CSCapvolaBack to Capvola

legal

Privacy Policy

What we collect, what we do not, and who the data belongs to. Last updated September 2026.

This website counts pages, not people

The public pages you are reading have no advertising pixels, no third-party embeds and no contact form. They do count page views, using Umami, which runs on our own server rather than anybody else’s.

It sets no cookie. It stores no identifier that survives the day, so you cannot be recognised tomorrow as the person who visited today, and you are not followed to any other website. What it records is the page, the referring site, and a rough country, screen size and browser. That is enough to know which pages are read and nowhere near enough to know who read them.

None of it goes to a third party. There is no Google Analytics here, no advertising network, and nothing is sold or shared. If that ever changes, this page changes first and a cookie banner appears with it.

Signing in

When you sign in we set one cookie so the application knows it is still you between pages. It is essential to the service working and it is not used for tracking or shared with anyone. Signing out ends it.

We keep ordinary server logs, which include IP addresses and the pages requested. They exist to keep the service running and secure, and they are rotated.

The data inside a CRM is the client’s, not ours

Each business on Capvola has its own instance holding its own records: its customers, their contact details, the work done for them, photos, documents, signed agreements and payment history.

That data belongs to the business, not to us. We hold and process it so the software can run, and for no other purpose. We do not sell it, we do not share it between clients, and we do not use one client’s data to build anything for another. Each instance is separated so that one business cannot reach another’s records.

If you are a customer of a business that uses Capvola and you want to see, correct or delete what is held about you, ask that business directly. They decide what is kept and for how long. We will act on their instruction.

Who else touches it

Payments are handled by Stripe, using the client business’s own Stripe account. Card details go to Stripe and never reach us or the client’s CRM; we only see that a payment succeeded and for how much.

Email and text messages are sent through the client’s own sending address or number where one is set up, otherwise through ours. The content of those messages is the client’s.

The application and its database run on servers we rent and administer. We do not copy client data anywhere else.

How long it is kept

For as long as the business is a client, plus whatever period they ask us to keep it after that. When a client leaves they can have an export of their data, and we delete the instance on request.

Backups are kept on a rolling basis and are overwritten in turn, so a deleted record can persist in a backup for a short period before it ages out.

Security

Everything is served over HTTPS. Credentials and sending passwords are stored encrypted. Customer-facing links carry a private token, are marked so search engines will not index them, and can be rotated.

No system is perfect. If something happens that affects a client’s data we will tell that client.

Changes and questions

If this policy changes materially we will change the date at the top and tell existing clients. Questions about your own business’s data go to us. Questions about a record held by a business that uses Capvola go to that business.

Written in plain language to describe what the software actually does. It has not been reviewed by a lawyer.

© 2026 Capvola SolutionsTerms of ServicePortuguês