Legal
This policy explains which personal data the platform processes, why, who it is shared with, and how to exercise your rights.
Last updated: July 4, 2026
Draft — pending legal review
The technical content of this page was taken from the platform's own code and reflects what it actually does. Even so, the text has not been reviewed by a lawyer and should not be treated as binding while this notice is here.
This distinction decides who answers for what, which is why it comes first.
We are the CONTROLLER of the data of whoever subscribes to the platform: name, e-mail, phone, profile picture and billing details of the agency and its users.
We are a PROCESSOR for the data the agency enters about third parties — end clients, guests, vendors. The agency decides why and how that data is processed and is its controller. We process it only on the agency's instructions and as needed to run the service.
From whoever creates an account: name, e-mail, password (stored only as a bcrypt hash, never in plain text), phone and profile picture when provided. Signing in with Google gives us the name, e-mail and picture from that account.
Data entered by the agency: names, e-mails and phone numbers of leads; names and phone numbers of guests; names, e-mails and phone numbers of vendors; plus project, task, schedule and financial records.
Usage data: pages visited and aggregate performance metrics, collected through Vercel Analytics.
Technical data: IP address and request headers, used for security, rate limiting, and to infer the country so prices show in the matching currency.
Providing the service and keeping your account and organization working.
Processing payments and issuing invoices.
Sending transactional messages: invitations, password resets, account and event notices.
Protecting the platform against fraud, abuse and malicious automation.
Improving the product from aggregate metrics that do not identify individuals.
Performance of a contract, for everything required to deliver and bill the service.
Compliance with a legal obligation, for tax and accounting retention.
Legitimate interests, for security, fraud prevention and product improvement, always balanced against your rights.
Consent, for non-essential cookies and marketing messages, which you can withdraw at any time.
We do not sell personal data. We share it only with providers needed to run the service, each processing it on our instructions:
Vercel — application hosting and route execution, plus usage metrics.
Neon — the PostgreSQL database where platform records are stored.
Stripe — payment processing and subscription management.
Resend — transactional e-mail delivery.
Cloudflare R2 — storage for files and images uploaded to the platform.
Cloudflare Turnstile — anti-bot verification on the sign-in screens.
Google — authentication, when you choose to sign in with a Google account.
We may also disclose data under a court order or a demand from a competent authority.
Essential cookies, which need no consent because the platform cannot work without them: the NextAuth session cookie that keeps you signed in; “st_active_org_id”, which records the active organization; “client_session”, which authenticates the client portal; and “NEXT_LOCALE”, which stores the chosen language.
Measurement cookies, used only with the consent given in the banner: aggregate audience and performance metrics.
You can revisit your choice at any time through the cookie banner or by clearing site data in your browser.
Account and organization data: for as long as the account exists.
After closure: export available for [30] days, then deletion, except for what the law requires us to keep.
Tax and billing records: for the statutory retention period.
Data processed as a processor: deleted on the controlling agency's instruction or at the end of our contract with it.
Traffic encrypted in transit, passwords stored only as hashes, data access segregated by organization throughout the data layer, and rate limiting on sensitive endpoints.
No system is immune. If a security incident carries meaningful risk, we will notify the affected people and the authority within the legal deadlines.
You may confirm whether processing exists, access your data, correct it, request anonymization, blocking or deletion, ask for portability, be told who it was shared with, and withdraw consent.
To exercise any of these, write to the officer named at the end of this page. We answer within the legal deadlines.
If you are a guest or an end client of an agency, address the request to that agency, which is the controller of that data — we will forward it if you come to us.
Some of the providers above run servers outside Brazil. Those transfers are made with the safeguards the law requires, including contractual clauses with the provider.
The platform is not intended for people under 18 and we do not knowingly collect children's data. Data about underage guests, when entered by an agency, is that agency's responsibility and requires a specific lawful basis.
We may update this policy. Material changes will be announced by e-mail or in the panel, and the date at the top will be revised.
Data Protection Officer: [name], [e-mail].