Privacy Policy
Last updated: September 8, 2026
Draft: this document is an initial template, framed by United States privacy law (including the California Consumer Privacy Act, as amended by the CPRA), the EU General Data Protection Regulation (GDPR) and the Brazilian General Data Protection Law (LGPD, Law no. 13,709/2018) where each applies, and has not undergone legal review.
1. Controller
Vasta, Inc., a California corporation with its principal office at 3313 Adriatic Ave, Long Beach, CA 90810, United States ("Vasta", "we"), is the controller (under the CCPA, the "business") of personal data processed on tryproa.com and the Proa platform. Data Protection Officer (DPO) and privacy contact: Bruno Cassimiro, bruno@vasta.me.
2. What data we process
- Contact data: name, email, and the messages you send when reaching out to us;
- Account data: credentials and usage records of the platform by subscribing customers;
- Data from customers' stores: when operating the platform on our customers' stores, we process aggregate browsing and purchase events (visits, orders, and amounts), without building individual visitor profiles and without third-party tracking cookies. In this case we act as a processor, under the instructions of the customer that owns the store.
- Data from the Proa Shopify app: for stores that install the app, we receive paid-order events limited to order identifiers, amounts, dates, the test variant and a hashed checkout token, and, with the shopper's analytics consent, three checkout steps from the Shopify Web Pixel. Shopper names, emails, phone numbers, addresses, line item contents and payment data are never persisted or logged. Exactly what is received, read and kept, what uninstalling does, sub-processors and retention are in our Data Processing Addendum.
3. Why we use it
- To answer inquiries and schedule demos (steps prior to entering a contract; GDPR art. 6(1)(b), LGPD art. 7, V);
- To provide, maintain, and improve the Service (performance of contract and our legitimate interest in running it; GDPR art. 6(1)(b) and (f), LGPD art. 7, V and IX);
- To comply with legal and regulatory obligations (GDPR art. 6(1)(c), LGPD art. 7, II);
- To establish, exercise or defend legal claims (GDPR art. 6(1)(f), LGPD art. 7, VI).
4. Sharing
We do not sell personal data. We share data only with processors necessary to provide the Service (for example, hosting and infrastructure providers), under contract and with adequate safeguards, or when required by law. We do not "sell" or "share" personal data as those terms are defined by the CCPA. Our infrastructure is located in the United States. Where the GDPR applies, transfers out of the EEA rely on the European Commission's standard contractual clauses or an adequacy decision; where the LGPD applies, transfers follow LGPD art. 33.
5. Cookies
The tryproa.com website uses no advertising cookies and no third-party tracking cookies. We may use cookies strictly necessary for the website to function.
6. Retention
We keep data for as long as necessary for the purposes in this Policy or for periods required by law. Store events and order records processed on behalf of our customers are kept for 400 days and then purged automatically; uninstalling the Shopify app stops collection through the app, and Shopify's redaction requests anonymize the orders they cover earlier. When processing ends, data is deleted or anonymized, except where retention is required by law or needed to establish, exercise or defend legal claims.
7. Your rights
Depending on where you live, you may have the right to know what personal data we hold about you and to access it, to correct it, to delete it, to receive it in a portable format, to restrict or object to certain processing, to withdraw consent, and not to be discriminated against for exercising these rights (CCPA/CPRA; GDPR arts. 15-22; LGPD art. 18). To exercise your rights, write to bruno@vasta.me. We will verify the request and respond within the timeframes set by the applicable law. Residents of the EEA and the UK may also lodge a complaint with their supervisory authority.
8. Security
We adopt technical and organizational measures proportional to the risk of processing, including access control, encryption in transit, and operation logging. No system is infallible; relevant incidents will be communicated to the affected individuals and to the competent authorities as required by the applicable law (including U.S. state breach-notification laws, GDPR arts. 33-34 and LGPD art. 48).
9. Changes to this Policy
We may update this Policy. The current version will always be available on this page, with its last-updated date.
10. Contact
Privacy questions: info@vasta.me.