Feira Social

Privacy Policy

How we collect, use, and protect your data, in compliance with the LGPD. Full transparency — we never ask for your password.

1. Who is the data controller

FeiraSocial, the operator of feirasocial.com, is the controller of the personal data processed here, under Brazil's General Data Protection Law (Law 13,709/2018 — LGPD).

2. Data Protection Officer (DPO)

Data Protection Officer: Osni
Email: [email protected]

Use this channel to exercise any right under the LGPD or to ask questions about privacy.

3. What data we collect

Registration and order data
Name, email, phone number (when provided), and the link or @handle of the public profile provided for delivery.

Payment data
Processed directly by our partner payment gateways (PIX, card, digital wallets). We do not store full credit card details. We only receive the transaction status and a payment identifier.

Browsing data
Cookies, IP address, device type, browser, and pages visited, used for security, fraud prevention, and usage metrics.

What we do NOT collect
Social media passwords. Ever. We don't ask for them, don't store them, and have no way to use them.

You can withdraw your consent to promotional communications at any time, using the unsubscribe link or by emailing the Data Protection Officer.

5. Who we share it with

We only share the data that's strictly necessary with:

  • Payment processors, to authorize and settle the transaction;
  • Technical fulfillment partners, who receive the link or public @handle of the destination to carry out delivery — fulfillment doesn't take place on Feira Social's own servers;
  • Infrastructure, hosting, and analytics providers;
  • Public authorities, when there's a legal or judicial request.

We do not sell personal data to third parties.

6. International data transfers

Some of our technical fulfillment partners and infrastructure providers are based outside Brazil. In these cases, the link or public @handle provided in the order — and, when applicable, technical browsing data — may be transferred to other countries.

These transfers take place under Art. 33 of the LGPD, through contractual clauses that require the partner to maintain a level of protection compatible with Brazilian law, and are limited to what's necessary to perform the service you purchased.

7. Data from minors

Our services are intended for people over 18 years old. We do not knowingly collect data from minors. If we identify data collected improperly, it will be deleted. Legal guardians may request deletion by emailing the Data Protection Officer.

8. Your rights (LGPD)

You may request, at any time and free of charge:

  • confirmation that your data is being processed;
  • access to your data;
  • correction of incomplete, inaccurate, or outdated data;
  • anonymization, blocking, or deletion of unnecessary or excessive data;
  • portability to another provider;
  • deletion of data processed based on consent;
  • information about who we share your data with;
  • withdrawal of consent.

Requests via email at [email protected]. We respond within 15 days.

9. Data retention

  • Order and transaction data: kept for 5 (five) years after completion, to comply with tax obligations and for defense in the event of a dispute.
  • Contact and support data: kept for as long as the relationship lasts, and for up to 2 years after the last contact.
  • Browsing and cookie data: as per each cookie's duration, listed in the following section.

Once these periods end, the data is deleted or anonymized.

10. Cookies

We use three categories of cookies:

  • Essential — keep your session, your cart, and the site's security running. These can't be disabled, since the site doesn't work without them.
  • Preference — remember the @handle saved on your device and display settings.
  • Analytics — measure site usage and performance in aggregate.

You can accept or decline non-essential categories in the banner shown on your first visit, change your choice at any time through the "Cookie preferences" link in the footer, or manage cookies in your browser settings.

11. Security

We use technical and administrative measures to protect your data: encrypted connections (HTTPS), internal access controls, environment segregation, and monitoring. No system is 100% breach-proof, but we maintain an incident response process and will notify data subjects and the ANPD if a relevant security incident occurs, as required under Art. 48 of the LGPD.

12. Changes to this policy

We may update this policy to reflect changes in our services or in the law. The version in effect is always the one published on this page, identified by the date at the top.

13. Contact