Legal

Privacy Policy

LAPIS Global LLC  ·  Effective Date: June 26, 2026  ·  Last updated: June 26, 2026

Table of Contents
  1. Who We Are
  2. Information We Collect
  3. Identity Verification & KYC Data
  4. Financial Data & GLBA Disclosure
  5. How We Use Your Information
  6. How We Disclose Your Information
  7. Platform-Specific Data Practices (app.lapisglobal.us)
  8. Cookies & Tracking Technologies
  9. Data Retention
  10. Security
  11. California Privacy Rights (CCPA / CPRA)
  12. Do Not Sell or Share My Personal Information
  13. Other U.S. State Privacy Rights
  14. International Data Transfers & Mexican Law (LFPDPPP)
  15. Children's Privacy
  16. Third-Party Links
  17. Changes to This Policy
  18. Contact & Data Requests
Section 01

Who We Are

LAPIS Global LLC ("LAPIS," "we," "our," or "us") is a Wyoming limited liability company (Registration No. 2026-001860036) operating a technology platform for real estate project management and coordination. Our principal services are accessible at lapisglobal.us (marketing website) and app.lapisglobal.us (the "Platform").

This Privacy Policy describes how LAPIS collects, uses, discloses, and protects personal information about Users of our website and Platform. By accessing or using our services, you agree to the practices described in this Policy. If you do not agree, please do not use our services.

For privacy-related inquiries, contact our Data Protection contact at: privacy@lapisglobal.us

Section 02

Information We Collect

We collect information in several ways depending on how you interact with our website and Platform:

A. Information You Provide Directly

B. Automatically Collected Information

C. Information from Third Parties

Section 03

Identity Verification & KYC Data

The Platform (app.lapisglobal.us) requires identity verification for all registered users. As part of our Know Your Customer (KYC) and Anti-Money Laundering (AML) compliance obligations, we collect sensitive personal information including government-issued identification.

Specifically, the Platform collects and processes the following sensitive personal information as required for KYC compliance:

This information is collected under legal obligation (AML/BSA compliance, FinCEN regulations) and is necessary to provide Platform services. We cannot offer Platform access without completing identity verification.

Document Image Processing: Government ID images are processed using automated identity verification technology that may involve biometric processing (facial recognition, liveness detection) to confirm document authenticity. If you are a resident of a state with biometric privacy laws (including Illinois under the Biometric Information Privacy Act ("BIPA"), Texas, Washington, or others), you will be presented with a specific biometric consent disclosure prior to any biometric data processing. You may contact us at privacy@lapisglobal.us to inquire about biometric data handling.

KYC data is shared with our identity verification service provider(s) and retained in accordance with our legal obligations (see Section 9). We do not sell KYC or government identification data to any third party.

Section 04

Financial Data & GLBA Disclosure

As a technology platform facilitating real estate investment transactions, LAPIS may collect and process financial information from Platform users, including:

Gramm-Leach-Bliley Act (GLBA) Notice. To the extent LAPIS is subject to the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) as a financial institution, we are required to inform you of our information-sharing practices with respect to nonpublic personal financial information ("NPI"). We do not sell your NPI to third parties. We share NPI only as described in this Policy — with service providers acting on our behalf, with financial institutions administering escrow accounts, and as required by law. You may have rights under your state's financial privacy laws in addition to GLBA.

Financial data is transmitted and stored using industry-standard encryption (TLS in transit, AES-256 at rest). ACH and banking information is used solely for the purpose for which it was provided and is not retained longer than necessary for that purpose.

Section 05

How We Use Your Information

We use the information we collect for the following purposes:

Legal Basis (for GDPR / international reference): Processing is based on contract performance (to provide services), legal obligation (KYC/AML compliance), legitimate interest (security and fraud prevention), and consent (marketing).

Section 06

How We Disclose Your Information

We do not sell your personal information to third parties for their own marketing purposes. We may share your information in the following circumstances:

Section 07

Platform-Specific Data Practices (app.lapisglobal.us)

The LAPIS Platform at app.lapisglobal.us is a separate application from our marketing website (lapisglobal.us) and involves more extensive data collection due to the nature of the services provided. The following data practices apply specifically to Platform users:

Database Infrastructure: Platform data (user profiles, project records, documents, wallet transactions) is stored in Supabase, a cloud database platform hosted on Amazon Web Services (AWS) infrastructure. Data may be stored in data centers located in the United States. Supabase is a sub-processor acting under contract with LAPIS.

Document Storage: Project documents, engineering plans, permit filings, and identity documents uploaded to the Platform are stored in encrypted cloud storage. Access is controlled by Platform authentication and role-based permissions.

Activity Logs: The Platform maintains detailed audit logs of user actions (document uploads, approvals, payments, status changes) for compliance, dispute resolution, and security purposes. These logs are retained for a minimum of 5 years.

Session Data: The Platform collects session tokens, authentication timestamps, and device fingerprints to maintain secure sessions and detect unauthorized access.

Project Collaboration Data: When multiple users collaborate on a project (e.g., investor, broker, and project owner), the Platform enables data sharing among those parties within the scope of the project. Each user can view project data consistent with their assigned role and permissions.

Wallet & Transaction Data: All Wallet activity — including funding amounts, service fee deductions, and transaction history — is logged and retained as required for financial recordkeeping and tax reporting compliance.

Section 08

Cookies & Tracking Technologies

Our website (lapisglobal.us) uses cookies and similar technologies to enhance user experience and analyze site performance. Our Platform (app.lapisglobal.us) uses session cookies and authentication tokens that are strictly necessary for Platform operation.

Types of cookies we use:

Your Choices: You may control cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing cookies. Note that disabling essential cookies will impair Platform functionality. For California residents and other state residents with opt-out rights, see Sections 11–13.

We do not use cookies or tracking technologies to build profiles for purposes unrelated to our services.

Section 09

Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:

When data is no longer needed, we delete or anonymize it using secure methods. Some information may be retained in anonymized or aggregated form for analytics purposes after deletion of personal identifiers.

Section 10

Security

LAPIS implements technical, administrative, and organizational security measures designed to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include:

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you as required by applicable state breach notification laws, including Wyoming's data breach notification statute (Wyo. Stat. § 40-12-501 et seq.) and the laws of states where affected users reside.

Section 11

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information:

To exercise your California privacy rights, submit a verifiable consumer request to privacy@lapisglobal.us or by written request to our address in Section 18. We will respond within 45 days of receipt of a verifiable request (extendable by an additional 45 days with notice).

Sensitive Personal Information We Collect: As disclosed in Sections 3 and 4, we collect sensitive personal information including government-issued ID numbers (SSN, EIN, passport number), financial account information (ACH routing and account numbers), and biometric data for identity verification. This information is collected solely to provide our services and fulfill legal obligations and is not used for purposes beyond those disclosed.

California Shine the Light: California Civil Code § 1798.83 permits California residents to request a list of third parties to whom we have disclosed personal information for direct marketing purposes in the preceding year. We do not share personal information with third parties for their direct marketing purposes.

Section 12

Do Not Sell or Share My Personal Information

Your Opt-Out Right

Under CCPA/CPRA and similar state laws, you have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising.

Submit Do Not Sell / Share Request

LAPIS does not sell personal information in exchange for monetary consideration. However, our marketing website (lapisglobal.us) uses advertising pixels (including Meta Pixel) that may constitute "sharing" of personal information under CCPA/CPRA for cross-context behavioral advertising purposes.

If you wish to opt out of the sharing of your information for cross-context behavioral advertising, you may:

Opt-out requests from authenticated Platform users (app.lapisglobal.us) are handled separately — within the authenticated Platform we do not use marketing pixels or engage in cross-context behavioral advertising.

We will process your opt-out request within 15 business days and confirm completion by email.

Section 13

Other U.S. State Privacy Rights

Residents of the following states have privacy rights similar to those described for California residents under their respective state laws:

To exercise any state privacy right, please contact us at privacy@lapisglobal.us with your name, state of residence, and a description of your request. We will respond within the timeframe required by applicable state law. We will not discriminate against you for exercising any privacy right.

Where permitted, we may require verification of your identity before processing a request. We will use the information you provide solely for identity verification and will not retain it for other purposes.

Section 14

International Data Transfers & Mexican Law (LFPDPPP)

LAPIS Global LLC is a U.S. company operating a platform that facilitates real estate projects located in Mexico. As a result, personal information flows between the United States and Mexico in the course of our operations.

Mexico — LFPDPPP Compliance. To the extent that LAPIS processes personal data of individuals located in Mexico (including Mexican project partners, contractors, or brokers using the Platform), LAPIS acknowledges the applicability of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) and its regulations. Such individuals have the right to Access, Rectification, Cancellation, and Opposition ("ARCO Rights") with respect to their personal data processed by LAPIS. ARCO Rights requests may be submitted to privacy@lapisglobal.us.

Cross-Border Data Transfers. Personal data collected in Mexico may be transferred to and stored on servers located in the United States. Such transfers are made pursuant to an international transfer agreement or other legal mechanism that ensures an adequate level of protection for personal data as required by LFPDPPP Article 37.

U.S. Data Storage. All Platform data is primarily stored in cloud infrastructure (Supabase / AWS) in the United States. By using the Platform, non-U.S. users consent to the transfer of their personal information to the United States, where privacy laws may differ from those in their home country.

GDPR / International Users. LAPIS does not currently target EU residents. If EU residents use the Platform, we will apply appropriate data protection measures consistent with GDPR principles, including data processing agreements with service providers and applying data subject rights upon request.

Section 15

Children's Privacy

The Platform and website are not directed to, and are not intended for use by, individuals under the age of 18. We do not knowingly collect personal information from minors under 18. If we become aware that we have inadvertently collected personal information from a minor under 18, we will promptly delete such information.

If you believe we have collected information from a minor, please contact us immediately at privacy@lapisglobal.us.

Section 16

Third-Party Links

Our website and Platform may contain links to third-party websites or services that are not operated by LAPIS. We are not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party site you visit through links from our Platform.

Key third-party services integrated into the Platform include: Supabase (database and auth infrastructure), Vercel (web hosting), Google Fonts (typography), and Meta Business Tools (marketing analytics on marketing website only). Each of these providers operates under its own privacy policy.

Section 17

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on this page and update the "Last Updated" date at the top.

For material changes — particularly those affecting how we handle sensitive personal information or financial data — we will provide additional notice via email to registered Platform users at least 30 days before the change takes effect, where feasible.

Your continued use of the Platform after the effective date of any updated Policy constitutes acceptance of the new terms. If you object to any change, you may close your account by contacting us at support@lapisglobal.us.

Section 18

Contact & Data Requests

For privacy inquiries, to exercise your data rights, or to submit a data deletion, correction, or access request, please contact us:

LAPIS Global LLC — Privacy / Data Protection
30 N Gould St, Ste R, Sheridan, Wyoming 82801, USA
Email: privacy@lapisglobal.us
Subject line for data requests: "Privacy Request — [Your Name] — [Type of Request]"

To protect your information and comply with verification requirements, we may ask you to verify your identity before processing certain requests. We will respond within the timeframe required by applicable law (typically 45 days for CCPA; 30–45 days for other state laws).

This Privacy Policy was last reviewed and updated on June 26, 2026. It supersedes all prior versions of LAPIS Global LLC's Privacy Policy.