Brazilian LGPD grants rights to personal-data subjects and defines roles such as controller and processor. This policy summarizes our practices and privacy contact.
Who controls the data
- The platform controller is ServerPlace Serviços de Internet LTDA, CNPJ 04.114.466/0001-79, responsible for the main decisions about cidades.io data processing.
- Businesses, brands and public bodies may also act as controllers for data they enter, receive or process in their own service, campaigns and obligations.
- Privacy contact: privacidade@cidades.io.
Data we collect
- Account and authentication: name, e-mail, WhatsApp, OTP code, session identifiers and, when required, CPF or document data for identity, campaign, coupon or regulated flows.
- Content and relationship: messages, quote requests, applications, support, favorites, follows, client status, coupons, wishes, citizen reports and official replies.
- Business and public-body data: CNPJ, categories, location, contacts, hours, team, products, services, jobs, deals, brands, photos, alerts and reports.
- Technical use and analytics: clicks, impressions, searches, traffic source, device, language, cookies/localStorage, push tokens, security logs and aggregate metrics.
- Location: optional user coordinates for Nearby, routes, AR Vision and nearby search; business map points; geocoding and routes when requested.
- Billing: plan, PIX reference, payment status, invoices and tax data. We do not store full card data.
Why we use data
- To provide the service, authenticate users, show nearby businesses, deliver search results, operate messages, coupons, bookings, citizen reports and support.
- To protect against fraud, spam, abuse, intrusion, illegal content and metric manipulation.
- To generate analytics for businesses and cities whenever possible in aggregate form, with privacy floors and without selling personal data.
- To send in-app/push notifications and transactional e-mail or WhatsApp communications when there is a valid basis, preference and integration.
- To fulfill contracts, tax, legal and regulatory obligations and exercise rights.
AI, moderation and translation
- We use AI models for semantic search, embeddings, text/image moderation, translation, content suggestions, recommendations, WhatsApp Concierge, virtual influencers and assisted support.
- Providers may include Google Gemini, DeepSeek, Grok/xAI and OpenAI depending on feature, cost and technical availability.
- We apply minimization and sanitization whenever possible. CPF, documents, financial data and sensitive data should not be sent to AI except for specific and controlled technical/legal necessity.
- AI answers may be wrong. Businesses and users should verify critical information before acting.
Sharing
- We share data with essential processors: hosting, database, CDN, media storage, maps/geocoding, e-mail, push, WhatsApp/Meta, payment, OCR/moderation and AI providers.
- Businesses receive data needed to respond to contacts, validate coupons, serve clients, analyze aggregate metrics and meet their own obligations.
- Public bodies receive reports, alerts and civic information when the module is active and configured for that municipality.
- We may share records when required by law, competent authority, fraud prevention, security or defense of rights.
Retention
- Accounts and operational data remain while the account or relationship is active, unless deletion is requested or retention is required.
- Raw analytics may be kept for up to 12 months; non-identifying aggregates may remain indefinitely.
- WhatsApp Concierge conversations may be kept for up to 180 days for audit, quality and defense of rights.
- To pick up where you left off, the WhatsApp Concierge stores the city you used, the last businesses it showed you and a short summary of the conversation topic (what you were looking for and what was left open), for up to 90 days without use. That summary is written by the system in one or two functional sentences: we do not keep the text of your messages in it, and we do not record health, religion, personal legal matters, politics or sexual life. At any time you can write "apagar meus dados" (delete my data) in the WhatsApp conversation: we immediately erase the memory, the summary, the interests, the stored city and the concierge conversation history.
- Push tokens expire or are removed after inactivity, logout or deletion; tax and payment records follow legal periods.
- When an account is deleted, we remove or anonymize personal data within 30 days, preserving minimum records required by law, security or audit.
Your rights
- You may request access, correction, portability, anonymization, blocking, deletion, information about sharing, review of automated decisions and consent withdrawal when applicable.
- Some data may remain when required by law, fraud prevention, security, exercise of rights or contractual necessity.
- Requests should be sent to privacidade@cidades.io. We may request identity confirmation before responding.
Security and choices
- We use access controls, logs, encryption in transit, media protection, moderation and role segregation to reduce risks.
- You control location, camera, notification and cookie permissions through the browser, app or operating system.
- External services may become unavailable or change policies. When this affects privacy or experience, we may disable integrations until they are safe.
Account inactivity
- Personal accounts with no activity for about 12 months may receive a notice; after about 15 months without access they may be deactivated to reduce operational risk and keep the database current.
- Deactivation is not automatic deletion: we keep minimum data required for security, audit, transaction history, support, campaigns, fraud prevention or legal obligations. The account can be reactivated by e-mail or WhatsApp verification.