Privacy Policy
Last updated: July 31, 2026
Top1031 ("Top1031," "we," "us") is operated by Mangold, Inc., 1111B South Governors Avenue, Suite 48507, Dover, Delaware, USA.
This policy describes what we collect, how we use it, and the choices you have. It applies to top1031.com.
What we collect
Account information. We first collect your email address and send a single-use verification code. While that code is in flight, a new member supplies the profile and consent information below; it becomes verified only after the member enters the code.
A new member self-attests that they meet the SEC definition of an accredited investor. We record the attestation time, its eventual verified-account provenance, and the version of the account and consent language presented. The optional Contact Opt-In is selected by default during signup and can be unchecked before submission without affecting account access. Name and phone number are required while it remains selected and optional after it is unchecked. Both are required for an advisor note; an advisor note also includes the message you provide.
Some signups originating from paid advertising use a partner-supported registration flow instead of the optional Contact Opt-In checkbox. In that flow, full name and US phone are required. By submitting the profile and verifying the email code, you authorize a Top1031 partner specialist to call or email you about your exchange, and a Lead is delivered for that purpose. This does not authorize text messages. Do not complete that registration flow if you do not agree to partner contact.
Registration context. Local browser storage keeps up to 10 recent site paths without query strings or fragments, a first referrer reduced to origin and path, and fixed UTM campaign fields with length and character limits. A supported calculator or deadline tool contributes only its tool name. We do not put exact financial inputs, results, dates, free text, credentials, search terms, or unrestricted URLs in this context. For paid advertising, Top1031 stores a limited campaign classification rather than the raw ad-click identifier in the account, Lead, or PostHog events. Advertising providers may separately process identifiers from the visit to attribute conversions. After verified onboarding, the sanitized context is copied to the account and removed from that browser.
Security and request data. Our hosting and security providers may process IP address, browser, device, and request information. The application uses keyed hashes of normalized email and IP values for signup rate limits rather than storing those raw values in its rate-limit buckets. When traffic reaches a risk threshold, Cloudflare Turnstile may process a brief automated check. We also keep bounded, pseudonymized security events.
Audience measurement. Before you make a cookie choice, we count page views and documented product interactions anonymously with PostHog. PostHog receives canonical page paths without query strings, the referring site reduced to origin and path, coarse browser and device information, sanitized campaign categories, and a closed event dictionary with code-owned categories or coarse bands. It never receives the ad-click identifier, email address, name, phone number, free text, search terms, watchlist contents, exact financial inputs, or Trust or Sponsor identifiers.
How PostHog runs depends on where you are, and Top1031 does not identify visitors to it in either case. In the United States it uses ordinary first-party analytics storage and receives your IP address, from which it derives an approximate location no more precise than a city. That lets us count returning visitors and see which regions our audience comes from. Outside the United States it runs in its storage-free cookieless mode: no analytics cookie, no local or session storage, and a privacy-preserving server hash that changes daily and discards the IP address, so it cannot join a visitor across days, browsers, or devices and provides us no location data at all.
We also use the approximate location your IP address indicates, as reported by our hosting provider, to tailor what we show you — for example, highlighting properties near you. This happens in your browser, we do not store the location, and the site works the same way if it is unavailable or wrong.
We also initialize Google Ads under denied Consent Mode. A newly verified account sends the signup conversion; when specialist contact is authorized, it also sends the advisor-contact conversion. A verified partner-supported paid-campaign signup therefore sends both conversions. These may be cookieless pings without advertising cookies, personalization, or user-data signals. The closed signup funnel and cookieless Google Ads conversions remain active under essential-only and Global Privacy Control; ordinary PostHog measurement, GA4, and Vercel Web Analytics remain disabled.
Optional analytics. If you accept optional analytics, we also enable Google Analytics 4 (GA4) for page views and the same approved product interactions, and Vercel Web Analytics for traffic. PostHog continues in the same mode it was already running in, and accepting does not identify you to it.
The analytics contract sends only documented product events with closed categories or coarse bands. PostHog URLs contain no query string or fragment. GA4 page locations may retain only Google advertising click identifiers and fixed source, medium, and campaign fields for acquisition attribution; other query parameters and fragments are removed. GA4 and Vercel Web Analytics stay disabled unless you consent.
Public securities-offering data shown on this site is separate from visitor information. It comes from public SEC filings, sponsor disclosures, and other cited public sources.
How we use it
- To verify email control and operate passwordless accounts, sessions, and watchlists.
- To apply the accredited-investor access self-attestation.
- To preserve the sanitized registration context described above.
- To provide security, investigate misuse, and prevent automated abuse.
- To measure the closed signup funnel anonymously regardless of cookie choice, and minimized audience and product usage while no choice is stored or after you accept optional analytics.
- To create and deliver a specialist Lead when Contact Opt-In remains selected and the account is verified, when a partner-supported paid-campaign registration is verified after the partner disclosure, or when you send an Advisor Note.
In standard signup, if Contact Opt-In remains selected when you submit and verify your account, a specialist may respond by email or phone; uncheck it for access without outreach. In a partner-supported paid-campaign signup, submitting the required profile and verifying the email code authorizes that email or phone response. Neither path authorizes texts.
We may still email sign-in codes, security notices, retention notices, and service notices about your account. We do not sell your personal information, share it for cross-context behavioral advertising, run third-party advertising on this site, or use your information for cross-site behavioral advertising.
Cookies and browser storage
We use cookies and local browser storage:
- Account and security: sign-in sessions, single-use verification state, abuse controls, and your versioned cookie-preference record.
- Registration context: local storage holds the sanitized paths, referrer, UTM fields, and tool name described above so verification can open in a second tab. This operates separately from optional analytics and is cleared after onboarding completes. You can also clear it through your browser's site-data controls.
- Analytics: PostHog audience, product, and signup-funnel measurement, which uses first-party analytics storage in the United States and no browser storage elsewhere. It runs while no choice is stored and continues after analytics acceptance. Google Ads uses denied Consent Mode for cookieless measurement of verified signups and authorized advisor-contact requests; a verified partner-supported paid-campaign signup sends both. GA4 and Vercel Web Analytics run only after you accept analytics; GA4 may use analytics cookies after consent. Change your choice through “Cookie preferences” in the footer.
Choosing essential-only stops ordinary PostHog page-view and product measurement, but not the closed signup funnel or cookieless Google Ads conversions. If you withdraw a prior grant, we immediately deny GA4 analytics storage and reload with only those essential registration measurements active. The change synchronizes to other open Top1031 tabs, which also withdraw and reload if analytics had been active.
When Global Privacy Control is enabled, we record essential-only, keep only the closed signup funnel and cookieless Google Ads conversions, and disable optional analytics even if an earlier grant exists. Disabling GPC later does not restore analytics automatically; essential-only remains stored until you deliberately change it through “Cookie preferences.”
Sharing
Leaving the default Contact Opt-In selected and verifying a standard signup creates and delivers a Lead. Explicitly unchecking it creates no Lead and does not affect account access. Submitting the required profile and verifying a partner-supported paid-campaign signup after its disclosure also creates and delivers a Lead.
If Contact Opt-In remains selected through verified signup, or you later send an advisor note, the application sends the resulting record to configured Top1031 operations and affiliated-partner recipients. A Lead can include your email address, name, phone number, attestation and contact-consent timestamps, consent-language version, and sanitized registration context. An Advisor Note also includes your note.
Service providers process information to host and protect the site and database, control authorized staff access, send account and lead-notification email, provide measurement, and retry failed deliveries. These include Vercel, Cloudflare, and Neon for hosting, security, and data infrastructure; Postmark for outbound email; and PostHog and Google for the measurement described above. We may also disclose information when required by law.
Retention
- Unused, unverified accounts are deleted after 30 days. Expired verification records are deleted after 7 days.
- Sign-in codes work once and expire after 10 minutes. Account-deletion confirmation links work once and expire after 15 minutes. Sessions close after 30 days without activity and can never last more than 90 days; expired session records and closed rate-limit buckets are deleted after 30 days.
- Verified accounts and watchlists are deleted after five years without activity, after a notice approximately 30 days before deletion.
- Leads, Advisor Notes, and their sanitized attribution are deleted three years after their last update.
- Pseudonymized security events are kept for up to 12 months.
- Minimal consent, attestation, and deletion evidence may be kept for five years. It is limited to a keyed email hash, timestamps, provenance, wording version, and event type.
A verified account-deletion request overrides the normal account, watchlist, Lead, and Advisor Note periods. Analytics retention is controlled by each provider's settings.
Your choices and rights
- Access and correction: email us or use the contact page and we will honor verified requests, subject to records we must keep by law.
- Account deletion: a signed-in member can request deletion from the account page. We send a fresh, single-use email link before permanently removing the account, sessions, watchlist, Leads, Advisor Notes, and linked personal profile data. Minimal pseudonymous legal or security evidence may remain for the periods above.
- Opt out of contact: you can ask us or the specialist who contacted you not to contact you again.
- California residents (CCPA/CPRA): you have the rights to know, delete, correct, and opt out of sharing as defined by the CPRA. We do not sell personal information or share it for cross-context behavioral advertising. Delivering a Lead after the contact authorization described above is not cross-context behavioral advertising.
- Privacy signals: we honor Global Privacy Control as an opt-out signal and will not discriminate against you for exercising a right.
- Do Not Track: we honor GPC; legacy DNT signals have no settled meaning and are not acted on separately.
Children
This site is for accredited investors and is not directed to anyone under 18. We do not knowingly collect information from children.
Security
Sign-in uses hashed, single-use email-code records. Sessions have inactivity and absolute lifetime limits. Application access to account, Lead, and Advisor Note records is restricted by authenticated, role-based access rules, and administrative systems use an additional identity-aware access layer.
Application secrets are supplied through protected environment configuration rather than stored in page code. No system is perfectly secure.
Changes
Changes to this policy will be posted on this page with a revised "Last updated" date.
Contact
Privacy questions and requests: privacy@top1031.com.
Mangold, Inc. · 1111B South Governors Avenue, Suite 48507, Dover, Delaware, USA · Contact page: /contact/.