Privacy Policy

Version: 2026-05-15 · Last updated: May 15, 2026

1. Introduction

LSA Escale ("we", "our") respects your privacy and protects your personal data. This Privacy Policy describes how we process your data in compliance with the Brazilian General Data Protection Law (Law 13.709/2018 — LGPD) and with international good practices (GDPR, ISO/IEC 27701).

This policy applies to https://lsaescale.com and to all services offered by the platform.

2. Data Controller and Data Protection Officer

Data Controller (Art. 5, VI LGPD): LSA Escale

Data Protection Officer (DPO, Art. 41 LGPD): LSA Escale team, contact: support@lsaescale.com

3. Personal data we collect

3.1 Data you provide

  • Email and password (stored only as a bcrypt hash)
  • Optional notification email
  • Payment data — processed directly by Stripe (we do not store card numbers)

3.2 Data collected automatically

  • IP address and User-Agent (access logs and legal acceptance records)
  • Essential session and authentication cookies
  • Audit log of actions performed on the platform

3.3 Integration data

  • Google Ads OAuth access and refresh tokens (to integrate with the Google Local Services API)
  • Accessible Google Ads customer identifiers
  • Lead data obtained via Google Ads (consumer phone number, call status, feedback)

3.4 Third-party data (public form)

When a third party fills the public form at /f/:token from a platform user, we collect the third party's name, email and selected services. In this scenario LSA Escale acts as a data processor (Art. 5, VII LGPD) and the platform user is the controller of that data.

4. Processing purposes (Art. 9 LGPD)

  • Authentication and account management
  • Delivery of the LSA Escale service (lead lookup, Google Ads integration, automations)
  • Subscription billing via Stripe
  • Operational and support communications
  • Fraud prevention and platform security
  • Compliance with legal and regulatory obligations

5. Lawful bases (Art. 7 LGPD)

  • Consent (Art. 7, I): acceptance of the Terms and this Policy at registration
  • Performance of a contract (Art. 7, V): delivery of the LSA Escale service
  • Legitimate interest (Art. 7, IX): platform security, fraud prevention, service improvement
  • Compliance with legal obligation (Art. 7, II): tax and regulatory duties

6. Data sharing

We share personal data only with processors essential to delivering the service:

  • Stripe — payment processor. Receives email and identifier for subscription billing.
  • Google (Ads and Local Services API) — integration processor. We access your Google Ads accounts on your behalf.
  • Infrastructure and CDN providers (jsDelivr, Cloudflare) — may log IP at the origin server, per Art. 33 LGPD.

We never sell, rent or share your data for marketing or advertising purposes.

7. International data transfers (Art. 33 LGPD)

Processors such as Stripe and Google may process your data on servers outside Brazil. Such transfers rely on adequate contractual safeguards and meet the requirements of Art. 33, II and IV LGPD.

8. Data retention (Art. 16 LGPD)

  • Account data: during the subscription term.
  • Tax data: 5 years after termination, per art. 173 of the National Tax Code and art. 15 of the Brazilian Internet Bill of Rights.
  • Acceptance and consent logs (consent_logs): retained as proof of compliance for the relationship duration + 5 years.
  • Once these periods elapse, data is deleted or anonymized (Art. 16 LGPD).

9. Data subject rights (Art. 18 LGPD)

You may, at any time, request:

  • Confirmation of processing
  • Access to your data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary data or data processed in non-compliance with LGPD
  • Data portability
  • Deletion of personal data processed under your consent
  • Information about who we share your data with
  • Withdrawal of consent

To exercise your rights, contact support@lsaescale.com. We will respond within 15 days (Art. 19, §1 LGPD).

10. Security

  • HTTPS (TLS) for all transport
  • Passwords stored only as a bcrypt hash
  • Authentication and role-based access control
  • Audit logs and continuous monitoring

11. Cookies

We only use essential cookies required for the platform to function:

  • _lsaescale_session — authenticated session
  • Devise "remember me" cookie — when you choose to stay signed in

We do not use marketing, analytics, or third-party tracking cookies.

12. Minors

LSA Escale is a B2B service and is not intended for users under 18. We do not knowingly collect data from minors.

13. Changes to this Policy

This policy may be updated to reflect legal or operational changes. Each new version will preserve previous texts by version number. For material changes we will request renewed acceptance at the next sign-in.

14. Contact

LSA Escale — Email: support@lsaescale.com