Privacy Policy
Last updated August 27, 2026
This policy explains how CycleClient handles personal data, in line with Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and comparable principles. The professional (business using the platform) is the controller of their clients' data. CycleClient, operated by BORBA VENTURES, a Brazilian company registered under CNPJ 49.335.610/0001-35 ("CycleClient", "we"), acts as a processor, handling that data under the professional's instructions. For the professional's own account, CycleClient is the controller.
1. Data we collect
We collect only what is needed to provide the service:
- Professional account: name, email, password (stored hashed), business details and preferences.
- The professional's clients (entered by the professional or by the client when booking): name, phone, email and booking history.
- Payment: processed by Stripe. We do not store card numbers on our servers; we receive only identifiers and the subscription status.
- Technical and usage data: session cookies, language, theme, IP address and access logs for security.
2. How we use it
To run scheduling and records, send confirmations and return reminders on the professional’s instruction, process subscription payments, generate reports for the professional, prevent fraud and abuse, and meet legal obligations.
3. Legal basis
We process data based on:
- Performance of a contract: providing the service to the professional.
- Legitimate interest: security, fraud prevention and product improvement.
- Consent: where applicable. Messages to clients are sent on the professional's instruction, who is responsible for having a legal basis and consent with their own clients.
- Compliance with a legal or regulatory obligation.
4. Subprocessors
We rely on providers that process data only to enable the service, under contract and confidentiality:
- Supabase: database and authentication.
- Hostinger: application hosting (server).
- Stripe: subscription payment processing.
- Meta Platforms (WhatsApp Business): sending messages to clients.
- Resend: transactional account emails (sign-up, password, invite).
- Cloudflare: content delivery network and abuse protection.
- Sentry: application error monitoring.
5. International transfer
Some subprocessors (for example Stripe, Meta, Resend, Cloudflare and Sentry) process data outside Brazil, including in the United States. In those cases, the transfer relies on appropriate contractual safeguards and only to the extent needed to provide the service.
6. Sharing
We share data only with the subprocessors above, with the professional responsible for the client, and when required by law or court order. We do not sell personal data and do not use it for third-party advertising.
7. Retention
We keep data while the account is active and for as long as needed to meet legal, accounting and security obligations. After the account is closed, data is deleted or anonymized within a reasonable period, unless a legal duty to retain applies.
8. Security
Per-business data isolation (database RLS), encryption in transit, hashed passwords, role-based access control, rate limiting and logging of sensitive operations. No system is fully immune, but we work to reduce risk continuously.
9. Cookies
We use essential cookies only: session (login), language and theme. We do not use advertising cookies or third-party ad trackers.
10. Your rights
Under applicable data-protection law, you may request:
- Confirmation that we process your data and access to it.
- Correction of incomplete or outdated data.
- Anonymization, blocking or deletion of unnecessary data.
- Portability and information about who we share with.
- Withdrawal of consent, where consent is the basis.
11. How to exercise your rights
Contact our data protection lead at [email protected]. If you are a client of a professional who uses the platform, please contact that professional first, as they are the controller of your data. We may ask for information to verify your identity before acting.
12. Minors
The platform is intended for professionals and businesses. We do not knowingly collect data from minors without a guardian's involvement. The professional is responsible for obtaining the consents needed when adding clients.
13. Automated decisions
We do not make solely automated decisions that produce legal effects or significantly affect the individual. Reports and reminders are support tools operated by the professional.
14. Security incidents
If an incident may pose a relevant risk to individuals, we will notify those affected and the competent authority as required by law.
15. Authority and complaints
You may lodge a complaint with the Brazilian data protection authority (ANPD). Before that, we would appreciate the chance to resolve it with you directly.
16. Changes
We may update this policy. Relevant changes will be communicated in the platform, and the update date above will be revised.
17. Contact
Privacy questions or requests: [email protected].