Privacy Policy

Effective date: August 15, 2026

1. Introduction

Spoor Caos LTDA (“Spoor,” “CAOS,” “we,” “us,” or “our”) provides the CAOS capital allocation operating system (the “Service”). This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you. By using the Service, you agree to the collection and use of information as described here.

2. Information We Collect

We collect the following categories of information:

  • Account information: name, email address, secondary email, phone number, profile photo, role, profession, and squad assignment, provided when an account is created or updated.
  • Operational data: content you or your organization enter into the Service, including daily performance entries, decisions, tasks, comments, compensation and performance-score data, and any files or images you upload.
  • Usage data: log data, device and browser information, IP address, pages viewed, and interactions with the Service, collected automatically through analytics tooling.
  • Cookies: small data files used to keep you signed in, remember your preferences (such as theme), and measure usage, as described in Section 4.

3. How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, and secure the Service;
  • Authenticate users and enforce role-based access within your organization;
  • Calculate and display operational, performance, and compensation data you or your organization request;
  • Send administrative notices, service updates, and respond to support requests;
  • Monitor, analyze, and improve the performance and usability of the Service;
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell your personal information.

4. Cookies and Similar Technologies

We use essential cookies required for authentication and session management, and preference cookies (such as your theme selection). Where required by applicable law, we request your consent before setting non-essential cookies, through the cookie banner presented on your first visit. You can control cookies through your browser settings, though disabling essential cookies may prevent the Service from functioning correctly.

5. Third-Party Service Providers

We share information with service providers who process it on our behalf, solely to operate the Service. These include, without limitation:

  • Supabase — authentication, database hosting, and storage of account and operational data;
  • Vercel — application hosting, infrastructure, and privacy- conscious usage analytics;
  • Cloudinary — hosting and processing of images and file attachments you upload.

These providers are contractually restricted from using your information for any purpose other than providing services to us. We may also disclose information if required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets.

6. Data Sharing Within Your Organization

The Service is designed for organizational use. Depending on the roles and permissions configured by your organization’s administrators, certain information you enter (such as tasks, decisions, comments, and performance data) may be visible to other members of your organization, including administrators, squad leaders, and, where applicable, the specific collaborator the data concerns. We are not responsible for your organization’s internal access and visibility configuration.

7. Data Retention

We retain personal and operational information for as long as your account remains active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Where data is retained for historical or auditability purposes (such as closed compensation periods), it may be retained after account deactivation as required for legitimate business or legal purposes.

8. Data Security

We implement technical and organizational measures designed to protect your information, including encryption in transit, access controls, and row-level authorization enforced at the database layer. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. This includes rights available under the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Brazil’s Lei Geral de Proteção de Dados (LGPD), to the extent applicable to you. To exercise these rights, contact us using the details in Section 13; note that some requests may need to be routed through your organization’s administrator, who controls the underlying account.

10. International Data Transfers

Our infrastructure providers may process and store information in the United States and other countries. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to legitimize international transfers of personal information.

11. Children's Privacy

The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If we learn we have collected information from a child without appropriate consent, we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, through additional notice. Continued use of the Service after changes become effective constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related questions or requests, contact us at privacy@spoorcaos.com.