Privacy Policy

Last update: September 2026 | CNPJ: 42.801.643/0001-84

Grupo Adventure ("we", "our" or "the company"), developer of Orion CRM, respects the privacy of its users and is committed to protecting their personal data. This Privacy Policy explains how we collect, use, store and protect your information when you use our website and our platform.

This policy complies with the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018).


1. About this Policy

Grupo Adventure Soluções, developer of Orion CRM, respects the privacy of its users and is committed to protecting personal data in accordance with the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018) and other applicable regulations.

This policy describes how we collect, use, store and protect your information when you use the Orion platform and its integrated services, including integrations with the Meta platform (Facebook, Instagram, WhatsApp) and the Google APIs (Ads, Calendar and Drive).


2. What data we collect

2.1 Data you provide

  • Full name

  • Email address

  • Phone number

  • Company name and CNPJ (Brazilian company registration number)

  • Payment information (processed by Asaas — we do not store card data)

2.2 Data collected automatically

  • IP address

  • Browser and device type

  • Pages visited and browsing time

  • Usage and behaviour data within the platform

2.3 Data from external integrations

When you connect an external service account to Orion, we collect only the data required for the features you have enabled. See sections 6, 7, 8 and 9 for details specific to the Meta and Google integrations.


3. How we use your data

Create and manage your account on the platform

  • Process payments and issue charges

  • Provide support and respond to your requests

  • Send communications about the product, updates and news (with your authorisation)

  • Improve the platform experience based on usage

  • Display data from active integrations (messages, campaigns, posts, calendar, files) exclusively to the account holder

  • Comply with legal and regulatory obligations


4. Data sharing

We do not sell or rent your personal data. We may share it only with:

  • Infrastructure partners: Supabase (database), Asaas (payments), Resend (email) — all under a confidentiality agreement

  • Integrations you have enabled: when you connect external services (Meta, Google, WhatsApp), data travels according to those services' policies and only to make the features you have enabled work

  • Competent authorities: when required by law or court order

Orion does not use data obtained through external integrations for advertising purposes, third-party analytics, sale of information, or any purpose other than providing the service directly to the account holder.


5. Storage, security and retention

5.1 Security

  • Encryption in transit (HTTPS/TLS)

  • Encryption at rest

  • Tenant isolation — each company accesses only its own data

  • Automatic daily backup

No system is 100% secure, but we adopt the best practices available to protect your information.

5.2 Retention

We keep your data for as long as your account is active. After cancellation:

  • Your data remains available for export for 30 days

  • After that period, it is permanently removed from our servers

  • Data required to comply with tax and legal obligations may be kept for the period required by law


6. Integration with the Meta platform (Facebook, Instagram, WhatsApp)

Orion uses Meta's official API to provide a unified inbox, post scheduling and campaign reporting. This section describes specifically how that integration works and which data is accessed.

6.1 How the connection works

The Meta integration is started exclusively by you, through a standard OAuth authentication flow. Orion never asks for your Facebook or Instagram password. The process is as follows:

  1. You click "Connect Meta account" in the Orion dashboard

  2. You are redirected to Meta's login screen, where you authenticate with your own credentials

  3. Meta displays the exact list of permissions Orion requests, and you approve them knowingly

  4. After approval, an access token is generated by Meta and stored securely in Orion

  5. You can revoke access at any time, both through Orion (in Settings > Integrations) and through your Facebook security settings

6.2 Permissions requested and purpose

  • business_management: Identify which Facebook Pages and ad accounts are linked to your Business Manager, so that you can select them when setting up Orion.

  • pages_messaging: Read and reply to messages received via Facebook Messenger in Orion's unified inbox.

  • pages_read_engagement: Check the status of scheduled posts and access conversation context in Messenger.

  • pages_manage_posts: Create and schedule posts on your Facebook Pages from Orion's scheduling module.

  • instagram_manage_messages: Read and reply to messages received via Instagram Direct in Orion's unified inbox.

  • instagram_content_publish: Schedule and publish posts to the Instagram Business or Creator account linked to your Facebook Page.

  • ads_read: Read performance data from your Facebook Ads and Instagram Ads campaigns to generate reports in Orion. Orion does not create, edit or delete campaigns.

  • pages_manage_metadata: Subscribe the connected Facebook Page to Meta's webhooks, so that new Messenger messages reach Orion's inbox in real time.

  • pages_read_user_content: Read the comments people leave on the client's Page posts, to display them next to each post in Orion.

  • Business Asset User Profile Access: Read the name and profile picture of people who message the client's Page, to identify them in the inbox.

  • Human Agent: Allow a person on the client's team to reply to a Messenger conversation up to 7 days after the customer's last message. Every reply is written and sent by a person; Orion does not send automated messages with this tag.

  • whatsapp_business_management: Connect the client's WhatsApp Business account through Meta's Embedded Signup, register the phone number, subscribe it to webhooks, and create message templates and follow their approval status.

  • whatsapp_business_messaging: Receive and send WhatsApp messages through the number connected by the client, in Orion's inbox.

6.3 How we handle Meta data

  • Data obtained through Meta's API is used exclusively for display and management within your own Orion account

  • Messenger and Instagram Direct messages are accessed for display in the inbox and replied to by you — they are not indexed or shared. The only processing beyond display is the reply suggestion described in section 10, and only when you trigger it

  • The name and profile picture of contacts who start a conversation with the client's Facebook Page or Instagram account are accessed exclusively to identify the contact within the inbox — they are not indexed or shared

  • WhatsApp messages received and sent through the number connected by the client are displayed in Orion's inbox and replied to by people on the client's own team — they are not indexed or shared. The only processing beyond display is the reply suggestion described in section 10, and only when someone on the team triggers it

  • Message templates created by the client are submitted to Meta for approval. Orion stores the template content and the status returned by Meta (for example: in review, approved, rejected) only for display and management within the client's own account

  • Data about the WhatsApp Business number and account — phone number, verified name and account identifiers — is used exclusively to operate the connection with Meta, and for no other purpose

  • Campaign data is read only to generate reports visible to you — it is not used for advertising purposes or shared with third parties

  • Scheduled posts are sent to Meta's API at the time you scheduled — Orion does not publish automatically without your prior configuration

  • Meta access tokens are stored encrypted and are never exposed to other users or third parties

  • Orion does not store message content beyond what is needed for display in the inbox

6.4 Revoking access

You can disconnect your Meta account from Orion at any time in Integrations > Instagram and Facebook. After disconnection, Orion no longer accesses new data from your account. You can also revoke access directly through your Facebook app settings at facebook.com/settings?tab=applications.

WhatsApp Business numbers are disconnected separately, in Integrations > WhatsApp Business, using the delete button next to the number. Disconnection can also be done on Meta's side, under Facebook Settings > Business Integrations.


7. Integration with the Google Ads API

Orion uses the Google Ads API to provide Google Ads campaign performance reports directly in the platform dashboard.

7.1 How the connection works

The Google Ads integration uses Google's standard OAuth flow. You authorise access through Google's consent screen, where the requested permissions are displayed clearly before any confirmation.

7.2 Data accessed

  • Campaign data: Performance metrics such as impressions, clicks, CTR, CPC, cost and conversions for campaigns linked to your Google Ads account.

  • Ad set data: Targeting and results per ad group for report breakdowns.

  • Individual ad data: Performance of each creative, to identify the best and worst performing ads.

7.3 How we handle Google Ads data

  • Orion accesses read-only data — it never creates, edits, pauses or deletes campaigns or ads

  • Campaign data is used exclusively to generate the reports visible to you within Orion

  • No Google Ads data is shared with third parties, used for advertising purposes or cross-referenced with other users' data

  • The Google Ads integration can be disconnected at any time in Settings > Integrations > Google Ads > Disconnect


8. Integration with Google Calendar

Orion offers an optional Google Calendar integration to sync appointments and meetings within the CRM.

8.1 How the connection works

The Google Calendar integration uses Google's standard OAuth flow. You start the connection in Settings > Integrations > Google and authorise access on Google's own consent screen, where the requested permissions are displayed clearly before any confirmation. Orion never asks for your Google password.

8.2 Data accessed

Events, times, attendees and descriptions from the Google calendars you connect to Orion.

8.3 How we handle Google Calendar data

  • Orion can also create events on your behalf and add collaborators from your team as guests to those events, when you decide to include someone in that capacity. When that happens, the invited collaborator's email address is shared with Google, which sends them a native notification about the event. Orion does not share this data with third parties or use it for any purpose beyond the display you requested

  • Access tokens are stored encrypted and are never exposed to other users

8.4 Revoking access

You can disconnect your Google account from Orion at any time in Settings > Integrations > Google > Disconnect, or directly through your Google Account settings at myaccount.google.com/permissions.


9. Integration with Google Drive

Orion offers an optional Google Drive integration to access project files you have stored, within the platform's Documents module.

9.1 How the connection works

The Google Drive integration uses the same standard Google OAuth flow described in section 8.1. Access is read-only.

9.2 Data accessed

Name, type and content of Google Drive files and folders that you select within Orion's Documents module.

9.3 How we handle Google Drive data

Orion accesses these files exclusively for display within the platform. Orion never creates, edits, moves or deletes files or folders in your Google Drive. We do not keep a permanent copy of the content of these files outside Google; access happens on demand, when you view the file within Orion. No Drive data is shared with third parties or used for any purpose beyond the display you requested.

9.4 Revoking access

You can disconnect your Google account from Orion at any time in Settings > Integrations > Google > Disconnect, or directly through your Google Account settings at myaccount.google.com/permissions.


10. Use of Artificial Intelligence

Orion uses artificial intelligence models in specific platform features, such as reply suggestions in WhatsApp conversations and caption generation for social media posts. This processing is carried out through third-party infrastructure (Lovable AI Gateway, which may use language models from different providers).

No data obtained through the Google Calendar, Google Drive or Google Ads integrations is processed, stored or used to train artificial intelligence models, whether our own or third parties'. The use of raw or derived data received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.


11. Your rights (LGPD)

You have the right to:

  • Access the data we hold about you

  • Correct incorrect or outdated information

  • Request the deletion of your personal data

  • Port your data in a structured format

  • Withdraw consent for marketing communications at any time

  • Request information about data sharing

To exercise any of these rights, contact us at: privacidade@adventurecreative.com.br

To request the deletion of your data, see the Data deletion page, which explains what to include in the request, what is deleted, and how long it takes.


12. Cookies

We use cookies to:

  • Keep your session active on the platform

  • Analyse browsing behaviour on the website (Google Analytics)

  • Improve the user experience

You can configure your browser to refuse cookies, but this may affect some platform features.


13. Marketing communications

When you sign up, you may choose to receive emails with news, tips and updates about Orion. You can cancel these communications at any time by clicking "unsubscribe" in the footer of any email or by contacting us.


14. Minors

Orion CRM is intended for companies and professionals over the age of 18. We do not knowingly collect data from minors.


15. Changes to this policy

We may update this Privacy Policy from time to time. When there are relevant changes, we will notify you by email or by a notice on the platform. The update date at the top of the document will always reflect the most recent version.


16. Contact

Adventure Creative — Developer of Orion CRM Email: privacidade@adventurecreative.com.br Address: Araguari, MG — Brazil CNPJ: 42.801.643/0001-84.