Gallo's work

Privacy Policy

Effective and version: 2026-08-11

1. Who we are

Gallo's work is operated by Richard Rodrigues Gallo, an individual based in Brazil, doing business as "Gallo's work" (galloswork.com). Richard is the controller of the personal data described in this Policy.

Contact for privacy matters: privacy@galloswork.com
General support: support@galloswork.com

2. Scope

This Policy covers the Gallo's work SaaS product only — the account, contract, and monitoring data described below. It does not cover your own n8n instance or the automations you monitor with Gallo's work; those remain entirely under your control and outside our systems, except for the specific metadata you choose to send us (Section 3).

3. What we collect

  • Account data: your name, email, and password (managed by our authentication provider), agency name, and billing plan.
  • Client and contract data: names you assign to your clients and monitored automations, the cadence and grace period you declare, and the email address you designate to receive alerts for each contract.
  • Monitoring event data: each time your workflow reports in (a "beat"), we record its status (success/failure), a timestamp, and up to three short optional text fields your workflow sends us (a message, a node name, a workflow name). We do not want, and ask you not to send, personal data, credentials, or secrets in these fields — see Section 5.
  • Reconciliation data: if you enable reconciliation, your own workflow reports counts (how many records were expected vs. landed) and, optionally, a list of identifiers for records that didn't land. These identifiers should be non-personal references (e.g. an internal record ID), never personal data — see Section 5.
  • Alert routing data: the email address and, if you configure it, the Slack webhook URL you want incident alerts sent to.
  • Billing data: we do not collect or store your payment card details. Checkout and billing are handled entirely by Stripe; we retain only your Stripe customer/subscription identifiers and status.
  • Session data: a small number of authentication cookies needed to keep you signed in. We do not use advertising, analytics, or tracking cookies.

4. Why we collect it

We process this data to provide the monitoring service you signed up for (performance of our contract with you) and, for account/billing data, to maintain and secure your account.

5. Your responsibility for what you send us

Gallo's work is designed to receive only operational metadata — status, timestamps, and short labels — never the records or data your workflow actually processes. However, the message, node name, workflow name, and reconciliation identifier fields are free text supplied by your own workflow configuration, and we do not inspect their content. You must not include personal data, sensitive personal data, credentials, access tokens, secrets, or any information you are not authorized to share in these fields. You are responsible for configuring your workflows accordingly. See Section 8 of our Terms of Service for the corresponding contractual obligation.

6. How long we keep it

We retain operational monitoring history for 12 months from when each record was created. After 12 months:

  • Status-update records keep only their status and timestamp — any message, node label, or workflow label attached to them is cleared.
  • An incident's recorded cause is cleared once the incident is at least 12 months old.
  • A reconciliation report's record identifiers are cleared once the report window is at least 12 months old.
  • A specific reconciliation gap's identifier is replaced with a fixed placeholder once that gap has been resolved for at least 12 months. A gap that is still open (not yet resolved) is not affected by this process regardless of age, since it remains information you may still need to act on.

This process is currently performed manually on a regular schedule — it is not yet fully automated. Account, client, and contract configuration data is kept for as long as your account is active, per Section 9.

7. Who we share it with

We use the following service providers to operate Gallo's work. Each processes data on our behalf, only as needed to provide the service:

  • Supabase — database hosting and authentication.
  • Vercel — application hosting.
  • Resend — sending incident alert emails.
  • Stripe — billing and payment processing.
  • Slack — only if you configure a Slack webhook, we send incident alerts to the Slack workspace you specify.

We do not sell your data, and we do not use it for advertising.

8. International data transfers

Our database is hosted by Supabase in São Paulo, Brazil. Our application infrastructure (Vercel) currently runs in the United States, and Resend, Stripe, and (when you configure it) Slack are US-based service providers. This means some processing of your data occurs outside Brazil. We do not claim that all data remains in Brazil.

9. Data retention on account closure

When you close your account, we deactivate your contracts and, on request, anonymize or delete your account and monitoring data as described in Section 10. Some records may be retained where necessary for legal, tax, or billing purposes (e.g. Stripe transaction records, which Stripe itself retains under its own obligations).

10. Your rights

Depending on applicable law, you may have the right to request access to, correction of, anonymization of, or deletion of your personal data, and to ask how it has been processed. To exercise any of these, email privacy@galloswork.com. We currently handle these requests manually. We will respond consistent with obligations under applicable law, including the Brazilian General Data Protection Law (LGPD).

11. Cookies

We use only the cookies strictly necessary to keep you signed in. We do not use analytics, advertising, or tracking cookies.

12. Children's privacy

Gallo's work is a business-to-business service intended for use by agency owners and professionals, not by children. We do not knowingly collect data from children.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected in a new effective date and version, and we may ask you to re-accept the updated Policy.

14. Contact

Richard Rodrigues Gallo, operating as Gallo's work.
Privacy: privacy@galloswork.com · Support: support@galloswork.com

See also our Terms of Service.