tario.
Privacy

Privacy in plain language.

What information we receive, why we use it, who processes it with us, and how you can exercise your rights. Last updated: September 27, 2026.

Who is responsible

Tario is responsible for the personal data it receives through this site and the application. You can contact us at hola@tario.io.

The data about your customers, suppliers, and employees that you upload to Tario is yours: you are responsible for that data and Tario processes it on your behalf, following your instructions and these terms.

Site data

We receive the information you send through forms, email, or sales requests so we can reply and coordinate demos.

We may also use basic technical site data for security, measurement, and service improvement when those functions are enabled.

What data we process in the product

Your account data: name, email, password (stored irreversibly hashed), language, and the companies you belong to.

Your company data: tax ID, economic activity, location, bank accounts you register, and your Hacienda certificate and credentials, which we store encrypted.

Your operational data: customers, suppliers, electronic documents, expenses, bank statements, inventory, employees, and the files you upload or receive by email.

Technical logs: IP address, browser, and actions within the system, for security and auditing.

Subscription payment data: received and stored by ONVO, the payment processor. Tario does not store your full card number.

Why we use it

To provide the service: issue and receive documents, keep your books, generate reports, and send the emails you request.

To bill the subscription, provide support, notify you of service events (for example a Hacienda rejection or a failed charge), and keep the platform secure.

To improve the product with aggregated metrics that do not identify your company.

We do not sell your data, do not use it for third-party advertising, and do not train artificial intelligence models on it.

Artificial intelligence

Tario AI runs under zero data retention: every model request requires providers that do not keep your conversations, documents, or data and do not train on them. If no provider qualifies, the request is not sent.

Tario never trains artificial intelligence models on your data. Your conversation history with Tario AI is stored in your company inside Tario, with the same protection as the rest of your information.

Providers that process data for us

Ministerio de Hacienda (Costa Rica): receives the electronic documents you issue and the acceptance or rejection messages you send. It is the recipient required by law, not a provider of ours.

Cloudflare: protection and delivery of the site and the application, bot verification on sign-up and login, and private file storage (Cloudflare R2) for XML, PDF, certificates, attachments, and backups, accessible only with Tario's keys.

OpenRouter: access to the artificial intelligence models. Every request requires zero-data-retention providers that do not train on the data; if none qualifies, the request is not sent.

SendGrid (Twilio): sending emails from Tario (invoices, estimates, notices) and receiving the documents your suppliers send to your reception address.

ONVO: billing of the Tario subscription and, if you use Tario POS, card payments from your customers through your own merchant account.

Our servers and databases are hosted with cloud providers. Some of these providers operate outside Costa Rica; by using Tario you accept that transfer, which we protect with encryption and data processing agreements.

How long we keep data

While your company is active, all of its data.

Electronic documents, Hacienda responses, and accounting records: at least five years, as required by the Código de Normas y Procedimientos Tributarios (article 109) and the Electronic Documents Regulation (Executive Decree 44739-H, article 22), even if you cancel your subscription.

Other data of a cancelled company is deleted when you ask or when it is no longer needed; site and sales request data, for as long as needed to handle them.

Technical and audit logs: for a limited period, for security and incident investigation.

Backups

We back up the database and files periodically to private, encrypted storage. Database backups rotate on a tiered schedule: daily for 14 days, weekly for 12 weeks, and monthly for 12 months.

Backups exist to recover the service after an incident. Data deleted from the application may remain in a backup until it rotates out.

Security

Encryption in transit (TLS) and at rest for certificates, Hacienda credentials, and other secrets; data separation per company; per-user roles and permissions; two-step verification available; audit logs of sensitive actions.

Tario's team only accesses your account to provide support, and that session is shown on screen with a notice for as long as it lasts.

If we detect an incident affecting your data we will notify you without undue delay, with what we know and what we recommend you do.

Your rights

Under Costa Rica's personal data protection law (Ley 8968), you can access your personal data, correct it, ask us to delete it when the law does not require us to keep it, and withdraw your consent.

Write to hola@tario.io from your account email; we respond within the legal deadlines. If you are not satisfied with our response, you can turn to the Agencia de Protección de Datos de los Habitantes (PRODHAB).

Cookies

The application uses only necessary cookies: the session, cross-site request forgery (CSRF) protection, and your language. We do not use advertising cookies.

This site may use a visitor measurement tool when enabled, as described under Site data.

Minors

Tario is a service for businesses and is not directed at people under 18. If you believe a minor has given us personal data, write to us so we can delete it.

Changes to this policy

If we change this policy we will publish the new version here with its date and, if the change is significant, notify you by email or inside the application.

Contact

For privacy questions, write to hola@tario.io.