Privacy Notice of Cuanto
Last updated: May 20, 2025
1. Introduction
This Privacy Notice describes how Cuanto AI Inc. (hereinafter, "Cuanto", "we" or the "Company"), with address at 251 Little Falls Drive, Wilmington, New Castle County, DE, 18909, USA, collects, uses, retains and shares Personal Data of users of the mobile application, browser extension and/or website (collectively, the "Platform").
2. Personal Data We Process
| Category | Examples | Collection Moment |
|---|---|---|
| Identification | name, last name, email, mobile phone, CURP | Account registration |
| Financial | Bank account number, masked card number, purchase history | Bank linking, reward crediting |
| Receipts | images of tickets, electronic invoices (XML) | Manual cashback claim |
| Usage and device | approximate location (GPS or IP), logs, device type, cookies/SDK | Platform navigation and use |
| Conversation | messages to support, in-app chats | Support interactions |
3. Processing Purposes and Legal Basis
| Purpose | Legal Basis |
|---|---|
| Operate the cashback program, issue rewards and prevent fraud | Contract execution |
| Customer service and technical support | Contract execution |
| Direct marketing, referral programs and analytics | Data subject consent |
| Compliance with legal obligations (e.g. tax, money laundering prevention) | Legal obligation |
| Continuous improvement of the Platform (optimization, bug detection) | Legitimate interest |
4. Transfers and Processors
We may share your Personal Data with: (i) payment processors and SPEI, (ii) banks and open-banking providers, (iii) affiliate platforms and partner merchants, (iv) cloud hosting providers located in the United States, (v) competent authorities when required by law.
5. Retention
We will retain Personal Data only for the time necessary to fulfill the purposes described or the terms provided by tax and fraud prevention legislation (usually 5 years for transaction receipts).
6. Security Measures
We apply TLS 1.3 encryption in transit and AES-256 at rest, role-based access control (RBAC) and periodic audits. All providers sign confidentiality and compliance clauses.
7. ARCO Rights and Procedure
You may exercise your rights of Access, Rectification, Cancellation or Opposition (ARCO), as well as revoke your consent, by sending an email to rafa@getcuanto.com.
Our Privacy Officer will respond within a maximum period of 20 business days.
8. Minors
The Platform is not directed to minors under 18 years of age. We do not intentionally collect data from minors; if a parent or guardian detects improper registration, they may request the corresponding cancellation.
9. Changes to this Notice
Any modification will be published on the Platform and notified via push or email with at least 5 calendar days notice.
10. Contact
Privacy Officer: Rafael Rubio Canton
Email: rafa@getcuanto.com