Privacy Policy
Last updated: September 3, 2026.
This Privacy Policy describes how Moonshot Digital collects, uses, shares, stores and protects personal data on this platform and on the other sites and domains we operate (together, the "Platform").
The Platform is a business management solution (CRM, customer service, scheduling and automation) offered as SaaS to small and midsize businesses. By using the Platform, you declare that you have read and understood this Policy.
1. Who controls your data
Moonshot Digital, registered under Brazilian company number (CNPJ) 55.900.072/0001-87, is the controller of the personal data processed in the activities described in this Policy.
Data Protection Officer (DPO) contact: fill in this form.
2. Our two roles in processing
- As controller: for data belonging to whoever creates an account and uses the Platform — registration, authentication, billing, support, security and product improvement.
- As processor: for data our customers (subscribing companies) enter into the Platform about their own contacts, end customers and staff. In those cases the subscribing company is the controller and defines the purposes of processing; we process such data only according to its instructions and the agreement in place. If you are an end customer of a company that uses the platform, address your access or deletion requests directly to that company.
3. Personal data we collect
3.1. Account and authentication data
Name, email address, profile picture, language, phone number (when provided), password stored in hashed form, and account identifiers from the social login provider.
3.2. Data received from social login providers
The Platform lets you create an account and sign in with Google, Microsoft and Facebook. In those flows we receive only the data covered by the scopes you expressly authorize on the provider's consent screen:
- Google —
emailandprofilescopes: email address, email verification status, name, profile picture and the unique Google account identifier. We do not request access to Gmail, Google Drive, Google Calendar, contacts or any other sensitive or restricted scope. - Microsoft — basic profile and email address.
- Facebook —
emailandpublic_profilescopes.
This data is used solely to create your account, authenticate your access, prevent duplicate registrations and display your name and picture inside the Platform. We do not post anything on your behalf on the provider's services, and you can revoke access at any time in the security settings of your Google, Microsoft or Facebook account.
3.3. Usage and technical information
IP address, browser and operating system type and version, device and session identifiers, pages visited, actions taken on the Platform, date and time of access, referrer and error logs. We collect this data for security, fraud prevention, fault diagnosis, performance measurement and product improvement, and to comply with the access log retention duty that applies to us as a company established in Brazil (Internet Civil Framework, Law 12,965/2014).
3.4. Billing data
Legal name, company or individual tax number, billing address, subscribed plan and payment history. Credit card data is collected and processed directly by our payment processors (Stripe and Pagar.me) — Moonshot Digital does not store full card numbers.
3.5. Communication and support data
Messages, attachments and contact information exchanged with us by email, support chat or forms, including the support history.
3.6. Content entered by the customer
Data the subscribing company and its users record on the Platform: contacts, deals, appointments, conversations, files and custom fields. We process this content as a processor, as described in item 2.
4. Purposes and legal bases (GDPR)
- Creating and managing your account, authenticating access and providing the contracted service — performance of a contract (art. 6(1)(b)).
- Billing, invoicing and collections — performance of a contract and compliance with a legal obligation (art. 6(1)(b) and 6(1)(c)).
- Technical support and operational communications about the service — performance of a contract (art. 6(1)(b)).
- Information security, fraud and abuse prevention, and access logs — compliance with a legal obligation and legitimate interest (art. 6(1)(c) and 6(1)(f)).
- Usage analysis, product metrics and Platform improvement — legitimate interest (art. 6(1)(f)), using aggregated or pseudonymized data whenever possible.
- Marketing communications about news and offers — consent (art. 6(1)(a)), revocable at any time through the unsubscribe link included in every message.
- Establishment, exercise or defence of legal claims — legitimate interest (art. 6(1)(f)).
Moonshot Digital is established in Brazil and is therefore also subject to the Brazilian General Data Protection Law (Law 13,709/2018 — LGPD), whose corresponding legal bases are art. 7, V (contract), art. 7, II (legal obligation), art. 7, IX (legitimate interest) and art. 7, I (consent).
5. Limited use of data obtained through Google APIs
The use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:
- We use data received from Google only to provide and improve user-facing features of the Platform — in our case, sign-in and account identification.
- We do not sell, rent or trade data obtained through Google APIs.
- We do not use this data for advertising, including personalized advertising, remarketing or third-party targeting.
- We do not use this data to develop, train or improve generalized artificial intelligence or machine learning models, nor do we transfer it to third parties for that purpose.
- We do not allow humans to read this data, except (i) with your express consent for specific cases, (ii) where necessary for security purposes, such as investigating abuse, (iii) to comply with applicable law, or (iv) where the data is aggregated and anonymized for internal operations.
6. Cookies and similar technologies
We use strictly necessary cookies (session, authentication, CSRF protection and load balancing), preference cookies (language and originating domain) and analytics cookies that measure use of the Platform. Necessary cookies cannot be disabled without breaking access. You can block or delete the others in your browser settings.
7. Sharing with third parties
We do not sell personal data. We share data only with service providers that process it on our behalf, under contract and confidentiality obligations, to the extent needed to operate the Platform:
- Amazon Web Services — hosting, file storage and transactional email delivery (SES).
- Google Cloud Platform — infrastructure and internal messaging (Pub/Sub).
- Stripe — payment processing and subscription management.
- Pagar.me — payment processing and subscription management.
- Brevo — customer support and email marketing communications.
- PostHog — product usage analytics.
- New Relic — application performance and error monitoring.
We may also share data (i) to comply with a legal obligation, court order or request from a competent authority; (ii) to protect the rights, security and integrity of Moonshot Digital, its users or third parties; and (iii) in the context of a merger, acquisition or corporate reorganization, in which case we will inform data subjects and tell them which policy applies under the new controller.
8. International data transfers
We are established in Brazil and some of the providers listed above operate from the United States and the European Union, so your data may be transferred outside the European Economic Area and the United Kingdom. Where that happens, the transfer is covered by the European Commission's standard contractual clauses (and the UK International Data Transfer Addendum, where applicable), together with the supplementary measures required by chapter V of the GDPR. You may request a copy of the safeguards in place through the contact in item 16.
9. Retention and deletion
- Account data and customer content: for the term of the subscription and for up to 90 days after it ends, during which the account can be reactivated.
- Tax and billing data: 5 years, as required by law.
- Internet application access logs: 6 months, under the Brazilian Internet Civil Framework.
- Data processed on the basis of consent: until consent is withdrawn.
Once those periods end, the data is irreversibly deleted or anonymized, except where we are required or permitted by law to keep it — for instance to comply with a legal obligation or to establish, exercise or defend legal claims.
10. Information security
We adopt technical and administrative measures to protect data, including: encryption in transit (TLS) and at rest, hashed password storage, role-based access control, logical data isolation between customers (multi-tenant architecture), audit logging, periodic backups and continuous monitoring. In the event of a personal data breach, we will notify the competent supervisory authority without undue delay and, where the breach is likely to result in a high risk to your rights and freedoms, we will notify the affected data subjects as well.
11. Your rights
Under the GDPR you may, at any time, request: access to your personal data; rectification of inaccurate or incomplete data; erasure ("right to be forgotten"); restriction of processing; data portability; and information about how your data is shared. You may also object to processing based on legitimate interest, withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal, and ask not to be subject to decisions based solely on automated processing.
Moonshot Digital is compliant with the General Data Protection Regulation (GDPR). To exercise these rights, fill in this form — requests sent through the form are processed within 7 days. We reply to any request within one month and may ask for additional information to confirm your identity. You may also lodge a complaint with the supervisory authority of your country of residence or, in the United Kingdom, with the Information Commissioner's Office.
12. Account and data deletion
Account deletion can be requested inside the Platform, in the user settings, or through this form. Once we receive the request we terminate access immediately and delete the personal data associated with the account, including data obtained through Google social login, within 30 days — retaining only the minimum required by law, as described in item 9. Accounts created by a subscribing company are deleted at the request of that account's administrator.
13. Children and adolescents
The Platform is intended for business use and is not directed at anyone under 18. We do not knowingly collect data from children or adolescents; if such collection is identified, the data is deleted.
14. Third-party sites and services
The Platform may contain links to sites we do not operate. We have no control over their content and practices, and we recommend reading their respective privacy policies.
15. Changes to this Policy
We may update this Policy to reflect legal, technical or business changes. The date of the last update appears at the top of this page and, in the event of a material change, we will give notice by email or through a notice on the Platform before it takes effect.
16. Contact
Questions about this Policy or about how your data is processed: fill in this form.