Privacy Policy
Your privacy matters to us. This policy explains what data we collect, how we use it and what rights you have over it.
1. What data we collect
From you as workshop owner: name, email, password (hashed), WhatsApp number, business name, country, optional tax data, workshop and machine data, payment configuration.
From your customers on the public quoter: uploaded file, contact data they enter when placing an order (name, email, phone, address), payment receipts.
Technical: IP address, browser, operating system, timezone. Only for diagnostics, anti-fraud and improving the service.
2. How we use your data
To operate the platform (auth, quoting, orders, payments), to send you operational notifications, to improve the service, to prevent fraud, and to comply with legal obligations.
3. Who we share with
Mercado Pago: to process subscriptions. Firebase (Google): for authentication, database and hosting. Resend / email provider: to send notifications. We do not sell your data to third parties under any circumstances.
4. Your rights
You can access, correct or delete your data at any time from your panel. You can also request data portability by writing to hola@nofacto.com.
5. Email notifications
We send emails for: account creation, successful or failed payments, received orders, limit alerts and critical service updates. You can disable non-essential notifications from your settings panel.
6. Cookies and local storage
We use cookies and localStorage to keep you signed in and store your preferences. We do not use advertising or cross-site tracking cookies.
7. Security
Passwords are hashed using Firebase Auth's standard algorithms. Communications are encrypted with HTTPS/TLS. Your customers' files are stored in Firebase Storage with per-workshop access rules.
8. Minors' data
Nofacto is not directed at minors under 18. If we discover a minor created an account, we will delete it.
9. Changes to this policy
If there are substantial changes we'll notify you by email. If they are only minor clarifications, we update this page.
10. Contact
To exercise your rights or resolve privacy questions, write to us at hola@nofacto.com.
Annex I — Habeas Data (Colombia)
Processing of your personal data is governed by Colombia's Statutory Law 1581 of 2012 and Regulatory Decree 1377 of 2013. As Data Subject you may exercise your rights to access, update, rectify, delete your data, and revoke consent by writing to hola@nofacto.com. Response time: 15 business days. Supervisory authority: Superintendence of Industry and Commerce (SIC) — www.sic.gov.co.