REAL ESTATE ANALYSISCapShark
Trust and transparency
Trust Centre · reviewed August 29, 2026

Clear about the data, the method and the limits.

CapShark is decision-support software. This page explains what runs locally, what may be sent to CapShark, how paid access should be verified, and where professional judgment is still required.

Free saved dealsOn deviceUntil cleared by the user/browser
Card processingStripeCapShark does not receive full card numbers
AnalyticsOpt-inNo property, borrower or input values
Method reviewAug 29Dates remain visible on public pages
Data

Browser-local by default

Free saved deals, the two-deal board and current CSV Deal Room processing remain in the browser unless the user intentionally begins a report or support workflow.

Payments and access

Server verification required

Stripe handles payment. A return URL, local record or email must never grant Pro access or mark a report paid. Webhook verification and account entitlement are required.

Methods and sources

Assumptions stay visible

Results depend on user inputs and simplified models. Public sources, key formulas, limitations and review dates are documented and must be checked against current requirements.

Current controls

What is protected—and what still needs production configuration.

AreaCurrent controlProduction requirement
Free calculatorsLocal inputs; visible assumptions and disclaimersHTTPS, error monitoring and release tests
AnalyticsConsent-first event layer; no deal or borrower valuesPrivate owner role, server aggregation and retention rules
ProPaid UI never trusts browser/URL stateAccount provider + verified Stripe webhooks + entitlement database
Paid reportsUnique local order reference and manual verification warningVerified order state, private file storage, access log and delivery SLA
Deal RoomCSV files processed locally in the betaSecure document service before enabling server-side Excel/PDF processing
Analytics privacy

Measure the funnel—not the borrower.

The analytics layer permits only approved event names and non-sensitive properties. It excludes property addresses, borrower/sponsor details, emails, report IDs, document contents and calculator input/output values.

Launch gate: do not publicly advertise secure cross-device Pro workspaces, automated paid-report access or document uploads until the production authentication, storage, Stripe webhook and owner-admin controls are deployed and tested.