explicit consent under Illinois law (720 ILCS 5/14-2), recordings.
- Support records: anything you send us and our replies.
We use enrollment data to deliver your program, run the portal, bill and collect fees, meet our tax and legal record-keeping duties, keep the portal secure, and improve what we teach.
What it means: we hold what is needed to answer you, teach you, bill you, and satisfy the IRS. Nothing is collected to resell or to target ads at you.
What we do not collect
Worth saying explicitly, because a lot of companies do collect these:
- Biometric identifiers as defined by the Illinois Biometric Information Privacy Act (740 ILCS 14/). No fingerprints, face scans, voice prints, iris scans, or hand geometry. If the portal ever adds a feature that would collect biometric data, we will get your separate written consent first, as BIPA requires.
- Precise geolocation. Nothing finer than the city we can infer from your IP address for security purposes.
- Data bought from brokers. We do not enrich or supplement what you give us directly.
- Anything from people under 18. Not knowingly. If we learn we have, we delete it.
Third parties who touch your data
We keep this list short on purpose. Each provider gets only what it needs. Where we can describe a provider by category instead of by name, we do, because publishing the exact software we run helps nobody except someone trying to attack us.
| Who | What they receive |
|---|---|
| Stripe (named because our agreement with them requires it) | Card number, cardholder name, billing address, payment history. We never see or store the full card number. |
| Our infrastructure and hosting provider, a single US company | Everything that lives on our servers, as the operator of those servers. They do not use it for any purpose other than providing the servers, network, and storage. |
| Our email and text message delivery provider | Email addresses, phone numbers, names, and delivery metadata for people on our lists. |
| Our archival storage provider | Fully executed contract files and their metadata. No coursework, portal activity, or messages. |
| Courts, government authorities, our accountants and lawyers | Whatever the law requires, or what we need to defend our legal rights. |
Bank transfers move through the ordinary interbank system, so we send nothing to a payment processor for those. Cash involves no third party at all. Every other tool we use to run the services (identity, learning, coursework, workflow automation, e-signatures) runs on the infrastructure above and sends your data nowhere else.
What we do not do with your data
- We do not sell or rent personal information to anyone.
- We do not share it for cross-context behavioral advertising.
- We do not run third-party advertising networks, ad-tech pixels, or tracking beacons on the site.
- We do not run third-party analytics on the site.
- We do not disclose your data to third parties for their own marketing.
- We do not use your coursework, assignments, forum posts, or coaching content to train any AI or machine-learning system.
Where your data goes
Every system holding your personal information is in the United States. That includes our production servers and the archival storage for signed contracts.
We do not offer our services to residents of the European Union or the United Kingdom, and we do not transfer personal information to processors located in those regions.
How long we keep it
| Data | Retention |
|---|---|
| Contact form submissions | 24 months, then deleted, unless the submission led to an enrollment or an active matter |
| Marketing list entries | Until you unsubscribe. We then keep a minimal suppression record (email or phone plus the unsubscribe flag) so we do not message you again by accident |
| Portal accounts and coursework | The term of your Client Service Agreement plus 90 days, then deleted from active systems. Backups age out within 30 days after that |
| Signed agreements and contract documents | 7 years from the last active date (IRS and state requirements) |
| Payment records (card, bank transfer, cash) | 7 years (IRS and state requirements) |
| Web-server access logs | 90 days |
| Portal security and authentication logs | 12 months, unless held longer for an active security investigation |
| Support and communication records | 3 years from the last exchange |
If a law, court order, or open legal matter requires us to keep something longer, we will. If you ask us to delete your information and we have a legal reason to keep part of it, we will tell you what we kept and why.
Security
All traffic between you and our services is encrypted in transit with current TLS. We run our own services instead of stringing together a dozen SaaS platforms, which keeps the number of places your data lives small. Portal passwords are stored as hashes using a current, well-reviewed algorithm, never in plaintext. Multi-factor authentication is available on portal accounts and we recommend turning it on.
Access to production systems is limited to the few people who need it for their role, and it is logged. We run current software versions and apply security updates promptly. Backups are encrypted at rest.
No system is perfectly secure. If a security incident affects your personal information, we will notify you as required by Illinois law (815 ILCS 530) and any other applicable law, without unreasonable delay. We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. To report a security concern, email [email protected].
Your rights
Wherever you live, you can ask us to give you a copy of what we hold about you, correct anything inaccurate, delete it, export it in a common electronic format, stop a particular use of it, or withdraw a consent you gave us. Deletion is subject to the record-keeping exceptions in the retention table above.
Email [email protected] from the address on file, or write to the mailing address above. We may need to verify who you are first, especially for account data, and we will not treat you worse for asking.
To stop marketing messages: reply STOP to any text, or HELP for help. For email, use the unsubscribe link in any marketing message. Either way you can also just email us. Opting out of marketing does not stop transactional messages about an active enrollment, a scheduled call, a signed contract, or a legal matter.
If you live in California, the CCPA as amended by the CPRA adds the right to know what we collect and who we share it with, to delete it, to correct it, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of it. We do not sell or share personal information for advertising and we do not use sensitive personal information in a way that triggers the limit right, so two of those have nothing to act on. You have them regardless. Email [email protected] with "California privacy request" in the subject line, and you may designate an authorized agent to make the request for you.
We have no actual knowledge of selling or sharing the personal information of consumers under 16, because we do not knowingly collect information from anyone under 18.
Cookies
On the marketing site we set no cookies of our own. No analytics cookies, no advertising cookies, no third-party trackers. Your browser may pick up cookies from third-party sites you follow links to, but that is between you and them.
In the student portal we set exactly one cookie: the session cookie that keeps you logged in after you authenticate. It is first-party, marked HttpOnly and Secure, and it is deleted when you log out or the session expires.
Our marketing emails carry no tracking pixels.
What it means: there is no cookie consent banner because there is nothing to consent to. If you block the portal session cookie you will not be able to log in.
Children
Our services are for adults. You must be 18 or older to submit the contact form, receive marketing messages, or enroll in a program. We do not knowingly collect personal information from anyone under 18, and if we learn that we have, we delete it and notify a parent or legal guardian where the law requires. If you believe we have collected information from a child, email [email protected].
Changes to this policy
We may update this policy. The current version and effective date are always on this page. For material changes we will post a prominent notice on the site, email portal account holders and marketing subscribers, or both, before the changes take effect. Continued use of the services after the effective date means you accept the update.
Prior versions are archived and available on request from [email protected].
Complaints
If you think we have handled your personal information in a way that breaks the law or this policy, tell us first at [email protected]. We will investigate and respond within 30 days. If our answer does not satisfy you, you can complain to the Illinois Attorney General at illinoisattorneygeneral.gov or to your state's equivalent authority.
Definitions
Personal information. Any information that identifies, relates to, describes, or could reasonably be linked with a particular person: name, email, phone, mailing address, account credentials, IP address, payment records.
Sensitive personal information. The subset given heightened protection under laws like the CCPA: government identifiers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, contents of private communications, biometric identifiers. We do not collect any of it, other than the payment-account information needed to take a payment, which Stripe handles and we do not store.
Processing. Anything done with personal information: collecting, storing, using, sharing, deleting.
Sell. Under the CCPA, transferring personal information to a third party for money or other valuable consideration. We do not do this under that definition or any other.
Share. Under the CCPA, transferring personal information to a third party for cross-context behavioral advertising. We do not do this either.
Service provider or processor. A company we hire to handle personal information on our behalf under a written contract, only for the purposes we specify.
Contact
Privacy and data requests: [email protected]
Security reports: [email protected]
Everything else: [email protected]
Real Estate and Wealth Building Institute LLC, [Registered mailing address to be added]