Skip to content

Legal document

Privacy policy

Last updated: September 29, 2026

This is a translation for convenience; the Portuguese version prevails.

What we do with your data, in plain language.

01Who processes your data

The controller of the personal data processed by Hyperpin is HYPER IA MARKETING, CNPJ (Brazilian company registration number) 50.622.314/0001-02. The person responsible for personal data processing (DPO, art. 41 of the LGPD) can be reached at contato@hyperiamarketing.com.br.

This policy explains what data we collect when you visit the site or use the platform, why we collect it, who we share it with, how long we keep it, and how you can exercise your rights under the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, LGPD — Law No. 13,709/2018).

02Data we collect

  • Sign-up: name, email and password. Your password is stored by the authentication service only in hashed form; no one on our team has access to it. If you sign in with Google, we also receive your name, email and profile picture.
  • Profile and contracts: data you fill in, such as phone, city and your contractor details (name or company name, CPF or CNPJ and address) used to build proposals and contracts.
  • Payment: name, email, plan or credit pack purchased, amount, payment method, installments, status and dates. To generate the Pix payment or process the card, the CPF is sent to Mercado Pago at the time of purchase; it is not stored in our database. Card details are typed into Mercado Pago’s secure component and never pass through our servers.
  • Affiliates: your enrollment data in the program and the Pix key you provide to receive commissions.
  • Platform usage: searches performed, saved leads, notes, projects and website versions, contracts, recorded sales and usage events (for example, “website published”), used to operate the service, track limits and improve the product.
  • Technical and session data: IP address, browser and device, logged by our hosting provider on every access. For simultaneous-session control, we store the device type, browser and a hash of the IP.
  • Visit source: the referral cookie hp_ref, valid for 60 days, when you arrive through an affiliate link, and the hp_utm cookie, valid for 90 days, with the campaign (UTM) parameters of the link. If you create an account or make a purchase, this data is recorded together with your sign-up or payment.
  • Abuse prevention: an irreversible identifier (hash) calculated from your IP and browser, used to limit the creation of free accounts in bulk, and IP hashes used to limit requests and deduplicate affiliate clicks. We cannot reconstruct your IP address from these.
  • Support: whatever you send us by email or WhatsApp.

We do not ask for sensitive data (art. 5, II, of the LGPD).

03What we use it for and the legal basis

  • Provide the contracted service: create and maintain your account, unlock your plan and credits, run searches, generate and publish websites, display the temporary preview link, publish to the account you connect, and send emails about access and payments. Legal basis: performance of a contract (art. 7, V, of the LGPD).
  • Process payments, refunds and affiliate commissions. Legal basis: performance of a contract (art. 7, V).
  • Comply with legal and regulatory obligations, such as tax records of payments and the access-log retention required by the Brazilian Internet Civil Rights Framework (Marco Civil da Internet — Law No. 12,965/2014, art. 15). Legal basis: compliance with a legal obligation (art. 7, II).
  • Security and fraud prevention, such as usage and request limits, session control and blocking bulk account creation. Legal basis: legitimate interest (art. 7, IX), with minimized data (hashes instead of the IP whenever possible).
  • Attribute referrals to affiliates and understand which campaigns bring customers. Legal basis: legitimate interest (art. 7, IX).
  • Internal product metrics, based on usage events recorded in our own database. Legal basis: legitimate interest (art. 7, IX).
  • Audience measurement with Vercel’s analytics tool, only if you accept it in the cookie notice. Legal basis: consent (art. 7, I), which you can withdraw at any time in the Cookie policy.

We do not sell personal data and do not use it for third-party advertising.

04Data about the businesses you prospect and about your clients

The search shows information that businesses publish on Google Maps, such as name, business phone number, address, rating and photos, obtained through the Google Maps Platform. When you save a business as a lead, log conversations, or enter a client’s data in proposals and contracts, you are the controller of that data and Hyperpin acts as the processor, handling it only to provide the service to you.

It is your responsibility to use these contacts legitimately, without bulk messaging, and to fulfill data-subject requests, such as deletion or objection to contact. If a data subject contacts us directly, we will forward the request to you.

05What we send to the artificial intelligence

To write the websites and outreach scripts, we send the AI provider (Anthropic, Claude model) only the content necessary for the task:

  • the business data in the briefing: name, industry, city, neighborhood, address, business phone or WhatsApp number, Instagram, hours, professional license when provided, Google rating and review count, services, menu, and the instructions or prompt you write;
  • the current text of the section you ask to have rewritten;
  • in the outreach scripts, the business name, city, industry and your first name.

We do not send payment data, CPF, password or your email. Avoid including other people’s personal data in the free-form instructions you give the AI. Under Anthropic’s commercial terms, content sent through the API is not used to train the models.

06Who we share data with (processors)

We share data only with vendors that help us operate the service, to the extent necessary for each function:

Vendors that process personal data for Hyperpin
VendorPurposeData involvedWhere
SupabaseDatabase, login and file storage (uploaded photos and website images).Account data, leads and CRM, projects, contracts, sales, payment records (no card data), usage events and uploaded files.Brazil (São Paulo region). Company headquartered in the United States.
VercelHosting of the platform, temporary approval preview links and domains connected through Hyperpin; site audience metrics, only with your consent.IP address, browser and pages visited (technical logs); aggregated visit metrics when you accept analytics.United States and a global server network.
Anthropic (Claude)The artificial intelligence that writes website copy, rewrites sections, suggests outreach scripts and organizes your prompt.Content from the business briefing (name, city, address, business phone number, Instagram, hours, services, menu, Google rating and instructions you type) and the reseller's first name in the scripts. Does not receive payment data or your password.United States.
Google Maps PlatformBusiness search by industry and city, public profile data and location photos.Search terms (industry and city) and links or names entered in manual search. We do not send your account data.United States and a global network.
Mercado PagoProcessing of Pix and card payments.Name, email, CPF, amount and payment method. Card details are typed into Mercado Pago's secure component and never pass through our servers.Brazil, with possible processing in other countries by the Mercado Livre group.
ResendSending the platform's emails: account confirmation, receipts and access notices.Name, email and message content.United States.
UpstashRequest rate limiting, to prevent abuse and brute-force attacks.Temporary technical identifiers (IP address or its hash, account identifier), kept for a few minutes to up to 1 day.Outside Brazil (region defined in the service configuration).
UnsplashStock photo library used to complete websites when the client has no photos of their own.Industry search terms (no personal data). Visitors to a website with an Unsplash image load the photo directly from Unsplash's servers, which receive the visitor's IP.United States and a global network.
Google (login)Only when Google sign-in is enabled and you choose to use it.Sign in with a Google account, when that option is enabled.Name, email and Google profile picture, received only if you choose to sign in with Google.United States and a global network.

Accounts you connect. When you connect your Vercel, Netlify ou GitHub account, we send that account the website files you choose to publish, including any client data included on the site. In that case, the platform is your own vendor, and the relationship follows its own terms and privacy policy.

Client websites. Visitors to a published website may load third-party resources, such as Unsplash images and the embedded Google Maps map, which receive the visitor’s IP and browser data under those services’ own policies.

We may also share data when required by law or by order of a competent authority, and with the affiliate who referred you only in aggregate form (clicks, sign-ups and sales), without your contact details.

07International transfer

Our main database is located in Brazil, but several vendors listed above process data outside the country, mainly in the United States. These transfers follow art. 33 of the LGPD: they are made to perform the contract with you (art. 33, IX, combined with art. 7, V) and with vendors that provide protection guarantees through contractual clauses and recognized information-security standards (art. 33, II).

08How long we keep it

  • Account, lead, project, contract and sales data: for as long as the account exists.
  • After account deletion: websites go offline immediately and data is kept in quarantine for 30 days, to allow recovery in case of a mistake. After that, it is permanently deleted, except for what the law requires us to keep.
  • Payment records: at least 5 years, as required by tax and accounting legislation, even if the account is deleted.
  • Application access logs (IP, date and time): 6 months, per art. 15 of the Marco Civil da Internet.
  • Location data obtained from searches: cached for up to 30 days.
  • Previous versions of each website: the 30 most recent.
  • Identifiers used for request rate limiting: from a few minutes to 1 day.
  • Usage events: for as long as they are useful for product metrics. Once an account is deleted, they are no longer linked to it.
  • Cookies and browser storage: per the periods in the Cookie policy.

09Security

We use encrypted connections (HTTPS), per-user database access control, service keys restricted to our servers, AES-256-GCM encryption for connected hosting-account tokens, hashes instead of IPs whenever possible, simultaneous-session limits and request-rate limits. No system is completely immune to incidents; if an incident occurs that could create a relevant risk or harm, we will notify affected data subjects and the National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD), as required by art. 48 of the LGPD.

10Your rights

Under art. 18 of the LGPD, you can, at any time:

  • confirm whether we process your data and access it;
  • correct incomplete, inaccurate or outdated data;
  • request anonymization, blocking or deletion of unnecessary, excessive or non-compliant data;
  • request portability of your data;
  • request deletion of data processed based on consent and withdraw that consent;
  • know who we share your data with;
  • be informed about the possibility of not consenting and its consequences;
  • object to processing based on legitimate interest, when the LGPD is not being complied with;
  • request review of decisions made solely through automated processing (art. 20).

In My account you will find the options “Download my data,” which generates a JSON file, and “Delete my account.” For other requests, write to contato@hyperiamarketing.com.br from your account’s email address. We may ask for identity confirmation before responding. We respond within 15 days. You can also file a complaint with the ANPD.

11Children and teenagers

Hyperpin is a professional tool intended for adults over 18 and does not knowingly collect data from children or teenagers. If we identify an account belonging to a minor, it will be closed and the data deleted.

12Cookies

We use cookies and local storage that are essential for the site to work and, only with your consent, an analytics tool. See the full list and how to change your choices in the Cookie policy.

13Changes to this policy

We may update this policy to reflect changes in the product, our vendors or the law. The date of the last update appears at the top of the page, and significant changes will be communicated by email or within the platform.