Overview
This Policy describes how TLJ Apps handles information in connection with the CEP Lookup application for Bitrix24. The Application acts as a bridge between your CRM and the public Brazilian postal code database, queried through the public ViaCEP and BrasilAPI services, without collecting or retaining users' personal data.
Data the Application Processes
During use of the Application, the following data is processed in real time:
- CEP number: sent on its own to the public ViaCEP and/or BrasilAPI services to retrieve the corresponding address. The CEP is transmitted without any link to the contact or company it refers to.
- Bitrix24 authentication token: used solely to write the returned address to the contact or company record. Tokens are used in memory and are never stored.
- Public address data: street, district, city, state, region, area code, and IBGE/GIA/SIAFI codes, returned by the public postal database and written to your Bitrix24.
Data the Application Stores
To operate the trial period and subscription, we store a minimal technical record per Bitrix24 portal, containing: the portal identifier (member_id), portal domain, subscription status and dates and, where applicable, customer and subscription identifiers generated by Stripe. We also keep, for up to 30 days, a cache of CEP lookup results (public address data, not linked to any person) to reduce repeated queries. None of these records contain end users' personal data.
What We Do Not Collect
- We do not collect or store any personal data about your employees, contacts, or end users.
- We do not persist names, addresses linked to individuals, authentication tokens, or your CRM content on our servers.
- We have no access to credit card data: payments are processed entirely by Stripe.
- We do not use cookies, tracking pixels, or any monitoring technologies.
- We do not share any information with third parties for advertising or marketing purposes.
Third-Party Services
- ViaCEP and BrasilAPI: public APIs that provide address data from the Brazilian postal database. They receive only the CEP number and are subject to their own privacy policies.
- Stripe: processes subscription payments. Payment details are provided by you directly to Stripe, subject to Stripe's privacy policy (stripe.com/privacy).
- Cloudflare: the Application's runtime infrastructure (Cloudflare Workers), with communication exclusively over HTTPS/TLS.
Retention and Security
Address lookups happen in real time and nothing related to individuals is persisted on our infrastructure. The technical subscription record is kept while the Application is installed or an active billing relationship exists, and can be deleted upon request. The CEP cache expires automatically within 30 days. All communication is performed exclusively over HTTPS with TLS, and authentication tokens are discarded immediately after each operation.
Your Rights (CCPA/CPRA)
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), because we do not store end users' personal information, there is no such information held by us that could be subject to access, correction, deletion, or opt-out rights. The data written to your Bitrix24 records is entirely under your control and responsibility. To request deletion of your portal's technical subscription record, contact us at contato@tlj.net.br.
