Skip to content

Privacy Policy

Last updated: August 9, 2026

Your privacy matters to us. This Privacy Policy describes how Sothen Consultoria em Tecnologia da Informação Ltda. (a Brazilian company, CNPJ 47.585.487/0001-85) collects, uses, stores, shares, and protects the personal information of users of the Rastro app.

By using Rastro, you agree to the practices described in this Policy, in compliance with the Brazilian General Data Protection Law (LGPD, Law 13,709/2018) and the Brazilian Internet Civil Framework (Law 12,965/2014).

1. Data Controller

Sothen Consultoria em Tecnologia da Informação Ltda. CNPJ: 47.585.487/0001-85 Website: sothen.me Contact/DPO: contato@rastro.day

2. Data We Collect

Data from your authentication provider (Google/Apple): name, email, profile picture, unique identifier.

Data generated by your use of the app: routines you create, check-in records, notification and language preferences, device time zone, subscription status.

Technical data: push notification token (FCM), device platform, and technical error records (the route accessed, the error message, IP address, and user agent) kept for diagnostics and security.

We do not collect: sensitive data, precise location, contacts, calendar, photos, microphone, camera, browsing history, or advertising identifiers.

3. Purposes

To authenticate and identify you, provide the app's features, send notifications according to your preferences, process and validate your subscription, ensure the security and improvement of the App, respond to support requests, and comply with legal obligations.

Performance of a contract, consent, legitimate interest, and compliance with legal obligations (Art. 7 of the LGPD).

5. What We Do Not Do

We do not sell your data. We do not share your data with data brokers. We do not use your data for targeted advertising. We do not track you across third-party apps or websites. Rastro does not use advertising tracking identifiers (IDFA/AAID).

6. Sharing and Processors

We share data only with providers necessary to operate the App, each limited to the purpose described:

Google and Apple: account authentication and subscription payment processing. Google Firebase: identity and push notification delivery. Google Cloud Platform: hosting for our API. Supabase: database. RevenueCat: subscription validation and status management.

We may also share data with public authorities when required by law or court order.

7. International Transfers

Some processors handle data outside Brazil. We ensure that these transfers occur with the safeguards required by the LGPD and applicable law.

8. Storage and Security

All data travels encrypted (HTTPS/TLS) and is stored with encryption at rest, strict access controls, and continuous monitoring. In the event of a significant security incident, we will notify you and the Brazilian Data Protection Authority (ANPD).

9. Retention and Deletion

We keep your data for as long as your account exists. When you request deletion, the account is deactivated immediately and all personal data is permanently erased within 30 days, except for records we are legally required to keep.

You can delete your account in two ways, without having to reinstall the App: In the app, under Profile › My account › Delete account. By email, writing to contato@rastro.day from the address linked to your account.

Step-by-step instructions are available at rastro.day/en/support.

10. Your Rights

Under Art. 18 of the LGPD, you have the right to confirmation, access, correction, anonymization, portability, deletion, information about sharing, withdrawal of consent, and objection to processing. The App offers a data export under Profile › Data and privacy.

If you are in the European Economic Area or the United Kingdom, you also have the rights provided by the GDPR, including access, rectification, erasure, restriction, portability, and objection, as well as the right to lodge a complaint with your local data protection authority. If you are a California resident, you have the rights provided by the CCPA/CPRA. We reiterate that we do not sell or share personal data for behavioral advertising purposes.

To exercise any of these rights: contato@rastro.day.

11. Children and Teenagers

Rastro is not intended for children under 13, and we do not knowingly collect data from children. If we identify an account in this situation, it will be removed.

12. Cookies

Rastro is a mobile app and does not use cookies. Our marketing website is static and also does not use tracking cookies.

13. Changes

This Policy may be updated. Relevant changes will be communicated through the App before they take effect.

14. Contact

Email: contato@rastro.day Website: sothen.me ANPD: gov.br/anpd

Sothen Consultoria em Tecnologia da Informação Ltda. · CNPJ 47.585.487/0001-85

contato@rastro.day