Legal · SaaS FP&A
Privacy Policy
This Policy explains how SaaS FP&A handles personal information when you visit, purchase, authenticate to, or request support for FFCC.
Last updated: July 26, 2026
1. Who is responsible
SaaS FP&A is operated by Leonardo Maza Teixeira, an individual based in Brazil. SaaS FP&A is the controller for account, license, and support data handled through FFCC. For questions or privacy requests, contact support@saasfpa.com.
Paddle processes payment information as Merchant of Record and authorized reseller under its own applicable terms and privacy practices.
2. Information we handle
- Authentication information: email address, user ID, session and authentication records needed to send and validate Magic Links.
- License and access information: license ID, purchase email, access status, start and expiration dates, product code, and records of access decisions.
- Payment-related identifiers: information received from Paddle such as customer ID, transaction ID, product ID, price ID, payment status, amount, currency, environment, and refund or adjustment status.
- Support communications: messages, contact details, and information you choose to provide when requesting help.
- Technical and security logs: request timing, route, status, sanitized error codes, and other limited operational records needed to secure and troubleshoot the service.
Payment-card details: Paddle acts as Merchant of Record and payment provider. SaaS FP&A does not receive or store complete payment-card numbers or card-security codes.
3. Financial assumptions and model data
The current FFCC implementation stores the financial assumptions and company-profile values you enter in your browser’s local storage. Calculations and Excel exports are generated in your browser. This financial model data is not uploaded to Supabase by the current implementation.
Because this working state is stored on your device, clearing browser data, changing browsers, or using another device may remove or make that local state unavailable. You should keep appropriate copies of exports you need.
4. Why we process information
We use personal information to:
- provide Magic Link authentication and secure account access;
- activate, maintain, expire, suspend, or revoke licenses;
- validate completed purchases and apply approved refunds;
- prevent fraud, unauthorized access, and abuse;
- respond to support requests and troubleshoot technical problems;
- maintain accounting, transaction, dispute, and compliance records; and
- comply with legal obligations and enforce our agreements.
5. Legal bases
Depending on your location and the activity, processing may be based on performance of a contract or steps requested before entering a contract, compliance with legal obligations, our legitimate interests in operating and securing FFCC and preventing fraud, and consent where applicable. Where consent is the basis, it may be withdrawn without affecting earlier lawful processing.
6. Service providers and international processing
We use service providers that process limited information on our behalf or under their own applicable terms:
- Supabase: authentication, user, license, access-status, and database services.
- Vercel: website hosting, content delivery, and server-side functions.
- Resend: delivery of authentication and Magic Link emails.
- Paddle: Merchant of Record, checkout and payment processing, receipts, tax handling, transaction support, and refunds under Paddle’s own applicable terms and privacy practices.
These providers may process information in countries other than your own. Where required, we rely on applicable contractual, organizational, or legal safeguards for international transfers.
7. Retention
We retain account and license information while needed to provide access and for a reasonable period afterward. Payment identifiers, refund records, and related communications may be retained as needed for accounting, tax, fraud prevention, chargebacks, disputes, and legal obligations. Security and troubleshooting logs are kept only as long as reasonably necessary for those purposes.
Retention periods may vary according to record type, applicable law, and whether a dispute or legal hold applies. Information is deleted or anonymized when it is no longer reasonably required, subject to technical backup cycles and legal obligations.
8. Security
We use reasonable technical and organizational measures designed to protect personal information, including passwordless access, server-side license checks, restricted service credentials, encrypted transport, access controls, and limited operational logging. No online system can be guaranteed completely secure.
9. Your rights
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, portability, information about sharing, or objection to certain processing. You may also have the right to withdraw consent and complain to a competent data-protection authority.
Rights under Brazil’s LGPD
Where Brazil’s Lei Geral de Proteção de Dados (LGPD) applies, you may request:
- confirmation that your personal data is being processed;
- access to your personal data;
- correction of incomplete, inaccurate, or outdated personal data;
- information about public and private entities with which personal data has been shared;
- data portability where applicable and subject to applicable regulation;
- deletion, anonymization, blocking, or restriction of personal data where legally applicable; and
- other rights available under applicable data-protection law.
To exercise these rights, email support@saasfpa.com. We may need to verify your identity and may retain information where law permits or requires it.
10. Policy updates
We may update this Policy when our practices, providers, product, or legal obligations change. The “Last updated” date identifies the current version. We will provide additional notice where required by applicable law.