Locate. (at locateapp.net and locator-hub.web.app, together with its companion browser extensions) is an independent tool built and operated by Jonathan Gilliam, an apartment locator working as an independent third-party contractor. It is not an official product of any brokerage, and no brokerage operates the Service or receives your data through it. Brokerage admins manage only their own members' access and market list.
Your clients' personal information stays in your own Google Drive, not on our servers. The shared property database is communal and visible to every authorized member. We store no passwords, sell nothing, run no ads, and use no third-party analytics.
You sign in with Google. The Service requests these permissions and uses them only as described:
| Permission | What it is used for |
|---|---|
| Google Drive | Creating and reading the Service's own files in your Drive: your client list file, grab screenshots, and guest card PDF attachments. The Service only ever looks up files it names itself and that you own. It does not browse, index, or touch the rest of your Drive. |
| Send email (Gmail) | Sending the guest card emails you compose, from your own address, only when you press send. |
| Email metadata (Gmail) | Checking the status of threads the Service created for you (sent, replied, or bounced) by reading headers and labels only, never message bodies of your other mail. |
| Calendar events | Creating tour events on your own calendar when you press Add to Calendar. |
Locate.'s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
| Data | Where | Who can see it |
|---|---|---|
| Clients: names, their property lists, grab details and screenshots, guest card PDFs, email status | Your own Google Drive | You. This data is not stored on the Service's servers and is not shown to other members through the app. |
| Communal property data: notes, contact details, terms, tags, regions, the search index | The Service's database (Google Cloud, United States) | Authorized members. Edits are stamped with the editing account's email address, which other members may see. |
| Craft documents (searches, tour sheets, cards) | The Craft space they are created in | Whoever has access to that Craft space. If your market uses a shared space, documents you create there, including client names in document titles, are visible to others with access to that space. |
| Sign-in state | Your browser's local storage | You. Clearing your browser data signs you out. |
The Service's backend (Google Cloud Functions, us-central1) verifies your Google sign-in on each request, reads and writes the communal property database, reads the shared market roster, and relays Craft requests. Your Google access token passes through per request and is never stored. When you sign in on an iPhone or iPad home screen app, a one-time sign-in code may be held for up to five minutes to pass it from the Google window to the app, then deleted; it cannot be used without a key that never leaves your device. Shared Craft credentials are held server-side and are not sent to browsers. We keep no server-side copy of your client data and no passwords of any kind.
Sign-in is Google OAuth only; the Service never sees or stores a password. Backend access is restricted to approved accounts and verified on every request. Client personal data deliberately stays in each member's own Google Drive so that no central database of client information exists to breach. No system is perfectly secure, so also keep your own Google account protected (strong password, two-factor).
The Service is a professional tool for working adults and is not directed at anyone under 18.
This policy may change as the Service evolves; the current version is always at this page, with its effective date above. Meaningful changes will be reflected here before they take effect.