Last updated: August 9, 2026
Your privacy matters to us. This Privacy Policy describes how Sothen Consultoria em Tecnologia da Informação Ltda. (a Brazilian company, CNPJ 47.585.487/0001-85) collects, uses, stores, shares, and protects the personal information of users of the Rastro app.
By using Rastro, you agree to the practices described in this Policy, in compliance with the Brazilian General Data Protection Law (LGPD, Law 13,709/2018) and the Brazilian Internet Civil Framework (Law 12,965/2014).
1. Data Controller
Sothen Consultoria em Tecnologia da Informação Ltda. CNPJ: 47.585.487/0001-85 Website: sothen.me Contact/DPO: contato@rastro.day
2. Data We Collect
Data from your authentication provider (Google/Apple): name, email, profile picture, unique identifier.
Data generated by your use of the app: routines you create, check-in records, notification and language preferences, device time zone, subscription status.
Technical data: push notification token (FCM), device platform, and technical error records (the route accessed, the error message, IP address, and user agent) kept for diagnostics and security.
We do not collect: sensitive data, precise location, contacts, calendar, photos, microphone, camera, browsing history, or advertising identifiers.
3. Purposes
To authenticate and identify you, provide the app's features, send notifications according to your preferences, process and validate your subscription, ensure the security and improvement of the App, respond to support requests, and comply with legal obligations.
4. Legal Basis
Performance of a contract, consent, legitimate interest, and compliance with legal obligations (Art. 7 of the LGPD).
5. What We Do Not Do
We do not sell your data. We do not share your data with data brokers. We do not use your data for targeted advertising. We do not track you across third-party apps or websites. Rastro does not use advertising tracking identifiers (IDFA/AAID).
6. Sharing and Processors
We share data only with providers necessary to operate the App, each limited to the purpose described:
Google and Apple: account authentication and subscription payment processing. Google Firebase: identity and push notification delivery. Google Cloud Platform: hosting for our API. Supabase: database. RevenueCat: subscription validation and status management.
We may also share data with public authorities when required by law or court order.
7. International Transfers
Some processors handle data outside Brazil. We ensure that these transfers occur with the safeguards required by the LGPD and applicable law.
8. Storage and Security
All data travels encrypted (HTTPS/TLS) and is stored with encryption at rest, strict access controls, and continuous monitoring. In the event of a significant security incident, we will notify you and the Brazilian Data Protection Authority (ANPD).
9. Retention and Deletion
We keep your data for as long as your account exists. When you request deletion, the account is deactivated immediately and all personal data is permanently erased within 30 days, except for records we are legally required to keep.
You can delete your account in two ways, without having to reinstall the App: In the app, under Profile › My account › Delete account. By email, writing to contato@rastro.day from the address linked to your account.
Step-by-step instructions are available at rastro.day/en/support.
10. Your Rights
Under Art. 18 of the LGPD, you have the right to confirmation, access, correction, anonymization, portability, deletion, information about sharing, withdrawal of consent, and objection to processing. The App offers a data export under Profile › Data and privacy.
If you are in the European Economic Area or the United Kingdom, you also have the rights provided by the GDPR, including access, rectification, erasure, restriction, portability, and objection, as well as the right to lodge a complaint with your local data protection authority. If you are a California resident, you have the rights provided by the CCPA/CPRA. We reiterate that we do not sell or share personal data for behavioral advertising purposes.
To exercise any of these rights: contato@rastro.day.
11. Children and Teenagers
Rastro is not intended for children under 13, and we do not knowingly collect data from children. If we identify an account in this situation, it will be removed.
12. Cookies
Rastro is a mobile app and does not use cookies. Our marketing website is static and also does not use tracking cookies.
13. Changes
This Policy may be updated. Relevant changes will be communicated through the App before they take effect.
14. Contact
Email: contato@rastro.day Website: sothen.me ANPD: gov.br/anpd
Sothen Consultoria em Tecnologia da Informação Ltda. · CNPJ 47.585.487/0001-85