Privacy Policy
Effective date: October 8, 2026
This Privacy Policy explains how JVL Agency ("JVL Agency," "we," "us" or "our"), the provider of TitleMagic (the "Service"), collects, uses, shares and protects information. It applies to our website at gettitlemagic.com, to the TitleMagic application used by title and escrow companies ("Customers") and their employees ("Authorized Users"), and to the secure forms completed by Customers' clients ("Signers").
Our role. For information Signers submit through a Customer's forms ("Client Data"), we act as a service provider to that Customer: we process Client Data only on the Customer's behalf and under its instructions, and the Customer's own privacy notice governs its use of that information. If you are a Signer, please direct questions about how your title or escrow company uses your information to that company. For information about Customers, Authorized Users and website visitors, JVL Agency is responsible for the information as described in this Policy. Client Data may include "nonpublic personal information" that title and escrow companies must protect under the Gramm-Leach-Bliley Act; we process it as the Customer's service provider and protect it as described in "How We Protect Information."
1.Information We Collect
Company and account information. When a Customer registers, we collect the company name and logo, and each Authorized User's name, business email address, role (Owner or Processor) and password (stored only as a one-way hash). If an Authorized User signs in with Google, we receive their name, email address and Google account identifier from Google.
Billing information. Subscriptions are paid through Stripe. We receive a Stripe customer identifier, the selected plan, subscription status, billing period and payment status. We do not receive or store full card numbers or card security codes.
Client Data submitted by Signers. Depending on the form a Customer sends, Signers may provide:
- identity and contact details, such as full legal name, email address, phone numbers, current and mailing addresses, marital status, citizenship and date of birth;
- Social Security numbers and tax identification numbers;
- financial information, such as mortgage, lender and payoff details (our forms do not ask for bank account or wire instructions; forms sent before October 7, 2026 may contain them);
- entity information, such as entity names, formation details, authorized representatives and ownership;
- property and transaction information relating to the real estate transaction;
- uploaded documents, such as driver's licenses, passports or other government-issued identification, entity formation documents and financial statements; and
- electronic signatures (a drawn signature image or typed legal name) and the Signer's acceptance of our Consent to Electronic Records and Signatures.
Client Data also includes answers to any additional questions and documents requested by a Customer's own customized forms. Customers decide what those questions ask.
Signature and technical records. When a Signer opens and signs a form, we record the date and time the link was viewed and signed, the Signer's IP address and browser (user-agent) information. This audit trail is kept with the signed record to evidence the electronic signature. We also keep server logs of requests to the Service (such as IP address, pages requested and timestamps) for security and troubleshooting.
Integration credentials. If a Customer connects a title production or other system, we store the credentials needed to do so, such as an API key and webhook address (API keys are encrypted).
Terms acceptance records. When an Authorized User accepts our Terms of Service, we record the version, the date and time, and the IP address and browser used.
Website inquiries. If you submit our contact or demo form, we collect your name, work email, phone number, company, plan of interest and message.
Cookies and similar technologies. See "Cookies and Analytics" below.
2.How We Use Information
We use information to:
- provide the Service, including sending Magic Links by email, displaying forms to the intended Signer, capturing electronic signatures, recording the signature audit trail, notifying the sending Authorized User when a form is signed, generating PDF records, and emailing each Signer a secure link to download a copy of the form they signed;
- transmit completed submissions to a system the Customer has connected, when an Authorized User selects that option or enables automatic transmission;
- create and manage accounts, authenticate Authorized Users, process password resets, and administer subscriptions, quotas and billing;
- provide customer support and respond to inquiries;
- protect the Service, Customers and Signers, including detecting and preventing fraud, abuse, spam and unauthorized access, and enforcing rate limits and our Terms of Service;
- comply with legal obligations and respond to lawful requests; and
- understand and improve our website and Service using aggregated or de-identified information.
We use Client Data only to provide the Service to the Customer that collected it and as that Customer instructs. We do not use Client Data for marketing or advertising, and we do not use Client Data to train machine-learning or artificial-intelligence models. Email notifications to Authorized Users never include Signers' form answers; they contain only who signed and a link to the secure dashboard.
3.How We Share Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share information only as follows:
- With the Customer. Client Data is available to the Authorized Users of the Customer that sent the Magic Link. Authorized Users of other Customers cannot access it.
- With systems a Customer connects. When a Customer transmits a submission to a title production or other system it has connected (for example, Qualia), we send the Client Data for that submission (including sensitive fields in decrypted form, over an encrypted connection) to that system. The provider's handling of that data is governed by its agreement with the Customer.
- With Stripe, for payment processing and billing, as described above.
- With email delivery infrastructure. Magic Links, signed-copy links, password-reset emails and notifications are delivered through authenticated email servers operated for us on our hosting infrastructure. Emails contain the recipient's name and email address, the company name, the form name and the secure link — never form answers or uploaded documents.
- With our hosting provider. The Service, its database, uploaded documents and our email server run on servers we lease from IONOS Inc. in the United States. We do not use a third-party email delivery service.
- With Google, when an Authorized User chooses Google Sign-In, and for website analytics (Google Analytics) on visitors who accept analytics cookies. Google Analytics is not used to collect Client Data.
- For legal reasons, when we believe in good faith that disclosure is required by law, subpoena or other legal process, or is necessary to protect the rights, property or safety of JVL Agency, our Customers, Signers or others.
- In a business transfer, such as a merger, acquisition or sale of assets, subject to this Policy's protections.
Our service providers (subprocessors) are: IONOS Inc. (hosting, database, document storage and email server, United States); Stripe, Inc. (subscription billing; no Client Data); and Google LLC (Google Sign-In for Authorized Users who choose it, and Google Analytics on our website for visitors who accept analytics cookies; no Client Data). We do not load fonts or other resources from third parties on secure form pages.
4.How We Protect Information
We use administrative, technical and physical safeguards designed to protect information, including:
- TLS (HTTPS) encryption for all data in transit between browsers and the Service, including strict transport security;
- AES-256-GCM encryption at rest for Social Security numbers, bank account numbers, routing numbers, tax identification numbers and other fields designated as sensitive, applied at the field level before storage;
- AES-256-GCM encryption at rest for every document uploaded by a Signer; uploaded documents are never publicly accessible and can be downloaded only by authenticated Authorized Users of the Customer that requested them;
- encryption of stored integration credentials, such as API keys for connected systems;
- strict, company-level access controls so that each Authorized User can access only their own company's records, with platform administrator access limited to named personnel and logged;
- unique, randomly generated Magic Links that expire after seven (7) days, stop accepting changes once a form is submitted, and are deactivated when replaced;
- one-way hashing of passwords and of password-reset tokens, with reset links that expire after one hour and can be used once;
- rate limiting of form submissions, contact forms and password-reset requests;
- masking of Social Security, bank account and routing numbers in generated PDF records and in signed copies sent to Signers;
- masking of sensitive values in the dashboard, where a full value is shown only on an explicit request that is recorded in an access log, together with document, PDF and bulk-export downloads (user, time, IP address and browser); and
- a snapshot of the exact form version each Signer was shown, kept with the signed record.
No system is perfectly secure, and we cannot guarantee the security of information. If we learn of a security incident affecting personal information in our systems, we will notify affected Customers without undue delay so that they can meet their obligations, and we will provide other notices required by law.
5.Data Retention and Deletion
Client Data is retained on behalf of the Customer for as long as the Customer's account is active, unless the Customer deletes it, asks us to delete it sooner, or selects a retention period in the Service, in which case each submission's answers, signatures and documents are deleted or de-identified automatically once that period has passed (the Customer may choose to keep a copy of the signed PDF record). Magic Links that are not used expire after seven days, but the associated record remains in the Customer's account.
When a Customer's subscription ends, the account remains available in read-only mode for thirty (30) days so the Customer can export its records, and we email the Customer's account owners reminders before its data is deleted. We then delete or de-identify Customer and Client Data within ninety (90) days, except for copies in backups (deleted as backups are overwritten in the normal course), billing records and other information we must retain by law, and limited records needed to establish or defend legal claims.
Signed-copy links emailed to Signers stop working after thirty (30) days or when the submission is deleted, whichever is first. Account information is retained while the account is active and for the period described above. Website inquiries are retained for as long as needed to respond and follow up, and may be deleted on request. Server logs are retained for a limited period for security and troubleshooting.
Deletion requests. Customers may request deletion of their account or specific records by emailing info@jvlagency.com from the account owner's email address. Signers should contact the title or escrow company that sent them the form; if a Signer contacts us directly, we will forward the request to that Customer and assist it as required. Customers may be required by law or by their underwriters to retain certain transaction records, in which case deletion may be limited.
6.Your Choices and Rights
Authorized Users can change their password in the Service at any time, and can contact us to access, correct or delete their other account information. You may opt out of non-transactional emails from us at any time by using the unsubscribe instructions in the email or by contacting us; we will still send service-related messages such as Magic Links, password resets and billing notices.
Depending on where you live, you may have rights under state privacy laws to request access to, correction of, or deletion of your personal information, and to not be discriminated against for exercising those rights. Some information we process on behalf of title and escrow companies is subject to the Gramm-Leach-Bliley Act and may be exempt from certain state privacy laws. To make a request, contact us as described below; we will verify your request and, where we process the information on behalf of a Customer, refer it to that Customer.
7.Cookies and Analytics
We use a small number of cookies and similar technologies:
- Essential: a secure session cookie that keeps Authorized Users signed in to the dashboard. The Service cannot function without it.
- Preferences: a setting stored in your browser that remembers whether you accepted or declined analytics cookies.
- Analytics: Google Analytics 4 helps us understand how visitors use our public marketing pages (such as the home, pricing, product, guide, FAQ, about, contact and sign-up pages). It is never loaded on pages where clients enter information (secure form pages opened from a Magic Link), on the sign-in and password pages, or anywhere in the dashboard. Its cookies are set only if you click "Accept" in our cookie notice; if you decline, analytics runs without storing cookies on your device.
We do not use advertising cookies. Secure form pages opened from a Magic Link do not display the cookie notice. You can also block or delete cookies through your browser settings.
8.Communications
We send transactional emails needed to provide the Service, including Magic Links and signed-copy links to Signers and account and data-retention notices to Authorized Users. We do not send text messages or make automated calls. If you contact us through our website, we may reply by email or telephone about your inquiry.
9.Children's Privacy
The Service is intended for businesses and adults. It is not directed to children under 18, and we do not knowingly collect personal information from children.
10.Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new effective date and, for material changes, notify Customers by email or in the Service before the changes take effect.
11.Contact Us
Questions or requests about this Privacy Policy may be sent to JVL Agency at info@jvlagency.com. To report a security vulnerability, email info@jvlagency.com with "Security report" in the subject line.