This Policy explains, in clear terms, how TupiPay processes personal data across its website, platform, and services that connect stores, a proprietary checkout, and a proprietary payment gateway for payment processing. It should be read together with the agreements and specific notices applicable to each relationship.
1. Who we are and scope
TupiPay is developed and operated by FLOWBORDER LLC. In this Policy, “TupiPay” refers to the platform, brand, and services made available within this ecosystem.
This document applies to the processing of personal data relating to:
- website visitors and people who contact us;
- clients, merchants, and their representatives, employees, and authorized users;
- buyers who complete transactions through stores connected to TupiPay;
- partners, service providers, and other individuals who interact with our services.
The type of data and manner in which it is processed vary according to the data subject’s profile, the product used, and the context of the interaction.
2. Data we process
Clients, merchants, and their representatives
- Identity and registration data: name, identification document, date of birth, signature, job title, relationship with the company, and information about representatives or ultimate beneficial owners, when necessary.
- Contact data: email address, telephone number, business address, and communication preferences.
- Business and financial data: legal name, trade name, registrations, business activity, banking information, settlement details, billing information, and account history.
- Verification and compliance data: documents and information used for registration checks, risk assessments, fraud prevention, and compliance with applicable obligations.
- Platform usage data: credentials, permissions, access logs, settings, actions performed, and support communications.
Buyers and transactions
- Identity and contact data: name, email address, telephone number, billing or delivery address, and other information provided through the store’s checkout.
- Payment and order data: amount, currency, items or order reference, payment method, installments, status, reversals, refunds, disputes, and transaction identifiers.
- Fraud prevention data: technical signals, transaction patterns, device information, and the results of risk assessments.
Sensitive payment data is processed only within the environments and fields intended for that purpose. The extent of processing depends on the payment method and configuration selected by the merchant.
Browsing, device, and communication data
- Technical data: IP address, date and time, browser, operating system, device type, identifiers, pages accessed, and error logs.
- Cookies and similar technologies: information required for sessions, security, preferences, and, when enabled, performance measurement.
- Communications: the content of requests, messages, feedback, and customer support records.
3. Purposes and legal bases
The applicable legal basis is determined according to the purpose and circumstances of each processing activity. The primary grounds may include:
| Purpose | Examples of use | Possible legal bases |
|---|---|---|
| Providing the services | Creating and managing accounts, connecting stores, operating the checkout, processing transactions, and providing support. | Performance of a contract and preliminary procedures related to a contract. |
| Enabling payments | Authorizing, recording, reconciling, settling, reversing, or refunding transactions and handling disputes. | Performance of a contract, compliance with legal or regulatory obligations, and the regular exercise of rights. |
| Verifying identity and managing risk | Performing registration checks, preventing fraud, protecting credentials, and investigating suspicious activity. | Compliance with legal or regulatory obligations, legitimate interests, credit protection, and fraud prevention. |
| Improving and protecting the platform | Monitoring performance, correcting failures, developing features, and preserving service security. | Legitimate interests, performance of a contract, and compliance with legal obligations. |
| Communicating and maintaining the relationship | Responding to requests, sending operational notices, and presenting content or offers consistent with the relationship. | Performance of a contract, legitimate interests, and consent, when required. |
| Meeting obligations and protecting rights | Maintaining records, responding to authorities, and participating in administrative, judicial, or arbitration proceedings. | Compliance with legal or regulatory obligations and the regular exercise of rights. |
When processing is based on legitimate interests, we consider its necessity, its potential impact on the data subject, and appropriate safeguards. When consent is the applicable legal basis, it may be withdrawn in accordance with applicable law.
4. How we obtain data
We may receive data:
- directly from the data subject, when they create an account, complete a checkout, request assistance, or communicate with us;
- from clients and merchants, when they integrate their stores and submit information required to manage orders and payments;
- automatically, while a person browses the website, uses the platform, or interacts with security features;
- from payment ecosystem participants and specialized service providers, to enable transactions, verification, security, and fraud prevention;
- from public or authorized sources, when access is permitted and relevant to the stated purpose.
5. Sharing
TupiPay does not sell personal data. We may share personal data, to the extent appropriate for the relevant purpose, with the following categories of recipients:
- clients and merchants: to identify and manage orders, payments, refunds, disputes, and buyer support;
- financial and payment ecosystem participants: to authorize, process, settle, and reconcile transactions;
- technology and operational service providers: including providers of infrastructure, hosting, communications, customer support, data analytics, and storage;
- security, identity, compliance, and fraud prevention services: for verification, risk management, and platform protection;
- professional advisers, auditors, and insurers: when necessary for operations, compliance with obligations, or the protection of rights;
- authorities and legally authorized third parties: when required by law, a valid order, or the need to protect rights and security;
- parties to a corporate reorganization: in connection with a potential merger, acquisition, investment, or asset transfer, subject to applicable safeguards.
Recipients must process the data for legitimate purposes and adopt measures appropriate to the nature of the information and applicable law.
6. International transfers
TupiPay’s operations may involve the storage of, access to, or processing of data in other countries. When an international transfer occurs, we will use mechanisms permitted under the LGPD and applicable regulations, together with contractual, technical, and organizational measures appropriate to the circumstances.
7. Retention and deletion
We retain data for as long as necessary to provide the services and fulfill the purposes described in this Policy. In determining the applicable period, we consider factors including:
- the duration of the relationship with the client or user;
- legal, regulatory, tax, accounting, and fraud-prevention obligations;
- applicable limitation periods and the need for the regular exercise of rights;
- security, audit, and dispute-resolution requirements.
At the end of the applicable period, data may be deleted or anonymized, unless its retention is permitted or required by law.
8. Data subject rights
Subject to the limits and conditions established by the LGPD, data subjects may request:
- confirmation that processing exists and access to their data;
- correction of incomplete, inaccurate, or outdated information;
- anonymization, blocking, or deletion of unnecessary or excessive data or data processed in violation of applicable requirements;
- data portability, subject to applicable regulations and the protection of trade and industrial secrets;
- information about data sharing and the possibility of withholding consent;
- withdrawal of consent and deletion of data processed on that basis, where applicable;
- objection to unlawful processing and review of decisions made solely on the basis of automated processing, as provided by law;
- the right to petition the Brazilian National Data Protection Authority (ANPD).
To protect the data subject, we may request information to confirm their identity. Certain requests may be limited by legal duties, security requirements, fraud-prevention measures, or the exercise of rights; where this occurs, we will provide the applicable justification.
When TupiPay processes data on behalf of a merchant, a request relating to a purchase may also be referred to the establishment responsible for the relationship with the buyer.
9. Cookies and similar technologies
The website may use cookies and similar technologies for:
- operation and security: maintaining sessions, authenticating access, and preventing misuse;
- preferences: remembering choices and settings;
- performance and analytics: understanding how the website is used and improving the user experience when these features are enabled;
- communications and marketing: measuring campaigns or making communications more relevant, when implemented and permitted.
Non-essential cookies will be used in accordance with the choices made available to the visitor. Browsers also allow cookies to be blocked or deleted, although doing so may affect certain features.
10. Security
We adopt technical, administrative, and organizational measures proportionate to the risks involved in processing, including access controls, credential protection, monitoring, vulnerability management, and incident-response procedures.
No transmission or storage system is completely invulnerable. If an incident occurs that may create a relevant risk or harm, we will take the measures and make the notifications required by applicable law.
11. Data processing roles
The roles established by the LGPD are determined according to each activity:
- TupiPay may act as a controller when it determines the purposes and essential elements of processing, including for account management, security, compliance, and operation of its own platform;
- TupiPay may act as a processor when it processes data under the lawful instructions of a client or merchant;
- in certain workflows, TupiPay and the merchant may act as independent controllers, each responsible for its own processing decisions.
Specific agreements and notices may describe these roles in greater detail for a particular product or operation.
12. Children and adolescents
TupiPay’s services are not intended to be contracted directly by children. If data relating to a child or adolescent is processed in connection with a purchase made through a connected store, the processing must observe their best interests, the purpose of the transaction, and applicable legal requirements. Parents or legal guardians may contact us to exercise rights relating to this data.
13. Changes to this Policy
This Policy may be updated to reflect changes to the platform, processing practices, or applicable law. The current version will be published on this page together with its effective update date. When the nature of a change requires it, we will take additional steps to communicate the update.
14. Contact
Questions, requests, and inquiries concerning personal data may be sent to contato@tupipay.com, preferably with “Privacy” in the subject line.
Please include only the information necessary for us to identify your relationship with TupiPay and understand your request. Do not send passwords, authentication codes, or complete payment card details by email.
