kaptto

Privacy Policy — kaptto

Last updated: September 2026

1. Data Controller

The entity responsible for processing personal data collected through the kaptto platform is kaptto, Lda., based in Portugal. For any data protection queries, you can contact us at: privacidade@kaptto.pt

2. Data Collected

In the course of using the platform, we may collect the following personal data:

  • Platform users: name, email, phone, role, authentication data, IP address and usage data.
  • Reviewing customers: name (when provided), email, phone, numerical rating, comment, date and time of review, device data.
  • Company data: business name, logo, address, contacts, billing data.
  • Google Business Profile data: when the user voluntarily connects their Google account, we access the account name, business locations, customer-published reviews (including author name, rating and comment), and the ability to publish replies on behalf of the owner. This data is obtained through the https://www.googleapis.com/auth/business.manage scope of the Google Business Profile API.

3. Purpose of Processing

Personal data is processed for the following purposes:

  • Provision and management of the review collection service;
  • Identifying the winner and delivering prize-draw rewards, where the customer chooses to leave their contact details;
  • Statistical analysis and generation of satisfaction reports;
  • Support communication and operational notifications;
  • Import and centralised management of Google Business Profile reviews, including the ability to respond to reviews directly from the platform;
  • Compliance with legal and regulatory obligations.

4. Legal Basis

The processing of personal data is based on the following legal bases, under Article 6 of the GDPR:

  • Consent: for collecting reviewers’ contact details and for identifying and delivering prize-draw rewards;
  • Contract performance: for the provision of the service to registered users;
  • Legitimate interest: for service improvement and usage analysis;
  • Legal obligation: for compliance with legal and tax requirements.

4b. Google Business Profile Integration

The kaptto platform allows users to voluntarily connect their Google account to integrate Google Business Profile data. This integration uses the OAuth 2.0 protocol and requires the user's explicit consent.

Scope used: https://www.googleapis.com/auth/business.manage

Data accessed and purposes:

  • Accounts and locations: listing of business accounts and locations for user selection;
  • Reviews: import of Google reviews (author name, rating, comment, date) for centralised viewing in the dashboard;
  • Replies: publication of replies to reviews on behalf of the location owner.

Token storage: OAuth access tokens are encrypted with AES-256-GCM before storage and are never shared with third parties. Tokens can be revoked at any time by the user in the platform settings.

Revocation: the user can disconnect their Google account at any time, which immediately revokes the platform's access to Google Business Profile data. Deactivating a location also automatically disconnects the associated Google account.

5. Data Sharing

Personal data is not sold to third parties. It may be shared with: (a) sub-processors essential to the platform's operation (see section 5.1), under data processing agreements; (b) the contracting company, regarding their customers' reviews; (c) competent authorities, when required by law. All sub-processors are bound by confidentiality and data protection obligations (Article 28 GDPR).

5.1. Sub-processors

kaptto relies on the following providers for the platform to operate. All have been assessed for GDPR compliance and security. Transfers outside the EEA are made under the Standard Contractual Clauses (SCC) approved by the European Commission.

  • Vercel Inc. (USA) — Application hosting and CDN. Transfer under SCC.
  • Neon Tech Inc. (servers in EU — Frankfurt) — Managed PostgreSQL database.
  • Resend Inc. (USA; sending region configured in the EU — Ireland) — Transactional email delivery (invitations, password recovery, access codes, alerts and reports). Transfer under SCC.
  • Anthropic PBC (USA) — Review analysis and response generation via Claude (Haiku 4.5 model). Transfer under SCC. Data sent is not used to train models.
  • Google LLC (USA) — Google Business Profile API (importing public reviews and posting replies). Only enabled if the user connects their Google account.
  • Functional Software Inc. (Sentry) (USA; storage region configured in the EU) — Technical error and performance monitoring. Transfer under SCC. Filters applied to remove personal data before sending.
  • Upstash Inc. (servers in EU) — Temporary cache for usage limits (rate limiting). No personally identifiable data.

This list is updated as of September 2026. Material changes will be communicated by email to users 30 days in advance.

6. Data Retention

Personal data is kept for as long as it is needed for the purposes it was collected for. User accounts and collected reviews are kept while the client company has an active service. Some data has its own deadline and is deleted automatically: password recovery links and unaccepted invitations, once they expire; access codes, after their 10 minutes of validity; expired, unredeemed prize codes, after 6 months; technical job and API call logs, after 90 days. The client company may at any time request deletion of its data and of its reviewers' data, through the email in the Contact section; the request is carried out within 30 days, unless the law requires the data to be kept.

7. Data Subject Rights

Under the GDPR, data subjects have the following rights:

  • Right of access: obtain confirmation and a copy of personal data processed (Article 15);
  • Right to rectification: request the correction of inaccurate or incomplete data (Article 16);
  • Right to erasure: request the deletion of personal data, where applicable (Article 17);
  • Right to portability: receive personal data in a structured, machine-readable format (Article 20);
  • Right to object: object to the processing of data in certain circumstances (Article 21);
  • Right to restriction: request the restriction of data processing (Article 18).

To exercise any of these rights, contact us at privacidade@kaptto.pt

8. Cookies

The platform uses cookies that are strictly necessary for the service to work (authentication and session). No advertising tracking or analytics cookies are used. You can set your browser to refuse cookies, although that may affect how the platform works.

9. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration. These measures include data encryption in transit (TLS), OAuth token encryption with AES-256-GCM, secure password hashing (bcrypt), role-based access control and regular security audits.

10. Changes

This Privacy Policy may be updated periodically. Any significant changes will be communicated to users by email or through a notification on the platform, with a minimum of 15 days' notice.

11. Contact

For any questions related to this Privacy Policy or the processing of your personal data, contact us at: privacidade@kaptto.pt

You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) — .www.cnpd.pt