Privacy Policy
Last updated: August 4, 2026
This is an English translation provided for your convenience. In case of any discrepancy, the Portuguese-language version prevails.
Your privacy is important to us. This Privacy Policy describes how YA Desenvolvimento de Softwares Ltda, operating as Empresa Digital, collects, uses, protects, and shares information through the http://empresadigital.io website, Apple's App Store, the Google Play Store, and the management system, in compliance with the Brazilian General Data Protection Law (LGPD - Law No. 13.709/2018). This Policy is available in the app's settings menu, in the App Store and Google Play metadata, and on the website.
1. Data Collection
We collect information to provide and improve our services, including:
- Users (any access level): name, email, phone, date of birth, gender.
- Companies: CNPJ (company tax ID), phone.
- Usage data: sales information (point of sale), product and customer records, and management metrics.
- NFC/QR Code device: the time of access and the physical address of the business where the tag is placed, collected anonymously when scanned in order to route digital catalogs, with implied consent through the act of scanning. Identifiable data is collected only with explicit consent when filling out a form or logging in (no dynamic geolocation).
Data is collected on the basis of performance of a contract (for management-level users, as necessary for the system to function, via a checkbox at sign-up that includes acceptance of this Policy and the Terms of Use) or explicit consent (for end customers, when filling out forms or via a checkbox at sign-up that includes acceptance of this Policy and the Terms of Use). End customers may choose to browse anonymously, without providing identifiable data, although the system suggests creating an account for a better experience. Information from before account creation may be requested via optional forms for anonymous users. This Policy aligns with the data-safety declaration in the Google Play Console and with the App Store privacy guidelines.
Payment data, such as card information, is processed by third-party APIs via IAP or external gateways where permitted, without storage on our servers.
2. Purpose of Collection
Data is used to:
- Operate the management system, including the management of sales, products, and customers.
- Personalize the experience of management-level users and end customers (e.g., digital catalogs accessible via an NFC/QR Code device).
- Generate metrics and reports to improve business management.
- Send service-related communications (e.g., maintenance notifications, plan updates).
3. Data Sharing
We do not share personal information publicly or with third parties, except:
- With payment services (e.g., payment gateways such as PagSeguro or Stripe, where permitted) to process transactions made via In-App Purchases (IAP) or external gateways, as described in the Terms of Use. These third parties provide protection equivalent to that of the shared data, as required by the App Store, Google Play, and LGPD guidelines. Payment data, such as card information, is not stored on our servers.
- With services integrated via OAuth or APIs (e.g., email services, Google Maps, payment gateways, artificial-intelligence tools), with your general consent upon accepting this Policy via a checkbox at sign-up. Third parties provide protection equivalent to that of the shared data, as required by the App Store and Google Play guidelines.
- When required by law or by the competent authorities, in accordance with the LGPD.
You may revoke OAuth integration credentials in the in-app settings. YA Desenvolvimento de Softwares Ltda is not responsible for failures or unavailability of third-party services.
4. Data Retention
Data is retained for an indefinite period in order to provide the services and improve business management, unless you request its deletion. Deletion of user or company data is scheduled to occur within 30 days of the request. Deletion processing normally begins 24 hours after the request. You may cancel the request before it is executed, but deletion is irreversible once performed. End-customer data linked to a company will be deleted together with the company, unless they maintain an independent active account.
5. Security Measures
We protect your data with commercially acceptable measures, including:
- HTTPS encryption for all communications, per the Bubble.io infrastructure.
- Optional OAuth authentication for login.
- Optional two-factor authentication (2FA) for all users.
- Processing of card data by secure third-party APIs, without local storage.
Nonetheless, no system is completely immune to risk, and we are not responsible for unauthorized access beyond our control.
6. Rights of Data Subjects
You have rights guaranteed by the LGPD, including access, correction, deletion, portability, objection, and withdrawal of consent for the processing of your data. To exercise these rights, contact our Data Protection Officer (DPO) at yoav@empresadigital.io.
7. Links to External Sites
Our website, app, and distribution platforms may contain links to external sites not operated by us (e.g., status.bubble.io, third-party services). We have no control over the content or practices of these sites and are not responsible for their privacy policies.
8. Modifications
We may update this Privacy Policy at any time. Changes will be notified by email or via a pop-up on the website or app, if a revision is required. Continued use of the software implies acceptance of the updated version.
9. Contact
For questions about this Policy or the processing of data, contact our Data Protection Officer:
- Yoav Amaral
- Email: yoav@empresadigital.io
- Support page: http://empresadigital.io/contato