Privacy Policy
Effective date: August 28, 2026 · Last updated: August 28, 2026
This Privacy Policy explains how Tueron ("Tueron", "we", "us") collects, uses, stores, shares and deletes information when a merchant uses our payment orchestration and conversion analytics platform (the "Service"), including information we access from advertising and payment platforms with that merchant's authorization.
1. Who we are and our role
The Service is operated by Tueron, from Brazil. For any question about this policy, or to exercise a data protection right, write to privacy@tueron.com. This is our designated contact channel for data protection matters, including requests from data subjects and from supervisory authorities.
For the account data of the merchants who subscribe to the Service, we act as a controller. For the data of a merchant's own customers and for the data we access from a merchant's advertising and payment accounts, we act as a processor, processing that data solely on the merchant's documented instructions. The merchant is the controller of that data and is responsible for having a lawful basis to provide it to us.
2. Information we collect
2.1 Merchant account information
Name, business name, email address, phone number, billing details, and authentication data (passwords are stored only as salted hashes and are never recoverable in plain text). We also record login timestamps, IP addresses and access logs for security purposes.
2.2 Transaction data from the merchant's payment providers
When a merchant connects a payment provider, we receive order and payment records for that merchant's sales: order identifier, amount, currency, payment method, payment status, refunds and chargebacks, product identifiers, and the customer identifiers the provider transmits with the order, which may include the customer's name, email address, phone number, tax identification number and shipping address where the merchant collects them.
2.3 Advertising platform data
When a merchant authorizes an advertising account, we access, within the scopes that authorization grants:
- aggregated campaign performance metrics from the merchant's own account, such as spend, impressions and clicks;
- identifiers and names of the advertising accounts, business accounts and pixels the merchant already owns, read so the merchant can select which of them to use;
- access and refresh tokens issued by the platform to the merchant's account.
We do not access, request or store audience lists, user-level advertising data, creative libraries belonging to third parties, or data belonging to any account the merchant has not authorized.
2.4 Conversion event data
For merchants who enable server-side conversion tracking, we process the events generated on the merchant's own storefront and checkout: event name, timestamp, order value and currency, page URL, campaign parameters, the advertising click identifier captured on the landing page, IP address, user agent, and email address and phone number where the merchant's customer provided them. Email addresses and phone numbers are hashed with SHA-256 before being transmitted to any advertising platform, in the format that platform requires.
2.5 Website visitors
Our public website uses only functional storage required to serve the pages. We do not run advertising or cross-site tracking cookies on tueron.com.
3. How we use information
- To provide the Service: reconciling payments, computing attribution, and displaying spend and revenue reporting to the merchant who owns the data.
- To forward the merchant's own conversion events to the merchant's own advertising pixels, as configured by that merchant.
- To authenticate merchants, maintain security, prevent fraud and abuse, and investigate incidents.
- To provide support, respond to enquiries, and send service and billing notices.
- To meet legal, tax and accounting obligations.
We do not use merchant data or advertising platform data to train machine learning models offered to other customers, to build audiences or profiles, or for any purpose unrelated to providing the Service to the merchant it came from.
4. Legal bases
| Purpose | LGPD (Brazil) | GDPR (EU/UK) |
|---|---|---|
| Providing the Service under contract | Art. 7, V — performance of a contract | Art. 6(1)(b) — contract |
| Security, fraud prevention, logging | Art. 7, IX — legitimate interest | Art. 6(1)(f) — legitimate interests |
| Legal, tax and accounting retention | Art. 7, II — legal obligation | Art. 6(1)(c) — legal obligation |
| Processing on behalf of a merchant | Operator under Art. 5, VII | Processor under Art. 28 |
5. Advertising platform data commitments
These commitments apply to all data we access from any advertising platform, including TikTok for Business, Meta and Google:
- Authorization. We access an account only after its owner grants access through that platform's own OAuth consent flow, and only within the granted scopes.
- Isolation. Data is stored scoped to the merchant account it came from. It is never exposed to, pooled with, or benchmarked against any other merchant.
- No sale or transfer. We do not sell, resell, license, sublicense, broker or otherwise transfer advertising platform data to any third party, and we do not use it to build, enrich or supplement any audience, profile, dataset or data product.
- No re-identification. We do not attempt to re-identify, reverse or de-hash any identifier received from or sent to an advertising platform.
- Token security. Access and refresh tokens are encrypted at rest, scoped to a single merchant account, never exposed to the browser, and never shared between merchants.
- Revocation and deletion. A merchant can disconnect an advertising integration at any time from their dashboard, which revokes our access. On disconnection or account closure we delete the associated tokens and platform data within 30 days, except where retention is legally required.
- Platform terms. Our use of each platform's API is additionally governed by that platform's developer terms and policies, which we comply with.
6. Sharing
We share information only in these cases:
- At the merchant's direction, with the advertising and payment platforms that merchant has connected, in order to deliver the events and reporting they configured.
- With subprocessors that provide infrastructure to us under written confidentiality and data protection obligations: cloud hosting and storage, content delivery and network security, transactional email delivery, and payment processing for our own subscription billing. Subprocessors act only on our instructions and may not use the data for their own purposes.
- Where legally required, in response to a valid, binding legal request, limited to what the request compels.
- In a corporate transaction, where the recipient is bound by terms at least as protective as this policy.
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising of our own.
7. International transfers
We operate from Brazil and use infrastructure providers that may process data in the United States and the European Union. Where data is transferred out of its country of origin, we rely on contractual safeguards with our providers, including Standard Contractual Clauses where applicable under GDPR, and on the international transfer provisions of LGPD Chapter V.
8. Retention
We keep merchant account records for the life of the account and for five years after closure where required by Brazilian tax and commercial law. Transaction and conversion event data is kept while the merchant's account is active and deleted within 30 days of account closure or of the merchant deleting it. Advertising platform tokens are deleted immediately on disconnection. Security and access logs are kept for up to 12 months.
9. Security
We use encryption in transit (TLS) and at rest for credentials and tokens, per-merchant data isolation enforced in the application layer, hashed passwords, least-privilege access for personnel, and audit logging of administrative actions. No system is perfectly secure, but we maintain controls proportionate to the sensitivity of the data we hold and investigate reported vulnerabilities. Report a security issue to security@tueron.com.
10. Your rights
Depending on where you are, you have the right to confirm whether we process your personal data, to access it, to correct it, to request deletion or anonymization, to request portability, to object to processing based on legitimate interests, to withdraw consent, and to lodge a complaint with a supervisory authority — the ANPD in Brazil, or your local data protection authority in the EU or UK.
Write to privacy@tueron.com. We respond within 15 days under LGPD and within 30 days under GDPR. If your data reached us through a merchant that uses the Service, we will forward your request to that merchant, who is the controller, and assist them in fulfilling it.
11. Children
The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child's data has reached us, write to privacy@tueron.com and we will delete it.
12. Changes
We may update this policy. The effective date at the top always reflects the current version. For material changes we notify account holders by email or in-product notice before the change takes effect.
13. Contact
Privacy and data requests: privacy@tueron.com
Security: security@tueron.com
General: contact@tueron.com
Tueron · Brazil