zap2crm

Privacy Policy

Last updated: October 5, 2026.

This Policy explains how zap2crm processes personal data when providing its platform for integrating WhatsApp communications with Pipedrive. It applies to the website, application, embedded Pipedrive panel, and related services.

1. Who we are and our roles

The service is contracted from Estude Vendas Treinamento LTDA, trade name Estude Vendas, Brazilian company registration number (CNPJ) 25.406.858/0001-81, with registered office at Rua Campolino Alves, 1021, Apartment 134, Block 01, Abraão, Florianópolis, Santa Catarina, Brazil, Postal Code 88085-155 (“Estude Vendas”).

Claudio Antunes Junior Tecnologia da Informação LTDA, trade name CAJ Tecnologia, CNPJ 68.136.491/0001-36, with registered office at Rua Padre Agostinho, 2026, Apartment 23, First Floor, Condomínio Oriente, Bigorrilho, Curitiba, Paraná, Brazil, Postal Code 80710-000 (“CAJ Tecnologia”), provides technical support, operates the infrastructure, and technically processes data on behalf of Estude Vendas.

For Platform Data received directly from Meta to operate the zap2crm app, Estude Vendas is the entity responsible for the app and determines the essential purposes and means of processing. CAJ Tecnologia performs development, support, and technical processing of that data on behalf of Estude Vendas.

For data that a business customer uploads or integrates into the service—including data about its contacts, customers, and recipients—that business will generally act as controller, while Estude Vendas and CAJ Tecnologia process the data according to its instructions and the applicable agreements. Estude Vendas may act as controller for registration, billing, security, and management of the service itself.

2. Data we may process

We do not ask customers to include sensitive personal data in messages. Customer-provided content may nevertheless contain such data, in which case the customer is responsible for having a lawful basis and applying appropriate safeguards.

3. How we obtain data

We receive data directly from users and business customers, from authorized Meta/WhatsApp and Pipedrive integrations, from providers engaged to operate the service, and automatically through use of the platform.

4. How we use data

5. Legal grounds

Depending on the context, processing may rely on performance of a contract or steps taken before entering into one, compliance with legal obligations, the establishment or exercise of legal claims, legitimate interests, fraud prevention, and consent where required. When we act as processors, the business customer acting as controller is responsible for determining the applicable legal basis.

6. Sharing and subprocessors

We may share strictly necessary data with Meta/WhatsApp, Pipedrive, cloud and storage providers, and database, communications, security, monitoring, billing, and support services. These parties process data under their own terms or as contracted subprocessors. We may also disclose data to comply with law or a valid authority request or to protect rights and safety.

Payments are processed by Stripe, which receives the company details used on the invoice (legal name, tax ID and address), the name, email and phone of the billing contact chosen by the company, and the payment details entered directly in Stripe’s environment; zap2crm neither receives nor stores full card details, only the card brand, last digits, subscription status and invoices. These company details are also used to issue the Brazilian service invoice (NFS-e) for each charge, which may be done by an invoicing provider integrated with Stripe. Transactional emails (signup confirmation, invitations, password resets and billing notices) are sent through Amazon SES.

We do not sell personal data or use the content of customer conversations for our own behavioral advertising.

7. International data transfers

Operation of the integrations and infrastructure may involve processing in other countries. Where required, we use appropriate contracts and safeguards in light of applicable law and the mechanisms made available by our providers.

8. Security

We use technical and organizational controls proportionate to the risks, including access controls, business-level segregation, credential protection, audit records, and safeguards for data in transit and at rest. No system is completely immune from security incidents.

9. Retention and account closure

During a subscription, we retain data for as long as necessary to provide the service and fulfill the stated purposes. For companies that signed up on the website, the company’s data — users, connections, contacts, conversations, media, templates and automations — is permanently deleted within these periods:

For other account closures, operational data in active systems will be scheduled for deletion or anonymization within 30 days, unless an earlier applicable request is made. Audit records of the deletion and of billing events, without conversation content, are kept for billing, security, and the establishment, exercise, or defense of legal claims.

Some data may be retained longer where necessary for legal or regulatory compliance, billing, fraud prevention, security, or the establishment, exercise, or defense of legal claims. Residual copies in protected backups will be deleted through the applicable replacement cycle and will not be restored for ordinary use. Data held directly by Meta, Pipedrive, or other third parties is subject to their respective procedures and policies.

10. Your rights

Subject to applicable law, individuals may request confirmation and access, correction, information about sharing, portability where regulated, anonymization, restriction or deletion of improper data, withdrawal of consent, and objection to processing.

Where we process data solely for a business customer, we may refer the request to that customer for a decision in its capacity as controller. We may request sufficient information to verify identity and prevent unauthorized access or deletion.

11. Cookies and similar technologies

We may use cookies strictly necessary for authentication, sessions, security, and operation of the application. If optional analytics or advertising tools are introduced, this notice and any required consent controls will be updated before their use.

12. Children

zap2crm is a business service and is not directed to children. Customers must not use the service to process children’s data without a lawful basis, authorization, and appropriate safeguards.

13. Requests and contact

To exercise your rights or ask a question, contact the zap2crm Privacy Team at privacidade@cajtecnologia.com.br. CAJ Tecnologia receives and handles these requests on behalf of Estude Vendas. See also our data deletion instructions.

14. Changes

We may update this Policy to reflect legal, technical, or business changes. We will publish the current version on this page and, where a change is material, provide notice through appropriate means.