In five lines
- We do not read your group messages. We counted how many there were, never what they said.
- We do not sell data. Never, to anyone.
- Integration secret is encrypted and is never redisplayed in its entirety.
- The pixels on the website are yours, and the events go to the ad accounts you've set up.
- You can delete it whenever you want, and we delete it within 30 days.
01 Who takes care of your data
The data controller is the Ambrosio Company Negócios Ltda, CNPJ 37.465.426/0001-20. For any privacy matter, including to exercise the rights provided for in the General Data Protection Law (Law 13,709/2018), speak to our person in charge by email [email protected].
This policy applies to the platform, the achadu.com website and the offer websites that customers publish with our tool.
02 What we keep, and why
We keep the minimum necessary for the tool to work:
| Given | For what | Legal basis |
|---|
| Name, email and password (saved as hash) | Create and protect your account | Contract execution |
| Affiliate identifiers (AppId, tags, network IDs) | Mark links with your commission | Contract execution |
| WhatsApp session and Telegram token | Post to your groups at your request | Contract execution |
| Groups, offers, shipping, coupons and scheduling | Operate the platform and prepare your reports | Contract execution |
| Member arrivals and departures, volume of messages per group | Group and funnel health reports | Legitimate interest |
| Invitation clicks: IP, browser and campaign parameters | Measure ad conversion and stop robot clicks | Legitimate interest |
| Access records (date, time, IP) | Security and legal obligation of the Marco Civil | Legal obligation |
What we don't do: We do not read the content of your group messages. The WhatsApp Monitor counts how many There were messages every day, never what was written or by whom.
03 How we protect what is sensitive
Integration secrets (such as Secret and Shopee and API tokens) are saved encrypted with AES-256-GCM and never redisplayed completely on the screen: you only see a mask.
Each operation lives in a logical database separate from the others, and access requires authentication with an expiring session. Traffic is always via HTTPS. The bank's backup copies are encrypted and stored in a private bucket.
04 Who do we share with
We do not sell data, ever. We only share what is necessary with those who operate parts of the service:
- Infrastructure: server and file storage where the platform runs.
- Artificial intelligence providers (at the discretion of the appliance owner, for example OpenRouter, Anthropic, OpenAI, Groq or Google): receive the offer text to generate copy. We do not send personal data of group members.
- Meta and Google: When you set up your pixels, visit and lead events go out to the ad platforms that you chose, including the visitor's own matching signals (browser identifier, IP and agent). These pixels are yours, and so is the responsibility for their use.
- Marketplaces and affiliate networks: receive the click with their identifier, to credit the commission.
- Authorities, when there is legal order.
Some of these suppliers are outside Brazil. In these cases, the international transfer is based on the clauses of article 33 of LGPD.
05 Cookies and measurement
On the achadu.com website we only use the essentials: a session cookie to keep you logged in and theme preference (light or dark). We do not use our own advertising cookies.
On offer sites published by customers, the Meta and Google pixels (and Google Tag Manager and AdSense, when activated) are configured by each customer, who is responsible for them as the controller of that data.
06 How long do we keep
As long as your account exists, we store the data necessary for the tool to work. After closure, we delete them within 30 days, with two exceptions: access records are kept for 6 months (Marco Civil da Internet) and tax billing data is kept for 5 years, as required by law.
07 Your rights, and how to use
Through LGPD you can, at any time: confirm whether we process your data, access it, correct what is wrong, request anonymization or deletion, request portability, know who we share it with, and revoke consent when it is the basis of the processing.
Write to [email protected]. We respond within 15 days. If you prefer, exporting your data is also available within the platform.
08 If an incident happens
If there is a security incident with a relevant risk for you, we will inform you and the National Data Protection Authority within a reasonable time, saying what happened, what data was affected and what we are doing.
09 Minors
The platform is for people over 18 years old. We do not knowingly collect data from children and adolescents. If we identify it, we delete it.
Last updated: August 24, 2026.