Приложение о местоположении и мобильности (Speed, SonhoLab Tiendas, Restaurant System)

    Предварительная версия на юридической проверке

    Версия 0.9.0

    Этот документ еще не переведен на русский язык. Он показан на английском; до появления перевода обязательную силу имеет английский текст.

    Table of contents

    1. Scope and roles
    2. Definitions
    3. Location data
    4. Notice to Riders and End Customers
    5. Other data
    6. Rider documents and account decisions
    7. Payments
    8. Retention
    9. Law enforcement and other requests
    10. Prohibited uses
    11. Business obligations
    12. Country rules
    13. No transport, delivery or employment relationship
    14. SonhoLab commitments

    1. Scope and roles

    1.1 This Addendum applies to:

    • (a) Speed, the ride-hailing System, including its web panel;
    • (b) the delivery features of SonhoLab Tiendas (online stores);
    • (c) the delivery features of Restaurant System; and
    • (d) the SonhoLab mobile apps used with these Systems, for End Customers, Riders or drivers. Speed has two apps: one for passengers and one for drivers. SonhoLab Tiendas has three: one for customers, one for sellers and one for riders. Restaurant System may use one app with separate screens for each role, or separate apps. In this Addendum, "the app" means whichever of these apps is used.

    1.2 It supplements the Terms of Service, the Data Processing Addendum (DPA) and the Acceptable Use Policy. For the data described here, this Addendum prevails over them if they conflict. The Brazil Supplement (LGPD, CDC, Marco Civil, ECA Digital), the EEA and UK Supplement, the United States Supplement and the Latin America Supplement also apply.

    1.3 The Business is the controller of the personal data of its End Customers, its Riders and its staff processed in these Systems. It decides why and how that data is processed.

    1.4 SonhoLab is the processor ("operador", "processor", "service provider"). It processes that data only on the Business's documented instructions (LGPD Art. 39; GDPR Art. 28), under the DPA.

    1.5 SonhoLab is the controller only for the Business's own account and billing data, under the Privacy Policy.

    2. Definitions

    • Business: the organization that uses Speed, SonhoLab Tiendas or Restaurant System to offer trips, sales or deliveries to the public, such as a fleet operator, a store or a restaurant. It is the "Customer" of SonhoLab under the DPA.
    • End Customer: a person who places an order or requests a trip from the Business.
    • Rider: a person who carries out a delivery or a trip for the Business, as a driver, motorcyclist, cyclist or courier. In Speed, Riders are the drivers.
    • Active Delivery: the period from the moment a Rider accepts a delivery or trip in the app until the delivery or trip is completed or cancelled.
    • Online: for a Rider in Speed, the period from the moment the Rider sets the status to available in the app, to wait for trip offers or carry out trips, until the Rider goes Offline. A Rider goes Offline by switching that status off or logging out, or automatically after a period without location updates.
    • Precise Location: data from the device's location services (for example, GPS coordinates) that places a person within a small radius.
    • Location Trail: the series of Precise Location points recorded during an Active Delivery. In Speed, it is the route of the trip.
    • Emergency Contact: a person whose name and phone number a passenger in Speed registers in the app to receive SOS alerts (section 3.7).

    3. Location data

    3.1 Riders.

    • (a) SonhoLab Tiendas: only during an Active Delivery. In SonhoLab Tiendas, the rider app collects a Rider's Precise Location, if at all, only during an Active Delivery and only while the app is in use. It never collects it in the background, and it does not collect it when no delivery is active, including when the Rider is signed in and waiting for work, has finished the delivery, or has closed the app. There is no background tracking and no live tracking: End Customers do not see the Rider's position on a map.
    • (b) Restaurant System: only while a delivery is on the way and the app is open. In Restaurant System, the app collects a Rider's Precise Location only while a delivery assigned to the Rider has the status "On the way" and the app is open in the foreground, and sends it about every 15 seconds. It never collects it in the background, when no delivery is on the way, or when the app is closed, and it uses no foreground service. The server stores at most one position every 10 seconds.
    • (c) Speed: only while Online. The app collects a Speed Rider's Precise Location only while the Rider is Online: while waiting for trip offers and during trips. It updates the position about every 20 seconds while the Rider waits and about every 5 seconds during a trip. It never collects it while the Rider is Offline. The last position is deleted when the Rider goes Offline (manually, by logging out or automatically after a period without updates) and when the Rider logs in again. The server rejects positions sent by an Offline Rider. The System keeps a single current position for each Online Rider, with no history of the positions recorded while waiting. During a trip, the app records the Location Trail of the trip.

    3.2 Screen off or app in the background. In Speed (while the Rider is Online), if the app needs to keep sharing the Rider's location while the screen is off or the app is in the background, it first shows a clear in-app notice that explains what is collected, why and when it stops, and then asks for the permission the phone's operating system requires. It does this only through a foreground service that shows a visible notification on the phone for as long as location is shared. The Rider can refuse or withdraw the permission in the phone settings. Some features may then not work. SonhoLab Tiendas and Restaurant System do not use background location: the SonhoLab Tiendas rider app does not ask for location access "all the time" and uses location only while the app is in use, and Restaurant System does not use a foreground service.

    3.3 End Customers. The app uses an End Customer's device location only if the End Customer allows it, to suggest a pickup or delivery address. In SonhoLab Tiendas, it does so only while the End Customer is using the app. In Restaurant System, it does so only when the End Customer taps the option to use their location. The End Customer can always type the address instead. The address the End Customer gives is used for the trip or delivery. In Speed, the SOS alert is prepared and sent from the passenger's own device (section 3.7).

    3.4 Who sees what. During an Active Delivery:

    • the End Customer sees the progress of the delivery or trip and, in Speed and Restaurant System, the Rider's position on a map (in Restaurant System, only while the End Customer's order has the status "On the way"); in SonhoLab Tiendas, the End Customer does not see the Rider's position;
    • the Rider sees the pickup point and the delivery or drop-off address;
    • the Business's authorized staff see the progress of its own deliveries and trips.

    When the delivery or trip ends, the End Customer no longer sees the Rider's position. No one else sees it.

    In Speed, the Rider's live position during the trip (coordinates, heading and time) reaches the passenger app through Google Firebase Realtime Database (Google LLC, United States). When the trip ends, that position and the other data of the trip kept there, including the trip chat, are deleted from Firebase Realtime Database.

    In Restaurant System, real-time order updates run on SonhoLab's own servers; no third-party real-time service is used.

    The Speed passenger app can also show the progress of the trip on the phone's lock screen. This is done on the device and sends no data to third parties.

    3.5 Purposes. Precise Location and the Location Trail are used only to:

    • assign, guide and complete the delivery or trip;
    • in Speed, send trip offers to Online Riders;
    • show its progress to the End Customer and the Business;
    • estimate arrival times, distances and fares;
    • handle complaints, disputes, fraud and incidents about that delivery or trip; and
    • meet the Business's legal obligations.

    3.6 Maps.

    • (a) Speed. The Speed apps do not use Google Maps. They show maps with OpenStreetMap map tiles (tile.openstreetmap.org, run by the OpenStreetMap Foundation). The map tile servers receive the device's IP address and the map area being viewed, which can reveal an approximate location. Only SonhoLab's servers use Google LLC (Google Maps Platform, United States) as a subprocessor for Speed: the Distance Matrix, Directions, Geocoding and Places services to calculate quotes and trip offers and search addresses, and the Static Maps service to create the trip map image. For that, Google receives the coordinates, addresses and search text that each request needs.
    • (b) SonhoLab Tiendas. SonhoLab Tiendas also uses Google Maps Platform as a subprocessor. Its apps show maps with the Google Maps SDK, and SonhoLab's servers use the Places, Geocoding and Distance Matrix services to search addresses and calculate distances. For that, Google receives the coordinates, addresses and search text that each request needs.
    • (c) Restaurant System. Restaurant System does not use Google Maps or other Google map services. The app and the web pages show maps with OpenStreetMap map tiles (run by the OpenStreetMap Foundation) and a pin on the map; Restaurant System uses the OpenStreetMap Foundation only for map tiles. The map tile servers receive the device's IP address and the map area being viewed, which can reveal an approximate location. The "Navigate" button opens the navigation app the Rider chooses, such as Google Maps or Waze. Opening it is the Rider's own action, that app is governed by its provider's own terms, and the Restaurant System app does not include maps software from those providers.

    SonhoLab lists every provider that receives location data from these Systems in Subprocessors and International Transfers before that provider is used.

    3.7 SOS button in Speed.

    • (a) Emergency Contacts. A passenger can register Emergency Contacts in the Speed passenger app, with their name and phone number. The passenger may add only people who agree and, before adding them, must confirm in the app that they have told them; the System records the date and time of that confirmation. A contact can ask the passenger or the Business to be removed, and the Business removes them.
    • (b) What happens when the passenger taps SOS. The app prepares an SMS or WhatsApp message for the passenger's Emergency Contacts, and the passenger sends it from their own phone or WhatsApp account. SonhoLab's servers do not send the alert.
    • (c) What is stored. SonhoLab does not store the alert. Only the list of Emergency Contacts (name and phone number) and the date and time of the passenger's confirmation are stored.
    • (d) Legal basis. The Business, as controller, processes the Emergency Contacts' data to protect the life and physical safety of the passenger: in Brazil, LGPD Art. 7 VII and, where the GDPR applies, GDPR Art. 6(1)(d). In Colombia, Peru and Mexico, the Business relies on the equivalent basis in local law for emergencies or for protecting a person's life or health, where it applies, and otherwise on the contact's consent, obtained through the passenger.
    • (e) Not an emergency service. SOS does not call the police, an ambulance or any other emergency service. In an emergency, call the local emergency number, for example 190 or 192 in Brazil, 123 in Colombia, 105 or 116 in Peru and 911 in Mexico.

    4. Notice to Riders and End Customers

    4.1 Prior notice to Riders. Before a Rider starts using the app, the Business must tell the Rider in writing, in a language the Rider understands:

    • that location is collected only as described in section 3.1 (during Active Deliveries or, in Speed, while the Rider is Online), and what the End Customer and the Business can see;
    • the purposes in section 3.5 and the retention periods in section 8;
    • which signals the Business uses to assign work or to decide on the Rider's access, if any (section 6); and
    • how to exercise data protection rights and whom to contact.

    4.2 Notice to End Customers. The Business must give End Customers a privacy notice that identifies the Business as responsible for their data, gives its privacy contact and explains how the delivery or trip uses location.

    4.3 The Business's identity. The Business must keep its name and a privacy contact visible to End Customers in its ordering, store or trip pages, and keep them accurate. In Restaurant System, the legal name and privacy email that the Business enters are shown to End Customers at checkout, in the order confirmation and details, and on the PDF invoice.

    5. Other data

    5.1 End Customers: name, phone, email, delivery or pickup addresses, orders or trip history, amounts and payment status, notes they add to an order, messages with the Business and support history. In Speed, passengers may also register Emergency Contacts (section 3.7) and save a "home" and a "work" place, and the System keeps the passenger's last position.

    5.2 Riders: name, phone, email, the documents and vehicle details the Business asks for (section 6), assigned deliveries or trips, delivery or trip history and the records the Business keeps of amounts due to the Rider. In Restaurant System, the Business may also store a photo of the Rider.

    5.3 Push notifications. In Speed and SonhoLab Tiendas, the app sends notifications about orders, deliveries and trips through Google Firebase Cloud Messaging and, for that, registers a notification token for the device. Restaurant System does not use Firebase Cloud Messaging: it sends web push notifications, under the Web Push standard, with the instance's own keys (VAPID), only to users who allow them. Each notification is delivered through the push service of the user's own browser (for example, Google, Mozilla or Apple), a service run by the vendor of the browser the user has chosen. The content of the notification is encrypted end to end, so that push service cannot read it. Users can turn notifications off in the phone or browser settings.

    5.4 Notes that reveal health data. An End Customer may write in an order note information that reveals health data, such as a food allergy. The Business must not require it and must use it only to prepare and deliver that order.

    5.5 Phone number verification in Speed. To sign in to Speed, the user's phone number is verified with a one-time code through Google Firebase Authentication (Google LLC, United States). For that, Google receives the phone number.

    6. Rider documents and account decisions

    6.1 Checks. The Business decides which documents and checks Riders must provide, such as a driver's licence, vehicle registration or insurance. The Business is responsible for the legal basis and notice for each check and for any licensing or background-check law that applies.

    6.2 Use of documents. Rider documents are used only for onboarding, verification and legal compliance. Only the Business's authorized staff can access them.

    6.3 Human review. The Business must not deactivate, suspend or penalize a Rider on the basis of ratings, location data or other automated signals alone. It must provide human review and a way to contest the decision (LGPD Art. 20; GDPR Art. 22 where it applies).

    6.4 No emotion monitoring. These Systems do not process the emotional or psychological state of Riders.

    7. Payments

    7.1 SonhoLab does not handle funds. SonhoLab does not collect, receive, hold, transfer or release any money paid by End Customers or owed to Riders. It is not the merchant of record and it is not a payment institution or payment arrangement operator under Brazilian Lei 12.865/2013.

    7.2 Payment methods. End Customers pay the Business directly, using the methods the Business offers: for example, cash, a bank transfer or Pix to the account the Business shows, or the Business's own payment gateway account. A payment gateway the Business connects is the Business's own vendor under its own contract, not a SonhoLab subprocessor.

    7.3 Balances. Any balance, earnings or amount due shown in the app is a record kept for the Business. The Business alone is responsible for paying its Riders and for fares, prices, fees, invoices, taxes and refunds.

    8. Retention

    8.1 The Business decides how long data is kept and must set periods that match its purposes and legal duties.

    8.2 Defaults. Unless the Business sets a shorter period, or a longer one where the law requires it:

    • Location Trail of each delivery in SonhoLab Tiendas and Restaurant System: deleted 90 days after the delivery ends;
    • Speed trips: the Location Trail (trip route) and the trip map image are deleted 90 days after the trip ends; after those 90 days, the pickup and destination coordinates are deleted and only the address text is kept; the trip record (date, addresses as text, fare and invoice data) is kept for the tax retention period set for the Business in the System, by default 5 years in Brazil, and then deleted. The reduction of coordinates and the deletion at the end of the tax period apply only to closed trips: a trip with a pending payment is kept until the payment is settled;
    • live position of a Speed trip in Firebase Realtime Database: deleted when the trip ends;
    • current position of a Speed Rider: kept only while the Rider is Online and deleted when the Rider goes Offline, logs out or logs in again;
    • saved places of a Speed passenger: the passenger's last position is deleted when each trip ends and, at the latest, 90 days after it was recorded; the "home" and "work" places are kept until the passenger deletes them or deletes their account;
    • last position of a Restaurant System Rider: cleared after 24 hours if the Rider has no delivery in progress;
    • app access tokens in Restaurant System: expire after 180 days for End Customers and after 30 days for staff and Riders; expired tokens are deleted every day;
    • Emergency Contacts in Speed: kept until they are removed from the list. SOS alerts are not stored;
    • summaries of deliveries in SonhoLab Tiendas and Restaurant System (start and end points, time, amount): as the Business instructs for its tax and legal records;
    • Rider data and documents: in SonhoLab Tiendas, documents are kept while the Rider is active and deleted 12 months after the Rider becomes inactive; in Restaurant System, the Rider's personal data and photo are anonymized 12 months after the Rider is deactivated, and past orders stay linked to the anonymized record; in Speed, documents are deleted 12 months after the Rider's last activity or deactivation, whichever is later;
    • server access logs: 6 months (Marco Civil Art. 15), up to 12 months for security investigations.

    In Restaurant System and Speed, these deletions and anonymizations run automatically every day. These daily jobs do not edit database backups, logs or job queues: those are overwritten in their own cycle (daily database backups are kept for up to 14 days on the server, with an encrypted off-site copy).

    8.3 After the Business's contract ends, the data is available for export for 30 days and is then deleted from active systems. Deleted data disappears from backups as they expire, within 30 days at most.

    9. Law enforcement and other requests

    9.1 Requests from police, courts or other authorities for End Customer, Rider or location data go to the Business, as controller. If SonhoLab receives one, it follows Government and Law Enforcement Requests: it redirects the request to the Business where possible and tells the Business, unless the law forbids it.

    9.2 SonhoLab discloses data only when legally required, and only the minimum required.

    9.3 The Business must have its own process for these requests and for urgent safety requests.

    10. Prohibited uses

    The Business must not use these Systems or their data to:

    10.1 sell Precise Location or share it for advertising;

    10.2 target advertising or messages based on Precise Location, or set geofences around health care facilities to identify, track, message or advertise to people;

    10.3 track Riders or End Customers outside Active Deliveries (for Speed Riders, outside the time they are Online), or monitor Riders covertly;

    10.4 infer health, religion, sex life or other sensitive traits from location;

    10.5 discriminate against Riders or End Customers on protected grounds;

    10.6 use Emergency Contacts for any purpose other than SOS alerts.

    11. Business obligations

    The Business must:

    11.1 give the notices in section 4 and obtain consent where the law requires it (section 12);

    11.2 hold every licence, permit and insurance that its transport or delivery activity needs;

    11.3 accept only adults as Riders, and only people legally allowed to do the work;

    11.4 answer data subject requests. SonhoLab forwards the requests it receives without undue delay and helps;

    11.5 carry out any impact assessment the law requires. Location tracking of workers usually requires one (LGPD Art. 38; GDPR Art. 35). SonhoLab provides the information in the DPA to support it;

    11.6 set retention periods that fit its legal duties (section 8).

    12. Country rules

    12.1 Brazil. Precise Location is not in itself sensitive data under LGPD Art. 5 II, but it is high-risk. The Business chooses its legal basis, usually performance of the contract with the End Customer (LGPD Art. 7 V) and, for Riders, performance of the work or service contract (Art. 7 V) or legitimate interest with a documented assessment (Art. 7 IX and Art. 10). Riders and End Customers have the rights in LGPD Art. 18, including review of automated decisions (Art. 20).

    12.2 Colombia. Ley 1581 de 2012 requires prior, express and informed authorization from the data subject, with the exceptions that law provides. The Business obtains and keeps proof of it.

    12.3 Peru. Ley 29733 and its Reglamento (DS 016-2024-JUS) require consent unless an exception applies, such as data needed to perform a contract with the data subject. The Business registers its data banks where required.

    12.4 Mexico. The Ley Federal de Protección de Datos Personales en Posesión de los Particulares requires a privacy notice (aviso de privacidad) before collection, and consent where that law requires it.

    12.5 EEA. Where the GDPR applies, the Business chooses its legal basis, carries out a data protection impact assessment and applies the rules on automated decisions (GDPR Art. 22) and, where transposed, on algorithmic management of platform workers (Directive (EU) 2024/2831).

    12.6 United States. These Systems are not directed to people in the United States. Many US state laws treat precise geolocation (location within a radius of about 1,750 to 1,850 feet, depending on the state) as sensitive data that needs opt-in consent. A Business must not use these Systems to offer deliveries or trips in the United States without first agreeing it with SonhoLab in writing.

    13. No transport, delivery or employment relationship

    13.1 SonhoLab provides software. SonhoLab does not provide transport, delivery or food services. It is not a transport company, carrier or courier.

    13.2 SonhoLab does not employ, contract or direct Riders. Their relationship is with the Business. The Business alone decides how that relationship is classified and meets its labor, tax, social security and insurance duties.

    13.3 SonhoLab is not responsible for the conduct of Businesses, Riders or End Customers.

    14. SonhoLab commitments

    SonhoLab:

    14.1 processes data in these Systems only to provide them to the Business;

    14.2 does not sell location or other personal data and does not use it for advertising or for its own purposes;

    14.3 does not train AI models on this data;

    14.4 uses the subprocessors listed for these Systems in Subprocessors and International Transfers, such as Hetzner Online GmbH (hosting, Finland), Google Firebase Cloud Messaging for Speed and SonhoLab Tiendas (push notifications, United States), Google Firebase Authentication for Speed (phone number verification, United States), Google Firebase Realtime Database for Speed (live trip position during the trip, United States), Google Maps Platform for Speed (on SonhoLab's servers only) and SonhoLab Tiendas (maps, routes and address search, United States) and the OpenStreetMap Foundation for Restaurant System and Speed (map tiles only, United Kingdom / EU), and gives advance notice of new subprocessors under the DPA;

    14.5 applies the security measures in Security and Incident Response, and holds no security certification;

    14.6 notifies the Business of a personal data breach without undue delay, with a target of 48 hours and no later than 72 hours after confirming it.


    Version 0.9.0 (preliminary) · Effective 29 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    Предварительная версия на юридической проверке

    Версия 0.9.0

    Отпечаток SHA-256 этого текста: 04f86751fbe840e14d4227396138f1b5a0bd37b8e53d28e4dc2367f09dfa5d02

    Вернуться в Правовой центр