Privacy notice
Last updated: September 30, 2026
This is a translation for convenience. If it differs from the Spanish version, the Spanish version prevails.
1. Who is responsible for your data
Atiéndalo is a service of Stratonauts, based in Mexico City. We are responsible for the personal data of the people who use Atiéndalo: owners, admins and each shop's team. You can reach us at hola@atiendalo.com.
The data a shop records about its customers and its brands belongs to that shop. In that case the shop is responsible for it, and we only store and process it on the shop's behalf to provide the service. If you are a customer or supplier of a shop, contact the shop first.
2. What data we keep
| What | Examples |
|---|---|
| Your account | Name, email, phone if you give it, language, time zone, and your hashed password if you created one. |
| Your sessions | The IP address and browser of each signed-in device, so you can see where you are signed in and close those sessions. |
| Your shop | Name, settings, brands, products, stock, sales, payments, cash register closings, coupons, gift cards and reports. |
| The shop's customers | Whatever the shop decides to record: name, email, phone and birthday. |
| The shop's brands | Name, contact, email, phone, Instagram and what they have been paid. |
| Your subscription | Plan, invoices, their amount and whether they are paid. For a card on file, only its brand and last four digits. If you pay at OXXO, the name shown on the reference. |
| Card terminals | If you connect Mercado Pago: the connection credentials, stored encrypted, and the result of each charge with its authorization number. Never the customer's card details. |
| Site usage | Pages visited and some events, such as a completed sale or printed labels, counted without cookies. |
We do not ask for sensitive data such as health, religion or ethnic origin. Please do not record it in the system.
3. What we use it for
We use your data to:
- create your account, sign you in and keep your session secure;
- provide the service: selling, keeping inventory, calculating reports and what each brand is paid;
- charge your subscription and send you invoices and receipts;
- send you the service's emails: sign-in links, invitations, payment notices, low stock alerts and the weekly summary. You turn the weekly summary off with the link in each email;
- send brands their statement, when the shop asks for it;
- give you support and answer your messages;
- detect errors, measure performance and learn which parts of the system are used, to improve it;
- meet legal and tax obligations.
We do not use your data for advertising, we do not sell it and we do not use it to train artificial intelligence models.
4. Whom we share it with
We share data only with providers that help us run the service, and only what each one needs. None of them may use it for their own commercial purposes. Several are outside Mexico, mainly in the United States.
| Provider | What for | What it receives |
|---|---|---|
| Hetzner | The server Atiéndalo runs on, in the United States | All of the system's data |
| Backblaze | Daily backup and files | A copy of the database and the files you upload to import data, deleted 30 days after the import ends |
| Stripe | Charging the subscription | The owner's email, the shop's name and language. You type card details directly into Stripe. |
| Resend | Sending emails | The recipient's address and each email's content |
| Anthropic | The weekly summary's comment, when it is active; the Agent, when your shop has it; and reading, on import, what has no clear columns (a PDF, pasted text, a list with brands as headings) | From the summary, only the week's figures with the names of the shop and its best-selling products and brands, with no customer data or individual sales. From the Agent, your questions and the shop data it looks up to answer them, which can include customer names if you ask about them. From the import, the text of that part of the file, with whatever it holds. Anthropic does not use it to train its models. |
| TypeSafe | Recognising, on import, what each column is and whether a brand, category or product is one you already have under another name | Column headings, a few sample values from each column, and the names of the brands, categories and products it compares, with their prices and codes |
| Mercado Pago | Charging through a terminal, only if you connect one | The amount and reference of each charge |
| Honeybadger | Error tracking | Technical details of the error and the request, such as the page, IP and browser. Emails, passwords and codes are masked. |
| Google Fonts | The typeface of the public pages and emails | The IP address of whoever opens the page or email |
Usage statistics are kept by Umami, a program we run on our own servers. It uses no cookies and that data does not leave our infrastructure.
We may also hand data to an authority when the law requires it, and only what it asks for.
5. Links the shop shares
A shop can share two kinds of link that open without signing in: a brand's portal, with its sales, stock and payouts, and a sale's receipt. Anyone with the link can see it. The shop can change a brand's portal link at any time, and the old one stops working.
6. Cookies and browser storage
We only use what the system needs to work. We use no advertising or tracking cookies.
- Session: a signed cookie that keeps you signed in, and another one Rails uses for one-time messages.
- Preferences: a cookie that remembers whether the sidebar is open or collapsed.
- Local storage: the draft of an inventory count, the terminal you picked at checkout, and whether you have used a barcode scanner. It stays in your browser.
Stripe's and Mercado Pago's pages use their own cookies.
7. How we protect it
- Everything travels encrypted over HTTPS.
- Passwords are stored hashed with bcrypt; nobody can read them, not even us.
- Terminal credentials are stored encrypted in the database.
- Each shop sees only its own data, and each person only what their role allows.
- Changing your password closes your other sessions, and from your profile you can see and close each signed-in device.
- We make a daily backup off the server.
No system on the internet is invulnerable. If a breach significantly affects your data, we email you without delay with what happened and what to do.
8. How long we keep it
| Data | How long |
|---|---|
| Shop data | As long as the shop exists, including while it is paused for non-payment or cancellation. |
| Closed shop | 30 days, in case you ask to restore it. Then it is deleted for good. |
| Backups | 45 days. Deleted data disappears from the backups within that time. |
| Sessions | Deleted after 30 days without use. |
| Email sign-in links | Deleted the next day. |
| Your user account | Until you ask us to delete it. Closing a shop does not delete it, because you may belong to other shops. |
| Subscription payments | The record of charges and of notices from Stripe and Mercado Pago is kept for tax and accounting obligations, even after the shop is closed. |
9. Your rights
You have the right to access your data, correct it, ask us to delete it, or object to a specific use. You can also withdraw your consent or limit a use.
- You can do many of these yourself: edit your profile, download the shop's data in Your store → Data, turn off the weekly summary from the email itself, or close the shop if you are its owner.
- For anything else, write to hola@atiendalo.com from your account's email. Tell us what you are asking for and about which data.
- We answer within 20 business days at most. If your request is granted, we apply it within the following 15 business days.
If you believe we did not handle your request properly, you can turn to Mexico's personal data protection authority.
10. Changes to this notice
If we change this notice, we publish the new version here with its date. If the change is significant, we also email you before it applies.