Security and data

Agency data stays private.Lead context stays useful.

FonatProp should store enough context for a broker to act, and nothing that creates unnecessary risk. The operating rule is simple: capture, route, measure and protect.

Security contact

01

Collect only what the broker needs

Lead records should contain source, agency token, card/widget, name, email, phone, property context, consent and timestamps.

02

Keep agency data separated

Each lead is attached to its agency token. Admin views and service-role actions stay server-side and are not exposed to the public widget.

03

Route, do not resell

FonatProp is built to route lead context to the agency that owns the widget. Lead data is not sold, scraped, trained on or reused commercially.

04

Measure without over-collecting

Funnel events can track page view, widget open, lead submit and meeting outcome with a session id before personal details are submitted.

Platform controls

Consent text before lead submission

Agency-token source on every lead and event

Server-only service role key

Rate limits and webhook validation

Private broker handoff destinations

Delete/export process through support

Agency control

The agency owns its website and ad account

The agency approves spend, copy and target market

The agency chooses WhatsApp, email or CRM handoff

The agency decides who can access its dashboard