Privacy Policy
1. Summary
Checklists is different from most Marketplace apps: it has a backend that we host, because the people who fill in a checklist are not Freshservice users and Freshservice cannot serve them a page. Answers, photos, signatures and location evidence are therefore stored on our infrastructure, for a period you set, and written back onto your tickets. This document says exactly what is stored, where, for how long, and how to remove it.
Under Brazil's LGPD and the GDPR you (the customer) are the controller of your requesters' data and we are the processor: we process only what you configure the app to collect.
2. What the app processes
2.1 About the person who fills in a checklist (the requester)
| Data | Where it comes from | Why |
|---|---|---|
| Name and e-mail address | The Freshservice ticket | To address the link and attribute the answers |
| Checklist answers | Typed on the checklist page | The content of the checklist |
| Photos | Camera or gallery, when a photo item asks for one | Evidence; reduced on the device before upload |
| Signature | Drawn on screen, when a signature item asks for one | Sign-off |
| GPS coordinates and accuracy | The browser, with the person's permission | Only for geofenced checklists, or recorded at submit when the phone offers them |
| Location attempts | Each time the page asks for a position | To tell "permission denied" from "too far away" |
| IP address and browser user agent | The submit request | A record of who submitted, from where, on what device |
| Timestamps | Sending, opening, submitting | Deadlines, expiry, history |
A photo taken in a checklist is also attached to the ticket in Freshservice. That copy is yours, inside your account, and is not touched by any deletion described in section 5.
2.2 About your account
| Data | Note |
|---|---|
| Freshservice domain, plan, language, logo and colour | Account configuration |
| Freshservice API key | Pasted by the admin on the app's installation page. Stored encrypted (AES-256-GCM under a key held only by the service) and never returned: the Settings screen shows that a key exists, never its value. It can only be replaced. |
| App token | The credential the app uses to talk to the backend. The installation page obtains it automatically when the admin pastes the API key; nobody types or sees it. Held as a secure installation parameter in Freshworks; the backend stores only its hash. |
| Admin audit log | Who published a checklist, changed a setting or a credential, or erased data, with author, action and changed fields. Never the value of a credential. |
There is no advertising tracking, no third-party cookie, no profiling and no automated decision about individuals. The checklist page keeps its link in the browser's sessionStorage and forgets it when the tab closes.
3. Where the data is
The backend (checklist-api.redlotus.com.br) runs on Microsoft Azure, region westus2 (Oregon, United States): a PostgreSQL database for answers, scores, e-mails, IP addresses and coordinates; a private blob container for photos and signatures; and the application's operational logs.
For customers outside the United States this is an international transfer of personal data. We offer standard contractual clauses between controller and processor, with the obligations in this document attached. If your assessment requires data to stay in-country, contact us: the service can be deployed in another Azure region.
Everything else stays in your Freshservice account and region: the tickets, the notes, the attachments and the e-mails to requesters. We run no e-mail service of our own; Freshservice sends the invitation and the reminders as public notes on the ticket.
3.1 Sub-processors
| Service | What it receives | Purpose |
|---|---|---|
Microsoft Azure (westus2) | Everything in section 2 | Hosting |
| Freshworks (your Freshservice account) | Tickets, notes, attachments, tags | It is your system of record |
| BrasilAPI | Only the postcode (CEP) of a Location's address | To find a store's coordinates for the geofence. No personal data is sent |
4. How long
Answers, photos, signatures, coordinates, IP address and user agent are deleted a number of days after the ticket is closed, not after the checklist is sent. The default is 90 days; you set the number on the app's Settings tab, between 7 and 3650.
After the purge only a de-identified checklist row remains: score, percentage, outcome and dates. Name, e-mail, IP, user agent and coordinates are cleared, and the answers and files are actually deleted. The blob is removed from storage, not merely flagged.
When the app is uninstalled, the account's data is purged on the same schedule and can be purged immediately on request to privacidade@redlotus.com.br.
5. Your requesters' rights
A requester may ask you for confirmation, access, correction, portability or erasure. As processor we act through you:
- Erasure: Settings › Erase a requester's data. Type the e-mail address and confirm. It removes answers, photos, signatures, coordinates, location attempts, IP, user agent and the e-mail address itself from every checklist that person submitted: the same as the automatic purge, not less.
- What erasure does not reach: photos already attached to tickets in Freshservice. Those are your copy and are removed there.
- Access and portability: export the person's checklists to CSV from the Sent checklists tab, filtered by e-mail.
6. Security
- All traffic is HTTPS. The requester's link carries a random token that is the only credential; it can be revoked by reopening or expiring the checklist.
- Every record carries the account it belongs to and every query is scoped to it.
- The Freshservice API key is encrypted at rest and is decrypted only for the call that needs it.
- Photos and signatures are served through signed, expiring links from our API, never from a public bucket.
- The admin audit log records every change to templates, settings and credentials.
7. What we do not do
- We do not read your tickets beyond the one a checklist is sent on.
- We do not sell, share or use your data for anything other than running the service for you.
- We receive no telemetry from the app beyond the requests it makes to work.
8. Changes and contact
We will post changes to this policy at the same URL and note the effective date. Questions and data requests: privacidade@redlotus.com.br. Support: info@redlotus.com.br.