Privacy policy
Updated July 24, 2026
How Elecore handles personal data in Minipa Link under Brazilian LGPD.
On this page
- 1. Who we are
- 2. Scope
- 3. Data we collect
- 3.1 Data you provide
- 3.2 Data collected automatically
- 3.3 Instrument data (Bluetooth)
- 3.4 Third-party data
- 4. Purposes and legal bases (LGPD)
- 5. Sharing and subprocessors
- 6. Storage, retention, and security
- 7. Your rights (LGPD — art. 18)
- 8. Children and adolescents
- 9. Location and monitoring
- 10. Automated decisions
- 11. Changes
- 12. Governing law
- 13. Contact
1. Who we are
This Privacy policy describes how Elecore (“we”, “us”, “our”) handles personal data in the Minipa Link product (Android mobile app and web site / dashboard, including domains related to minipa.com.br / link.minipa.com.br).
General privacy and support contact: support@elecore.com.br
Minipa Link is software provided in connection with the Minipa brand. For controller identity details beyond what is stated here (legal name registration, address), contact us at the email above.
2. Scope
This policy applies to:
- users of the Minipa Link mobile app (Android and, when available, iOS);
- users of the Minipa Link web dashboard;
- visitors of the marketing / institutional site;
- people invited to a team (invite email).
It does not apply to third-party websites or to Minipa measuring instruments as hardware, except when the app collects readings transmitted over Bluetooth.
3. Data we collect
3.1 Data you provide
- Account and identity: name, email, password (stored securely by the authentication provider);
- Google or Apple authentication data when you choose “Sign in with Google” or “Sign in with Apple”;
- Team and organization data: team name, roles, invites;
- Work content: projects, work orders, assets, forms, checklists, notes, reports, quotes, and other records you or your team enter;
- Media: photos, videos, audio, and image annotations;
- Billing data: information needed to process payments (handled primarily by Stripe; we receive subscription status, identifiers, and plan metadata — we do not store full card numbers);
- Support communications;
- Waitlist: email address, consent timestamp, locale, and optional profile details you choose to share (name, company, phone, role, sector) when joining the product waitlist before public sign-up opens.
3.2 Data collected automatically
- Device and usage data: technical identifiers, device / OS type, product events (analytics);
- Geographic location (GPS): especially on mobile login and, when the team enables location features, in audit events tied to create/update of records (coordinates + user + context);
- Offline sync data (local database on device, later sent to our servers when online);
- Cookies and similar technologies on the website;
- Push notification tokens when you allow notifications.
3.3 Instrument data (Bluetooth)
When you pair a compatible instrument, we may receive and store measurement readings and connection metadata in the context of field work. That information becomes part of your team’s content.
3.4 Third-party data
- Invites: email of the invited person, provided by a team admin;
- Maps / geocoding: address / coordinate lookups sent to map providers;
- Payment processors and analytics (see subprocessors below).
We do not request credit card data inside the mobile app. Billing happens in the web environment / Stripe.
4. Purposes and legal bases (LGPD)
| Purpose | Examples | Legal basis |
|---|---|---|
| Create and manage account and authentication | login, password, Google / Apple OAuth | Performance of a contract / pre-contractual steps |
| Waitlist / early access communications | email updates, launch-pricing eligibility notices | Consent |
| Provide the SaaS service | projects, sync, media, reports | Performance of a contract |
| Location for audit / team operational compliance | GPS on login; location events | Legitimate interest and/or performance of a contract with the team that enables the feature |
| Security, fraud and abuse prevention | logs, anomaly detection | Legitimate interest / legal obligation |
| Product analytics (improvement) | PostHog, Vercel Analytics | Legitimate interest |
| Push notifications | operational notices | OS permission consent / performance of a contract |
| Billing and delinquency | Stripe, invoices | Performance of a contract / legal obligation |
| Legal compliance | authorities, legal defense | Legal obligation / regular exercise of rights |
For employee / contractor data visible to a team admin, the customer (team) may be a controller of that data; we act as a service provider / processor for workspace content. Contact us if you need a data processing agreement.
5. Sharing and subprocessors
We may share data with:
- infrastructure and database providers (e.g. Supabase);
- hosting and site analytics (e.g. Vercel);
- product analytics (e.g. PostHog);
- payments (Stripe);
- maps (Mapbox);
- push notification providers (e.g. Firebase Cloud Messaging);
- Google and Apple authentication;
- email delivery providers;
- PDF / backend processing workers, when applicable;
- authorities when required by law;
- successors in a corporate reorganization, with safeguards.
International transfers (providers with servers outside Brazil) occur as needed to operate the service, with contractual and technical safeguards appropriate under LGPD.
6. Storage, retention, and security
- Cloud data: providers listed above; media in object storage; the mobile app keeps a local copy for offline use, largely cleared on logout (this does not delete the cloud account).
- Retention: we keep data while the account / team workspace is active and for as long as needed to provide the service, resolve disputes, and meet legal, tax, and security obligations. Backup and logs may persist for a limited period after deletion.
- Security measures: access control, TLS in transit, team policies (including database row-level security), and secure development practices. No method is 100% secure.
7. Your rights (LGPD — art. 18)
You may request:
- confirmation that processing exists;
- access; correction; anonymization, blocking, or deletion of unnecessary data;
- portability, when applicable;
- information about sharing;
- withdrawal of consent;
- opposition to irregular processing.
How to exercise: email support@elecore.com.br with subject “LGPD – data subject rights”, and identify yourself securely. We will respond within the timeframes required by law (we aim to reply within 15 days).
Account deletion: request deletion via the same email. Deletion may affect team data; an admin may need to transfer or export content first. Archived accounts may prevent immediate re-registration with the same credentials for a cooldown period.
8. Children and adolescents
Minipa Link is intended for professional / business use. It is not directed to anyone under 18. If we learn of an improper registration, we will delete the account.
9. Location and monitoring
The app may require location permission for certain features (including Android login, for technical and audit requirements). Coordinates may be recorded and visible to admins of your team, depending on location feature settings.
If you are an employee or contractor, clarify internal monitoring policy with your employer.
10. Automated decisions
In its current state, Minipa Link does not make automated decisions with significant legal effects on the data subject (such as credit scoring). Templates, checklists, and AI-assisted drafting features are documentation tools; you remain responsible for reviewing generated content.
11. Changes
We may update this policy. The current version is published at /privacy with an update date. Material changes may be communicated by email or in-product notice.
12. Governing law
Brazilian law applies, especially Law No. 13.709/2018 (LGPD). Venue follows Brazilian law, including consumer-protection rules when applicable.
13. Contact
Privacy and support: support@elecore.com.br