H
HomeNavi Finance
← Back to sign in

Privacy Policy

Effective date: July 12, 2026

Overview

HomeNavi Finance ("HomeNavi," "we," "us," or "our") is a financial reporting dashboard operated by TM & KS Partners LLC. This Privacy Policy explains what information we access, how we use it, and how we protect it when you connect your third-party advertising, CRM, and payment platforms to the service.

By connecting a platform or using the dashboard, you consent to the practices described in this policy. We access third-party data solely on your behalf and only to produce the reporting and metrics shown in your dashboard.

Information We Collect

We connect to the platforms you authorize and read the data required to calculate your agency's profit-and-loss, client performance, and payment metrics. Specifically:

Meta (Facebook) Advertising

  • We collect Meta ad account IDs, campaign IDs, and advertising performance data including spend, impressions, clicks, and cost-per-lead (CPL).
  • We access this data through Meta's Marketing API using an access token you authorize via Meta's OAuth login.
  • We store ad performance metrics in order to display spend and performance trends in the dashboard.
  • We do not sell or share your Meta advertising data with any third parties.
  • You can revoke our access at any time through your Meta Business Settings, which immediately stops any further data access.

GoHighLevel (GHL)

  • We collect GHL sub-account/location IDs and the private integration token you provide.
  • We access contact lists, appointment calendars, and booking data associated with the locations you connect.
  • We use this data solely to calculate appointment-delivery metrics (leads, booked, confirmed/showed appointments).
  • Your integration tokens are stored encrypted at rest using AES-256-GCM encryption.
  • Our access is strictly read-only — we never modify, create, or delete any data in your GoHighLevel account.

Whop

  • When you connect Whop via OAuth, you grant read-only access to: your company identity, payment and transaction history, member (customer) records including member email addresses, products and access passes, subscription plans and plan statistics, and promo codes.
  • We use payment data to calculate revenue collected and outstanding client balances, and member/product data to map payments to the correct client.
  • We access Whop business-card transaction data for expense tracking.
  • We do not access, store, or use member phone numbers. Although Whop's API requires the phone-read permission to be granted for its payment and member endpoints to function at all, we never read phone data.
  • We do not store full payment card details. We only retain the transaction amounts, dates, and merchant descriptions needed for expense reporting.
  • Whop also processes payment for access to HomeNavi Finance itself; that transaction is handled by Whop under its own terms and privacy policy.

How We Use Your Information

We use the information described above exclusively to operate the dashboard on your behalf: to compute revenue, expenses, profit, amounts owed, appointment metrics, and advertising performance, and to surface alerts about your accounts. We do not use your data for advertising, profiling, or any purpose unrelated to providing the service, and we do not sell your data.

Data Storage & Security

  • Data is stored in Supabase (PostgreSQL) with row-level security so that only authenticated users of your account can access it.
  • All third-party API tokens are encrypted at rest using AES-256-GCM. Tokens are never exposed to the browser or included in any client-side response.
  • The application is hosted on Vercel, a SOC 2 compliant hosting provider.
  • Access to the dashboard requires authentication, and each request is validated server-side.

Data Sharing

We do not sell, rent, or share your data with third parties for their own purposes. Data is processed only by the infrastructure providers and sub-processors that power the service, and by the platforms you explicitly connect (Meta, GoHighLevel, and Whop). Each of those platforms handles data under its own privacy policy.

Our sub-processors are:

  • Supabase — database hosting and authentication.
  • Vercel — application hosting.
  • Resend — sending transactional and alert/digest emails. Resend processes the recipient email address and the contents of those emails, which may include your workspace's summary financial figures and client names. It acts solely as an email-delivery provider and does not use this data for its own purposes.

Cookies

The Service uses cookies only for essential authentication and session management. These session cookies are set with the httpOnly, Secure, and SameSite=Lax flags, meaning they cannot be read by client-side JavaScript and (in production) are transmitted only over secure connections. We do not use third-party advertising, analytics, or cross-site tracking cookies.

Children's Privacy

The Service is intended for use by businesses and is not directed at, and should not be used by, anyone under the age of 18. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us with personal information, contact us at tmandkspartnersllc@gmail.com and we will delete it.

Data Retention & Deletion

We retain your connected-account data for as long as your account is active so the dashboard can display historical trends. You may revoke any platform connection at any time, and you may request deletion of your account by contacting us at tmandkspartnersllc@gmail.com. Upon a verified deletion request, your workspace data, connected third-party platform tokens, and stored financial data will be permanently deleted within 30 days, except where retention is required for legal, tax, or fraud-prevention purposes.

Your Choices

  • Revoke Meta access through Meta Business Settings at any time.
  • Remove or replace your GoHighLevel and Whop tokens from the dashboard's Connections settings at any time.
  • Request data deletion by emailing us.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date at the top of this page.

Contact Us

TM & KS Partners LLC
Email: tmandkspartnersllc@gmail.com