Privacy Policy

How we handle your data.

This Policy describes how the Mining Ops platform collects, uses, shares and protects personal data of operators, supervisors and administrators using the Command Center (web) and Glass Cockpit (tablet). Written under the Brazilian General Data Protection Law (LGPD - Law 13.709/2018).

Last updated: May 27, 2026Version: 1.0

01About this Policy

This Privacy Policy applies to all products in the Mining Ops platform: the Command Center web app (used by dispatchers and supervisors), the Glass Cockpit tablet app (used by equipment operators in the cabin), the backend Edge Functions, and the landing page itself (mining-ops.com.br).

It documents what we collect, why we collect, with whom we share, how long we retain, and the rights you, as a data subject, have under the LGPD.

Material updates are communicated through in-platform notices and via email to the administrators of customer companies.

02Who we are

Data controller

  • Legal name: Blue Horizons LTDA
  • CNPJ (Brazilian tax ID): 54.200.672/0001-70
  • Address: Rua São Mateus, 396, room 101 — Sagrada Família, Belo Horizonte/MG, Brazil — postal code 31035-330

Data Protection Officer (DPO)

  • Contact: privacidade@miningops.com.br
  • Response time for data subject requests: up to 15 business days (LGPD Art. 19).

Customer companies (mining operators that license the platform) act as controllers of their own employees' data. Mining Ops acts as a processor under LGPD Art. 5, VII, processing data solely under the customer's contractual instructions.

03Data we collect

We collect only the data needed to operate the platform. The inventory below lists, by category, exactly what is stored.

3.1 Identification and profile

Identification data

User typeData collected
Operators (employees table)Name, badge number, email, phone, photo, date of birth, hire date, role, department, status (active/inactive).
Administrators (users table)Name, email, phone, avatar, associated company.

3.2 Authentication

  • Operator PIN - stored only as a bcrypt hash; never in plaintext.
  • Administrator password - managed by Supabase Auth (one-way hash).
  • Device hardware ID (Android ID or iOS identifierForVendor) - used to bind a specific tablet to a specific piece of equipment.
  • Device binding audit history (which tablet was paired with which equipment, by whom, and when).

3.3 Location (sensitive category)

  • Real-time GPS coordinates: latitude, longitude, altitude, speed and heading, captured roughly every 10 seconds.
  • Collection occurs only during the work journey recorded in Glass Cockpit (from operator login to logout/shift end).
  • Full journey trails, stored as encoded polylines.
  • Geofence entry/exit events configured by the customer.

Purpose: operational safety (tracking heavy equipment at risk), cycle-time monitoring, dynamic task dispatch, and operational reporting to the end customer.

3.4 Operational metrics

  • Equipment hour meter and odometer.
  • Duration of work journeys.
  • Task assignment, acceptance and rejection (including free-form reason when the operator rejects a task).
  • Minute-by-minute activity-code timeline (activity_logs table).
  • Execution timeline of task segments.

3.5 Media

  • Pre-operation checklist photos (up to 5 per item), compressed to WebP and stored in Supabase Storage region sa-east-1 (Sao Paulo).
  • User avatars uploaded by the data subjects themselves.

3.6 Audit

  • History of who assigned, forced or closed tasks, with timestamps.
  • Messages sent from the dispatcher to the operator (notifications table).

04What we use the data for

Each data category is processed for the specific purposes listed below. We do not repurpose data without prior notice.

CategoryPurpose
Identification and profileUser onboarding, display of name in the app, company binding, operational communication.
AuthenticationVerify identity at login, protect access to the system, bind tablet to equipment.
GPS locationOperational safety, task dispatch, cycle-time calculation, reporting to the customer.
Operational metricsProduction, productivity KPIs, bottleneck detection, operation optimization.
Media (checklist photos)Proof of pre-operation inspection, evidence in case of incident, audit.
AuditTraceability of operational decisions, incident investigation, compliance.

06Who we share with

We do not sell personal data. We share only with sub-processors strictly necessary for platform operation, listed below.

Sub-processorPurposeCountryPolicy
SupabasePostgreSQL database, authentication, media storage, realtime.Brazil (region sa-east-1)supabase.com/privacy
VercelHosting for the landing page and the Command Center.United Statesvercel.com/legal/privacy-policy
MapboxReal-time map rendering in Command Center.United Statesmapbox.com/legal/privacy
Google PlayDistribution of Glass Cockpit (Android).United Statespolicies.google.com/privacy

We also share data with the customer company itself - it acts as the controller of its employees' data and has access to the admin panel.

07International data transfers

Some sub-processors (Vercel, Mapbox and Google Play) process data on servers located in the United States. This transfer is grounded on LGPD Art. 33, II (transfer necessary for the performance of a contract with the data subject).

As an additional safeguard, sensitive data (including GPS trails, checklist photos and audit logs) is stored primarily in Supabase region Sao Paulo (sa-east-1). Routing through foreign services is limited to map tiling (Mapbox), asset delivery (Vercel CDN), and app distribution (Google Play).

08How long we store

We currently follow these general principles:

  • Active operational data (journeys, tasks, metrics) is retained while the contract with the customer company is active.
  • Audit data is retained for the legal period applicable to each category - including, where relevant, Brazilian labor and social-security statute-of-limitation periods.
  • Upon contract termination with the customer, personal data is deleted or anonymized per the contractually agreed schedule.
  • Data subjects may request earlier deletion under LGPD Art. 18, VI, subject to the exceptions of Art. 16.

09How we protect the data

Technical and organizational measures in place to protect the data:

  • Per-company isolation (multi-tenancy) - each customer's data is logically segregated via PostgreSQL Row Level Security (RLS).
  • Operator PIN stored only as a bcrypt hash - never in plaintext.
  • Administrator passwords handled by Supabase Auth with a one-way hash.
  • Data in transit always over TLS 1.2 or higher (HTTPS).
  • JWT-based authentication (JSON Web Tokens) with short expiry.
  • Automatic audit of critical operations (task assignment/force, equipment changes).
  • Production data access restricted to authorized engineers, logged.
  • Periodic backups with encryption at rest.

Despite these measures, no system is fully immune. In the event of a security incident with relevant risk to data subjects, we will notify the ANPD and the affected individuals as required by LGPD Art. 48.

10Your rights as a data subject (LGPD Art. 18)

As a data subject, you have the following rights guaranteed by the LGPD:

  • Confirmation that we process your data.
  • Access to the data we hold about you.
  • Correction of incomplete, inaccurate or outdated data.
  • Anonymization, blocking or deletion of unnecessary or excessive data, or data processed in violation of the LGPD.
  • Portability of data to another service provider, subject to trade and industrial secrecy.
  • Deletion of personal data processed on the basis of consent, subject to LGPD Art. 16 exceptions.
  • Information about the public and private entities with which we share data.
  • Information about the possibility of withholding consent and the consequences of doing so.
  • Revocation of consent, where applicable.
  • Right to lodge a complaint with the ANPD for non-compliance.

11Cookies and similar technologies

The mining-ops.com.br landing page uses only strictly necessary cookies (navigation preferences, session state). We do not install advertising, retargeting or third-party analytics SDKs such as Sentry, PostHog or Mixpanel.

If Vercel hosting includes its own essential cookies (load balancing, anti-bot), they have a purely technical purpose and do not individually track the data subject.

The Command Center and Glass Cockpit apps do not use third-party cookies. All authentication uses JWT tokens stored in a secure location (httpOnly cookies or secure storage on the device).

12Children and adolescents

Mining Ops does not intentionally collect data from individuals under 18 years of age. The platform is for professional use only, by workers employed by customer companies (mining operators), all of legal age as required by Brazilian labor law.

If we identify inadvertent collection of minors' data, we will delete it immediately.

13Automated decisions

Mining Ops does not perform profiling or make fully automated decisions that produce significant effects on the data subject (such as automatic salary, dismissal or promotion decisions).

Operational metrics produced by the platform serve as informational input for human decisions made by supervisors and managers of the customer company. Under LGPD Art. 20, you have the right to human review of decisions that affect your interests.

14Changes to this Policy

This Policy may be updated to reflect changes in our services, applicable law or industry best practices. The "Last updated" date at the top of the page indicates the current version.

Substantive changes (new data categories, new sub-processors, changes in purposes) will be communicated reasonably in advance by email to customer-company administrators and via prominent in-app notice.

15Brazilian National Data Protection Authority (ANPD)

If you are not satisfied with how we handled your request, you have the right to lodge a complaint directly with the Brazilian National Data Protection Authority.

  • Official website: gov.br/anpd
  • The ANPD is the Brazilian federal agency in charge of overseeing personal data protection and enforcing the LGPD.

16Version history

This is the first publication of this Policy. No previous versions exist.

VersionDateSummary
1.02026-05-27Initial publication.