- 1. Who controls this data
- 2. What we collect
- 3. Why we process it (lawful bases)
- 4. International transfers
- 5. Your rights
- 6. Retention
- 7. Security
- 8. Cookies and analytics
- 9. Children
- 10. Contact and complaints
1. Who controls this data
The controller of the personal data described in this policy is CodeSpar LLC, a Delaware limited liability company. In Brazil, its affiliate CodeSpar Tecnologia Ltda (Rio de Janeiro) acts as its representative for the purposes of the LGPD. For any privacy question, request, or complaint, contact privacidade@codespar.dev (or privacy@codespar.dev).
2. What we collect
We collect the following categories of data:
- Account data: name and work email, collected through our authentication provider, Clerk, when you create an account or sign in.
- Usage and telemetry data: API calls, tool-call metadata, and operational logs generated as you use the Service, so we can operate, secure, and support it.
- Billing data: processed through our payment processor, Stripe. We never store card numbers ourselves.
- Consumer-side KYC data: where our customers use the Service to run know-your-customer checks on their own end users, we process that data as a processor, on the customer's behalf and instructions. See our Data Processing Addendum.
3. Why we process it (lawful bases)
Where LGPD (Brazil) applies, we rely on the bases in LGPD articles 7 and 11, including performance of a contract, our legitimate interest, compliance with a legal obligation, and consent where we ask for it. Where GDPR applies, we rely on the equivalent bases under GDPR article 6: contract performance, legitimate interest, legal obligation, and consent where required.
4. International transfers
Our processing occurs in the United States and Brazil, on the infrastructure of our subprocessors (see the subprocessor list). Where we transfer personal data internationally, we use appropriate safeguards, including standard contractual clauses where GDPR applies.
5. Your rights
If LGPD applies to you, you have the data-subject rights set out in LGPD, including confirmation of processing, access, correction, anonymization, portability, deletion, and information about who we share your data with. If GDPR applies to you, you have the equivalent GDPR rights, including access, rectification, erasure, restriction, portability, and objection. If you are a California resident, we give you the CCPA notice that you have the right to know, delete, and correct your personal information, and the right to portability. Across all of these regimes: we do not sell personal data. To exercise any of these rights, contact privacidade@codespar.dev.
6. Retention
We keep account data for the life of your account, plus any additional period required by law. Audit records (including the payment audit trail the Service generates) are retained for the period required by applicable financial-audit and recordkeeping requirements.
7. Security
We encrypt data at rest using AES-256-GCM and encrypt data in transit. Our audit logs are hash-chained so they cannot be silently altered after the fact, and customer data is isolated per tenant.
8. Cookies and analytics
We use essential cookies required to run the site and keep you signed in. We use Vercel Analytics and Vercel Speed Insights to understand aggregate site usage and performance; these do not sell your data and are configured for our own product analytics, not third-party advertising.
9. Children
The Service is a developer platform and is not directed to children.
10. Contact and complaints
For any question about this policy, contact privacidade@codespar.dev. If you are in Brazil and are not satisfied with our response, you may file a complaint with the Autoridade Nacional de Protecao de Dados (ANPD). If you are elsewhere, you may file a complaint with your local data protection supervisory authority.