Sign in Start a workspaceStart free

Legal

Privacy policy

How Tophat handles the information you put into it. Last updated 28 August 2026. Operated by SOPHIA XT LLC, trading as 3 Point Forward.

1. Who we are

Tophat is commercial real estate operations software published by SOPHIA XT LLC, trading as 3 Point Forward, and built on the SophiaXT platform. When you use Tophat, we are the data controller for your account and billing records, and the data processor for everything you and your colleagues put into your workspace. That distinction matters and section 9 explains what it means for you.

Reach us at privacy@3pointforward.com.

2. What we collect

What you give us on purpose

  • Account details. Your name, work email, the name of your firm and your role.
  • Your workspace content. Properties, leases, rent rolls, comparables, contacts, deals, proposals, documents you upload and anything you type into a note. This is your business record and we treat it as yours.
  • Billing details. Handled by our payment processor. Card numbers never reach our servers and we never see them.
  • Support correspondence. What you write to us when something breaks.

What the system records by operating

  • An audit trail. Who changed what, and when. This is a feature rather than surveillance: a brokerage needs to be able to answer who approved a document.
  • Sign-in records. Timestamp and IP address, kept so you can see whether somebody else has been in your account.
  • Error reports. When a page fails we record the route, the fault and a fingerprint so we can fix it. These are grouped by fault, not by person.
  • Delivery records. Whether a notification reached your email or phone, so a failure is visible instead of silent.

3. Why we hold it

Each of these has one reason and we will not stretch it into another:

  • To run the service you are paying for. Contract.
  • To keep the service secure and working. Legitimate interest, and it is the reason for the sign-in records and the error reports.
  • To bill you. Contract and legal obligation.
  • To email you about the product. Only about your own account and its workflow. Marketing email is separate and requires you to opt in.

4. What we never do

This section exists because it is the one most people actually want answered.

  • We do not sell your data. Not to anyone, in any form, aggregated or not.
  • We do not use your workspace content to train AI models, ours or anyone else's. Your rent rolls and your client list stay in your workspace.
  • We do not mine your portfolio for market data to resell as a research product, and we do not pool your comparables with another firm's.
  • We do not advertise to you and there are no third-party trackers, advertising pixels or analytics beacons anywhere in the application.
  • We do not read your documents except when you ask us to, in support, and we log it when we do.

5. Who else sees it

A short list, and it stays short:

  • Your colleagues, according to the roles you set. Brokers see their own book; principals see the desk.
  • Your clients, but only the tracking page for a request you shared, and only what that page shows.
  • Our hosting provider, which stores the encrypted volume your database sits on.
  • Our payment processor, for billing.
  • Your outbound mail provider, if you connect one so notifications leave from your own domain.
  • Anyone you connect on purpose, through an API key, a webhook or the MCP endpoint. Those are yours to create and yours to revoke, and every key shows when it was last used.

We will disclose data if a court validly orders it. Where the law allows us to tell you first, we will.

6. How it is protected

Every firm's data is isolated at the database level. Every query naming a customer table must carry that workspace's identifier, and a static checker fails the build if one does not. An automated test provisions two workspaces and then tries to reach across them from every address in the product, asserting each attempt returns a plain not found.

  • Passwords are hashed with Argon2. We cannot read yours, and nobody here can tell you what it is.
  • Sessions are signed, HTTP-only, same-site cookies, marked secure in production, with a strict content security policy on every page.
  • Encryption in transit with modern TLS, and encryption at rest on the storage volume.
  • Backups are nightly and restore-tested, rather than assumed to work.
  • A wrong-workspace request returns not found, never forbidden, because forbidden would confirm the record exists somewhere and hand out a way to enumerate other firms.
  • Outbound integrations are checked against private address ranges, so a webhook cannot be pointed back at our own infrastructure.

If you believe you have found a vulnerability, write to security@3pointforward.com. We will confirm receipt within two business days and we will not pursue anyone who reports in good faith.

If a breach affects your data we will tell you without undue delay and in any case within 72 hours of becoming aware, with what happened, what was affected and what we are doing about it.

7. How long we keep it

  • Workspace content for as long as your account is open.
  • After you close an account, 30 days, so an accidental cancellation is recoverable, then permanent deletion. Backups roll off within 35 days.
  • Sign-in and audit records for 12 months.
  • Error reports for 90 days.
  • Billing records for seven years, because tax law requires it.

8. Your rights

Wherever you are, you can ask us to show you what we hold, correct it, delete it, or hand it over in a portable format. Tophat has a built-in export that produces your entire workspace as JSON or CSV whenever you like, without asking us, which is the fastest route for most of these.

If you are in the UK or the EEA you have the rights in the UK GDPR and the GDPR, including the right to object, the right to restrict processing and the right to complain to your supervisory authority. If you are in California you have the rights in the CCPA as amended, including the right to know and the right to delete. We do not sell or share personal information as those terms are defined there, so there is nothing for you to opt out of.

Write to privacy@3pointforward.com. We answer within 30 days.

9. Data processing

For everything in your workspace, you are the controller and we are the processor. We process it only on your documented instructions, which in practice means only to run the service. Our staff are bound by confidentiality, we keep a list of subprocessors and will give you 30 days' notice before adding one, and we will help you respond to a request from one of your own clients. A signed data processing agreement is available on request at privacy@3pointforward.com; if you are subject to the GDPR, ask for it before you load real data.

10. Cookies

Tophat sets two cookies and neither one tracks you. One holds your signed session so you stay logged in. One holds a token that stops another site submitting a form on your behalf. Both are strictly necessary, both expire, and there is no consent banner because there is nothing to consent to. Your light or dark theme preference is stored in your own browser and never reaches us.

This marketing site sets no cookies at all.

11. Children

Tophat is business software sold to firms. It is not directed at anyone under 18 and we do not knowingly collect their information.

12. Changes and contact

If we change this policy in a way that materially affects you, we will email the account owner at least 30 days before it takes effect. The date at the top of this page always reflects the current version.

SOPHIA XT LLC, trading as 3 Point Forward. privacy@3pointforward.com ยท security@3pointforward.com