Privacy Policy

Last updated: June 5, 2026

1. Overview
Turno Pro is not designed to sell personal data or track you for behavioral advertising. We process data needed to operate login, registration, synchronization, organizations, tables, messages, subscriptions, notifications, support, and security.

Data controller: Turno Pro is operated by an independent developer, who determines the purposes and means of the processing described here. For privacy questions or to exercise your rights, use the contact in section 15.

2. Account and profile data
When you create an account or sign in with a provider, we may process account identifier, email address, name, photo/avatar, language, preferences, profile details you provide, and technical authentication metadata. We use this data to authenticate you, maintain your session, identify you to other users where needed, sync account-linked data, provide support, and enforce the Terms.

3. Organizations, tables, and members
When you create or participate in organizations, we may process organization name and data, logo, invitation emails, members, roles, permissions, work locations, tables, schedules, events, ratings, audit data, and changes made by authorized users. This data is used for collaboration, permission management, table display, history, synchronization, and administrative features.

4. Messages and conversations
When you use message sending or exchanges, we process data such as sender, recipients, related organization or table, subject, message body, attachments, replies, conversation history, date/time, read state, archive state, delivery, and selected channel (for example, internal message or push notification). This data is used to deliver messages, enable replies, display conversations, prevent abuse, resolve support, and comply with legal obligations.

5. Subscriptions, purchases, and app stores
Purchases and subscriptions are processed by Apple and/or Google. The App uses a subscription management service, such as RevenueCat, to tie subscription status to your in-app account, including recognizing the same subscription on iOS and Android when you use the same account, subject to the stores' and provider's rules. For that purpose, account identifier, email, display name, and subscription data may be sent to the subscription provider. We do not store payment card data on our systems; payment is handled by the stores.

6. Notifications and device permissions
If you allow notifications, we use a push notification provider, such as OneSignal, which may process technical device identifiers, push token, account identifier, and data needed for delivery, operational segmentation, and message confirmation. You can revoke permission in device settings.

Location: with your permission, the App uses foreground location for the address picker and to identify your current place. The "Chegou no Ponto" (arrival alarm) feature may use background (continuous) location for the sole purpose of triggering your alarm when you enter or leave the place you chose — not to track employees or share your position with third parties. Background location is enabled only after a specific disclosure and your consent, and can be turned off at any time by disabling the feature or revoking the permission in device settings.

When you grant photos, files, or camera permissions, we use those accesses only for features you request in the App, such as attachments, images, or content customization.

7. Infrastructure, storage, and security
We use authentication, database, storage, and cloud infrastructure providers, such as Supabase, to maintain accounts, registered data, organizations, messages, and attachments. For error diagnostics and stability, we use a crash-reporting service, such as Sentry. We may also process technical logs, IP address, device information, App version, and error events for security, diagnostics, abuse prevention, and stability improvement.

8. Data sharing
We may share data with contracted providers that operate the App (authentication, database, storage, notifications, subscriptions, app stores, infrastructure, and support), with organization administrators or members within product permissions, and when needed to comply with law, authority requests, protect rights, prevent fraud, or investigate misuse.

9. Legal basis for processing (users in the EU/EEA and the United Kingdom)
Where the GDPR (or UK GDPR) applies, we process your data based on: (a) performance of a contract — to create and maintain your account, provide the App's features, process subscriptions, and offer support; (b) legitimate interests — for security, fraud and abuse prevention, diagnostics, and service improvement, balanced against your rights; (c) consent — for push notifications and for location (including the "Chegou no Ponto" background location), which you can withdraw at any time; and (d) compliance with a legal obligation — where required by law. Withdrawing consent does not affect the lawfulness of processing already carried out.

10. International data transfers
Some of our providers (for example, Supabase, OneSignal, RevenueCat, and Sentry) may process data outside your country, including in the United States. When we transfer data outside the EU/EEA or the United Kingdom, we rely on recognized safeguards, such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision. You can request more information through the contact in section 15.

11. Retention
We keep data as long as needed to operate the App, comply with legal obligations, resolve disputes, maintain security, and preserve legitimate history of organizations, messages, subscriptions, and support. Removed content or closed accounts may remain in backups, audit records, or shared histories for a limited period as required for technical, legal, or security reasons.

12. Your controls and rights
You can update profile data in the App, sign out, permanently delete your account under Account → Delete account (with in-app confirmation), manage device permissions, and cancel subscriptions in the stores. Subject to applicable law (including the GDPR/UK GDPR and Brazil's LGPD), you have the right to access, correct, delete, restrict, or object to processing, to data portability, and to withdraw consent. To exercise any of these rights, write to the contact in section 15. Account deletion removes your authentication and profile data from our systems; active Apple or Google store subscriptions must be canceled separately by you. Some requests may be limited by legal obligations, fraud prevention, organization history, or messages already delivered to other users. If you believe the processing infringes the law, you have the right to lodge a complaint with your country's supervisory authority — for example, the CNPD in Portugal, the ANPD in Brazil, or the competent authority in your EU Member State.

13. Children
The App is not intended for independent use by minors below the applicable digital-consent age in your country (between 13 and 16 in the EU, depending on the Member State; 13 in Portugal and Brazil). Use by minors should be supervised by a parent or guardian.

14. Changes
We may update this policy to reflect App changes, legal requirements, or providers. Continued use after changes constitutes acceptance of the new version where allowed by law.

15. Contact
Privacy / questions: support@turnoproapp.com.