Privacy Policy
This Privacy Policy explains how Listio collects, uses, stores, shares, and protects personal data of Platform users, in line with applicable data protection law, including — for users in the European Economic Area or UK — the GDPR, and — for California residents — the CCPA/CPRA where applicable.
Listio is an inventory, stock-counting, and replenishment platform for small and mid-sized retailers, available on the web at app.listio.com.br and as a mobile app, with documentation at help.listio.com.br and a marketing site at listioinventory.com.
Rodolfo Sousa Cruz - ME
CNPJ: 27.618.739/0001-18
Address: Rua Antonio da Costa Santos, 17 — Jardim Nova América, Hortolândia, SP, Brazil
Data protection contact: Rodolfo Cruz
E-mail: talk@listio.com.br
1. Who we are and scope of this policy
This Policy applies to all personal data Listio processes in connection with our marketing site (listioinventory.com), the Platform (app.listio.com.br), our mobile app, our documentation (help.listio.com.br), our communications with you, and the integrations we offer.
This Policy does not apply to third-party sites, platforms, or services you may access through links or integrations. We recommend reading those third parties' own privacy policies.
2. Data we collect
Personal data is any information that identifies you, directly or indirectly. We also process anonymized data, which is not personal data as long as the anonymization is irreversible. Listio does not intentionally collect sensitive personal data (such as health, racial or ethnic origin, religious belief, political opinion, union membership, genetic, or biometric data), except in exceptional cases and with your specific, separate consent.
2.1. Data you provide directly
- a) Account data: name, e-mail, password (stored encrypted), phone number, language preference.
- b) Organization data: company name, trade name, tax ID (where applicable), address, business type, operation size, and other contact details.
- c) Invited-user data: name, e-mail, and permission level.
- d) Payment data: processed directly by our payment provider (Stripe); Listio does not store full card data.
- e) Support data: information you send through support channels, feedback forms, surveys, and direct communications.
2.2. Operational data entered into the Platform
This includes product records, categories, variants, suppliers, stock quantities, counts, orders, and other operational information. This data is generally not personal data, but may include supplier contact details (name, phone, e-mail) or data about invited staff acting as operators. In that case, the regime described above applies: you are the controller and Listio acts as processor. You are responsible for having the appropriate legal basis and consents to enter this data into the Platform.
2.3. Data collected automatically
- a) Technical data: IP address, browser type, operating system, device identifiers and attributes.
- b) Usage data: pages visited, features used, access times, clicks, session length, navigation flow.
- c) Approximate location (inferred from IP address).
- d) Traffic source: UTM parameters, referrer, gclid, fbclid, and other campaign identifiers.
- e) Cookies and similar technologies, as described in our Cookie Policy.
2.4. Data from third parties and integrations
- a) Data from integrations you activate (for example, e-commerce platforms, ERPs, point-of-sale systems, and similar tools), including authorized credentials (OAuth tokens) and data shared by the third-party service for the purpose of that integration.
- b) Data from analytics and marketing tools (such as Google Analytics, Google Ads, and Meta/Facebook Pixel), subject to your consent settings.
- c) Publicly available data from official or market databases, when needed to validate a business registration, enrich a record, or prevent fraud.
3. How we use your data
We process personal data for the following purposes:
- a) to let you register, authenticate, and access the Platform;
- b) to provide the services you have subscribed to, including inventory management, counts, orders, multi-store, and integrations;
- c) to process payments, issue invoices, and manage subscriptions;
- d) to operate integrations you activate with third-party services;
- e) to send transactional communications (confirmations, operational notifications, security alerts);
- f) to send marketing communications, news, and informational material, with your consent and an option to unsubscribe at any time;
- g) to provide technical support and customer service;
- h) to analyze use of the Platform to improve it, diagnose issues, and build new features;
- i) to prevent fraud and abuse and to keep the Platform and its users secure;
- j) to comply with legal, regulatory, tax, and judicial obligations;
- k) to exercise our rights in legal, administrative, or arbitration proceedings;
- l) to produce reports, benchmarks, and studies from anonymized and/or aggregated data that cannot identify an individual.
4. Legal bases
Where applicable law requires a legal basis, we rely on:
- a) Performance of a contract — to provide your account, the Service, payment processing, and support;
- b) Consent — for marketing communications, non-essential cookies, and activation of certain integrations;
- c) Compliance with a legal obligation — for invoicing, tax record-keeping, and responding to lawful requests from authorities;
- d) Legitimate interest — for fraud prevention, security, service improvement, transactional communications, anonymized statistical analysis, and keeping minimal records after account closure, balanced against your rights and interests;
- e) Exercise of legal claims — in judicial, administrative, or arbitration proceedings.
5. Sharing with third parties
5.1. Infrastructure and service providers. Vendors that support the Platform, acting as processors under confidentiality and security obligations:
- Supabase — database hosting, authentication, and storage;
- Vercel — application hosting;
- Hostinger — hosting for our marketing site and documentation;
- Stripe — payment processing;
- Resend — transactional and marketing e-mail delivery;
- Google (Analytics, Tag Manager, Ads) — analytics, campaign measurement, and advertising, with your consent;
- Meta (Facebook Pixel) — marketing measurement and campaigns, with your consent;
- Make.com — operational and marketing automations.
This list of sub-processors may be updated as the Platform evolves; we vet each vendor and require adequate security measures.
5.2. Integrations you activate. When you voluntarily activate an integration, relevant data is shared between Listio and the integrated service, and you also become subject to that service's own terms and privacy policy. Listio is not responsible for the operation, availability, quality, or policies of integrated third-party services.
5.3. Authorities and specific situations. We may share data in response to a court order or legal requirement, or to protect rights, safety, or the security of the Platform or others.
5.4. Corporate transactions. In a merger, acquisition, reorganization, or sale of assets, data may be transferred to the successor, subject to the same protections described in this Policy.
5.5. Anonymized and aggregated data. We may produce, license, publish, and monetize reports, benchmarks, and studies built from anonymized and/or aggregated data that cannot identify an individual. Recipients are expressly prohibited from attempting to re-identify individuals.
6. International data transfers and security
Some of the personal data we process may be stored or processed on servers located outside your country (for example, in the United States or the European Union), because we use cloud infrastructure providers such as Supabase, Stripe, Google, and Resend. Where required, we apply appropriate safeguards for these transfers, such as standard contractual clauses or equivalent mechanisms, and verify that the recipient country or provider offers an adequate level of protection.
We use reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure, including encryption in transit (HTTPS/TLS) and, where applicable, at rest; encrypted passwords; permission-based access control (Owner, Admin, Manager, Operator); data isolation between organizations (row-level security); activity logs and audit trails; periodic backups; continuous infrastructure monitoring; and careful vetting of vendors and sub-processors.
No security measure is completely infallible. If a security incident is likely to result in a meaningful risk or harm to affected individuals, we will notify affected users and any competent authority within a reasonable time, as required by applicable law.
Your responsibility. You are responsible for keeping your credentials confidential, using a strong and unique password, not sharing your login with others, signing out on shared devices, and notifying us immediately if you suspect unauthorized access to your account.
7. Retention and deletion
We retain personal data only as long as necessary for the purposes it was collected for:
- a) While your account is active — for as long as you use the Platform;
- b) After account closure — for up to 5 years, to exercise legal rights, defend against claims, and comply with legal obligations;
- c) Tax and financial records — for the minimum periods required by applicable law;
- d) Support and communication records — for up to 5 years after our last contact;
- e) Logs and audit trails — for up to 6 months, unless a longer period is legally required;
- f) Anonymized or aggregated data — may be kept indefinitely, since it cannot identify you.
Once the applicable retention period ends, data is securely deleted or anonymized, except where the law requires us to keep it longer.
8. Your rights
Depending on where you live, you may have the right to: confirm whether we process your data; access it; correct incomplete, inaccurate, or outdated data; request deletion, blocking, or anonymization of unnecessary or unlawfully processed data; request portability of your data; withdraw consent at any time; object to processing based on legitimate interest; and be informed about who we have shared your data with. California residents may also have rights under the CCPA/CPRA to know, delete, correct, and opt out of the "sale" or "sharing" of personal information (Listio does not sell personal data) and will not be discriminated against for exercising these rights.
Limitations. We may limit or decline a request where the law allows — for example, where keeping the data is necessary to comply with a legal obligation or to exercise or defend legal claims. In that case, we will explain why.
9. Cookies
Listio uses cookies and similar technologies for essential, analytics, and marketing purposes. You can manage your preferences at any time through the consent banner on our site or your browser settings. See our full Cookie Policy for details.
10. Children, changes to this policy, and contact
Listio is intended for people 18 or older and for business use. We do not knowingly collect data from minors; if we learn we have, we will take steps to delete it.
We may update this Policy periodically to reflect changes to the Platform, our processes, applicable law, or industry practice. We will announce material changes by e-mail, a notice on the Platform, or on listioinventory.com, with reasonable notice. The date at the top of this page shows the last update. Continued use of the Platform after changes take effect means you agree to the current version. Where a change affects consent you previously gave for a specific purpose, we will ask for your consent again.
For questions, requests, or complaints about this Policy or how we handle your data: talk@listio.com.br.