Legal Documents

Privacy Policy

Last updated: April 7, 2026


Localismo respects your privacy. This policy explains what data we collect and your rights under GDPR.

1. Introduction

This Privacy Policy explains how Localismo collects, uses, stores, and protects your personal data. By using the Platform you consent to these practices. We comply with the GDPR and applicable Portuguese data protection law.

2. Data We Collect

We collect: account data (name, email, hashed password); business listing data (name, address, phone, photos); usage data (pages visited, search queries, device type); technical data (IP address, browser type); and messages sent through contact forms.

3. How We Use Your Data

We use your data to provide and improve the Platform, manage your account, display your listings, send transactional emails, detect fraud, and comply with legal obligations. We do not sell your personal data to third parties.

4. Legal Basis (GDPR)

We process your data under: contract performance (to provide the service); legitimate interests (security and Platform improvement); consent (marketing where applicable, withdrawable at any time); and legal obligation.

5. Cookies and Tracking

We use session cookies for authentication and language preferences. We log visitor data (IP, page, device, approximate location) for security and analytics, accessible only to platform administrators. We do not use advertising cookies or tracking pixels.

6. Data Sharing

We may share data with email service providers (such as Brevo) to deliver transactional emails, hosting providers under data processing agreements, and law enforcement when required by law. All processors are contractually bound to handle your data appropriately.

7. Data Retention

We retain your data while your account is active or as needed to provide the service. If you delete your account, we delete your personal data within 30 days unless retention is required by law.

8. Your GDPR Rights

You have the right to: access your data; rectify inaccurate data; request erasure; restrict processing; receive your data in a portable format; and object to processing. To exercise these rights, contact us at the email address in Platform settings.

9. Data Security

We protect your data using password hashing (bcrypt), HTTPS encryption, CSRF protection, IP-based rate limiting, and regular database backups. No internet transmission is 100% secure, but we take all reasonable precautions.

10. Children

The Platform is not directed to children under 16. We do not knowingly collect data from children under 16. If you believe we have done so inadvertently, contact us immediately.

11. Policy Updates

We may update this Privacy Policy periodically and will notify registered users of material changes by email or via a prominent notice on the Platform.

12. Contact and Complaints

For privacy questions or to exercise your GDPR rights, contact us via Platform settings. You may also lodge a complaint with the Portuguese data protection authority, the Comissao Nacional de Protecao de Dados (CNPD), at www.cnpd.pt.