Privacy Policy
1. Who the controller is
Concealed, Unipessoal Lda, with the single registration and tax number 514 292 695 and share capital of €6,000, with its registered office at Rua da Fonte, nº13, Toledo, 2530-781 Vimeiro LNH, operator of Apronta (apronta.co, apronta.site), is the controller of the personal data described in this policy, except where stated otherwise (section 4).
Contact for privacy questions: [email protected].
No data protection officer (DPO) is currently appointed: the size of the team (two founders) does not require one by law at this time. This assessment will be reviewed as the volume of data grows.
2. What data we process, and for whom
2.1 Business owners (direct users of Apronta)
Email, name, authentication session, onboarding answers, content they put on the site (business address, NIF tax number, opening hours, photos, menu). Legal basis: performance of the subscription contract. With the draft, and then with the account, we also keep the identifier Datafast gave the browser on which the draft was made or, if that one has none, the browser on which the business was registered. When the business is registered, we tell Datafast the account’s internal identifier and that of the organisation the business belongs to, with the kind of business and the language, and we tell it the account’s again each time someone signs in to it. This serves to join up the visits of the same person across different browsers and devices and to know which visit to Apronta’s site brought each business (section 2.2). Neither with these identifiers nor with the moments in section 2.2 does Apronta send Datafast anyone’s email or name; what Datafast reads in Stripe about payments to Apronta, which includes the payer’s email and name, is set out in section 2.4. [TO CONFIRM: legal basis for linking the visit to the account, legitimate interest or consent. It is a legal decision, still to be made.]
To write the draft of the site, to read the photographs or PDFs of the menu that the owner sends, to suggest translations of the site’s texts and to suggest texts for campaigns and replies to reviews, this data about the business is processed by an artificial intelligence model from Anthropic (section 5). Apronta does not keep those photographs: they serve only to read the list. The owner confirms the list, the translations and each suggested text before they are published or sent.
Google listing. If the owner connects the business’s listing on Google (Google Business Profile), Apronta uses that authorisation for three things: updating the listing (site address, opening hours and booking button); reading the listing’s reviews when the owner opens the Reviews screen, without storing them; and publishing a reply to a review only when the owner presses publish on that review. For each reply published, we keep who published it, when, and the text, as proof of the owner’s authorisation. The text of a review only goes to Anthropic when the owner asks for a suggested reply (section 2.3). The owner can disconnect the listing at any time in Settings.
2.2 Visitors to published sites (*.apronta.site)
Visit statistics are deliberately anonymous and cookie-free: a count is kept per (business, day, source of the visit: for example QR, Google, Instagram, WhatsApp, direct access), never a record per visitor. No cookie notice is needed for this feature, because no personal data and no visitor identifiers are collected. Published sites do not load Google Analytics, Meta Pixel, or any other third-party analytics tool.
Google content. Two things on a published site come directly from Google: the map, when the business has a section with a map, which loads when the visitor comes near it on the page; and the business’s rating, reviews and photographs on Google, when the business shows them, which Google itself draws on the page. In those cases the visitor’s browser connects to Google’s servers, and Google receives the visitor’s IP address and may store its own cookies, as controller and under the Google Privacy Policy and the Google Maps/Google Earth Additional Terms of Service. Apronta receives and stores nothing from that side, and a site with neither a map nor Google content does not connect to Google.
On Apronta’s own site (apronta.co, and not the businesses’ sites), we use Datafast to count visits and to understand what they lead to. Unlike the count on published sites described above, this one uses a cookie to recognise a returning visitor, and that is why the distinction matters: the cookie exists on Apronta’s site and does not exist on any business’s published site. Besides the pages viewed, it counts the main buttons pressed and how far the home page and the pricing page are read. To the visitor identifier that cookie holds, our server adds a few moments only it can see: a draft made, the questions finished, a link requested to register the business, the business registered, the page published for the first time, a plan chosen, a payment started and a plan paid for. Each moment carries only details that identify nobody (such as the kind of business, the plan, monthly or yearly, the number of locations, the language or the page of the site where it started), never anyone’s name, email or phone, nor the business’s name or address. We do not follow anyone onto other sites, nor do we share this data with advertisers. [TO CONFIRM: consent for this cookie on apronta.co, or switching Datafast to its cookie-free mode. Those are the two ways out, and it is a product decision. In cookie-free mode, the moments above, the link to the account (section 2.1) and the attribution of payments (section 2.4) no longer reach Datafast.] [TO CONFIRM: Datafast’s processing region, for section 5.]
Since September 2026, on the same site, we also count robots (Googlebot and the crawlers of AI assistants), because they do not run JavaScript and were invisible to the count above. That count is made on the server and only happens when the request identifies itself as a known crawler: this count never sends a person’s request to Datafast. What is sent from a robot’s request is the address requested, the address it came from (Referer), its user agent, its IP and the robot’s classification (whose it is and what it is for): data about a machine, not about a visitor. It still does not exist on the businesses’ published sites.
2.3 Each business’s end customers (people who book, order or are customers of a business that uses Apronta)
Here Apronta acts as a processor, not as controller: the data belongs to the business, not to Apronta. See section 4 and the Data Processing Agreement (DPA) for the details. This section describes what exists, for transparency.
Data stored: name, phone, email, booking/order history, free-text notes and tags that the business adds.
Identity across businesses (cross-shop). To allow a person to be recognised as the "same customer" at different businesses that use Apronta (for example, to see their history), the phone/email is transformed through an HMAC function with a secret key of Apronta’s own (IDENTITY_SALT), not a simple hash. This means that the result is not a simple public fingerprint of the number/email (a simple hash of a phone number can be reversed by brute force, given the small space of possible numbers; an HMAC with a secret key cannot). Even so, this identifier is considered pseudonymised personal data under the GDPR, not anonymised data: it remains subject to all the rights described in section 6.
Suggested texts. When the business asks for a suggested reply to a Google review, the text of that review and its stars are processed by Anthropic (section 5) to write the suggestion. The name of the person who wrote it is not sent: Apronta adds it to the greeting. To suggest campaign texts, Anthropic receives what the group of customers is (for example, "have not come in for more than 120 days") and figures about the group: how many people receive it, how many by SMS and what most of them usually book. Never anyone’s names, contacts or visits, and a group of fewer than five people is described without figures.
2.4 Payment data
Apronta neither stores nor has access to card data. Payments are processed directly by Stripe (see sub-processors, section 5). On purchases from Apronta (the plans, sold through Link, by Stripe, from a Stripe account of their own, and the set-up service, "Arranque", sold by Apronta itself from its own Stripe account), the Stripe payment session, and the subscription or payment that results from it, carry Datafast’s visitor identifier and visit identifier, so that Datafast, which reads those payments in Apronta’s Stripe accounts, knows which visit led to each one. For each of those payments, Datafast reads in Stripe the amount and the payer’s email and name, as Stripe holds them, and adds them to that visit’s profile. [TO CONFIRM: whether the plans’ Stripe account, on which Link sells as the seller (Managed Payments), can be connected to Datafast. If it cannot, only the Arranque’s payments reach Datafast.] Payments that a business receives from its customers never carry any of this.
3. What we use the data for
- Providing the Service (publishing the site, managing bookings/orders, authentication).
- Operational communications (confirmations, reminders by email or SMS when enabled by the business, notices about the account).
- Complying with legal obligations (invoicing, tax records).
- Detecting and preventing abuse (request rate limiting).
- Measuring which visits to Apronta’s site lead to drafts, accounts and plans, to decide where to invest in promoting Apronta (section 2.2).
We do not use the data to target advertising at anyone, we do not sell data to third parties, and there is no automated profiling with legal effects on data subjects.
4. Two different relationships with the data (important)
This policy distinguishes two roles that Apronta plays:
- Controller: for the data of the business owners who use Apronta directly (section 2.1) and for Apronta’s own operational data.
- Processor: for the data of each business’s end customers (section 2.3). Here, the business that uses Apronta is the controller of its own customers’ data, and Apronta processes that data only on that business’s instructions, under the DPA signed between Apronta and each customer business. If you are an end customer of a business that uses Apronta and want to exercise your rights over your data, you should contact that business directly: Apronta answers this kind of request through the business, unless the law requires otherwise.
5. Who we share data with (sub-processors)
| Sub-processor | Function | Status |
|---|---|---|
| Stripe | Payment processing | Active |
| Resend | Sending transactional email (magic link, notifications) | [TO CONFIRM: not yet configured in production as of this draft] |
| Twilio | Sending SMS (reminders, confirmations) | [TO CONFIRM: not yet configured in production as of this draft] |
| Cloudflare | Network/CDN, protection against attacks, file storage (R2) | Partial: proxy active; photo storage still [TO CONFIRM] |
| Hetzner | Server hosting | Active |
| Anthropic | Artificial intelligence models (Claude): writing the draft of the site from the business’s data, reading the photographs or PDFs of the menu that the owner sends, suggesting translations of the site’s texts, and suggesting texts for campaigns and replies to reviews. It receives data about the business and, only when the owner asks for a reply to a review, the text and stars of that review, without the name of the person who wrote it. From campaigns it receives figures about the group, never a customer’s data | Active |
| Slack | Internal alerts to the Apronta team: when a page, a screen in the browser or a server job fails (the page’s address, without the access codes, and the error message), and notices about accounts, such as a business being created, with the email of the person who created it | Active |
| Datafast | Counting visits on Apronta’s site (apronta.co), with a cookie for recognition, and the moments the server adds to those visits, from a draft made to a plan paid for, with the internal identifiers of the account and the organisation, without Apronta sending it anyone’s name, email or phone; attributing payments to Apronta to the visit that brought them, with the amount and the payer’s email and name, which Datafast reads in Stripe; and counting known crawlers (Googlebot, GPTBot and the like) on the server, with the address requested, the referrer (Referer), the robot’s user agent and IP, and its classification. None of this exists on the businesses’ published sites or comes from their customers | Active. [TO CONFIRM: processing region] |
[TO CONFIRM with engineering: the physical location of the Hetzner servers (EU vs. outside the EU). It determines whether standard contractual clauses (SCC) are needed for international transfers. The same for the processing region of Stripe/Twilio/Resend if it is not exclusively the EU.]
Anthropic is a United States company. It processes this data as a processor, under its data processing agreement, which incorporates the European Commission’s standard contractual clauses for transfers outside the European Economic Area.
We do not share data with third parties for use in their own marketing. Datafast, in the table above, measures Apronta’s own marketing, on our behalf.
6. Your rights
Under the GDPR, you have the right to access, rectify and erase your personal data, to restrict its processing, to object to its processing, and to data portability. You may also lodge a complaint with the CNPD (Comissão Nacional de Proteção de Dados, the Portuguese data protection authority), www.cnpd.pt.
To exercise these rights, contact [email protected]. If you are an end customer of a business that uses Apronta (section 2.3), see the note in section 4.
7. How long we keep the data
After a business account is cancelled or deleted, the data of that business and of its customers (sections 2.1 and 2.3) is kept for 90 days, as a recovery period in case of accidental cancellation, after which it is permanently erased.
This rule does not apply to records that the law requires to be kept for a different period, in particular accounting records and invoices, which must be kept for a minimum of 10 years under Portuguese tax law [figure given from memory, not checked in this session or with an accountant; accepted as it stands for now, by a deliberate decision to proceed without external review before validation; invoicing itself follows the processes already used by Concealed].
8. Security
[TO CONFIRM with engineering before publishing the actual technical measures in force: encryption in transit (TLS), encryption at rest, access control, backups. This draft asserts no specific measure beyond those already documented: the use of HMAC with a secret key for the cross-shop identity (section 2.3), request rate limiting via Redis, and automatic error alerts. Do not insert generic "bank-grade security" language without confirmation.]
9. Minors
Apronta is intended for business owners and professionals (B2B use). It is not directed at, nor does it knowingly collect data from, minors under 18 as direct users of the platform.
10. Changes to this policy
Material changes will be notified at least 30 days in advance, by email to the associated account.
11. Language
This policy is published in Portuguese and in English. This English text is a translation: in case of any divergence between the two versions, the Portuguese version prevails.