Privacy Policy
Last updated: March 24, 2026
1. Who We Are
Capitalize (capitalize.media) is a product operated by BSS Servicos de Consultoria e Tecnologia LTDA (“we”, “us”, “our”). We provide an e-commerce analytics dashboard that aggregates data from Shopify, Meta Ads, Google Ads, TikTok Ads, and other platforms.
2. Data We Collect
When you use Capitalize, we collect and process:
- Account information — name, email address, and authentication data via Clerk (our identity provider).
- Shopify store data — orders, revenue, product information, analytics (sessions, page views), and abandoned checkouts. This data is accessed via Shopify’s API with your explicit authorization.
- Advertising platform data — campaign metrics (spend, impressions, clicks, conversions) from Meta Ads, Google Ads, and/or TikTok Ads, accessed via their respective APIs with your explicit authorization.
- Google Analytics data — sessions, users, page views, and traffic sources via the GA4 API with your authorization.
- Customer data — limited to email addresses associated with orders, used solely for abandoned cart recovery detection and RFM segmentation. We do not collect or store sensitive personal information such as payment details, addresses, or identification documents.
- Usage data — browser type, pages visited, and feature usage to improve our service.
3. How We Use Your Data
- Display aggregated analytics and KPIs on your dashboard.
- Generate financial reports (P&L, breakeven analysis).
- Detect abandoned carts and calculate recovery rates.
- Send email alerts and reports you have configured.
- Improve and maintain our service.
We do not sell, rent, or share your data with third parties for advertising or marketing purposes.
4. Third-Party Services
We use the following services to operate Capitalize:
- Clerk — authentication and user management.
- Supabase — database hosting (data stored in AWS infrastructure).
- Vercel — application hosting and deployment.
- Stripe — subscription billing and payment processing.
Each provider processes data in accordance with their own privacy policies and applicable regulations.
5. Data Retention
We retain your data for as long as your account is active. When you disconnect an integration, synced data from that platform is removed. When you delete your account or uninstall the Shopify app, all associated data is permanently deleted within 48 hours.
6. Data Security
All data is transmitted over HTTPS/TLS. Access tokens for third-party platforms are stored encrypted. We implement row-level security policies to ensure tenants can only access their own data. Authentication is handled by Clerk with industry-standard security practices.
7. Your Rights (LGPD / GDPR)
You have the right to:
- Access — request a copy of the data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your data at any time.
- Portability — request your data in a machine-readable format.
- Revoke consent — disconnect integrations or delete your account at any time via Settings.
To exercise any of these rights, contact us at info@capitalize.media.
8. Shopify Data Handling
As a Shopify app, we comply with Shopify’s API Terms of Service and Partner Program Agreement. We handle mandatory GDPR webhooks (customer data requests, customer data erasure, and shop data erasure). We only request the minimum scopes necessary for the service to function.
9. Meta Platform Data Handling
We access Meta (Facebook) data solely through the Marketing API with the ads_read permission. We do not post content, modify campaigns, or access personal Facebook profiles. Data retrieved from Meta is used exclusively to display analytics on your dashboard.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on the dashboard. Continued use of Capitalize after changes constitutes acceptance.
11. Contact
BSS Servicos de Consultoria e Tecnologia LTDA
Email: info@capitalize.media