Privacy Policy
Last updated: August 16, 2026
This Policy explains how Kesta, operated by Gabi Duarte LTDA (CNPJ 45.815.145/0001-89), processes personal data in compliance with Brazilian Law 13,709/2018 (LGPD). It covers the website, the platform and the Instagram and online-store integrations.
1. Our roles
We are the controller of the merchant's registration and account usage data: that is our relationship with you.
We are the processor of the merchant's customers' data. There, the merchant decides the purposes and acts as controller; we process the data on their behalf to provide the service.
If you are a buyer who commented on a broadcast, the controller of your data is the store you bought from. We may forward your request directly to them.
2. Merchant data
Registration: email, password (stored hashed and irreversibly by the authentication provider), store name and language.
Connections: Instagram account identifier and username, online store identifier and address.
Access credentials for integrated platforms (tokens): stored encrypted in a vault, accessible only by the server, with every read recorded in an audit trail. They are never exposed to the browser.
Usage and billing: record of actions taken in the platform, broadcasts, generated orders, commissions and invoices.
Technical records: IP address and timestamp on sensitive actions, for security and abuse prevention.
3. Buyer data — the minimum necessary
When someone comments on a merchant's broadcast or post, we process: the public Instagram username (@), the comment's identifier and text, the date and time it was made, and the reserved items.
We collect the @ because it is the only way to identify who requested what and to send the payment link. The comment time is necessary because the reservation queue respects the order in which people asked.
Through Kesta we do not collect the buyer's email, phone, tax ID, address or payment data. Those are entered by the buyer directly at the store's checkout and stay with the store and the payment provider — they do not pass through us.
If you reply to the message we send, we read the reply for one purpose only: to identify whether you asked to stop receiving messages (words such as PARAR or STOP). The content of that reply is not stored. We do not interpret it, do not reply automatically and do not monitor the conversation — direct-message support is handled by the store itself.
When someone asks to stop, we keep only the username and the date, so that we can honour the request.
We do not build advertising profiles, do not sell data and do not use it for any purpose other than enabling that purchase.
4. Legal bases
Merchant data: performance of a contract (art. 7, V), compliance with legal and regulatory obligations (art. 7, II) and legitimate interest for security and fraud prevention (art. 7, IX).
Buyer data: performance of a contract or of preliminary procedures relating to a contract to which the data subject is a party (art. 7, V) — the person publicly expressed the intention to buy, and the processing exists to fulfil that request.
Non-essential communications rely on consent (art. 7, I), which can be withdrawn at any time.
5. How we use it
Operating the service: identifying orders in comments, reserving stock in the correct order, building the bag, creating the order in the store and sending the payment link.
Interpreting comments: the comment text is analysed by an artificial intelligence service to identify which product was requested and in what quantity. The text is sent for that purpose only and is not used to train models.
Billing: calculating subscription and commission on paid sales.
Honouring stop requests: detecting the opt-out word in a reply and ceasing to send messages to that person for that store.
Security: recording sensitive actions in an audit trail, limiting abusive attempts and investigating incidents.
Improving the product, using aggregated data that does not identify individuals.
6. Who we share with
We do not sell personal data and do not share it for third-party advertising. We share only with suppliers necessary to operate, and only what is necessary:
Meta Platforms — Instagram API, to read comments and send replies and messages (United States).
The online-store platform connected by the merchant — catalogue, order creation and payment confirmation. It is the platform the merchant chooses and authorises when connecting the store.
Database, authentication and credential-vault provider, with data hosted in São Paulo, Brazil.
Hosting provider for the application and API routes (United States).
Artificial-intelligence provider that interprets comment text (United States). The text is sent for that purpose only and is not used to train models.
Orchestration infrastructure provider, which triggers the service's periodic routines.
Transactional email provider, for account messages.
When card billing is active, a subscription payment provider (United States), which receives billing data only — Kesta does not store card data.
The identification of the specific suppliers in each category above may be requested at any time through the contact channel in this Policy, under article 18, VII of the LGPD.
We may also share data to comply with a court order or legal obligation.
7. Requests from public authorities
Public authorities may approach us asking for data about people who use the platform. When that happens, the rules below apply. They exist so that a request is met within the limits of the law — and not beyond them.
Legitimacy review: no request is honoured automatically. We verify who is asking, the legal basis invoked, and whether the authority has competence to ask for it. Informal requests, by phone or messaging, are not honoured: we require a formal written order or decision.
Challenge: if a request is unlawful, overly broad or disproportionate, we challenge it through the appropriate means, or ask for it to be narrowed, before handing over any data.
Minimisation: we hand over the minimum that answers the request. Never the whole database, never other people's data alongside it, never fields beyond those requested. It is worth recalling what actually exists: of the buyer we keep only the public username, the comment's identifier and text, and the date and time.
Recording: every request received is recorded in our audit trail — date, authority, what was asked, the legal reasoning behind the decision, what was handed over and who decided. That record cannot be altered or deleted.
Notice: where the law allows, we inform the affected person and the merchant responsible for that data. Where a gag obligation applies, notice is given as soon as it lifts.
Emergency: where there is an imminent risk to someone's life or physical safety, we may act before completing the review. The case is recorded in the same way and reviewed afterwards.
8. International transfer
Some of the suppliers above are located outside Brazil, mainly in the United States. This means data may be transferred internationally.
We draw attention to one specific case: the text of broadcast comments is sent to an artificial intelligence service based in the United States to be interpreted.
Transfers rely on art. 33 of the LGPD and are supported by contracts with data protection clauses signed with the suppliers.
9. Security
Third-party credentials are encrypted in a vault, decrypted only on the server, with every access logged.
The database enforces per-merchant isolation at row level: one merchant's data is not accessible to another.
Sensitive actions generate an audit record that cannot be altered or deleted.
All traffic is encrypted in transit. Incoming webhooks are verified by cryptographic signature.
No system is immune. In the event of a security incident with relevant risk, we will notify affected data subjects and the Brazilian Data Protection Authority under art. 48 of the LGPD.
10. How long we keep it
Account data: while the account exists and for up to 5 years after closure, the general limitation period for consumer relationships and tax document retention.
Broadcast, reservation and order data: while necessary for the merchant's commercial history and tax obligations.
Audit and access logs: up to 6 months for application access logs under the Brazilian Internet Civil Framework, and longer where a legal obligation applies.
Integrated platform credentials: deleted from the vault immediately upon disconnection or revocation.
At the end of these periods, data is deleted or anonymised.
11. Your rights
The LGPD grants you: confirmation that processing exists; access to the data; correction of incomplete or outdated data; anonymisation, blocking or deletion of unnecessary data or data processed in breach of the law; portability; information about sharing; information about the possibility of refusing consent; withdrawal of consent; and objection to processing based on legitimate interest.
To exercise any of these, write to contato@kesta.com.br. We respond within 15 days.
If you are a buyer and want your data deleted, you may ask us directly or ask the store you bought from — in both cases the request is honoured.
12. Data deletion
Disconnecting Instagram or the online store stops the processing and immediately deletes the corresponding credentials.
If you remove Kesta from your Instagram settings, Meta notifies us automatically and we delete the data linked to that account, with nothing further required from you.
Deletion requests made through Instagram receive a tracking code, and the status can be checked at any time.
To delete the entire account, write to contato@kesta.com.br.
Records we are legally required to keep, such as tax documents and the audit trail, are preserved for the legal period even after the rest is deleted.
13. Cookies
We use only cookies necessary for operation: keeping you signed in and remembering your chosen language.
We do not use advertising cookies or third-party tracking for marketing purposes.
14. Children and adolescents
The platform is intended for people over 18. We do not knowingly collect children's data. If we identify improper processing, the data will be deleted.
15. Data protection officer and contact
Data protection officer (art. 41 of the LGPD): Gabi Duarte LTDA — contato@kesta.com.br.
Controller: Gabi Duarte LTDA, CNPJ 45.815.145/0001-89. Contact: contato@kesta.com.br.
16. Changes to this Policy
We may update this Policy. The date of the last revision appears at the top of the page, and material changes will be communicated by email or within the platform.