Privacy policy
Updated at: 9/27/2026
This Policy explains how 52.906.200 Guilherme Quadros Werner, CNPJ 52.906.200/0001-01, operating the Tribufu brand from Ribeirão das Neves, MG, Brazil, processes personal data across websites, accounts, communities, APIs, hosting and other Services. We act as controller for Tribufu registration, billing, support and operations data. For data a customer hosts or processes for its own purposes, we may act as processor under that customer’s instructions; requests about that data should also be addressed to the customer as controller.
1. Data and sources
We may receive data you provide: name, email, account identifiers, contact details, support messages and submitted content. When you use the Services, we receive technical data such as IP address, session identifiers, device, browser, timestamps, access logs, security events and resource usage. For purchases, we process order, invoice, payment and refund details; full card details are handled by the payment provider where checkout is configured that way. We may also receive data from authentication or payment providers and people reporting abuse. Customer-hosted data depends on what customers choose to store.
2. Purposes and legal bases
We use account, order and support data to enter into and perform a contract, provide the Services and respond to requests. Tax information and required records are processed to meet legal obligations. Logs and abuse signals support security, fraud prevention and legal claims based on legitimate interests, legal obligations or establishment, exercise or defense of rights, as appropriate, after considering your rights. We use aggregated Cloudflare Web Analytics statistics to understand traffic and performance on this website, based on legitimate interests where permitted by applicable law. Non-essential preferences and analytics using cookies or identifiers rely on consent where required; promotional messages use the applicable basis and offer an opt-out. Using a Service is not blanket consent.
3. Providers and disclosure
We share data needed for each function with providers such as Cloudflare (network, protection, storage and Web Analytics on this website), Google Fonts (fonts loaded by the browser), Sentry (error diagnostics), Stripe (payments) and Mailgun (email delivery). A provider may act as processor, independent controller or both depending on the service and agreement. See the Providers and Subprocessors page for data and purposes by provider. We may also disclose data where legally required, to protect rights, or in a business reorganization subject to applicable safeguards.
4. Cookies, analytics and external resources
Necessary cookies support sessions and security. Optional categories depend on the choice offered in cookie settings. On this website, Cloudflare Web Analytics is inserted by the CDN and measures visits and performance without cookies, local storage or fingerprinting; reports are aggregated, although technical requests to Cloudflare may include IP address and browser data. This measurement is not controlled by the analytics cookie setting. Loading Google Fonts directly discloses technical data, such as IP address and browser information, to Google even without a cookie. The Cookie Policy has more details.
5. International transfers
Providers may access or store data outside Brazil and your country of residence. Actual locations vary by product, configuration and provider infrastructure. Transfers subject to the LGPD, GDPR or other laws must use an applicable mechanism, such as an adequacy decision, standard contractual clauses or another valid legal ground. You can request information about applicable providers and mechanisms through the contact below.
6. Retention and security
We keep data while needed for accounts and Services, tax and legal obligations, abuse prevention and legal claims. Periods vary by category and product; afterwards we delete or anonymize data when no retention ground remains. Deletion requests may not cover records the law requires us to keep. We apply access controls, credential protection and other measures proportionate to risk; no system removes every risk. Report suspected incidents through the contact below.
7. Your rights
Depending on applicable law, you may request confirmation and access, correction, deletion or anonymization, portability, sharing information, objection, restriction of processing and review of automated decisions where applicable. You may withdraw consent at any time without affecting earlier lawful processing. In Brazil, you may complain to the ANPD; in the EU/EEA, to the competent data protection authority. We may verify your identity and explain legal limits on a request. For data controlled by a Tribufu customer, we will direct or forward you to that customer where appropriate.
8. Children and teenagers
The Services are not intended for children without a legal guardian’s involvement. Where minors’ data is processed, we observe their best interests and applicable consent or other legal-basis requirements. Parents or guardians may contact us to request a review of minors’ data.
9. Changes and contact
Material updates to this Policy will be reflected in its version date and communicated where the law requires. Controller: 52.906.200 Guilherme Quadros Werner, CNPJ 52.906.200/0001-01, Ribeirão das Neves, MG, Brazil. Data protection officer (Encarregado): Guilherme Quadros Werner, contact@tribufu.com. To exercise rights or ask about privacy, use that address or the general contact below.
Contact: contact@tribufu.com.