Legal · English
Privacy Policy
This Policy explains how Sempre Aberto processes personal data and how you may exercise your rights under Brazil's General Personal Data Protection Law (LGPD).
1. Who controls the data
Sempre Aberto determines the purposes and essential means of the processing described in this Policy and acts as controller of that data. Businesses, event organizers, identity providers, and other third parties may be independent controllers for processing they perform for their own purposes.
2. Data we process
Depending on how you use the service, we may process:
- account data: name, email, internal identifier, and a hashed password;
- Google sign-in data when selected: account identifier, name, email, profile picture, and information authorized on the consent screen; we never receive your Google password;
- messaging profile: mobile number, handle, and location area; your phone number is not shown in public search;
- bookings: business, service, date, time, note, and status;
- content and interactions: events, RSVPs, posts, votes, communities, messages, invitations, blocks, and reports;
- business submissions: commercial contacts, address, service area, hours, and the selected verification information or method;
- technical data: IP address, date and time, requested route, browser and device type, security logs, and failures;
- location data only with browser permission in the circumstances described below.
3. How we use location
When you create an event, venue coordinates are stored and may be published as part of the event. When you post in a live event conversation, your precise location is compared in real time with the event perimeter to validate presence and is not stored with the post.
You may deny browser permission, but location-dependent features may not work. The directory also displays maps and directions based on business addresses and coordinates.
4. Purposes and legal grounds
We process data to:
- create and authenticate accounts, fulfill requests, and provide contracted features;
- process bookings, event attendance, posts, votes, communities, and messages;
- verify location when you request a feature that depends on it;
- protect users and the platform, prevent fraud and abuse, enforce blocks, and review reports;
- maintain, diagnose, and improve performance, accessibility, and security;
- comply with legal and regulatory obligations and valid orders;
- establish, exercise, or defend rights in legal, administrative, or arbitration proceedings.
5. Legal bases
Depending on the context, we rely on performance of a contract or pre-contractual steps; consent, including device permissions where applicable; legitimate interests balanced against data-subject rights; compliance with legal obligations; and the exercise of legal rights. Where processing relies on consent, you may withdraw it without affecting prior lawful processing.
6. Public and private content
Public profiles, businesses, events, feed posts, news, and communities may be viewed and shared by anyone and indexed by search engines. Direct and group messages are available to participants and authorized personnel where necessary for security, support, moderation, or legal obligations.
Do not place personal data in public areas if you do not want it disclosed. Deletion or modification in the service cannot guarantee removal of copies previously made by third parties or search engines.
7. Sharing
We may share strictly necessary data with:
- infrastructure and hosting providers, currently including Amazon Web Services;
- Google when you choose Google sign-in;
- OpenStreetMap and its providers when an embedded map loads;
- the selected business or professional as needed to fulfill a booking or request;
- providers supporting security, communications, support, or operations under data-protection obligations;
- authorities or third parties where required by law, a valid order, or protection of rights and safety.
8. International transfers
Current infrastructure may process data in the United States, and Google, OpenStreetMap, or other providers may operate in different countries. For international transfers, we will use mechanisms allowed by the LGPD and contractual and technical measures appropriate to the risk.
9. Retention
We retain data for as long as needed to provide the service and fulfill the purposes described. Account data and content remain while the account or publication is active; booking, security, report, and transaction records may be preserved as needed for legal obligations, fraud prevention, and the exercise of rights.
After the purpose ends, data will be deleted or anonymized unless retention is allowed or required by the LGPD. Backups follow technical replacement cycles.
10. Security
We use HTTPS, access controls, database isolation, hashed passwords, and update and monitoring practices. No system is completely secure; if a relevant incident occurs, we will take the measures and provide the notices required by law.
11. Cookies and similar technologies
The service may use cookies, tokens, or local storage strictly necessary for authentication, security, and preferences. We currently do not use behavioral advertising cookies. External providers may apply their own technologies when their resources load.
12. Your LGPD rights
Where applicable, you may request without charge:
- confirmation of processing and access to data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data;
- portability subject to applicable regulation;
- deletion of consent-based data, subject to lawful retention exceptions;
- information about sharing and the consequences of withholding consent;
- withdrawal of consent and objection in legally applicable circumstances;
- review of decisions based solely on automated processing that affect your interests.
13. Exercising your rights
Send requests to privacidade@sempreaberto.com.br. We may request proportionate information to verify identity and protect the account. If you are dissatisfied, you may petition Brazil's National Data Protection Authority (ANPD) or seek consumer-protection bodies.
14. Children and teenagers
The service is not intentionally directed to children. People under 18 should use Sempre Aberto with the knowledge and supervision of a legal guardian. If we learn that a child's or teenager's data was processed improperly, we will take appropriate measures, including deletion where applicable.
15. Changes to this Policy
We may update this Policy to reflect technical, operational, or legal changes. The published version will identify its effective date, and material changes will be communicated appropriately. For users in Brazil, the Portuguese version controls if translations conflict.