Privacy Policy
Last updated: August 20, 2026
This policy explains what data Sports & Caffeine collects, why we collect it, who we share it with, and how you can exercise your rights under Brazil's data protection law (LGPD). It describes what the product actually does today — not generic boilerplate.
Who is the data controller
[TO BE FINALIZED] At this early stage, Sports & Caffeine is operated by an individual developer (no incorporated company yet). Full controller identification — name, tax ID and address — and the contact for a data protection officer (DPO/encarregado) will be published here before public launch, as LGPD requires.
What data we collect
Account data: your email address and authentication credentials, processed by our identity provider (Supabase Auth). We do not store your password in plain text — that is handled by the provider.
Profile data: display name, username (handle), profile photo, city, sports activities you're interested in, and the visibility settings you choose for each of these fields.
Social data: who you follow and how many people follow you (a public count; the list of your followers is not exposed to other users).
Business profile data: if you claim or register a venue, we collect that venue's name, description, address, map coordinates, photos, and contact links (Instagram, phone, website, WhatsApp).
Content you post: posts on a venue's wall, when that feature is available for your account type.
Usage and browsing data: we log events such as venue views and clicks, with the event type, the surface it originated from (search, feed, or map), a session identifier generated in your browser, and a country/region-level location derived from a geolocation header supplied by our hosting provider. We never store your raw IP address or precise coordinates for this purpose.
Payment data: paid subscriptions are not yet available in this version of the product. When they are, payment processing (Pix and card) will be handled by a payments partner (Asaas); we do not store your full card details on our servers.
Why we use this data
We use this data to operate the service (authentication, displaying venues and content, social features), to maintain and improve the product (aggregated usage metrics), to prevent abuse and fraud, to comply with legal obligations, and, when applicable in the future, to process subscription payments and to show advertising.
Legal basis
Contract performance: processing necessary to provide the account, profile, and features you use once you create an account (LGPD art. 7, V).
Legitimate interest: aggregated usage metrics, fraud and abuse prevention, and platform security (LGPD art. 7, IX), always weighed so it does not override your fundamental rights and freedoms.
Consent and legal obligation: for specific purposes that require explicit consent (for example, joining a city-coverage waitlist) and to retain records where the law requires it.
How long we keep your data
We keep your account data while your account is active. If you request account deletion, your profile is hidden immediately from every other user; the data remains until an administrator processes the final deletion (see "Your rights" below) — there is no automated fixed timeline today, this step is manual and reviewed. Usage event records are kept in aggregated form, without a durable direct link to your personal identity.
Who we share your data with
Infrastructure providers that process data on our behalf as operators: Supabase (database, authentication, and file storage), Vercel (application hosting), and Cloudflare (network and abuse protection).
If you enable push notifications, we use Firebase Cloud Messaging (Google) to deliver them to your device.
When paid subscriptions launch, payment processing will be handled by Asaas, our payments partner. We do not share your data with third parties for our own marketing purposes.
Advertising
We do not show third-party ads today. In the future, we plan to show advertising in the feed as a fallback when no eligible sponsored content of our own is available, using the Google AdSense network. When that launches, a consent notice will be shown before any third-party advertising script loads, and paying subscribers will not see network ads. This policy will be updated with the specific details once that feature ships.
Cookies and local storage
We use cookies strictly necessary to keep your session authenticated, and a local session identifier for the usage events described above. We do not use third-party advertising tracking cookies today; if that changes with network advertising, a consent banner will be shown before any non-essential cookie is set.
Your rights
Under LGPD, you have the right to confirm whether we process your data, to access it, to correct it, to request anonymization, blocking or deletion of unnecessary data, to request data portability, to be informed about who we share your data with, and to withdraw consent where that is the applicable legal basis.
In practice: you can download a copy of your profile, activity, follow, and consent-record data at any time from the account settings page. To correct your data, edit your profile directly in the app. To request deletion, use the account deletion button on that same page — this hides your profile immediately and creates a request that an administrator reviews; the final deletion anonymizes your personal data and cannot be undone once complete. You can also contact us via the email on the Contact page for any of these requests.
International data transfer
Some of our infrastructure providers (Supabase, Vercel, Cloudflare, and in the future Google, for advertising and notifications) may process data on servers outside Brazil. We choose providers with recognized security practices and, where applicable, contractual international data-protection safeguards.
Children and teenagers
The service is not directed at anyone under 18 without the specific, prominent consent of a legal guardian, as LGPD requires. If we become aware of an account created by a child without that consent, we will take steps to delete it.
Security
We take technical and administrative measures to protect your data, including database-level access control, server-verified authorization for every sensitive operation, and we never trust client-submitted values for authorization decisions. No system is entirely risk-free; if we identify a security incident affecting your personal data, we will notify you and the competent authority as required by law.
Changes to this policy
We may update this policy as the product evolves — for example, once paid subscriptions or network advertising actually launch. The date at the top of this page shows the last update; material changes will be communicated visibly in the app.
Contact
For questions about this policy or to exercise your rights directly, use the Contact page. [TO BE FINALIZED] The contact for our data protection officer (DPO) will be published here before public launch.