Privacy Policy
Last updated August 23, 2026
This policy explains what personal data Vantrik collects, why we collect it, who we share it with, and what you can ask us to do with it. Vantrik is a social media scheduling and publishing service operated by Tavlabs, a company incorporated in Brazil.
1. Who is responsible for your data
Tavlabs is the data controller for the personal data described here — the "controlador" under Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and the controller under the EU/UK GDPR.
You can reach us about any privacy matter, including requests to exercise your rights, at privacy@vantrik.net. That address also reaches our data protection contact (the "Encarregado" required by LGPD article 41).
2. What we collect
We only collect what the product needs in order to work. Concretely, that is:
- Account data — your email address and the display name you set on your profile.
- Workspace data — the names of the workspaces you create and who belongs to them.
- Connected social accounts — for each network you connect: the provider, the account's public username, and the connection status.
- Access credentials — the OAuth access token and refresh token the network issues to Vantrik so it can publish on your behalf.
- Post content — the captions you write, the publication times you schedule, the destinations you pick, and the result of each publishing attempt (including error messages returned by the network).
- Media — the images and videos you upload to attach to your posts.
- Billing data — your plan, subscription status and invoices. Card numbers are handled by our payment provider and never reach Vantrik's servers.
- Affiliate data — if you join the affiliate programme: your referral links, the referrals attributed to you and the commissions owed.
- Technical data — standard server and application logs, including IP address and timestamps, kept for security and troubleshooting.
3. How your social network tokens are protected
The tokens that let Vantrik post to your accounts are the most sensitive data we hold, so they get the strictest handling. They are stored server-side only, in a dedicated credentials table that is protected by database row-level security and encrypted at rest by our database provider.
Those tokens are never sent to your browser, never exposed through our public API, and are never used for anything other than performing the actions you asked for — publishing your scheduled posts and reading the account details we show you in the app.
When you disconnect a social account in Vantrik, the account row is deleted and the stored tokens are deleted with it, immediately and permanently.
4. How your media is stored
Images and videos you upload go into a private storage bucket. The bucket has no public URLs: files are readable only through short-lived signed links generated for your own session, and access policies scope every file to the workspace it belongs to.
5. Why we process your data, and on what legal basis
Under LGPD article 7 and GDPR article 6, we rely on the following bases:
- Performance of a contract — to create your account, run your workspaces, connect your social accounts and publish the posts you schedule.
- Legitimate interests — to keep the service secure, prevent abuse, debug failures, and understand aggregate usage. We do not sell your data or use it for third-party advertising.
- Compliance with a legal obligation — to keep tax and accounting records for invoices, as Brazilian law requires.
- Consent — for anything optional, such as product emails you can unsubscribe from. You can withdraw consent at any time without affecting what was done before.
6. Who we share data with
We do not sell personal data. We share it only with the service providers ("operadores" under LGPD / processors under GDPR) needed to run Vantrik, and only to the extent they need it:
- Supabase — database, authentication and file storage.
- Vercel — application hosting and content delivery.
- Asaas — payment processing for customers billed in Brazil (PIX, boleto and cards).
- The social networks you connect — Meta (Facebook and Instagram), TikTok, YouTube, LinkedIn and any other network you link. We send them the content you asked us to publish, using the permissions you granted.
7. International transfers
Our providers may process data on servers outside Brazil, including in the United States and the European Union. Where that happens we rely on the transfer mechanisms permitted by LGPD article 33 and GDPR chapter V, such as standard contractual clauses in our agreements with those providers.
8. How long we keep it
We keep your account data for as long as your account exists. When you ask us to delete your account, we delete your personal data within 30 days, except for records we are legally required to keep — principally invoices and tax records, which Brazilian law requires us to retain for up to five years.
Application logs are kept for a limited period for security and diagnostics, then discarded or anonymised.
9. Your rights
LGPD article 18 and GDPR articles 15 to 22 give you the right to:
- Confirm whether we process your data, and get access to it.
- Correct data that is incomplete, inaccurate or out of date.
- Ask for anonymisation, blocking or deletion of data that is unnecessary, excessive, or processed unlawfully.
- Receive your data in a portable, machine-readable format, or have it transferred to another provider.
- Object to processing based on legitimate interests, and withdraw consent where consent is the basis.
- Be told which public and private bodies we have shared your data with.
- Lodge a complaint with Brazil's data protection authority (ANPD) or, in Europe, your local supervisory authority.
10. Children and teenagers
Vantrik is a business tool and is not directed at children. You must be at least 13 years old to create an account, and at least 16 in the European Economic Area and the United Kingdom unless your country sets a lower age.
Under LGPD article 14, processing the data of children and adolescents requires the specific consent of a parent or guardian. We do not knowingly collect data from anyone below the applicable age. If you believe a minor has given us personal data, write to privacy@vantrik.net and we will delete it.
11. Security
Access to your data is enforced at the database level: every table is protected by row-level security so one account cannot read another's data. Traffic is encrypted in transit, data is encrypted at rest by our providers, and credentials are kept out of the browser entirely.
No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the ANPD as required by LGPD article 48.
12. Changes to this policy
If we change this policy materially we will update the date at the top and, where the change affects your rights, notify you by email or in the app before it takes effect.
13. Contact
For any privacy question or request, write to privacy@vantrik.net. We answer requests to exercise your rights within the deadlines set by LGPD and GDPR.