Privacy policy
This is a courtesy translation. If there is any difference, the Portuguese version prevails.
In short. We process the minimum needed for the platform to work: your sign-up data, the links you save and what the tools store for you. We do not sell data or use ad pixels. Google Analytics is only turned on if you accept it in the cookie notice, and nothing you type into the tools is sent to it. You can download or delete everything in My account. The data is stored on servers in the United States. This summary does not replace the text below.
1. Who the controller is
The controller of the personal data processed on UTM Builder is , Brazilian company registration number (CNPJ) , with its address at . This policy follows Brazil’s General Personal Data Protection Law (Law No. 13,709/2018, the LGPD) and Brazil’s Internet Civil Rights Framework (Marco Civil da Internet, Law No. 12,965/2014).
2. What data we process
| Data | When |
|---|---|
| Name, company or agency, and email | At sign-up and when you edit your profile |
| Password | At sign-up. It is stored by the authentication service only in encrypted form (hash); we never see the password |
| Link history: URL, channel, campaign, creative, tags and date | When you save a link, or generate links in bulk and save them |
| Tool data: naming convention, checklists, templates, your branding (logo, color and agency name) | When you save something in the tools while signed in |
| Usage count: a short code calculated from the link, and the date, not the URL | When you copy, download or save a new link |
| Plan, subscription status, expiration date and the subscription ID at the payment provider | When you subscribe to, renew or cancel a paid plan |
| Record of interest in a paid plan | When you click to subscribe before payment opens |
| Access logs: IP address, date, time and browser used | When you sign in to your account |
The UTM builder, the QR code generator and the calculators run in your browser. The URL you type only leaves your browser when you save the link to your history. We do not request or process sensitive data.
Card details are entered on the payment provider’s own page (Stripe or Asaas) and do not pass through us.
3. Why we use it and on what legal basis
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Create and maintain the account, store history, templates and tool data, apply plan limits | Performance of a contract (item V) |
| Activate the paid plan for the account email, charge, issue invoices (nota fiscal) and handle cancellations and refunds | Performance of a contract (item V) and compliance with a legal or regulatory obligation (item II) |
| Notify those who asked when payment opens | Preliminary procedures related to a contract, at your request (item V) |
| Keep access logs for 6 months | Compliance with a legal obligation (item II; Marco Civil, art. 15) |
| Protect the account and the service against fraud and abuse, and fix errors | Legitimate interest (item IX), always limited to what is necessary |
| Exercise rights in judicial, administrative or arbitration proceedings | Regular exercise of rights (item VI) |
We do not use your data for advertising, we do not sell data and we do not make automated decisions that affect your interests beyond applying the limits of the plan you purchased.
4. Who we share it with
Only with providers that process the data on our behalf (processors), so that the service works:
- Supabase: database, authentication and sending of confirmation and password reset emails.
- Cloudflare: hosting and delivery of the site’s pages. Cloudflare processes visitors’ IP addresses to deliver the pages and protect the site against attacks, in accordance with its own privacy policy.
- Resend: sending of account emails (confirmation, password and service notices: welcome, auditor and daily limit). It receives your email address, your name and, in the welcome email, the links you generated. The notices can be turned off in My account; confirmation and password emails continue.
- People on your team (Agency plan): if you join a team, the other people on it see your name, your email, the date you joined and the links you generate from then on. The naming convention, templates and branding become the team’s. Links and data from before you joined remain yours only. The team owner also sees invited emails that have not yet accepted.
- Google (Google Analytics 4): site usage statistics, only for those who accept in the cookie notice. It receives the pages visited, without what was typed on them, the source of the visit, browser and device data and the counted actions (generate link, download QR, reach the limit, create account and start subscription). It does not receive email, name, your campaign URLs or anything typed into the tools.
- Stripe: payment provider for subscriptions bought on the English site, in US dollars. It processes the subscription on its own page, stores the card details and informs us of the status of the subscription and of each charge. To link the subscription to your account, we send Stripe your account ID and email.
- Asaas: payment provider for subscriptions bought on the Portuguese site, in Brazilian reais. It processes the subscription on its own payment page, stores the card details and informs us of the email, the plan and the status of each charge.
We may also share data when required by law or by an order from a competent authority. Access logs are only handed over under a court order, as provided by the Marco Civil da Internet.
5. International transfer
The database and authentication are hosted on Supabase servers in the eastern United States region, the pages are served through Cloudflare’s global network, and subscriptions on the English site are processed by Stripe, in the United States. Therefore, the data described in section 2 is transferred outside Brazil. The transfer is necessary to perform the contract with you (LGPD, art. 33, item IX, in conjunction with art. 7, item V), and the providers adopt security measures compatible with those described in section 9. For those who accept cookies, usage statistics also go to Google’s servers, based on your consent (LGPD, art. 33, item VIII).
6. Browser storage and cookies
The platform does not use ad pixels. The only third-party cookie is the Google Analytics 4 cookie (_ga and _ga_57BB3BDJJT), and it is only set if you click Accept in the cookie notice. Before that, and if you decline, the Google script is not even loaded. You can change your choice at any time with the Cookies button in the footer. The legal basis is your consent (LGPD, art. 7, item I).
In addition, the platform uses the browser’s local storage (localStorage) to:
- keep you signed in (session token);
- keep a copy of your profile, history and tool data, so the screen opens quickly;
- count the free links made without an account;
- remember preferences, such as light or dark theme and standard or advanced mode;
- store your choice in the cookie notice.
Signing out deletes the session from this browser. Clearing the site data deletes everything stored in it; whatever is in your account remains in the database.
7. How long we keep it
- Account, history and tool data: for as long as the account exists. When you delete the account, they are erased from the database immediately. Backups kept by the provider may take a few days to be overwritten.
- Access logs: 6 months, as required by the Marco Civil da Internet. After that they are deleted. If you delete your account earlier, the log is no longer linked to it and is kept only until the period is complete.
- Payment data and invoices (notas fiscais): for the period required by tax and accounting laws, even after cancellation.
- Record of interest in a plan: until payment opens and the notice is sent, or until you delete your account.
8. Your rights
Under the LGPD (art. 18), you may request at any time:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of data that is unnecessary, excessive or processed in breach of the law;
- data portability;
- deletion of data processed based on your consent, where applicable;
- information about who we share your data with;
- objection to processing carried out without your agreement, where the law allows.
You can do much of this yourself in My account: edit your profile, download all your data as JSON and delete your account. For anything else, write to . We respond within 15 days, as provided in art. 19 of the LGPD, and may ask you to confirm your identity before fulfilling the request. You can also file a complaint with Brazil’s National Data Protection Authority (ANPD).
9. Security
- All communication with the site and with the database uses an encrypted connection (HTTPS).
- In the database, each account can only read and change what belongs to it: the rule is enforced in the database itself (Row Level Security), not only on screen.
- The paid plan only changes upon payment confirmation or by the administrators, never from the account.
- The password is stored only in encrypted form by the authentication service.
- Administrative access to the database is restricted.
No system is completely immune to failures. If a security incident occurs that may cause you significant risk or harm, we will notify you and the ANPD, as provided in art. 48 of the LGPD.
10. Children and adolescents
The platform is intended for people aged 18 and over and does not knowingly collect data from children or adolescents. If we learn of an account belonging to a minor, it will be deleted.
11. Changes to this policy
When we change the way we process data (a new provider, a new type of data or a new purpose), this policy is updated before the change and we notify you by email or within the platform. The date at the top shows the current version.
12. Contact and data protection officer
To talk about your personal data, use the channel . Data protection officer (encarregado): .
Last revised: October 9, 2026, to include the Agency plan and Stripe for the English site.