Privacy Policy
Last updated:
- Controller
- Goat Are Us (Goat)
- CNPJ (Brazilian company ID)
- 20.500.865/0001-24
- Data Protection Officer (DPO)
- Felipe Lemos — privacidade@goatareus.com
- Contact
- Rua Jacinto Favoreto, 580 — São Carlos, SP, Brasil — CEP 13560-515 · contato@goatareus.com
This document is a translation of the Portuguese original. In case of any discrepancy between versions, the Portuguese version prevails.
1. Who we are and who this policy applies to
Goat is the trade name of Goat Are Us, registered under CNPJ 20.500.865/0001-24, headquartered at Rua Jacinto Favoreto, 580 — São Carlos, SP, Brasil — CEP 13560-515 (“Goat” or “we”). Goat is a marketing agency that operates, on behalf of service businesses in the United States, a platform for websites, ads, customer service, quotes and scheduling.
This policy applies to:
- visitors of the goatareus.com website;
- people who fill out the website’s contact form;
- Goat’s client companies and the people who use the platform on their behalf;
- end customers of client companies, whose data passes through the platform when they contact those companies.
For end customers’ data, Goat acts as a processor (LGPD (Brazil’s General Data Protection Law, Law 13.709/2018)) and service provider (CCPA/CPRA): it processes the data on behalf of and according to the instructions of the client company, which is the controller and is responsible for that data to the data subject. In all other cases, Goat is the controller.
2. Data collected on the website
The website collects personal data only when you submit the contact form:
- name, company name, mobile phone number, email, city and the message you write;
- whether or not you checked the consent box to receive text messages (SMS);
- IP address and browser identification (user agent), recorded at the time of submission;
- ad source parameters present in the address you used to reach the website:
utm_source,utm_medium,utm_campaign,utm_content,utm_term,gclidandfbclid. These are kept only in the browser session (sessionStorage) until submission and are discarded when the tab is closed.
The website does not use cookies, analytics tools or tracking pixels. Fonts and images are served by the website itself. Cloudflare, which delivers the website, logs technical access data (such as IP and time) for network security and operation.
3. Data processed on the platform on behalf of client companies
- Leads and contacts: name, phone, email, address, city, ZIP code, service history and contact source, including the ad that generated it.
- Messages: SMS exchanged through the client company’s numbers and direct messages from Instagram and Messenger on connected pages, with attachments.
- Calls: records of calls made and received through the client company’s numbers (numbers, date, duration and outcome) and recordings, when the client company enables recording — in that case, the caller hears a notice before being connected.
- Calendar: events from the connected Google Calendar (title, time, location and attendees), to display and create appointments.
- Campaigns: metrics from the connected Google Ads and Meta ad accounts (campaigns, spend, impressions, clicks and conversions).
- Quotes and estimate visits issued by the client company.
- Platform users: name, email, password (stored only as a hash) and access logs.
4. Purposes and legal bases
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Responding to the contact form and presenting Goat’s services | Preliminary procedures to a contract, at the data subject’s request (item V) |
| Sending SMS about your contact request | Consent (item I) |
| Providing the services contracted by the client company (website, CRM, customer service, quotes, scheduling and ads) | Contract performance (item V); for end customers’ data, according to the controller’s instructions |
| Linking each contact to its originating ad and measuring campaign return | Legitimate interest (item IX) |
| Security, fraud and abuse prevention (IP, user agent, submission limits) | Legitimate interest (item IX) |
| Complying with legal and regulatory obligations | Legal obligation (item II) |
| Defending rights in judicial, administrative or arbitration proceedings | Regular exercise of rights (item VI) |
For US residents, these uses correspond to CCPA/CPRA business purposes: providing the requested services, ensuring security and integrity, correcting errors and responding to those who requested contact. Goat does not sell personal data nor share it for cross-context behavioral advertising.
5. Text messages (SMS)
If you check the consent box on the form, Goat may send you SMS about your contact request, such as replies, confirmations and conversation reminders. Client companies send SMS to their own customers through the platform based on the consent they themselves collect.
- Message frequency varies.
- Message and data rates may apply, charged by your carrier.
- Reply STOP to stop receiving messages and HELP for help. You may also write to contato@goatareus.com.
- Consent is not a condition of purchase.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Delivery is handled by Twilio, which processes the numbers only to deliver the messages.
6. Google user data
When a client company connects its own Google account to the platform, Goat requests only:
| Scope | Use |
|---|---|
https://www.googleapis.com/auth/adwords | Reading campaigns and metrics from the client company’s Google Ads accounts, for reports and to link each contact to its originating ad |
https://www.googleapis.com/auth/calendar | Reading events from the chosen calendar and creating, changing or canceling appointments made on the platform |
Google data is used only for these functions, visible to the client company itself. It is not used for advertising, not sold, not used to train artificial intelligence models, and not read by people, except with the client company’s authorization, for support, security or legal obligation purposes.
Goat’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The client company may disconnect the account at any time on the platform or at myaccount.google.com/permissions.
7. Meta data (Facebook and Instagram)
When a client company connects Facebook pages, Instagram accounts or Meta ad accounts, Goat accesses:
- the list of pages and accounts the company manages, so it can choose which to connect;
- direct messages from Instagram and Messenger on those pages, to display and reply to them in the platform’s inbox, along with the sender’s public name;
- campaigns and metrics from the ad accounts, for reports and contact attribution.
This data is used only to operate the client company’s own customer service and reports; it is not sold or used for any other purpose. To remove access, follow the data deletion instructions.
8. Processors and sharing
Goat shares data only with the vendors necessary to operate the website and platform, each limited to its role:
| Vendor | Role |
|---|---|
| Cloudflare | Website delivery, DNS, network protection and email routing |
| Hostinger | Server where the platform runs (United States) |
| Supabase | Database and file storage (logos, website photos, attachments and recordings), in the United States |
| SendGrid (Twilio) | Sending platform emails |
| Twilio | Phone numbers, SMS, calls and recordings |
| Google Ads and Google Calendar, when connected by the client company | |
| Meta | Facebook, Instagram, Messenger and Meta Ads, when connected by the client company |
We may also share data when required by law, court order or competent authority. We do not sell personal data.
9. International transfer
Goat is based in Brazil, while the platform, vendors and most data subjects are in the United States. Data is transferred to and stored in the United States based on contract performance at the data subject’s request and on vendors’ contractual clauses that ensure protection compatible with the LGPD (art. 33).
10. Retention and disposal
- Website form: while there is a business relationship or interest in the contact, and, absent a relationship, for up to 2 years after the last contact.
- Platform data: for the duration of the client company’s contract; after it ends, data is deleted within 90 days, unless the client company gives different instructions or a legal obligation requires otherwise.
- Access and submission logs (IP, user agent, date): 6 months, under Brazil’s Marco Civil da Internet (art. 15).
- Tax and contractual documents: for the period required by law.
Once the period ends, data is deleted or anonymized.
11. Your rights
Under the LGPD, you may request: confirmation that we process your data; access; correction; anonymization, blocking or deletion of unnecessary or non-compliant data; portability; deletion of data processed with consent; information about who we share data with; and withdrawal of consent. You may also file a complaint with Brazil’s National Data Protection Authority (ANPD).
Under the CCPA/CPRA (California residents) and similar state laws, you may: know what data we collect and how we use it; request access, correction and deletion; and not be discriminated against for exercising these rights. Since we do not sell or share data for behavioral advertising, there is no sale opt-out to offer.
To exercise any right, write to privacidade@goatareus.com. We may ask for information to confirm your identity. We respond within 15 days. If you are an end customer of a client company, we forward the request to it, as the controller, and assist with handling it.
12. Security
Access tokens for Google, Meta and Twilio are stored encrypted; passwords, only as a hash. Access to data is restricted by company and user role, all communication uses HTTPS, and the website and platform are behind Cloudflare’s protection. No system is fully immune to incidents; if one occurs that may cause relevant risk or harm, we will notify those affected and the ANPD.
13. Minors
The website and platform are intended for adults representing companies. We do not knowingly collect data from anyone under 18. If this happens, write to privacidade@goatareus.com and the data will be deleted.
14. Data protection officer (DPO) and contact
Goat’s data protection officer is Felipe Lemos, reachable at privacidade@goatareus.com. Mailing address: Goat Are Us, Rua Jacinto Favoreto, 580 — São Carlos, SP, Brasil — CEP 13560-515.
15. Changes to this policy
We may update this policy when the website, the platform or the law changes. The last update date appears at the top of the page. Relevant changes will be announced on the website and, for client companies, by email.
