This translation is provided for convenience. If it differs from the Portuguese version, the Portuguese version prevails: Política de Privacidade (português)
Summary
- Who we areTF Chat is a service of TF SOFTWARE LTDA. We are the controller (controlador) of your account data (we decide how it is processed) and the processor (operador) of your buyers' data, which we process on your behalf to provide the service.
- What we collectRegistration and access data and data from the shops and channels you connect: conversations, orders (with the recipient's name, phone number and address and, on Mercado Livre, the buyer's tax data), after-sales, products and, on WhatsApp, the number's contacts and groups. For PIX top-ups, the payer's name and CPF/CNPJ.
- AI and translationAI auto-reply only works in the shops where someone on your account turns it on, with the provider chosen for each agent: Anthropic (USA), OpenAI (USA) or DeepSeek (China). Translation always uses DeepSeek and only happens when someone on your team clicks translate.
- Who we share withPrimary storage is in Brazil (Tencent Cloud, São Paulo), and we only send data to those who need it for the service to work — marketplaces, WhatsApp, AI providers, SMS and e-mail delivery, notifications, the PIX bank and TF Software's own systems, some of them outside Brazil — or to authorities, when the law requires it. We do not sell personal data.
- How longConversations are deleted 7 days after the conversation's last message; to-do items and WhatsApp contacts, only when the shop is removed. Orders, buyer profiles, after-sales and products have no automatic deletion and remain stored even if you remove the shop or delete the account; you can request their deletion from our Data Protection Officer (Encarregado).
- Your rights and contactYou can request access to, correction and deletion of your data, among other LGPD rights, subject to the exceptions provided by law. Write to privacidade@tfsoftware.com.br or delete your account in the Android or iPhone app.
1. Who we are and to whom this policy applies
TF Chat is a customer service hub for e-commerce sellers: it brings together conversations with buyers from Shopee, TikTok Shop, Mercado Livre and WhatsApp, lets you reply with the help of artificial intelligence (AI), translates messages and shows orders, after-sales and products from your shops. The service is provided by TF SOFTWARE LTDA, CNPJ 40.673.061/0001-34, headquartered at Praça João Duran Alonso, 34 — Cidade Monções, São Paulo/SP, Brazil (“TF Software” or “we”).
This policy explains how we process personal data under the Brazilian General Personal Data Protection Law (Lei Geral de Proteção de Dados Pessoais — LGPD, Law No. 13,709/2018). It applies to the website tfchat.com.br (including the help center and the downloads page), the web app, the Windows app (which opens the same web app) and the Android and iPhone apps.
“You” means the seller who subscribes to TF Chat or a member of their team. The person who creates and administers the account is the “account owner” (in the app, the “Main account”); each team member signs in with their own login created by the owner, called a “seat”. The “company account” brings together the owner's account, the seats, the connected shops and the balance. A “buyer” is the person who talks to the shop through the marketplace or WhatsApp.
Our role for each type of data
| Data | TF Software's role | Who decides |
|---|---|---|
| Your registration, login and account security; billing, top-ups and financial records; app and website data | Controller (art. 5, VI) | TF Software |
| Buyer and contact data that arrives through the shops and channels you connect: conversations, orders, after-sales, buyer profiles, WhatsApp contacts and groups | Processor (art. 5, VII, and art. 39) | You, the seller, are the controller |
| Buyer data that appears in technical logs, in copies of the platforms' automatic notifications and in AI usage records | Controller (art. 5, VI), for security, diagnostics and billing of the service | TF Software |
| The same data in the marketplaces' and WhatsApp's systems | None | Shopee, TikTok Shop, Mercado Livre and WhatsApp, as independent controllers |
You are also the controller of your team management data: who is given a seat, which shops it can access and each seat's last access date, which you see in the dashboard. Some processing is defined by us for all accounts, such as retention periods (section 7), technical logs and billing records, and is described in this policy.
As the controller of your buyers' data, it is up to you to have a legal basis for processing it, to inform buyers about this processing (including the use of TF Chat, AI and translation) and to handle their requests. We help with anything that involves TF Chat.
2. Data we collect
2.1 Account and seats
| Data | Details |
|---|---|
| Mobile phone number (with country code) and e-mail (at least one of the two) | To create the account, sign in and receive verification codes by SMS or e-mail. Codes for seats go to the account owner's mobile phone or e-mail. |
| Password | Stored only as an irreversible cryptographic digest (BCrypt hash): the original password cannot be read and is not displayed. |
| Identifiers | User number (userId), username and internal identifiers of your account and of the company account. |
| Display name, time zone and language | Display in the interface. The language also sets the target language for translations. |
| Seats | Name, display name, password set by the owner, assigned shops, role, status and last access date (visible to the owner). Seats do not have their own mobile phone number or e-mail. |
| Sessions | A random code keeps you signed in and expires after 7 days without use. |
| Log in or register with TF HUB | We receive from TF HUB, TF Software's own system, your identifier, e-mail and name, used as the login e-mail and display name. The phone number sent by TF HUB is only kept during login (up to 5 minutes) and is not used. |
2.2 Connected shops (Shopee, TikTok Shop and Mercado Livre)
When you connect a shop, you authorize TF Chat on the platform, which gives us access keys (“tokens”) to fetch and send data on your behalf. We process:
| Category | What it includes |
|---|---|
| Shop identification | Name, identifier on the platform (on Mercado Livre, your seller number), region, authorization status and access tokens. |
| Conversations and messages | The buyer's nickname, identifier and photo (link); text, type and time of messages; references to orders and products; the full copy of the data the platform sends about the conversation; requested translations. Includes Mercado Livre pre-sale questions. |
| Media | Images, videos and stickers from Shopee and TikTok Shop stay on the platform; we store only the link. Mercado Livre attachments are not downloaded. Media you send go straight to the platform, with no copy in TF Chat. |
| Orders | Number, status, amounts, payment method, carrier, tracking, items, note and the buyer's name or nickname (on TikTok Shop, this may be the e-mail). We also store the full copy of the data the platform sends about the order, the shipment and the financial settlement, which includes the recipient's name, phone number and full address and, on TikTok Shop, the buyer's e-mail. |
| Tax data on Mercado Livre | The billing data Mercado Livre returns for the order, usually CPF or CNPJ, name and billing address. It is fetched and stored when the order is updated on the platform or viewed in TF Chat. It is available in the order details to anyone with access to the shop; it is not sent to the AI or used by other TF Chat features. |
| Older Shopee orders | Orders synced before a TF Chat update in August 2026 may contain the buyer's CPF, invoice (nota fiscal) data and the sender's (dropshipper's) phone number, which we stopped requesting as of that update. |
| Buyer profile | City and state of the last delivery address, number of orders, total spent and a summary of the last 10 orders, for the customer service panel and the AI context. |
| After-sales | Returns, refunds and cancellations: the buyer's reason and text, amounts, the buyer's name and e-mail provided by the platform, tracking, evidence links and the full copy of the data sent by the platform. Evidence and contact e-mail that you submit in Shopee disputes go straight to the platform, with no copy in TF Chat. |
| Products | Name, image (link), price, stock, sales, description, attributes and variations. |
| To-do items (conversations handed off to human agents) | The buyer's nickname, an excerpt of up to 512 characters of the message that generated the to-do item, reason, assignee and dates. |
| Settings you create | Quick replies, automatic message texts, invitation image, AI agents with their instructions, and to-do rules. We also record which user last turned on, turned off or changed the AI of each shop. |
| Platforms' automatic notifications (webhooks) | Copies of the notifications the platforms send to our server for each event, such as a new message or an order change. On Shopee and TikTok Shop, they include the text of messages and the sender's name; on WhatsApp, we only store connection-status and failure notifications, which may contain the message. |
2.3 WhatsApp channel (pilot feature)
- The channel is a pilot and does not use the official WhatsApp API: your number is connected to TF Chat as a “linked device”, as in WhatsApp Web. Before connecting, you confirm a notice about the pilot's risks, and we record who confirmed it and when. In TF Chat, the connected number appears as a shop; removing it has the effects described in “When you remove a shop” (section 7).
- We store on our servers the linked device's credentials and session data (number, profile name, phone type and connection status).
- When you connect, WhatsApp syncs the conversations from the last 7 days (with a message limit), the list of contacts and conversations and the number's groups (name, description and each participant's number). This may include people who do not buy from your shop.
- We receive individual and group messages and download to our servers the media received and the media you send; these files are deleted 7 days later (section 7).
- The component that connects the number keeps on disk a technical queue with a copy of the events received from WhatsApp (messages, contacts and groups) until they are delivered to our main server; the retention period is in section 7.
- For contacts, we store the number, profile name, verified business name, photo (link), block indicator and date of the last conversation.
- When someone on your team opens a conversation in TF Chat, a read receipt may be sent to the contact.
- The channel does not use AI auto-reply, the welcome message or the inactivity reply. Translation can be used.
2.4 Payments and credits
- PIX top-up: full name and CPF or CNPJ of the payer (who may be another person or company), amount, top-up number and PIX charge data, required by the bank to issue it. If you provide another person's data, make sure they are aware of it.
- Owner data in the top-up: display name (or username), e-mail, mobile phone number and identifier of the account owner, to identify your company in our financial system, and the username of whoever initiated the top-up.
- Wallet and usage: balance, bonuses, top-ups and ledger entries. For each AI auto-reply call, we record the shop, agent, provider, model, number of tokens (units of text that AI providers use to measure usage), cost and an internal conversation identifier, without the text of the messages. Translation generates no charge and no usage record.
- In the iPhone app, top-ups are not available; you can only view invoices.
2.5 Devices, website and security
- Notifications: on iPhone (and on Android, when enabled), if you allow it, we register the notification token (a code that Apple or Google use to deliver notifications to the device), the system (iPhone or Android), the language and the date of last activity.
- Windows app: stores the preference to start with Windows and a random installation identifier, sent to our server when checking for updates.
- Files you choose: photos, videos, audio and documents to send to a buyer are read only when you use the feature.
- IP address: besides appearing in technical logs (below), it is kept for 1 minute to 1 hour in counters that limit login attempts, captcha and code sending. The captcha is generated by our servers, without third-party services.
- Login attempts: failures are counted for 15 minutes, associated with a cryptographic digest (hash) of the login entered, not with the login itself.
- Technical logs: our servers record operational and security events, such as IP address, URL accessed, browser, date and time and account actions (for example, a password change, with the user identifier). These logs may also contain excerpts of buyer messages and AI replies, buyer names and e-mails present in the platforms' responses, connected WhatsApp numbers, conversation and user identifiers and order numbers, used for diagnostics.
- Shop binding: to prevent a shop from being bound to another TF Chat account for 3 months, we record the shop, the account and the binding date.
2.6 Sensitive data
TF Chat does not ask for or use, on its own initiative, sensitive personal data (such as health data, racial or ethnic origin, religious belief, political opinion, trade union membership, sex life, genetic or biometric data). Messages from buyers and contacts, however, are free text and may contain this type of information when the person writes it themselves. In that case, they are treated like other messages: they are visible to the team members with access to the shop, may be sent to the AI provider when auto-reply is active and to DeepSeek when someone requests a translation, and follow the periods in section 7. Do not ask buyers for sensitive data through TF Chat.
3. How we use data and on what legal bases
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Create and maintain your account, authenticate access, send codes and manage seats | Performance of a contract (V) |
| Protect accounts and prevent fraud: captcha, attempt limits, temporary login lockout, 3-month block on binding a shop to a new account, technical logs | Legitimate interest (IX); legal obligation regarding the retention of access logs (II) |
| Connect shops and channels; sync and display conversations, orders, after-sales, products and buyer profiles; send your replies | Your data: performance of a contract (V). Buyer data: we process it as a processor, to provide the service you subscribed to; the legal basis is defined by you, as controller. The processing we define for all accounts, such as retention periods and technical logs, is described in sections 1 and 7. |
| AI auto-reply, translation, automatic messages and the to-do queue | Processing as a processor, according to the features you enable; performance of a contract (V) |
| Send notifications to your device | Performance of a contract (V) |
| Billing, top-ups, PIX charges, balance and usage control, tax and accounting records | Performance of a contract (V); legal or regulatory obligation (II); legitimate interest (IX), regarding the data of a payer who is not the account owner |
| Support and notices about the service and about changes to this policy | Performance of a contract (V); legitimate interest (IX) |
| Maintain, diagnose and fix the service | Legitimate interest (IX) |
| Comply with laws, court orders and requests from authorities | Legal or regulatory obligation (II) |
| Defend rights in judicial, administrative or arbitration proceedings; keep the acceptance of the WhatsApp pilot notice | Regular exercise of rights (VI) |
Mandatory and optional data: to create the account you must provide a mobile phone number or an e-mail and a password (or use the TF HUB account, which provides us with the e-mail); without them TF Chat cannot be used. To connect a shop you must authorize TF Chat on the platform. To top up via PIX you must provide the payer's name and CPF or CNPJ, required to issue the charge; without them a PIX top-up is not possible. Notifications, AI auto-reply, translation, automatic messages and the WhatsApp channel are optional: without them, the other features remain available.
What we do not do: we do not sell personal data; we do not use your data or your buyers' data for advertising or to build profiles for ads; we do not send advertising by SMS or e-mail (currently, TF Chat's automatic SMS and e-mails are only verification codes; notices about the service and about this policy may be sent by e-mail); TF Software does not use the content of conversations to train AI models. The buyer profile exists only to support your customer service.
4. Artificial intelligence and translation
4.1 AI auto-reply
Auto-reply is off by default. It only works in the shops where a user on your account links an AI agent and turns auto-reply on. For each agent, you choose the provider and the model: Anthropic (Claude, USA), OpenAI (USA) or DeepSeek (China). The WhatsApp channel does not use AI auto-reply.
Any user on your account, including seats, can create, edit and delete any AI agent on the account — including changing the provider, model and instructions of an agent used in shops they do not have access to — and can turn AI on or off in the shops they have access to. Instruct your team accordingly.
With AI turned on, for each new buyer message we send to the agent's provider:
- the instructions you wrote for the agent and the situations for handing off to a human agent that you configured, along with the platform, the region and the shop name;
- the buyer's nickname, the delivery city and state, the number of orders and the total spent at the shop;
- up to 5 recent orders and the orders mentioned in the conversation: number, status, amount, date, carrier, tracking code and latest tracking events, and up to 4 items;
- the products mentioned and the shop's best sellers (name, price, stock, attributes and summarized description);
- up to the 30 most recent messages of the conversation, each limited to 500 characters (images and videos are sent only as an indication that they exist);
- a sentence about the state of the conversation (for example, whether it is the first contact).
We do not send the AI the buyer's identifier, phone number or e-mail, the recipient's full address or the tax data (CPF/CNPJ). The text of the messages, however, is sent as written and may contain data the buyer provided themselves.
The context is sent even when the AI decides not to reply, and may be resent later if a reply fails. Each call generates a usage record, without the text. The replies generated are sent to the buyer through the platform and stored as messages in the conversation. The providers process the data they receive in accordance with the terms of their respective APIs.
The welcome message and the inactivity reply are off by default, use only the texts you write and do not send data to AI providers.
4.2 Translation
- Translation is free and always uses DeepSeek (China); you cannot choose another provider.
- It only happens when someone on your team clicks to translate a message or a draft. It is never automatic.
- We send only the text to be translated (up to 5,000 characters) and the target language. We do not send names or identifiers, but the text itself may contain personal data.
- A message's translation is stored with it, visible to those on your account with access to the conversation, and is deleted along with the message. Draft translations are not stored.
4.3 AI limitations and your responsibility
- AI replies and translations may contain errors or incorrect information. Review your agents' instructions and monitor the conversations.
- Replies are sent on behalf of your shop, and TF Chat does not indicate to the buyer that they were generated by AI. It is up to you to inform your buyers about the use of automatic or AI-generated replies whenever marketplace rules or the law require it.
- Do not put unnecessary personal data in the agents' instructions. If you do not want buyer data to reach an AI provider, do not enable that provider's agents; if you do not want it to reach DeepSeek (China), do not use translation either.
5. Who we share with
We share personal data only to the extent necessary to provide the service, comply with the law or protect rights. We do not sell personal data.
| Recipient | Purpose | Data |
|---|---|---|
| Tencent Cloud (hosting, Brazil) | TF Chat infrastructure | All stored data |
| Anthropic and OpenAI | Auto-reply with an agent from these providers | Context described in section 4.1 |
| DeepSeek | All translation; auto-reply with a DeepSeek agent | Text to be translated and language; context from section 4.1 |
| Tencent Cloud SMS | SMS codes | Mobile phone number and code |
| Twilio SendGrid | E-mail codes | E-mail and code |
| Apple (Apple Push Notification service) | Notifications on iPhone | Device token; buyer's nickname or shop name; short preview of the message, to-do item or balance; shop and conversation identifiers (on WhatsApp, this identifier may contain the contact's number) |
| Google (Firebase Cloud Messaging) | Notifications on Android, when enabled | The same data sent to Apple |
| C6 Bank | PIX charges | The payer's name and CPF/CNPJ, amount and top-up number |
| Shopee, TikTok Shop and Mercado Livre | Integration with your shops | Messages and media sent by you, your team or the AI; answers to questions; after-sales decisions and evidence; contact e-mail in disputes. From them we receive the data in section 2.2 |
| WhatsApp (Meta) | WhatsApp channel (pilot) | Messages and media sent, read receipts and lookups of the linked device's contacts and groups |
| TF Software's own systems (TF HUB and financial system) | Login with the TF HUB account; recording paid top-ups; account monitoring | TF HUB: account identifiers to confirm the link; status, balance and top-up and usage totals. Financial system: the owner's name, e-mail, mobile phone number and identifier, amount, top-up number and PIX charge identifier (without the payer's name and CPF/CNPJ) |
| Public authorities | Compliance with the law, a court order or a request from a competent authority | The data required, within the limits of the law |
Third-party safeguards: the suppliers that process data for TF Chat (hosting, AI and translation providers, SMS and e-mail delivery, and notifications) receive only the data needed for the function indicated in the table. TF Software does not authorize them to use this data for other purposes and undertakes to use only suppliers that offer data protection compatible with this policy and with the LGPD. The marketplaces, WhatsApp and C6 Bank also process the data they receive as independent controllers, under their own policies.
Within your account: the owner sees data from all shops. Each seat sees only the shops assigned to it and, in them, the conversations and orders, with the recipient's name, phone number and address and, on Mercado Livre, the buyer's tax data, which can be copied. Assign shops only to those who need them.
TF Software staff: authorized TF Software personnel may access account data, including conversations, orders and buyer data, only to the extent necessary to operate, support, protect and maintain the service, and are bound by confidentiality duties. Our operations team also sees the accounts' registration data (such as display name, e-mail and mobile phone number) and balance and usage information, for support and billing.
Platform images: stickers, product images and conversation media from Shopee and TikTok Shop are loaded by your browser or app directly from those platforms' servers, which receive your IP address and technical browser data.
6. International data transfers
TF Chat's primary storage (database, files and technical logs) is in Brazil, on Tencent Cloud, São Paulo region. Some recipients process data outside Brazil:
- USA: Anthropic, OpenAI, Apple, Twilio SendGrid, Google Firebase (when enabled) and WhatsApp (Meta), the latter also in other countries;
- China: DeepSeek, for all translation and for replies from DeepSeek agents; and Tencent Cloud's SMS service, which receives the mobile phone number and the verification code;
- Singapore and other countries: Shopee;
- Other countries, depending on each company's infrastructure: TikTok Shop (outside Brazil) and, possibly, Mercado Livre.
These transfers take place because they are necessary to perform the contract with you and to provide the services you requested (art. 33, IX, in conjunction with art. 7, V, of the LGPD). For buyer data, they follow the features that you, as controller, decide to use, such as an AI agent's provider or translation. In these countries, the data is also subject to local laws.
7. How long we keep data
These are the periods that apply today. Where there is no automatic deletion, this is stated clearly.
| Data | Period |
|---|---|
| Conversations and messages from all channels (text, media links, AI replies, translations) | Automatically deleted 7 days after the conversation's last message; while the conversation remains active, its entire history is kept. They are also deleted when you remove the shop. Conversations without a last-message date (for example, created only by a WhatsApp system record, such as a missed call) may not be deleted automatically. For WhatsApp, see also the channel's technical queue. |
| Platforms' automatic notifications (webhooks), which may contain the text of messages | 14 days |
| WhatsApp media files | Deleted 7 days after being saved on our servers. Records of sent media that are no longer linked to a message: 90 days. |
| WhatsApp channel technical queue (copy of the events received from WhatsApp, including the content of messages, contacts and groups) | No fixed period. The files are deleted in blocks after being delivered to our main server, which may take more than 7 days for numbers with little activity. They are fully deleted when the number is disconnected or removed. |
| WhatsApp contacts and groups | No automatic period; deleted when you remove the number from TF Chat. Merely disconnecting the number does not delete them. |
| WhatsApp credentials | Deleted when the number is disconnected, when WhatsApp ends the session or when you remove the number. |
| Orders (including the recipient's name, phone number and address and, on Mercado Livre, the buyer's tax data), buyer profiles, after-sales and products | No automatic deletion period. They remain stored while the account exists and continue to be stored after the shop is removed, after the authorization on the platform is revoked or expires and after the account is deleted, until their deletion is requested from the Data Protection Officer (section 14). |
| To-do items; each shop's AI settings (including the record of who last changed them) and automatic message settings; marketplace authorization tokens | No automatic period; deleted when you remove the shop (tokens remain stored even if the authorization expires). |
| AI agents and their instructions, to-do rules and quick replies | No automatic period; they remain until deleted in the tool itself, and are not deleted when the shop is removed or the account is deleted. |
| Shop binding record; acceptance of the WhatsApp pilot notice | No automatic period. |
| Account data (mobile phone number, e-mail, display name, link to the TF HUB account) | While the account exists. On deletion, they are deleted immediately; the rest of the account record is deleted after 30 days (section 9). |
| Device registration for notifications | Until you sign out of the account on the device (if the cancellation reaches the server), change your password or delete the account, or until Apple or Google indicate that the token is no longer valid. |
| Temporary technical data | Sessions: 7 days after last use. Verification codes: 5 minutes. Captcha: 2 minutes. Login with the TF HUB account: 5 minutes. Security counters: from 1 minute to 24 hours. Order cache and markers against duplicate messages: from minutes to 30 days. |
| Financial records: wallet, ledger entries, top-ups (including the payer's name and CPF/CNPJ and the account owner's data), bonuses and AI usage | Kept to comply with tax and accounting obligations and for the regular exercise of rights. They are not deleted when the account is deleted and currently have no automatic deletion. |
| Server technical logs | There is no fixed period defined for these logs. |
Access logs: TF Software will comply, where applicable, with the legal duty to retain internet application access logs under art. 15 of the Brazilian Civil Rights Framework for the Internet (Marco Civil da Internet, Law No. 12,965/2014), for the period and under the conditions set by law.
Deleting data in TF Chat does not delete the copies kept by the marketplaces and WhatsApp, nor any copies kept, under their respective terms, by the AI and translation providers, Apple, the SMS and e-mail services and C6 Bank. TF HUB and TF Software's financial system are not automatically notified of a deletion; ask the Data Protection Officer if you want the data deleted from them as well, except for the records the law requires us to keep. Data deleted from our active databases may remain in backups for an additional period.
When you remove a shop
Seats cannot remove shops; this function belongs to the account owner. We immediately delete the conversations and messages, to-do items, AI and automatic message settings, the shop's assignment to seats and the authorization tokens. On WhatsApp, we also disconnect the number and delete the session, the channel's technical queue, the contacts, the groups and the media records (the files follow the 7-day cleanup). Not deleted automatically: orders, buyer profiles, after-sales, products, AI usage records, agents, to-do rules and the shop binding record. To delete them, ask the Data Protection Officer. Because this data remains linked to the shop on the platform, if the same shop is connected to TF Chat again — by your account or, after the 3-month block, by another account — it may reappear and be used in that account's customer service and AI context. If you do not want this, request its deletion from the Data Protection Officer before removing the shop.
On the marketplaces, removal deletes the access keys stored in TF Chat, but does not revoke the authorization on the platform; to do that, remove TF Chat's access in the marketplace's dashboard.
Data received from the marketplaces
Data obtained through the Shopee, TikTok Shop and Mercado Livre APIs is used only to provide TF Chat, in the features described in sections 3 and 4; it is not sold or used for advertising. If the authorization is revoked directly on the marketplace or expires, the data already synced is not deleted automatically: remove the shop in TF Chat and ask the Data Protection Officer to delete the remaining data. We comply with deletion requests made by the seller and with those required by the marketplaces.
8. Security
The technical measures in place include:
- Encrypted connections (HTTPS/TLS) on the website, the web app, the apps and the real-time connection.
- Passwords stored only as a BCrypt hash.
- Verification codes that are random, single-use, valid for 5 minutes and limited to 5 attempts, stored only as a cryptographic digest (HMAC).
- Abuse protection: captcha before codes are sent; sending limits per IP, per destination and per day; temporary lockout after 8 incorrect login attempts within 15 minutes; attempt limits per IP.
- Sessions with a random code that expires after 7 days without use. Changing or recovering the password, deactivating or deleting a seat and deleting the account sign that user out of all sessions and devices.
- Access control by role and by shop: requests concerning a shop's data (conversations, orders, after-sales, products) check whether the shop belongs to your account and whether the seat has access to it. AI agents belong to the whole account. Seats have no access to billing, top-ups, seat management or shop removal: these functions belong to the account owner.
- Masking in the interface: the mobile phone number and e-mail appear masked in the profile; marketplace tokens are never displayed; the payer's CPF/CNPJ appears masked in the invoice details.
- Authenticated integrations: PIX charges use a digital certificate and access credentials with the bank; we verify the digital signature of Shopee and TikTok Shop automatic notifications; on Mercado Livre, whose notifications are not signed, we check the application and the seller and fetch the data directly from the platform; communication with TF HUB and between the WhatsApp components is digitally signed and rejects repeated or old messages.
- WhatsApp: the credential files have access permissions restricted to the service that uses them. The WhatsApp connection component hides the content of messages and masks phone numbers in its own logs; the main server, however, logs the connected number and an excerpt of the messages received (section 2.5). Media files open via links containing a long random code; anyone who has the link can open the file, so do not share these links.
- Minimization when sending to AI: the context sent does not include the full address (only city and state), the phone number, the e-mail, the CPF/CNPJ or the buyers' identifiers (section 4).
No system is completely secure. Protect your password, create a seat for each person instead of sharing logins, sign out on shared devices and remove the seats of people who have left the team.
Incidents: if a security incident occurs that may cause significant risk or harm to the people whose data we process, we will notify the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD) and the affected people (the data subjects, or titulares), as provided in art. 48 of the LGPD and ANPD regulations. When it involves data we process as processor, we will notify you, the controller, so that you can fulfill your obligations.
9. Your rights
Under art. 18 of the LGPD, you may request, at any time and free of charge:
- confirmation that we process your data and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data or data processed in breach of the LGPD;
- portability of the data to another provider, in accordance with ANPD regulations;
- deletion of data processed on the basis of consent, except in the cases of art. 16;
- information about the public and private entities with which we share data;
- information about the possibility of not giving consent and its consequences, and withdrawal of consent, when it is the legal basis;
- objection to processing carried out on a legal basis other than consent, in case of non-compliance with the LGPD (art. 18, § 2), including the processing based on legitimate interest described in section 3;
- review of decisions made solely on the basis of automated processing that affect your interests (art. 20), where applicable.
How to exercise them
You can correct your mobile phone number, e-mail, display name and time zone in your profile. For other requests, write to privacidade@tfsoftware.com.br. We may ask you to confirm your identity, for example with a code sent to your registered mobile phone or e-mail; requests made by a representative require proof of authorization.
We respond within the LGPD time limits. Confirmation that we process your data and access to it are provided immediately, in simplified form, or within 15 days of the request, by means of a complete statement (art. 19). Some data may be kept after a deletion request where the law allows it, for example to comply with tax obligations or to exercise rights (art. 16). When we correct, anonymize, block or delete data at your request, we will inform the agents with whom we have shared it, under art. 18, § 6 of the LGPD, unless this proves impossible or involves disproportionate effort. Requests about buyer data are forwarded to the responsible seller (section 10).
Deleting your account
- In the Android or iPhone app: Profile → Delete my account, confirming with your password.
- By e-mail: ask the Data Protection Officer at privacidade@tfsoftware.com.br. Use this route if you access TF Chat from a computer (web app or Windows app), where the option does not appear.
- In the e-mail, provide your user number or your registered mobile phone number or e-mail and say whether you want to delete only your login or also the company's data that is not deleted automatically (orders, buyer profiles, after-sales and products). We will confirm your identity before carrying out the request.
- If you created the account with the “Log in or register with TF HUB” button and do not have a password, use “Forgot password?” on the login screen to create one, or request deletion by e-mail.
What happens:
- Immediately: you are signed out of all devices, notifications stop and your mobile phone number, e-mail, display name and link to the TF HUB account are deleted; the username is replaced. Your TF HUB account, if you have one, is not deleted.
- After 30 days: the rest of the account record (identifiers, password hash, time zone, last access date) is deleted.
- What remains in the company account: connected shops and their authorizations, which stay active; conversations, until they expire; orders, buyer profiles, after-sales, products and to-do items; WhatsApp contacts and groups; AI agents and quick replies; balance and financial records, including the owner's and payer's data recorded in top-ups.
- Seats are separate accounts, managed by the owner, and are not deleted or deactivated when the owner deletes their own account. The owner can delete a seat at any time, with immediate effect. A seat can also delete its own login through the app; the owner is not notified automatically.
- After the owner's deletion: seats keep access to the shops assigned to them, but no one in the company can top up, manage seats or remove shops anymore, and seats cannot change or recover their password, because the codes went to the owner's mobile phone or e-mail.
Deletion is permanent: we do not offer restoration of deleted accounts. If the company is going to stop using TF Chat, the owner should, in this order: remove the connected shops and the seats; ask the Data Protection Officer to delete the data that is not deleted automatically (section 7), while we can still confirm identity through the registered mobile phone or e-mail; and only then delete the account. Financial records remain stored to comply with legal obligations and currently have no automatic deletion.
If you believe your rights have not been honored, you may file a complaint with the National Data Protection Authority (www.gov.br/anpd) or with consumer protection bodies.
10. If you are a buyer or a contact of a shop
If you talked to a shop via Shopee, TikTok Shop, Mercado Livre or WhatsApp and that shop uses TF Chat, TF Software processes your data on behalf of the seller responsible for the shop, as processor. That seller is the controller and decides how to use TF Chat.
On the seller's behalf, we may process: your nickname, identifier on the platform and profile photo; your e-mail, when the platform provides it (for example, in TikTok Shop orders and Shopee returns); your messages and attachments; your orders, including the recipient's name, phone number and delivery address and, on Mercado Livre, billing data such as CPF or CNPJ; your after-sales requests; and a summary of your purchase history with the shop (delivery city and state, number of orders and total spent). On WhatsApp, also your number and profile name and, if you are in the connected number's contact list or in a group it takes part in, your contact details and the group's messages, even if you have never bought from the shop.
The shop may use AI to reply to and to translate your messages, with providers in the USA or China (section 4). Conversations are deleted 7 days after the last message; orders and after-sales have no automatic deletion (section 7).
Your nickname and an excerpt of your messages may appear in notifications on the shop team's devices, sent by Apple (and by Google, when enabled) or displayed by Windows, and message excerpts may appear in our servers' technical logs. Authorized TF Software personnel may access this data only to the extent necessary to operate, support, protect and maintain the service. On WhatsApp, the shop uses a pilot channel that is not the official WhatsApp API (section 2.3).
How to exercise your rights: contact the shop first, through the same channel as the conversation. If you cannot, write to our Data Protection Officer (privacidade@tfsoftware.com.br): we will forward your request to the seller and help them fulfill it where TF Chat is involved. The marketplaces and WhatsApp also process your data as independent controllers, under their own policies.
11. Apps, local storage and cookies
Cookies and local storage
The TF Chat website and app do not use cookies. Login works through a session code sent by the app with each request. The browser and the apps store locally:
| Item | When it is deleted |
|---|---|
| Session code | On sign-out, when the session expires or when switching accounts |
| Notification token | On sign-out, if the cancellation on the server succeeds |
| Language, time zone and conversation list filters (including the selected shops) | Remain on the device after sign-out |
| Other preferences: mobile display mode, custom server address, skipped update version, and the help center's language and a copy of its public content | Remain until changed |
| Temporary data from logging in with the TF HUB account and notices already shown | When the tab or the app is closed |
On shared devices, sign out of the account and clear the browser or app data.
No advertising, tracking or analytics tools
We do not use ads, advertising identifiers, cross-app or cross-site tracking, or analytics, crash reporting or telemetry tools. The Android app includes the Google Firebase notifications library, which is currently inactive and sends no data; when enabled, it will be used for notifications.
System permissions
- iPhone: camera (to take photos and send them to the buyer), microphone (to record audio) and photos (to attach images), requested only when you use the feature; and notifications.
- Android: the app does not request camera or microphone permission; it uses the system's own file picker and camera. Notifications, when enabled.
- No app requests access to your location or to the device's contacts.
Notifications
On iPhone, notifications are sent by Apple when you do not have TF Chat open. They show the buyer's nickname or the shop name and a short preview of the message; for a new to-do item, the buyer's nickname and the excerpt that generated it; for the owner, low or depleted balance alerts, with the amount. On Android, when enabled, they will work the same way, through Google. The Windows app uses Windows' own notifications, with the buyer's nickname and a preview of the message; the web app does not use browser notifications. Notifications may appear on the lock screen and remain in the device's notification center. You can turn them off or hide previews in the system settings; when you sign out of the account, the device stops receiving them; if the device is offline when you sign out, the cancellation may not reach the server — in that case, change your password to sign out all devices.
Windows app and mobile apps
- The Windows app opens the web app at tfchat.com.br/app, under the same rules as this policy. The built-in browser's data is stored in the app's folder in your Windows user profile.
- The Android app is downloaded from our downloads page, not from Google Play. Android may include the app's local data, such as the session code, in the device backup, depending on your Google account settings.
- External links and the marketplaces' authorization pages open in the system browser.
- If you change the server address in the app settings, your login and usage data will go to that server; if it is not operated by TF Software, this policy does not apply to it.
- Files you download, such as WhatsApp attachments or exported reports, go to the device's downloads folder and are under your control.
12. Children and adolescents
TF Chat is a service for e-commerce businesses and professionals and is not intended for anyone under 18. We do not knowingly collect data from children and adolescents as users. If we learn that an account belongs to someone under 18, we will close the account and delete the registration data, except for data the law requires us to keep.
Buyers and contacts who talk to shops may include adolescents. This data is processed on behalf of the seller, who, as controller, is responsible for complying with art. 14 of the LGPD; if we become aware of such a case, we will help the seller where TF Chat is involved.
13. Changes to this policy
We may update this policy to reflect changes in the service, in our suppliers or in the law. The date of the last update appears at the top of this page. When the change is significant, such as a new type of data, a new purpose, a new recipient of personal data or a change in retention periods, we will notify you before it takes effect, through an in-app notice, by e-mail or both.
This policy is published in other languages for your convenience. In case of any discrepancy, the Portuguese version prevails.
14. Contact and Data Protection Officer
For questions about this policy or requests regarding your data, contact TF Software's Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais). E-mail is the main channel, because it allows us to record and respond formally, especially to access or deletion requests.
