LEGAL · 002

PRIVACY POLICY

Last updated: April 20, 2026

1. What we collect

To run PlacarPro, we collect the minimum needed:

  • Account: name, email, profile image (from Twitch/Google/Kick OAuth)
  • Usage: team presets, overlay settings, goal sounds you upload
  • Billing: subscription status (we never see your card - handled by Stripe/Hotmart)
  • Technical: IP address, browser, device, for security and rate limiting

2. How we use it

Your data is used to:

  • Authenticate you and keep your account secure
  • Deliver the overlay and sync live match data
  • Process payments via Stripe/Hotmart
  • Send transactional emails (welcome, subscription changes)
  • Prevent abuse (rate limiting, anti-fraud)

We don't sell your data. We don't profile you for ads. We don't run third-party analytics that track you across sites.

3. Third-party processors

  • Veloz - infrastructure hosting
  • Stripe - USD/EUR/MXN payments
  • Hotmart - BRL payments
  • Resend - transactional email
  • API-Football - match data (you connect your own key)
  • Twitch/Google/Kick - OAuth sign-in

Each processor has its own privacy policy governing data they handle.

4. Cookies

We use essential cookies only (session, auth). No analytics cookies, no ad trackers, no fingerprinting. If we add analytics later, we'll use a privacy-first tool (like Plausible) and update this policy.

5. Your rights (LGPD / GDPR)

You can at any time:

  • Request a copy of your data
  • Update or correct your data
  • Delete your account (settings → delete, or email us)
  • Export your team presets
  • Withdraw consent for marketing (we don't send any yet)

DM us on X at @placarpro for data requests. We respond within 15 days.

6. Data retention

Account data is kept while your account is active. When you delete, we remove personal data within 30 days (except billing records kept 5 years for legal/tax compliance). Logs are rotated after 90 days.

7. Security

Data is encrypted in transit (HTTPS) and at rest (database encryption). API keys you provide are encrypted with AES-256-GCM. We use OAuth for auth (no passwords stored). Infrastructure is on SOC 2 compliant providers.

8. Children

PlacarPro is not intended for users under 13. If you're under 18, you need a parent/guardian to agree to the Terms on your behalf.

9. International transfers

Our infrastructure runs in Brazil and the US. By using the Service, you consent to data being processed in these regions.

10. Changes

Material changes to this policy will be announced by email 30 days in advance.

11. Contact

Privacy or support questions? Reach us on X at @placarpro.