Legal
Privacy Policy
Version 1.0 — May 2026
1. Introduction
Bakerly values the privacy and protection of its users' personal data. This Privacy Policy describes how we collect, use, store and protect your personal information, in accordance with Brazil's General Data Protection Law (LGPD — Law No. 13,709/2018).
2. Personal Data Processed
To operate the Platform, we process the following personal data:
- Full name of the account holder
- Email address
- Phone number
- Order data (items, quantities, amounts, dates)
- Customer data registered by the user on the Platform
- Financial data (revenue, expenses, payments)
3. Cookies Used
We use cookies and similar technologies to improve the user experience. Cookies are categorized as follows:
Strictly necessary
Always active — cannot be disabled
Necessary for the basic operation of the Platform, including authentication, session security and essential preferences.
Functional
Enable enhanced functionality, such as remembering user preferences and personalizing the Platform's interface.
Analytics
Help us understand how users interact with the Platform, enabling continuous improvements to the user experience.
Marketing
Used to display relevant content and measure the effectiveness of communication campaigns.
4. Third-Party Services
The Platform integrates the following third-party services, which may process personal data:
- Stripe — payment gateway used to process charges, issue invoices and manage subscriptions. Payment data (card, tax ID) is collected directly by Stripe on a secure page, without passing through our infrastructure.
- wppconnect— WhatsApp Business API integration provider, used for customer communication and sending notifications. Data such as the contact's name and phone number may be processed to enable communication.
Each third-party service has its own privacy policy and is subject to LGPD rules.
5. Security Measures
We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, destruction, loss, alteration or improper processing, including:
- Data encryption in transit (TLS/HTTPS)
- Password hashing with modern algorithms
- Role-based access control (RBAC)
- Continuous monitoring of access and suspicious activity
- Encrypted backups with tested recovery
6. Data Subject Rights (LGPD)
In accordance with the LGPD, you have the following rights regarding your personal data:
- Access — confirm that processing exists and access your data
- Correction — request correction of incomplete, inaccurate or outdated data
- Deletion — request deletion of data processed based on consent
- Portability — request portability of data to another service or product provider
- Revocation — revoke consent at any time, when applicable
To exercise any right, contact our Data Protection Officer (DPO) at privacidade@bakerlyapp.com. Requests will be answered within the legal deadline of up to 15 (fifteen) days.
7. Data Retention
Personal data is retained while the user's account is active. After account deletion, data is kept for 90 (ninety) days to allow for recovery and compliance with legal obligations, being securely deleted after that period.
8. Changes to this Policy
This Privacy Policy may be updated at any time. Significant changes will be communicated by email or notification on the Platform. The date of the last update will always be indicated at the top of this document.
9. Contact
For questions, requests or complaints related to the processing of personal data, contact our Data Protection Officer (DPO):
Email: privacidade@bakerlyapp.com