Effective as of August 12, 2026

Privacy Policy

How CS Digital handles data in Gaintent: what is collected, how long it is kept, where it is processed, and what is never done.

Who processes the data

CS Tecnologia e Soluções Digitais Ltda (trading as CS Digital), registered under Brazilian Tax ID (CNPJ) 68.507.685/0001-09, is the controller of data processed in Gaintent. Privacy contact: ads@gaintent.com.

What data is processed

Gaintent is a tool for operating advertising campaigns. The data processed is what that operation requires:

  • User identification: email and the authentication provider identifier. We do not store passwords — those stay with the provider.
  • Client ad account data: account identifier, currency, time zone and review status, obtained from OpenAI Ads.
  • Client API credentials, encrypted in a vault. The database stores only a reference — no column can hold a key.
  • Campaign metrics from the channel: impressions, clicks, cost and conversions.
  • Audit records: who made each change, when, and the prior state.
  • Technical records of channel calls, for failure diagnosis.

What the data is used for

Solely to provide the contracted service: connecting the ad account, creating and managing campaigns upon authorization, measuring economic results and keeping an audit trail.

Data is not used for our own advertising, is not sold, and is not shared with third parties beyond the infrastructure providers listed below.

How long data is kept

Automatic purging runs on a per-type schedule:

  • Technical records of channel calls: 30 days.
  • Synchronization drifts: 180 days.
  • Ad policy evaluations: 365 days.
  • Audit trail and financial records: retained under legal and accounting obligations. They are append-only — the system cannot alter or delete them.

Where data is processed

Infrastructure is located in the United States (us-east-1 region). This entails international data transfer, carried out under the applicable contractual safeguards.

Infrastructure providers are: Supabase (database and authentication), Render (application) and Vercel (website). Each processes data solely to host the service.

How data is protected

Isolation between clients is enforced by the database, with Row Level Security enabled and forced on every table holding client data. The application connects with a role that cannot bypass it.

API credentials are encrypted in a vault, with access restricted by client scope. Operations affecting spend require two-factor authentication.

Your rights

Under Brazilian data protection law (LGPD) you may confirm processing, access, correct, anonymize, port your data, learn about sharing, and withdraw consent.

To exercise any of these, write to ads@gaintent.com. Deletion requests are honored to the extent the law allows — audit and financial records carry mandatory retention.

Cookies

This website uses no tracking, analytics or advertising cookies.

The application uses a session cookie, strictly necessary to keep you signed in, and a cookie storing which account is active. Neither is used to track behavior.

Changes

Changes to this policy take effect on the date shown at the top. Material changes will be communicated by email to active clients.