Privacy Policy
Privacy Policy
Effective date: August 1, 2026
This Privacy Policy describes how Campos Sales Soluções Para Internet Ltda. ("Inventra", "we", "us", "our") collects, uses, shares, and protects personal data when you visit https://www.inventra.sh, create an account, or otherwise use our Platform ("Service").
This Policy is issued in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais – Law No. 13.709/2018, "LGPD") and the Brazilian Internet Civil Framework (Law No. 12.965/2014). Where applicable to Organizations and End Clients located in the United States, we also describe our practices in light of applicable U.S. state privacy and communications rules.
1. Roles and key definitions
For purposes of this Policy:
- User — a natural person who creates an Inventra account (typically a business owner, staff member, or invited collaborator).
- Organization — a workspace on Inventra that holds configuration, catalogs, appointments, integrations, and subscription data.
- End Client — a person served by an Organization (for example, a client or patient) whose contact and appointment data the Organization stores in Inventra so that the Organization can manage its agenda and send notifications.
Inventra as controller. We are the controller of personal data related to User accounts, billing, Platform security, support, and our own marketing website.
Inventra as processor / service provider. When an Organization enters End Client data or instructs Inventra to send appointment notifications or sync appointments to Google Calendar, Inventra processes that data on the Organization’s instructions as a processor under the LGPD (and, where applicable, as a service provider under U.S. state privacy laws). The Organization remains responsible for deciding what End Client data to store, which notification channels to enable, and for having a lawful basis to contact End Clients.
2. Controller contact
The data controller for Inventra’s own processing is:
- Company: Campos Sales Soluções Para Internet Ltda.
- CNPJ: 37.753.203/0001-69
- Address: Av. Paulista, 1636, Suite 1504, Bela Vista, São Paulo – SP, ZIP code 01.310-200, Brazil
- Contact / Data Protection Officer: legal@inventra.sh
3. Scope
This Policy applies to personal data collected through the Inventra Platform, including the public website, the admin panel, our APIs, transactional notifications we send on an Organization’s behalf, marketing communications we send about Inventra, and customer support.
It does not apply to third-party websites or services you access through links from Inventra (for example, Google, Meta, Twilio, Stripe, or a Google Business review page), which are governed by their own privacy policies.
Inventra is an office-management Platform for service businesses. It is not an electronic health record (EHR) or medical charting system. Organizations should not store clinical diagnoses, treatment notes, or other protected health information (PHI) in Inventra unless they have a lawful basis and an express written agreement with us authorizing that use (including any required business associate agreement under HIPAA, if applicable).
4. Personal data we process
4.1 Data Users provide about themselves
- Account data: name, email address, profile image (when provided by Google or uploaded), language preference, and Platform role.
- Authentication: Inventra supports email magic-link sign-in and Google Sign-In. We do not require Users to create a local password for primary authentication.
- Organization profile: organization name, slug, logo, business description, offers, locale, and configuration needed to operate the Service.
- Billing data: billing name, email, address, country, currency, and tax identifiers when you subscribe. Card numbers and security codes are collected and stored by Stripe; we receive tokenized references and limited metadata (such as subscription status).
- Support communications: content of messages you send us by email, contact forms, or in-app channels.
4.2 End Client and back-office data entered by Organizations
When an Organization uses Inventra’s back office, it may store:
- End Client records: name, phone number (stored in E.164 format when provided), email (optional), notes, active/inactive status, and related metadata.
- Services catalog: service names, duration, pricing configuration, reminder settings, and feedback options.
- Appointments: date and time, status (for example scheduled, confirmed, cancelled, completed), notes, recurrence settings, assignee information, public appointment identifiers used in short links, and sync fields related to Google Calendar and Meet.
- Notification settings: which channels the Organization enables (Email, SMS, WhatsApp), reminder offsets, and review URL configuration.
End Clients do not log into Inventra as Platform Users. Their data is managed by the Organization that serves them.
4.3 Data collected automatically
- Technical data: IP address, browser type and version, operating system, device identifiers, language, time zone, and referring URL.
- Usage data: pages and features accessed in the admin panel, session timestamps, and approximate location derived from IP address.
- Cookies and similar technologies: see Section 11.
4.4 Data from third parties and integrations
Depending on which features an Organization enables, we may receive or exchange data with:
- Google — Sign-In profile data; Calendar connection health; event identifiers and Meet links created for Inventra appointments (see Section 7).
- Stripe — subscription status, transaction history, and limited payment metadata.
- Resend — delivery metadata for transactional emails.
- Twilio — SMS delivery status events for operational logging.
- Meta WhatsApp Cloud API — template message identifiers and delivery status events for operational logging.
- Analytics providers — aggregated or pseudonymous usage data when Inventra or Organization analytics are enabled (for example Google Analytics).
- AI and research providers — Organization brand/context and content-generation inputs needed to produce AI-assisted content features, when those features are used.
5. Purposes of processing
We process personal data to:
- Provide and operate the Service, including Organizations, catalogs, agenda, notifications, and content tools.
- Authenticate Users and protect accounts and sessions.
- Sync appointments to Google Calendar and attach Google Meet links when an Organization connects Calendar.
- Send appointment notifications by Email, SMS, and/or WhatsApp on the Organization’s instructions and channel settings.
- Process subscriptions, invoices, trials, failed payments, and related billing notices.
- Provide customer support and respond to requests.
- Monitor reliability, debug errors, prevent abuse, and improve the Service.
- Comply with applicable law and respond to lawful requests from authorities.
- Send Inventra product updates or marketing communications to Users, with the ability to opt out of marketing.
6. Legal bases
Under Articles 7 and 11 of the LGPD, our processing relies on the following bases, depending on the activity:
- Performance of a contract (Art. 7, V) — account creation, subscriptions, and delivery of the Service.
- Legal or regulatory obligation (Art. 7, II) — tax, accounting, and consumer-protection record-keeping.
- Legitimate interests (Art. 7, IX) — security, fraud prevention, service improvement, and operational logging, provided fundamental rights are not overridden.
- Consent (Art. 7, I) — where consent is the appropriate basis (for example certain marketing activities). Consent may be withdrawn without affecting prior lawful processing.
- Exercise of rights in legal proceedings (Art. 7, VI) and credit protection (Art. 7, X), when applicable.
For End Client data processed on an Organization’s instructions, the Organization is responsible for establishing its own lawful basis to collect and use that data and to instruct Inventra to send communications.
Where U.S. state privacy laws apply, we process personal information for the business purposes described above and do not sell personal information. Organizations that use Inventra to message End Clients remain responsible for complying with applicable U.S. communications rules (including TCPA, CAN-SPAM, and carrier/platform policies).
7. Google Sign-In, Google Calendar, and Google Meet
When you sign in with Google or an Organization owner/administrator connects Google Calendar, Inventra accesses Google user data through OAuth 2.0.
7.1 Sign in with Google
- Scopes:
openid,email, andprofile. - Data accessed: Google account email, display name, and profile picture.
- Purpose: create or link your Inventra account and authenticate you to the Service.
- Storage: account identifiers and session information are stored through our authentication stack (Better Auth). We do not store your Google password.
7.2 Google Calendar (optional Organization connection)
If an Organization connects Google Calendar, Inventra may use:
https://www.googleapis.com/auth/calendar.readonlyhttps://www.googleapis.com/auth/calendar.events
What Inventra does today:
- Checks the connected account’s calendar list to verify that the connection remains valid.
- Creates, updates, and deletes events on the Organization’s primary Google Calendar that correspond to appointments created or changed in Inventra.
- When requesting a remote meeting, asks Google to generate a Google Meet link and stores that link with the Inventra appointment.
- Stores Google event identifiers, recurrence identifiers when applicable, sync/ETag metadata, and Meet links needed to keep the Inventra-to-Google projection up to date.
Data Inventra may send to Google for an appointment event:
- Event title containing the service name and End Client name.
- Start and end date/time and the Organization’s time zone.
- Recurrence rules when the appointment is part of a recurring series.
- Appointment notes/description when provided by the Organization.
- The End Client’s real email address as a calendar attendee when the Organization has stored one (placeholder/synthetic emails are not used).
What Inventra does not do today:
- Inventra does not import, display, or continuously monitor pre-existing Google Calendar events inside Inventra.
- Inventra does not offer Google → Inventra inbound sync in the current product.
- Inventra does not rely on Google to email calendar invitations for appointment notifications (
sendUpdatesis disabled). Appointment notifications (Email, SMS, WhatsApp) are controlled by Inventra according to the Organization’s settings.
7.3 Limited Use and sharing of Google user data
Inventra’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertisements, sell that data to third parties, or train generalized AI/ML models. We share Google user data only with infrastructure providers that process it on our behalf under confidentiality obligations and solely to operate the Service, or when required by law.
7.4 Revoking Google access
An Organization may disconnect Google Calendar in Integrations. Disconnecting stops future Inventra-to-Google sync for that Organization. You may also revoke Inventra’s access entirely at Google Account permissions. Revocation stops future API access; data already stored in Inventra is handled according to Sections 10 and 12.
8. Appointment notifications (Email, SMS, and WhatsApp)
Organizations may enable appointment notifications for lifecycle events such as:
- Appointment created / scheduled
- Appointment confirmed
- Reminders
- Reschedule
- Cancellation
- Optional post-visit feedback / review requests
Depending on the channel and message type, notifications may include the End Client’s name, service information, appointment date/time, Organization name, and public short links to confirm, cancel, join a meeting, or open a review page configured by the Organization.
Channels and providers:
- Email via Resend
- SMS via Twilio
- WhatsApp via Meta WhatsApp Cloud API using approved message templates
WhatsApp is off by default at the Organization level until an authorized User enables it. Enabling the Organization WhatsApp toggle is a sender/channel configuration step; it is not proof that each End Client has consented to receive WhatsApp messages.
Delivery and status webhooks from Twilio and Meta may be processed for operational logging (for example, to diagnose failures). Inventra does not currently provide a customer-facing delivery-log product and does not automatically process carrier “STOP” replies or WhatsApp opt-out keywords as a preference center.
Organization responsibility. The Organization decides which End Clients to message and which channels to activate. The Organization is responsible for informing End Clients, obtaining any required consent, maintaining opt-in/opt-out records, and honoring suppression requests under applicable law and platform rules. See also our Terms of Service.
9. Data sharing and subprocessors
We share personal data only when necessary and under appropriate safeguards. Core recipients include:
- Stripe, Inc. — payments and subscription management.
- Google — Sign-In, Calendar, Meet, and (when used) analytics or AI-related services.
- Resend — transactional email delivery.
- Twilio — SMS delivery.
- Meta Platforms — WhatsApp Cloud API template messaging and related status callbacks.
- Vercel / Neon — application hosting, databases, and related infrastructure.
- Trigger.dev — background job execution for notifications, calendar projection, billing reminders, and content pipelines.
- Vercel AI Gateway and underlying model providers (including Anthropic, Google, Perplexity, and Recraft, as used) — AI-assisted content features when enabled.
- DataForSEO — research inputs for content-generation features when used.
- Professional advisors — lawyers, accountants, and auditors under confidentiality obligations.
- Authorities and successors — when required by law or in connection with a corporate transaction, subject to equivalent protection.
We do not sell personal data. Third parties receive only the data needed for their specific purpose and process it under their own terms and privacy policies in addition to our instructions where we act as controller or processor.
10. International transfers
Some providers process data outside Brazil, including in the United States and the European Union. When personal data is transferred internationally, we rely on the legal bases in Article 33 of the LGPD — including contractual safeguards, recipient compliance mechanisms, or specific consent when applicable — to ensure an adequate level of protection.
11. Cookies and similar technologies
We use cookies and similar technologies to operate the Platform, authenticate sessions, remember preferences, and measure performance. Categories may include:
- Strictly necessary cookies — authentication and core Platform operation.
- Functional cookies — settings and preferences.
- Analytics cookies — understanding how the Platform is used (for example Google Analytics when enabled).
You can control cookies through your browser settings. Disabling certain cookies may affect Platform functionality. Inventra’s public site may also use privacy-preserving analytics (for example Vercel Analytics).
12. Retention and deletion
We retain personal data only as long as needed for the purposes in this Policy, including:
- Active account and Organization data — while the account/Organization remains active.
- Billing and tax records — for periods required by Brazilian tax, accounting, and commercial law (typically up to five years after the relevant fiscal year).
- Access logs — for at least six (6) months under Article 15 of the Brazilian Internet Civil Framework, and longer when needed for security investigations.
- Backups — for the duration of our backup rotation with infrastructure providers.
- Support communications — as reasonably necessary to resolve requests and related follow-up.
- Appointment and notification operational data — while needed to operate the Organization’s agenda and diagnose delivery issues, subject to Organization deletion requests and legal retention needs.
After the applicable period, data is deleted or irreversibly anonymized, except where longer retention is required or allowed by law. Account or Organization deletion requests may be submitted to legal@inventra.sh. Some third-party cleanup (for example objects in object storage or provider-side logs) may follow provider retention cycles.
13. Security
We use administrative, technical, and organizational measures designed to protect personal data, including transport encryption (TLS), access controls, Organization-level segregation of tenant data, operational logging, backups, and encryption of selected Organization credentials stored in Inventra. No system is completely secure. If a security incident may create significant risk or harm to data subjects, we will notify affected parties and the ANPD as required by Article 48 of the LGPD.
14. Your rights
Under Article 18 of the LGPD, you may request to:
- Confirm whether we process your personal data.
- Access your personal data.
- Correct incomplete, inaccurate, or outdated data.
- Anonymize, block, or delete unnecessary or excessive data, or data processed in non-compliance with the LGPD.
- Request portability, subject to commercial and industrial secrecy.
- Request deletion of personal data processed based on consent, except where retention is required or permitted by law.
- Be informed about entities with which we share data.
- Be informed about the possibility of refusing consent and the consequences.
- Withdraw consent.
- Object to processing carried out without consent if you believe it does not comply with the LGPD.
- Request review of decisions based solely on automated processing that affect your interests.
Where applicable U.S. state privacy laws grant similar rights (for example access, deletion, or correction), you may submit the same request to legal@inventra.sh. We may need to verify your identity and, for End Client requests, coordinate with the Organization that controls the relevant record.
You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD) at https://www.gov.br/anpd.
15. Children's data
The Platform is intended for adults. We do not knowingly collect personal data from children. If you believe a minor provided personal data without proper authorization, contact legal@inventra.sh.
16. Updates to this Policy
We may update this Policy from time to time. When changes are material, we will notify Users by email or through the Platform at least fifteen (15) days before they take effect. The “Effective date” at the top indicates the latest update.
17. Contact
For questions or requests related to this Policy or personal data processing:
- Company: Campos Sales Soluções Para Internet Ltda.
- CNPJ: 37.753.203/0001-69
- Address: Av. Paulista, 1636, Suite 1504, Bela Vista, São Paulo – SP, ZIP code 01.310-200, Brazil
- Email: legal@inventra.sh