Legal
Privacy Policy
Last updated: 20 June 2026
This Privacy Policy explains how Homfli ("Homfli", "we", "us", or "our") collects, uses, stores, and protects personal data when you use our website and platform at homfli.com. Homfli is a Bulgarian real estate marketplace for browsing, buying, renting, saving, and managing property listings. The platform is currently in an early-stage development / preview phase. You should not rely on Homfli as the only source of information for real estate decisions or actual property transactions. Listing information may be incomplete, outdated, inaccurate, or used for testing and demonstration purposes. This Privacy Policy applies to visitors, registered users, real estate agents, company members, and anyone who contacts us through the platform.
1. Who is responsible for your personal data?
For the purposes of the General Data Protection Regulation (“GDPR”), the data controller is:
Homfli, currently operated by an individual platform owner.
Public business address: Not currently listed. Please contact us by email for privacy, legal, or platform-related requests.
Email: contact@homfli.com
Company registration number: Not applicable — Homfli is not yet operated through a registered company.
VAT number: Not applicable — Homfli is not currently VAT registered.
If Homfli is incorporated as a legal entity in the future, this Privacy Policy will be updated to reflect the correct controller details.
2. What personal data we collect
We collect different types of personal data depending on how you use Homfli.
2.1 Account data
When you create or use a Homfli account, we may collect:
- Email address
- Display name
- Phone number, if provided
- Authentication identifiers, such as Firebase UID and provider ID
- Account creation date
- Last-updated timestamp
We use this data to create and manage your account, authenticate you, secure your session, and provide account-related functionality.
2.2 Company and agency data
If you create, join, or manage a company or real estate agency profile, we may collect:
- Company name
- Company phone number
- Company email address
- Company description
- Company street address
- Locality
- Postal code
- Latitude and longitude of the company location
This information may be used to display agency information on Homfli, manage company membership, and allow company members to create or manage listings.
2.3 Property listing data
When agents, companies, or authorised users create property listings, Homfli may process listing data such as:
- Property type
- Listing type, such as sale or rent
- Price and currency
- Street, house number, postal code, locality, neighbourhood, latitude, and longitude
- Number of rooms, bedrooms, bathrooms, parking spaces, floor, and total floors
- Total area, living area, land area, outside area, and garage area
- Year built
- Interior type
- Upkeep condition
- Heating type
- Free-text description and key points
- Photos
- Active status
- Expiry date
Some listing data may relate to a property, an agency, or the person who created the listing. Property addresses and photos may be visible to users of the platform, depending on how the listing is published.
2.4 Saved listings
If you are logged in and save or bookmark a listing, we store the relationship between your account and the listing.
We use this to show your saved listings and allow you to remove them later.
2.5 Saved searches
If you save a property search, we store the search criteria connected to your account. This may include filters such as:
- Location
- Property type
- Listing type
- Price range
- Area range
- Room count
- Other selected filters
We use saved searches to allow you to access them later and, where enabled, to send you notifications when matching listings are available.
2.6 Recently viewed listings
When you are logged in and view listing pages, we may store which listings you recently opened.
We use this to provide a recently viewed listings feature and improve your user experience.
At the moment, recently viewed listing records are retained indefinitely unless removed manually or through future platform functionality.
2.7 Contact form data
If you contact us through the contact form, we collect:
- Name
- Email address
- Phone number, if provided
- Subject, if provided
- Message content
The contact form also contains a hidden anti-spam field. If this field is filled in, the submission may be treated as a bot submission and silently discarded.
Contact form submissions are not stored in our main database. They are forwarded by email to contact@homfli.com through our email provider.
2.8 Company membership invites
If you invite someone to join a company or agency on Homfli, or if you receive such an invite, we may process:
- Sender user ID
- Recipient email address
- Company details
- Assigned role
- Invite expiry date
- Accepted or declined timestamps
We use this data to manage company access and permissions.
2.9 Invoices and subscriptions
If subscription or invoicing functionality is used, we may process:
- User account linked to the invoice or subscription
- Company linked to the invoice or subscription
- Amount
- Description
- Invoice or subscription date fields
- Subscription plan
- Start date, end date, renewal date, cancellation date
At the current stage, Homfli does not appear to process payment card data directly and no payment gateway integration has been identified in the application codebase.
2.10 IP addresses and security data
We may read IP addresses from request headers for security and rate-limiting purposes.
For example, IP addresses may be used to limit login attempts, such as a maximum number of login attempts per minute per IP address.
IP addresses are stored only temporarily in Redis for the relevant rate-limit window and are not stored in the main database.
3. How we use your personal data
We use personal data for the following purposes:
- To provide and operate the Homfli platform
- To allow users to create and manage accounts
- To authenticate users and keep sessions secure
- To allow users to browse, save, and manage listings
- To allow agents and companies to create and manage property listings
- To manage company memberships and invitations
- To provide saved searches and recently viewed listings
- To send service-related and transactional emails
- To forward contact form messages to Homfli
- To prevent abuse, spam, and unauthorised login attempts
- To maintain platform security
- To debug, maintain, and improve the platform
- To comply with legal obligations where applicable
4. Legal bases for processing
Under the GDPR, we rely on different legal bases depending on the type of processing.
4.1 Performance of a contract
We process account data, listing data, saved listings, saved searches, company membership data, and subscription-related data where this is necessary to provide the Homfli service to you.
4.2 Legitimate interests
We may process data based on our legitimate interests, including:
- Securing the platform
- Preventing spam, abuse, and unauthorised access
- Rate limiting login attempts
- Maintaining platform functionality
- Improving the user experience
- Keeping records of platform actions needed to operate the service
Where we rely on legitimate interests, we consider whether your rights and freedoms override those interests.
4.3 Consent
We may rely on consent where required, for example for optional features, certain types of notifications, or future analytics or marketing cookies if these are introduced.
At the current stage, Homfli does not set analytics, advertising, retargeting, or tracking cookies through the application code itself.
4.4 Legal obligation
We may process or retain certain data where required by applicable law, accounting obligations, tax obligations, dispute resolution, or requests from public authorities.
5. Authentication and session cookies
Homfli uses Firebase Authentication, provided by Google infrastructure, to authenticate users. Supported login methods may include email/password login and Google Sign-In.
When you log in, Homfli may set the following cookies:
| Cookie name | Purpose | Expiry |
|---|---|---|
| __session | Session authentication with a Firebase session credential | 7 days |
The __session cookie is set as httpOnly, sameSite: lax, and secure in production. It cannot be read by client-side JavaScript.
This cookie is necessary for login and session functionality. Without it, authenticated parts of Homfli may not work properly.
7. Emails and notifications
Homfli may send or process the following emails:
7.1 Contact form forwarding
When you submit the contact form, your name, email address, phone number if provided, subject if provided, and message are forwarded to contact@homfli.com.
No automatic copy is currently sent to the submitter.
7.2 Saved search notifications
Homfli contains functionality for saved-search match notifications. If enabled, users may receive emails when new listings match their saved search criteria.
These emails may include your email address and matched listing details.
At the current stage, this saved-search notification functionality is disabled in the application code. If enabled later, Homfli may keep a record of which saved-search notifications have already been sent in order to prevent duplicate notifications.
8. AI-generated property descriptions
Homfli includes functionality for AI-generated property descriptions using OpenAI.
At the current stage, this feature is disabled and returns an unavailable response.
If this feature is re-enabled, property description text and related listing content may be sent to OpenAI to generate or improve descriptions. We will update this Privacy Policy where necessary before or when this feature becomes active.
You should not enter sensitive personal data into listing descriptions or AI description tools.
9. Third-party service providers
We use third-party service providers to operate Homfli. These providers may process personal data on our behalf or as independent controllers, depending on the context.
9.1 Firebase Authentication
Firebase Authentication, provided by Google, is used to authenticate users. Homfli exchanges verified Firebase ID tokens for a server-managed httpOnly session cookie. Firebase may process email addresses and authentication metadata.
9.2 Firebase Storage / Google Cloud Storage
Listing photos are stored using Firebase Storage / Google Cloud Storage. Image URLs may contain Google access tokens.
9.3 Google Maps and Places API
Google Maps / Places API may be used for address autocomplete and location-related search features. When you type an address into relevant fields, address strings and related request data may be sent to Google.
9.4 Resend
Resend is used for transactional email delivery. It may process contact form submissions and saved-search notification emails.
9.5 Vercel
Homfli is hosted on Vercel. HTTP requests to Homfli pass through Vercel infrastructure. Vercel may process IP addresses, request metadata, logs, and technical information necessary to host and secure the platform.
9.6 Redis
Redis is used as an in-memory store for rate limiting. IP addresses and user IDs may be stored temporarily for security and usage-limiting purposes. These entries expire automatically and are not intended for long-term storage.
9.7 PostgreSQL database
Homfli uses a cloud-hosted PostgreSQL database as the primary storage for user, company, listing, saved listing, saved search, recently viewed listing, invite, invoice, and subscription data.
9.8 OpenAI
OpenAI may be used for AI-generated property descriptions if the feature is re-enabled. At the current stage, this feature is disabled.
10. International data transfers
Some of our service providers may process data outside Bulgaria or outside the European Economic Area.
Where personal data is transferred outside the EEA, we rely on appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms under the GDPR.
11. How long we keep your data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
11.1 User accounts
User account data is retained indefinitely unless manually deleted by an administrator or unless deletion is required by law. There is currently no self-service account deletion feature.
11.2 Listings
Listings are soft-deleted. This means that when a listing is deleted, a deletion timestamp is set, but the record is not automatically removed from the database. As a result, property data, address data, and related listing content may be retained indefinitely unless manually deleted or unless a different retention process is introduced.
11.3 Recently viewed listings
Recently viewed listings are currently retained indefinitely per logged-in user. No automatic cleanup period is currently implemented.
11.4 Saved listings and saved searches
Saved listings and saved searches are retained until you delete them or until they are manually deleted by an administrator.
11.5 Contact form data
Contact form submissions are not stored in the main database. They are forwarded by email to Homfli. Copies may remain in Homfli's email inbox or email provider systems according to email retention settings.
11.6 Rate-limit data
Rate-limit entries stored in Redis are temporary and expire automatically within the relevant rate-limit window.
11.7 Invoices and subscriptions
Invoice and subscription records may be retained for as long as needed for accounting, tax, legal, administrative, or dispute-resolution purposes.
12. Your GDPR rights
Depending on the situation and applicable law, you may have the following rights in relation to your personal data:
- The right to be informed about how your data is used
- The right to access your personal data
- The right to correct inaccurate or incomplete data
- The right to request deletion of your data
- The right to restrict processing
- The right to object to processing
- The right to data portability
- The right to withdraw consent where processing is based on consent
- The right to lodge a complaint with a supervisory authority
Some rights may not apply in all circumstances. For example, we may need to retain certain data for legal, accounting, security, or dispute-resolution reasons.
13. How to exercise your rights
To exercise your privacy rights, contact us at:
contact@homfli.com
Please include enough information for us to identify your account and understand your request.
We may need to verify your identity before responding to a request. We aim to respond within the time limits required by applicable data protection law.
At the current stage, Homfli does not provide a self-service data export or account deletion feature. If you want to request access, deletion, correction, or export of your data, please contact us by email.
15. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include:
- Firebase Authentication
- Secure session cookies in production
httpOnlysession cookiesameSite: laxcookies- HTTPS in production
- Rate limiting for login protection
- Role-based and company-based access controls
- Invitation-based company membership
- Access restrictions for listing management features
However, no online platform can guarantee absolute security. You are responsible for keeping your login credentials secure and for notifying us if you suspect unauthorised access to your account.
16. Access control and visibility
Unauthenticated users can browse and view public listings.
Authenticated users can save listings, save searches, view recently viewed listings, and submit contact forms.
Company members can create and manage listings on behalf of a real estate agency or company, depending on their assigned role.
Company membership is invitation-based. Invitations are sent to an email address and may have an expiry date.
17. Children
Homfli is not intended for use by children. We do not knowingly collect personal data from children.
If you believe that a child has provided personal data to Homfli, please contact us so we can take appropriate action.
18. Real estate listing accuracy and preview-phase notice
Homfli is currently in an early-stage development / preview phase.
Although we aim to present useful real estate information, listings may be incomplete, inaccurate, outdated, duplicated, used for testing, or otherwise unreliable.
Homfli does not verify every listing, property detail, address, photo, price, availability status, company profile, or agent claim. You should independently verify all information before making decisions, contacting agents, visiting properties, signing agreements, making payments, or entering into any transaction.
Homfli is not a party to real estate transactions between users, buyers, tenants, landlords, sellers, agents, or companies.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, especially as Homfli develops, new features are added, service providers change, or legal requirements evolve.
The updated version will be posted on this page with a new “Last updated” date.
If changes are material, we may provide additional notice where appropriate.
20. Contact
For questions, requests, or concerns about this Privacy Policy or your personal data, contact us at:
Homfli
Website: homfli.com
Email: contact@homfli.com
For questions about this policy, please contact us via our contact form.
Back to home