Privacy Policy

Last updated: June 1, 2026

Maximo Digital Service's LTDA (Brazilian Tax ID/CNPJ 56.348.569/0001-05), headquartered at Rua Jose Lima de Almeida, 195, Floramar, Belo Horizonte/MG, Brazil, ZIP 31742-033, operating under the brand MaximoCRM (available at https://maximocrm.com.br), values our users' privacy and is committed to protecting personal data collected during the use of our platform. This Privacy Policy describes, clearly and transparently, how we collect, use, store, and protect the information of our users and the end contacts (leads) who interact via WhatsApp through our solution.

1. Definitions

For the purposes of this Policy:

  • "Platform" or "Service" refers to MaximoCRM, a customer relationship management (CRM) system based on the WhatsApp Business API, accessible at https://maximocrm.com.br.
  • "Controller" is Maximo Digital Service's LTDA, responsible for decisions regarding the processing of personal data.
  • "User" is any individual or legal entity who creates an account on the Platform, being a direct customer of Maximo Digital.
  • "Lead" or "Contact" is any individual who communicates with the User via WhatsApp, whose data is processed by the Platform on behalf of the User.
  • "Personal Data" is information related to an identified or identifiable natural person, as defined by Brazilian Law No. 13.709/2018 (LGPD).
  • "Processing" covers any operation performed with personal data, including collection, storage, use, transfer, deletion, among others.

2. Data We Collect

2.1. User Data (paying customers of the Platform)

When you register as a User of MaximoCRM, we collect:

  • Registration data: full name, email, phone number, password (stored encrypted using bcrypt), CNPJ (Brazilian business tax ID) or CPF (Brazilian individual tax ID), legal name or business name.
  • Usage data: access logs (date, time, IP address, device, browser), actions performed on the Platform, custom configurations, administrator activity records.
  • Payment data: when applicable, billing data is processed by an external gateway (Stripe or Pix); we do not store full credit card numbers.
  • WhatsApp Business API credentials: WABA ID, Phone Number ID, App ID, Access Token (encrypted), verified name of the number.

2.2. Lead Data (end contacts conversing via WhatsApp)

When a Lead initiates or receives a conversation via WhatsApp through a User of the Platform, we may process:

  • Identification data: name (when provided by the Lead via WhatsApp), phone number, WhatsApp public profile picture.
  • Message content: text, audio, images, videos, and documents exchanged between the Lead and the User through the WhatsApp Business API.
  • Metadata: send and receive timestamps, delivery and read status, unique message identifiers (wamid).
  • Behavioral data: tags assigned by the User, stage in sales funnel, service history.

Important: Leads are not direct customers of Maximo Digital. They are contacts of our Users, and their data is processed by Maximo Digital as a processor, under the guidance and responsibility of the User (controller of Lead data).

2.3. Automatically Collected Data

  • IP address, device type, operating system, browser, language.
  • Essential cookies for authentication and Platform functioning.
  • Anonymous telemetry data for service improvement purposes.

3. How We Use the Data

The collected data is used exclusively for:

  • Operating, maintaining, and improving the MaximoCRM Platform.
  • Authenticating Users and protecting accounts against unauthorized access.
  • Processing and storing conversations via WhatsApp Business API, as contracted by the User.
  • Sending operational communications (maintenance notices, relevant updates, technical support).
  • Complying with legal, tax, and regulatory obligations.
  • Detecting, preventing, and investigating fraud, abuse, and violations of the Terms of Use.
  • Generating aggregated and anonymous statistics about Platform usage.

We do not use personal data for purposes other than those informed in this Policy without the explicit consent of the data subject.

4. Legal Basis for Processing (LGPD)

The processing of personal data by Maximo Digital is based on the following legal bases under the LGPD:

  • Performance of contract (Art. 7º, V): to deliver the service contracted by the User.
  • Compliance with legal obligation (Art. 7º, II): to meet tax, accounting, and regulatory requirements.
  • Legitimate interest (Art. 7º, IX): to ensure Platform security and prevent fraud.
  • Consent (Art. 7º, I): when applicable, especially for marketing communications.

5. Data Sharing with Third Parties

We share personal data only with service providers essential to the Platform's operation, all under contractual obligation of confidentiality and protection. The main subcontractors are:

SubcontractorPurposeProcessing Location
Meta Platforms, Inc.Sending and receiving messages via WhatsApp Business APIGlobal (Meta data centers)
Supabase, Inc.PostgreSQL database and file storageBrazil (sa-east-1 region)
Vercel Inc.Web application hosting (front-end and APIs)Global (CDN edge)
Railway Corp.Message queue processing and scheduled tasksUnited States (us-west)
Cloudflare Inc.DDoS protection, DNS, and (future) email routingGlobal (CDN edge)
Upstash Inc.Redis cache for performanceBrazil (sa-east-1 region)

We do not sell, rent, or share personal data with third parties for commercial purposes unrelated to MaximoCRM operations.

6. Storage and Security

  • Data is stored on servers located in Brazil (Supabase sa-east-1) and global CDNs (Vercel/Cloudflare) with in-transit (TLS 1.2+) and at-rest encryption.
  • User passwords are stored with bcrypt hash (cost 10).
  • WhatsApp access tokens are encrypted before storage.
  • Access to data is restricted to authorized employees and protected by multi-factor authentication.
  • We perform automatic daily backups with 30-day retention, stored in a private Supabase Storage bucket.
  • We maintain audit logs (AdminAuditLog) of all administrative actions performed by SUPER_ADMIN.

7. Data Retention

  • Active User data: maintained while the account is active.
  • Cancelled User data: maintained for up to 5 years after cancellation, to comply with tax obligations (Brazilian Federal Revenue Service requires 5-year accounting retention).
  • Messages and conversations: maintained while the User's account is active. After cancellation, they are anonymized within 30 days, unless legal determination dictates otherwise.
  • Audit logs: maintained for 12 months.
  • Backups: automatically rotated, keeping only the last 30 days.

8. Data Subject Rights (LGPD)

Under the LGPD, you have the following rights:

  • Confirmation of the existence of processing of your data.
  • Access to processed personal data.
  • Correction of incomplete, inaccurate, or outdated data.
  • Anonymization, blocking, or deletion of unnecessary data or data processed in non-compliance with the LGPD.
  • Portability of data to another provider.
  • Deletion of data processed based on consent.
  • Information about sharing with third parties.
  • Revocation of consent.
  • Opposition to processing in case of non-compliance with the LGPD.

To exercise any of these rights, send an email to maximodigitalservice@gmail.com with the subject "LGPD Request — [your right]". We will respond within 15 business days.

9. Children's and Adolescents' Data

MaximoCRM is not intended for minors under 18. We do not intentionally collect data from children and adolescents. If we identify improper processing of minors' data, we will provide for immediate deletion.

If you are the legal guardian of a minor and identify their data on our Platform, please contact us at maximodigitalservice@gmail.com for deletion.

10. Cookies and Similar Technologies

We use essential cookies for the Platform's functioning (authentication, session, theme preferences). We do not use third-party tracking cookies for advertising purposes.

You can disable cookies in your browser settings, aware that this may impact the Platform's functioning.

11. International Data Transfer

Some of our subcontractors (Vercel, Railway, Meta, Cloudflare) process data outside Brazil. We ensure all transfers are carried out in compliance with the LGPD, through the adoption of adequate protection measures such as standard contractual clauses and international certifications (ISO 27001, SOC 2).

12. Changes to this Policy

This Policy may be updated periodically to reflect changes in our services or applicable legislation. The most recent version will always be available at https://maximocrm.com.br/privacy. Material changes will be communicated at least 15 days in advance by email or notification on the Platform.

13. Data Protection Officer (DPO)

Data Protection Officer: Thiago Maximo (representative of Maximo Digital Service's LTDA) Email: maximodigitalservice@gmail.com

14. Contact

For questions, suggestions, or requests related to this Privacy Policy or the processing of your personal data:

Maximo Digital Service's LTDA CNPJ: 56.348.569/0001-05 Address: Rua Jose Lima de Almeida, 195, Floramar, Belo Horizonte/MG, Brazil, ZIP 31742-033 Email: maximodigitalservice@gmail.com Website: https://maximocrm.com.br


This Privacy Policy was drafted in compliance with the Brazilian General Data Protection Law (Law No. 13.709/2018), the Brazilian Internet Civil Framework (Law No. 12.965/2014), and the Consumer Defense Code (Law No. 8.078/1990).