Privacy Policy
Last updated: February 2026
1. Who we are
Zupy (zupy.com) is a loyalty program platform that connects businesses and consumers. We are responsible for processing your personal data and act as Controller under the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018).
2. Data we collect
- Registration data: name, email, phone number (WhatsApp).
- Usage data: points history, redemptions, and transactions in the loyalty program.
- Device data: device identifiers for sending push notifications via Apple Wallet and Google Wallet.
- Navigation data: IP address, session cookies, access logs.
- Social login data: basic profile information when you authenticate via Google, Facebook, or Apple (name, photo, and email provided by the provider).
3. How we use your data
- Create and manage your account and loyalty cards.
- Process points, rewards, and redemptions.
- Send notifications about updates to your loyalty card (via Apple Wallet / Google Wallet).
- Transactional communications via WhatsApp or email about your account.
- Improve our services based on aggregated and anonymous analysis.
- Comply with legal and regulatory obligations.
4. Data sharing
We do not sell your personal data. We may share it only with:
- Partner businesses: the business you visit has access to your points history and transactions within the respective program.
- Service providers: companies that help us operate the platform (hosting, email, analytics), bound by confidentiality agreements.
- Authorities: when required by law or court order.
5. Cookies
We use strictly necessary cookies for authentication and platform operation. We also use analytical cookies (PostHog) to understand how users interact with our services, always in aggregate form. You can disable analytical cookies in your browser settings.
6. Data retention
We keep your data as long as your account is active or as necessary to provide services. After account closure, data is anonymized or deleted within 90 days, unless legal retention is required.
7. Your rights (LGPD)
Under the LGPD, you have the right to:
- Confirm the existence of data processing.
- Access your data.
- Correct incomplete, inaccurate, or outdated data.
- Request anonymization, blocking, or deletion of unnecessary data.
- Request data portability.
- Revoke consent at any time.
To exercise your rights, contact us: privacidade@zupy.com
8. Security
We adopt appropriate technical and organizational measures to protect your data against unauthorized access, loss, or improper disclosure, including encryption in transit (TLS) and at rest, access controls, and continuous monitoring.
9. Contact
For questions about this policy or to exercise your rights, contact us: