SupraPay Privacy Policy
This Privacy Policy explains how SupraPay (“we”, “us”, or “the Platform”) collects, uses, stores, shares, and protects personal data when you use our mobile application, websites, APIs, and related services.
By using SupraPay, you acknowledge that you have read this Policy. If you do not agree, do not use our services.
1. Who we are
SupraPay is a technology platform that enables digital payment and financial operations for merchants and authorized users, including, depending on features enabled for each account:
- payments and collections;
- PIX and related transfers;
- financial and transaction information;
- cryptocurrency / USDT operations when enabled;
- management, support, and security tools.
Privacy / support contact: suporte@suprapay.com.br
2. Scope
This Policy applies to:
- the SupraPay mobile application;
- web dashboards, APIs, and integrations;
- push notifications and operational communications;
- support, security, and fraud-prevention processes.
Some processing may occur jointly with the merchant that owns the business account. In those cases, the commercial agreement and merchant instructions may complement this Policy.
3. Personal data we may collect
Depending on how you use the service and which features are enabled, we may process:
3.1 Identity and account data
- name;
- email address;
- user identifiers;
- phone number (when applicable);
- credentials and authentication information;
- profile, roles, and permissions.
3.2 Payment and financial information
- data needed to process payments;
- transaction information;
- history of charges, payouts, and movements;
- PIX-related data;
- balances, statements, and operational reports;
- settlement and reconciliation data.
3.3 Cryptocurrency / USDT (when enabled)
- wallet addresses linked to the operation;
- amounts, statuses, and references for deposits/withdrawals;
- technical metadata needed to execute and audit the operation.
3.4 Device and technical data
- device identifiers;
- device model, operating system, and app version;
- notification tokens (for example, Firebase Cloud Messaging);
- IP address and access logs;
- crash logs, diagnostics, and performance metrics;
- session data and security events.
3.5 Support and communications
- content of support tickets, messages, and attachments;
- customer-care records.
We do not request data that is not reasonably necessary to provide, secure, or improve the service.
4. Purposes of processing
We use data to:
- create and manage accounts;
- authenticate users and protect access;
- process payments, PIX, transfers, and other enabled operations;
- run cryptocurrency/USDT operations when available;
- issue receipts, statements, and histories;
- provide technical support and customer care;
- prevent fraud, abuse, and unauthorized access;
- comply with legal, regulatory, accounting, and audit obligations;
- improve product stability, security, and experience;
- send operational service notifications;
- generate diagnostics and analyze failures.
5. Legal bases
We process personal data when necessary or legitimate to, among other things:
- perform the contract or service relationship;
- comply with legal or regulatory obligations;
- protect security, integrity, and fraud prevention;
- pursue legitimate interests compatible with the service, respecting data-subject rights;
- rely on consent where required by law (for example, certain optional notifications).
6. Sharing of data
We may share data with:
- vendors and service providers needed to operate the Platform (infrastructure, hosting, payment processing, messaging, technical analytics, support);
- technical services such as Firebase / Google or other providers of notifications, diagnostics, or infrastructure, when integrated;
- payment / settlement partners required to complete transactions;
- the merchant responsible for the business account, within the scope of its operations;
- competent authorities, when required by law or valid order.
We do not sell personal data.
7. International transfers
Some providers may process data in other countries. When that happens, we adopt reasonable contractual and security measures consistent with applicable data-protection requirements.
8. Data retention
We retain data for as long as necessary to:
- provide the service;
- meet legal, tax, accounting, and regulatory obligations;
- handle disputes, audits, and security requirements;
- prevent fraud and abuse.
Important: we do not claim that all data can be deleted immediately. Certain financial, transactional, tax, accounting, anti-fraud, security, or compliance records may be retained when there is a legal obligation or legitimate need for retention, even after an account-deletion request.
Where possible and legally permitted, we delete or anonymize data that is no longer needed.
9. Security
We apply reasonable technical and organizational measures, which may include:
- access controls and authentication;
- encryption in transit where applicable;
- monitoring, audit logs, and fraud prevention;
- minimization and segregation of access.
No system is 100% secure. Please protect your credentials and notify us of suspicious access.
10. User rights
Depending on applicable law, you may request:
- access to your data;
- correction of inaccurate data;
- information about processing;
- deletion or anonymization where applicable;
- objection or restriction in legally provided cases;
- withdrawal of consent where processing is based on consent.
To exercise rights, contact: suporte@suprapay.com.br. We may request information to verify your identity before fulfilling the request.
11. Data and account deletion
You may request deletion of your account and associated personal data by following the instructions on our Data Deletion page.
Deletion or anonymization will occur to the extent legally permitted. Records that must be kept for law, regulation, accounting, security, anti-fraud, or legal defense may remain retained for the necessary period.
12. Children
SupraPay services are intended for authorized users in a business/operational context. They are not designed for use by minors without proper authorization and legal capacity.
13. Alignment with Google Play Data safety disclosures
For transparency with app stores, SupraPay may collect and process categories such as:
- personal info (name, email, user IDs, phone when applicable);
- financial and payment information;
- device identifiers;
- diagnostics and crash logs;
- app data and technical activity needed for security and operation.
These data are used for app functionality, security, fraud prevention, operational analytics, and compliance, in accordance with this Policy.
14. Changes to this Policy
We may update this Policy. The “Last updated” date indicates the current version. When changes are material, we may notify you through reasonable means (app, email, or other channels).
15. Contact
SupraPay
Email: suporte@suprapay.com.br
Related pages: