Skip to content

Legal

Privacy Policy

Learn how we collect, use, and protect your personal information

Last updated: · v2026-08-19

Introduction

This Policy describes how OrcaCostPrint processes personal data, in compliance with the Brazilian data-protection law (LGPD, Law 13,709/2018). It covers your account data — for which we are the CONTROLLER — and the data of end clients you register, for which YOU are the controller and we are the PROCESSOR, handling it only to provide the service. Acceptance of this policy is recorded at sign-up, together with the version accepted.

Data Collection

How we collect and use your data

Your account data

  • Email (authentication and communication)
  • Name (and your Google display name, if you use Google sign-in)
  • Phone (optional), language, currency, logo and other profile data you provide

Data you register in the service

  • Printers, materials, costs and tariffs
  • Stock, product catalog and uploaded images
  • Calculation history and quotations
  • End-client data you register (name, contact, quotes) — processed by us as processor

Data use and legal bases

Providing the service: authentication, calculations, quotations, catalog and support (performance of contract).

Improving the product and preventing fraud and abuse (legitimate interest, with data minimization).

Sending transactional communications (security, billing) and — only with your consent — news and research invitations.

Complying with legal and tax obligations and exercising rights in legal proceedings.

Data Sharing

We do not sell personal data. We share it only with the sub-processors needed to provide the service (listed below) and in the cases required by law:

We never share: Your data with advertisers, data brokers or marketing companies.

We only share when: When required by law or court order, to protect rights and prevent fraud, or with sub-processors under contract.

Data security

Encryption in transit (TLS) and at rest (Google Cloud infrastructure default).

Per-user isolation — each account can only access its own data, with an automated test of that guarantee — and restricted, audited administrative access.

Immutable audit trails for consents, data exports and administrative actions.

Automatic backups with limited retention and point-in-time recovery (PITR).

Your Rights

Confirmation and access: Confirm whether we process your data and receive a copy of it.

Correction: Correct incomplete, inaccurate or outdated data.

Deletion and anonymization: Delete data processed with consent or that is unnecessary — including by deleting your account — except for records we must keep by law.

Portability and withdrawal: Receive your data in a structured format and withdraw consent at any time (for example, marketing communications, in Settings).

Cookies and Similar Technologies

We use the essentials and, only with your consent, audience measurement on public pages — there are no advertising cookies and no cross-site tracking:

Session and authentication: Firebase Auth tokens to keep you signed in securely.

Abuse protection: reCAPTCHA v3 (Google) on sensitive actions, to tell people apart from bots.

Local preferences: Language, currency and theme, stored in your browser (localStorage).

Audience measurement (optional): Google Analytics 4, on public pages only (home, pricing, about), with anonymized IP and only if you accept the cookie notice. You can decline or withdraw at any time; it is never loaded inside the app.

Feature usage: We record, on our own servers, which screens and functions of your account you use (e.g. "generated a PDF"), without any data about your customers. It helps us improve the product and decide what to keep; it is not shared with third parties and is deleted after 12 months.

Legal bases (LGPD, art. 7)

  • Performance of contract: account, authentication, calculations, quotations and billing.
  • Consent: marketing communications and research (separate, revocable opt-in) and publication of testimonials.
  • Legitimate interest: security, fraud prevention and product improvement — always with minimization and the possibility to object.
  • Legal obligation: keeping tax and access records.

Other data we collect

  • Consent record: accepted version, date and time, IP and browser — evidence of acceptance.
  • IP address on first access, used only to suggest your currency (MaxMind GeoIP); we do not build a location profile.
  • Payments: processed by Stripe; we receive only subscription status and identifiers — never your full card number.
  • Export trail: who exported what and when (security measure).

Sub-processors

They provide services under contract and their own data-protection policies:

  • Google Cloud / Firebase (USA) — authentication, API hosting and database;
  • Stripe (USA) — payments and subscriptions;
  • Vercel (USA) — website hosting;
  • Cloudflare (USA) — DNS and edge protection;
  • MaxMind (USA) — country resolution by IP (to suggest your currency).

International transfer

The sub-processors above may process data outside Brazil (USA). Transfers rely on the mechanisms of art. 33 of the LGPD, including contractual clauses and the providers’ own certifications.

Retention

  • Account and service data: for as long as the account exists.
  • After account deletion: removed from active systems; backup copies expire within 30 days.
  • Consent records and audit trails: 5 years, as evidence (limitation period).
  • Tax and billing records: 5 years, as required by law.
  • Marketing opt-in: until withdrawn — the withdrawal is also recorded.

Minors

The service is intended for people aged 18 or over, and we do not knowingly collect data from children or adolescents. If we identify a minor’s account, it will be closed and the data deleted.

Security incidents

Incidents posing relevant risk to data subjects will be reported to the ANPD (Brazilian DPA) and to those affected under art. 48 of the LGPD, describing the nature of the incident, the data involved and the measures taken. When we act as processor, we notify you (the controller) so you can inform your clients.

Data Protection Officer (DPO)

The contact for the officer in charge of personal-data processing is support@orcacostprint.com. Use this channel for data-subject requests; if unsatisfied, you may escalate to the ANPD (gov.br/anpd).

Changes to this policy

Each version is identified by date (the current one appears at the top). Material changes will be communicated and, when required, we will ask for a new acceptance; the history of accepted versions is recorded on your account.