Ponte11

Privacy Policy

Effective since / last updated: August 9, 2026
Data controller: FORTGEST LLC (hereinafter, "FORTGEST" or "we")
Postal address: 30 N Gould St Ste N, Sheridan, WY 82801, United States
Privacy contact: info@fortgest.com

This Policy explains how we process personal data when you use the Ponte11 mobile application, its public pages, and related services (collectively, the "Service"). Ponte11 lets you discover nearby merchants and coupons, follow merchants, and claim or redeem coupons.

This Policy applies without prejudice to the mandatory rights granted to you by the law of your place of residence. If a local rule grants greater protection, we will apply that protection.

1. Who is responsible for your data

FORTGEST decides for what and how the personal data described in this Policy are processed and acts as the data controller.

You may send inquiries, rights requests, or complaints to info@fortgest.com, with the subject "Privacy — Ponte11". We do not state that we have appointed a data protection officer or a regional representative unless their details are expressly published in an update to this Policy.

2. Personal data we process

Depending on the features you use and the permissions you grant, we may process:

Ponte11 does not process payments or card data within the application. The evaluated version of the Service also does not request access to contacts, microphone, health data, or biometrics to identify you, and does not sell data or use behavioral advertising SDKs. If we incorporate new categories or purposes, we will update this Policy and the in-app notices before starting the processing when the law so requires.

3. Where we obtain the data

We obtain data directly from you, from your device, and from your use of the Service. We also receive data from Google or Apple when you choose to sign in with those providers, and from participating merchants when an interaction or redemption must be associated with their establishment.

4. What we use the data for and the legal basis

The exact legal basis depends on your jurisdiction. When laws such as the GDPR, the UK GDPR, or equivalent rules require it to be identified, we rely on the following:

Purpose Main data Legal basis
Create, authenticate, and administer your account Account, credentials, and external sign-in Performance of the contract or pre-contractual measures
Show nearby merchants and coupons Location and preferences Your consent to access location; performance of the requested service
Claim and validate redemptions Account, coupon, merchant, date, and location when necessary Performance of the contract; legitimate interest in verifying redemption
Save preferences, followed merchants, and functional history Account, activity, and preferences Performance of the contract
Send operational alerts and optional notifications Account, token, and preferences Performance of the contract for essential alerts; consent for optional or promotional notifications
Protect the Service and prevent fraud, abuse, or unauthorized access Account, device, logs, activity, and event-related location Legitimate interest in security, subject to balancing of rights; legal obligation where applicable
Handle support, rights, and complaints Account, contact, and request content Performance of the contract, legal obligation, and legitimate interest in managing and evidencing the response
Comply with valid orders and regulatory obligations Data required in each case Legal obligation or defense of rights
Maintain and improve stability and performance Minimized or aggregated technical and usage data Legitimate interest in operating and improving the Service

Where processing is based on your consent, you may withdraw it at any time from Ponte11 settings or the device, or by writing to us. Withdrawal does not affect the lawfulness of prior processing. Refusing to provide optional data does not prevent you from using features that do not need it; without location, notifications, or certain account data, some features may not be available.

We may convert data into aggregated or anonymized statistics that do not allow a person to be reasonably identified. We use that information to measure the operation, security, and general use of the Service. We will not attempt to re-identify anonymized data, except to verify that the anonymization process works or when the law permits.

5. Device permissions

6. Providers and other disclosures

We do not sell or rent personal data and do not share it for cross-context behavioral advertising. We may disclose the minimum necessary data to:

Providers act as processors or as independent controllers depending on the function they perform. Their services may also be subject to their own privacy policies.

When you choose to communicate directly with a merchant, visit its website, use its services outside Ponte11, or provide it additional information, that merchant may process the data as an independent controller under its own policy. Ponte11 does not control that independent processing.

7. International transfers

FORTGEST is established in the United States and some providers operate globally. As a result, data may be processed in countries other than the one where you reside, whose laws may offer different levels of protection.

When an international transfer requires safeguards, we use the legal mechanism that corresponds to the specific flow, such as adequacy decisions, approved contractual clauses, UK addenda, binding corporate rules, or another permitted exception. We also apply proportionate contractual, technical, and organizational measures. You may request information about the applicable mechanism and a copy of the safeguards, subject to redaction of confidential information, by writing to info@fortgest.com.

8. Retention and deletion

We do not retain personal data longer than necessary. We apply these periods or criteria:

Data Period or criterion
Account, profile, and preferences While the account is active; afterward, during the deletion process described below
Notification token While associated with an active installation or account, until replaced, no longer valid, or the account is deleted
Location and functional activity Only for the time needed to provide the feature, record the redemption, or resolve incidents; thereafter deleted, aggregated, or unlinked when no longer needed
Security, fraud, and operation logs The minimum period reasonably necessary for security, incident investigation, and defense of claims, applying restricted access and periodic rotation
Support and rights requests While the request is handled and afterward for the period necessary to evidence its handling and comply with legal obligations
Backups Until their secure rotation according to the applicable technical cycle; they remain isolated and are not restored for ordinary use

We may retain minimal information when a law requires it or when necessary to prevent fraud, resolve disputes, or exercise and defend claims. In those cases we block or restrict it, do not use it for other purposes, and delete or anonymize it when the obligation ends.

9. How to delete your account

You can initiate deletion:

The account enters a recovery period of up to 30 days. During that period it is deactivated and not used to provide the Service, unless you decide to reactivate it. At the end, we permanently delete the account and request providers to delete the associated data, except for the minimal information we must retain for the reasons indicated in section 8. Deleting the application from the device is not equivalent to deleting the account.

10. Your rights and how to exercise them

Depending on where you reside, you may have the right to:

Send your request to info@fortgest.com. State the right you wish to exercise and the email associated with your account. We will verify your identity proportionately and may ask for additional information; we will never ask for your password. You may also act through an authorized representative where the law permits.

We will handle the request free of charge and within the applicable legal period. We may refuse or charge a reasonable cost only where the law permits, for example in the case of manifestly unfounded, excessive, or unverifiable requests, explaining our decision and the available remedies.

11. Regional information

European Economic Area, United Kingdom, and Switzerland

You may exercise access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. When we rely on a legitimate interest, you may request information about our balancing analysis. You may also lodge a complaint with the authority of your residence, place of work, or the alleged infringement. If the law requires appointing a representative or officer, we will publish their details before offering the Service in the corresponding territory.

California and other states of the United States

In the past 12 months we may have collected the categories described in section 2: identifiers; account and commercial activity information; internet or application activity; precise geolocation; technical information; and basic inferences about preferences. The sources, purposes, and recipients are described in sections 3, 4, and 6.

We do not sell personal information or share it for cross-context behavioral advertising, including information of minors that we become aware of. We use precise location solely to provide the requested features, security, and fraud prevention. Where applicable state law recognizes it, you may request access/knowledge, correction, deletion, portability, limitation of sensitive data, and opt-out of sale, targeted advertising, or profiling, and appeal a denial. Since we do not currently engage in sale, targeted advertising, or sharing for cross-context advertising, no opt-out needs to be activated for those practices.

Brazil

Persons protected by the Lei Geral de Proteção de Dados (LGPD) may request confirmation and access, correction, anonymization, blocking, or deletion in the legal cases, portability, information about sharing, revocation of consent, and review of automated decisions. They may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

Ecuador and other Latin American countries

Persons protected by the Ley Orgánica de Protección de Datos Personales of Ecuador may exercise, as applicable, information, access, rectification and updating, deletion, objection, portability, suspension, and rights in relation to automated decisions, and may lodge a complaint with the Superintendencia de Protección de Datos Personales. In other countries we will apply the mandatory rights and procedures of local legislation.

12. Automated decisions

Ponte11 may apply automatic rules of proximity, availability, and detection of unusual patterns to show content, validate redemptions, and flag potential abuse. We do not make decisions exclusively by automated means that produce legal or similarly significant effects on you. If you believe a measure was applied incorrectly, you may request human review through the contact channel.

13. Security

We apply reasonable and proportionate technical and organizational measures, including encryption in transit via HTTPS/TLS, access controls, minimization, credential management, and storage of session tokens using the operating system's secure mechanisms, such as Keychain or Keystore. No system is completely secure; notify us of any suspected unauthorized access and use a unique, strong password.

We maintain procedures to assess and respond to incidents. If a personal data breach poses a risk that must be notified, we will inform the competent authority and the affected individuals within the deadlines and with the content required by applicable law.

14. Minors

Ponte11 is a general-audience service intended exclusively for persons who have reached the age of majority in their place of residence. We do not knowingly collect data from minors. If we learn that a minor created an account, we will take reasonable steps to close it and delete their data, except for legally required retention. Parents or guardians may contact info@fortgest.com.

15. Websites, cookies, and external links

The mobile application does not use browser cookies or behavioral advertising SDKs. Ponte11's public web pages may generate standard technical logs — such as IP address, date, browser, and requests — through the hosting provider for security and availability. If in the future we use non-essential cookies, we will offer the required notice and consent options.

The Service may contain links or content from merchants and third parties. We do not control their independent practices; review their policies before providing them data.

16. Changes to this Policy

We may update this Policy to reflect operational, legal, or technological changes. We will publish the current version with its date and, when the change is substantial or the law so requires, we will communicate it within the application or by another appropriate means and request new consent where applicable.

17. Contact and complaints

For privacy-related questions or requests:

FORTGEST LLC

30 N Gould St Ste N, Sheridan, WY 82801, United States

info@fortgest.com

Recommended subject: "Privacy — Ponte11"

We will try to resolve your concern directly. You may also lodge a complaint with the competent data protection authority in your place of residence.