Plainstart Back to the kit

Article

Your Vendor's Reserve Should Not Be in a Chat Window

There is a specific moment in a sales campaign when an agent types something they should not. The campaign is moving fast. There are three interested parties, a vendor who has shifted their position twice, and an auction three days away. The agent opens an AI tool to draft a buyer update email, and they paste in the conversation notes to give the tool context.

Those notes contain the reserve. They contain the reason the vendor is selling. They might contain a line about the vendor's timeframe and what they said about the price they need to walk away happy.

That information is now in a prompt.

This article is about why that matters commercially, what category of risk it sits in, and what a small agency can actually do about it.


The Information That Drives Negotiation Outcomes

Not all sensitive information in a real estate agency creates the same kind of harm when it leaks. There are two broad categories, and agencies tend to focus on the wrong one.

The first category is personal data: names, identity documents, financial statements, contact details. Whatever privacy rules apply where you operate vary by jurisdiction and are worth checking with someone who knows your local rules. Agencies are generally aware of this category. They have processes for it, or at least intentions.

The second category is negotiation-critical commercial information. This is what actually determines the price a vendor achieves.

Specifically:

Reserve and walk-away figures. The price below which a vendor will not sell. If a buyer knows this number before auction, the entire competitive tension of the campaign collapses. A buyer who would have bid to 1.18 million bids to 1.02 million instead.

The vendor's reason for selling. A vendor selling because of a divorce, a deceased estate, or a job relocation is in a different negotiating position from a vendor testing the market. If a buyer knows the reason, they know how much pressure time creates.

Timeframe and urgency. Similar to reason for selling, but more specific. "Vendor needs to settle before end of financial year" is worth tens of thousands of dollars to a well-resourced buyer who knows it.

Buyer feedback and offer levels. What party A offered, what party B said they were willing to pay, where each buyer sits in terms of conditions and finance approval. Any buyer who knows this information has a structural advantage.

Campaign strategy. When the agency plans to move to auction, whether they are considering a board meeting, what the vendor's instruction is on pre-auction offers.


Why This Is a Different Risk Class

Most agency data risk conversations focus on privacy rules, breach notifications, and regulatory outcomes. That framing misses the point for commercial negotiation data.

The harm from leaking a vendor's reserve is not regulatory. It is immediate and financial. It happens in the next conversation a buyer has with their buyer's agent. It happens before the auction. It cannot be undone after the fact. There is no notification process, no remediation, no reputational management that repairs a vendor who sold for 80,000 less than they should have because their position was known.

The agency may face a very unhappy vendor and a complaint. The complaint may or may not go anywhere depending on how the engagement letter was worded. But the financial harm is already done.

This makes negotiation-critical information a higher-urgency operational risk than most privacy risks, not because privacy does not matter, but because the damage timeline is so compressed.


How It Gets Into the Tool

Agencies that brief their agents on data handling often focus on what not to upload. Do not upload ID documents. Do not upload financial statements. That is sensible.

What they miss is the summarisation habit.

Agents are busy. They are dealing with multiple parties across multiple campaigns. AI tools have become genuinely useful for drafting emails, summarising meetings, preparing vendor reports, and drafting scripts. The problem is that the fastest way to use these tools is to paste in your notes and ask the tool to work with them.

Those notes are not structured documents that an agent thinks of as sensitive files. They are often a few lines in a CRM, a voice memo transcript, or a running notes document. The agent does not frame it as "uploading sensitive client data." They frame it as giving the AI context.

The worked example of how this plays out is common enough that any experienced principal will recognise it.

An agent has a vendor meeting after a third open home. The vendor has shifted. They were asking for a strong result but have now said they will accept 995,000 if it is a clean offer. The agent takes notes. Later that day, they want to draft a buyer update email. They open an AI tool, paste the notes, and write: "Draft a professional email to our buyer register updating them on the campaign, keeping it warm but not giving too much away."

The notes they pasted gave everything away. The tool used some of that context in the draft. More importantly, the notes are now in a prompt submitted to a third-party service.


What an Agency Can Put in Place

The goal is a rule that agents will actually follow, not a policy document that sits in a folder.

The most effective single rule for most small agencies is this: before you paste anything into an AI tool, check whether it contains a number, a reason, or a timeframe that your vendor or buyer gave you in confidence.

If it does, remove it before pasting.

This is not a technical control. It is a habit built by a short briefing and occasional reinforcement. It works because it gives the agent a specific check rather than a vague instruction to be careful.

The worked example. A five-agent agency in a mid-sized market introduced one rule at a team meeting. The rule was: no reserve figures, no vendor motivation, no offer history goes into any external tool. The principal demonstrated what a prompt looked like with that information removed. Agents were shown that you can still get a useful email draft if you describe the campaign in general terms rather than pasting notes verbatim.

Six weeks later, one of the agents flagged a moment where they had nearly pasted a full set of negotiation notes. The habit had caught it. No extraction tool, no technical audit, just a clear rule that the agent had retained.

That is the realistic outcome of a well-briefed rule. Not perfect coverage. Not a guarantee. But a meaningful reduction in the most common failure mode.


The Broader Policy Behind the Rule

The single rule above is enough to reduce the immediate risk. But it sits better when it lives inside a written AI usage policy that the whole agency can point to.

A written policy does a few things beyond compliance. It tells the team what the agency's actual position is. It gives agents something to reference when a new tool or new workflow raises a question. It gives principals something concrete to point to when briefing new staff.

A policy built for real estate agencies is available free at Plainstart.


The Short Version

AI tools are useful in a campaign. They save time on email drafting, vendor reporting, and follow-up scripts. The risk is not the tool. The risk is what agents paste into it.

Reserve figures, vendor motivation, timeframe, buyer feedback, and offer history are the information that determines what price a vendor achieves. If that information enters a third-party tool mid-campaign, the potential harm is immediate and financial.

Put one clear rule in place. Brief the team on what it looks like in practice. Review it when the workflow changes.

That is not a policy. That is a working habit. The distinction matters because habits hold under pressure and policy documents do not.


This article is general guidance for agency principals thinking about operational data practices. It is not professional advice on legal, compliance, or regulatory obligations. Your adviser, your engagement letters, and your professional body are the right sources for those questions.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator