1. Introduction

This policy explains how Tonomo Serviços Digitais Ltda. (“Tonomo”) collects, uses and protects personal data when you interact with our marketplace.

2. Controller and contact

Tonomo Serviços Digitais Ltda.
E-mail: [email protected]

3. Data we collect

  • Account/authentication: name, e-mail, hashed password, optional phone, OAuth data.
  • Provider profile: business info, address, categories, photos and documents voluntarily uploaded.
  • Leads and communications: requests, messages, attachments, reviews, conversation history.
  • Preferences and consent: locale, theme, card layout, cookie banner decisions (accepted scopes, timestamp, banner version).
  • Usage and analytics: hashed IP, approximate city/country, browser, device, referral source, on-site events, cookies, localStorage, Analytics Beacon session identifiers.
  • Support/compliance: access logs, support tickets, information requested by authorities.

4. Purposes and legal bases

  • Provide the marketplace and enable lead exchange (contract performance).
  • Display profiles, leads and dashboards (contract performance).
  • Personalize experience (saved preferences, locale, viewing mode) when required to deliver the service or expressly consented to.
  • Detect fraud, ensure platform security and maintain logs (legitimate interest/legal obligation).
  • Measure usage and improve products via Analytics Beacon or partners such as Google Analytics only after analytics consent.
  • Send alerts, onboarding flows and promotional messages (legitimate interest/consent).
  • Comply with obligations under consumer, tax or regulatory laws (legal obligation).

5. Sharing

Data may be shared with: other users (when sending leads), infrastructure suppliers (hosting, e-mail, analytics, monitoring), marketing partners (aggregated or pseudonymized data) and public authorities when legally required.

6. Cookies and consent

We group cookies and similar technologies into:

  • Essential – required for login, locale, security, anti-fraud and baseline preferences (contract performance/legitimate interest).
  • Analytics – audience measurement, funnel tracking and performance, including Google Analytics and our first-party Analytics Beacon (processed only after explicit consent).

The cookie banner surfaces balanced “Accept all” and “Reject analytics” actions. You can revisit the decision anytime through the “Cookie preferences” link in the footer or your browser controls. We log consent metadata to demonstrate compliance. Disabling essential cookies may break parts of the experience.

7. Retention

Active accounts remain stored until deletion is requested. Archived provider profiles are deleted 30 days after archival. Logs and analytics are kept only as long as necessary for security, legal or analytical purposes.

8. Security

We adopt encryption, network segmentation, RBAC, secret rotation and continuous monitoring. No system is perfectly secure; if an incident occurs we will notify impacted users and authorities as required.

9. Data subject rights

You may request confirmation, access, correction, portability, restriction, deletion or consent withdrawal by contacting [email protected]. Cookie preferences can also be updated via the footer link. Requests will be answered within the legally required timeframe.

10. International transfers

Vendors may process data outside Brazil. By using the Platform you consent to the transfer subject to contractual safeguards ensuring an adequate level of protection.

11. Minors

The Platform targets users 18+. If we learn that we processed data from minors without authorization, we will delete it promptly.

12. Updates

We may revise this policy to reflect new features or legal requirements. The latest version will always be available on this page and material changes will be communicated via e-mail or in-app notice.

13. Contact and supervisory authority

Questions: [email protected]. If issues remain unresolved you may escalate to the Brazilian ANPD or your local data protection authority.

We use cookies

We rely on essential cookies for login and security and optional analytics cookies to measure visits. Read our Privacy Policy.