treebird
pten

Privacy Policy

How Treebird processes personal data of businesses and of businesses’ customers, under the Lei Geral de Proteção de Dados (LGPD), Brazil’s data protection law.

Last updated: August 6, 2026

In short

Treebird is operated by Purple Engineering Ltda. For your company’s data (registration, billing), Purple is the controller; for the data of a Business’s customers (reservations, contacts, spending), the Business is the controller and Purple is the processor, handling everything under its instructions. We collect what the service needs, such as name, phone and email for reservations and messages, and CPF (Brazilian taxpayer number) when payment requires it; card data never passes through our servers, and the content of the messages sent is not stored, only delivery metadata.

We do not sell personal data: we share it only with the providers that make the platform work, named in this policy. You can request access, correction, deletion and portability. A Business’s customer talks to the Business first, which is the controller of their data, or writes to our Data Protection Officer at dpo@treebird.com.br. This English text is a convenience translation of the Portuguese original, which is the official version and prevails over it.

The summary is there to help you read; what is legally binding is the full text below.

1. Overview and who this policy applies to

In short

This policy covers both sides of the platform: the companies that hire Treebird and the people who use those companies’ storefronts.

1.1. This Privacy Policy describes how Purple Engineering Ltda (“Purple”, “we”), operator of the Treebird platform, processes personal data in Brazil, in compliance with Lei nº 13.709/2018 (LGPD, Brazil’s data protection law), the Marco Civil da Internet (Lei nº 12.965/2014, Brazil’s Internet Civil Framework) and other applicable rules.

1.2. Purple and Treebird are not the same. Purple Engineering Ltda is the legal entity that processes the data and answers for it in the roles described in section 2. Treebird is the brand and the software platform through which Purple provides the service; it is not a legal entity of its own. When this policy says “Treebird”, the processing agent behind it is always Purple.

1.3. It applies to:

  • Businesses: the companies that hire the platform, and the individuals who represent them (partners, team, billing contacts);
  • Customers: the people who use a Business’s storefront to reserve, book, join a queue, pay or take part in a loyalty program;
  • visitors to Treebird’s public pages.

1.4. This policy complements the Terms of Use. Capitalized terms not defined here have the meaning given there.

1.5. Which addresses it covers. Treebird uses two addresses with different roles, and this policy covers both:

  • treebird.com.br: the brand’s institutional site (product, plans, contact and the publication of these documents). It belongs to Purple, hosts no Business’s storefront, and there Purple is the controller of the little data it processes (contact details sent through the forms, aggregate audience metrics).
  • treebird.app: the running platform, that is, the storefronts on the shared subdomain (yourbusiness.treebird.app) and the Businesses’ admin panel. The Customer data processed here belongs to the Business, which is the controller, as set out in section 2.
  • a Business’s own domain, once connected: the same platform served at its address, under its brand. The rules in this policy apply the same way, and the Business remains the controller.

1.6. It does notcover a Business’s own sites, social networks and systems outside the platform, even when linked from the storefront, nor the sites of the providers named in section 6, which have policies of their own.

2. Roles: who is controller, who is processor

In short

Data of the contracting company: Purple decides and answers for it (controller). Data of a Business’s customers: the Business decides (controller) and Purple carries it out (processor). This split defines who you go to in order to exercise your rights.

2.1. Purple as controller. For the data of Businesses and their representatives (registration, contacts, billing data, team access records, communications with our support), Purple defines the purposes and is the controller, under art. 5º, VI, of the LGPD.

2.2. Purple as processor. For the data of a Business’s Customers (identification, contact, reservations, spending history, loyalty balances, preferences), the Business is the controller and Purple is the processor (art. 5º, VII), processing that data solely to provide the contracted service and in line with the Business’s lawful instructions, documented in the Terms of Use.

2.3. The practical consequence: data subject requests about data processed on a Business’s storefront must be addressed to the Business first, which is the party that decides on them. Purple helps the Business respond and, when contacted directly, forwards the request to the Business, without prejudice to acting in the cases where the law imposes an obligation of its own.

2.4. In limited situations Purple processes Customer data as controller: compliance with its own legal obligations (tax, accounting, security), defense in proceedings and fraud prevention on the platform.

2.5. The relationship between the Business (controller) and Purple (processor) is governed by documented instructions, as set out in art. 39 of the LGPD: section 22 of the Terms of Use governs security, subprocessors, assistance to the controller, incident notification and what happens to the data at the end of the contract.

3. What data we collect

In short

Name, phone and email for reservations and accounts; CPF when payment requires it; spending and loyalty data inside the storefront; technical access records. Card data is tokenized in your browser and never reaches our servers.

From Businesses and their teams

  • company registration: legal name, CNPJ (Brazilian company tax number), address, contacts, billing and tax data;
  • team: name, email, role and permissions of each member, records of invitation, activation and access;
  • identifiers of integrations authorized by the Business: Mercado Pago (connection tokens, stored encrypted), Stripe (customer, subscription and invoice identifiers), WhatsApp (account and number identifiers) and Google Calendar (connection credentials of providers who choose to connect).

From Customers of Businesses

  • identification and contact: name, phone (normalized to the international E.164 format) and email. A Customer may exist in a Business’s records without ever creating an account, for example when booking by phone or in person;
  • storefront activity: reservations, appointments, positions in queues and waitlists, orders, amounts paid, cashback balance and statement, preferences, tags and notes made by the Business in its CRM;
  • payment: amount, method, transaction identifiers at Mercado Pago and, when required by the rules of the Pix (Brazil’s instant payment system) scheme or by antifraud, the CPF. Card data is tokenized in the browser, directly against Mercado Pago, and never passes through Purple’s servers;
  • messages: metadata of each send (channel, purpose, contact, delivery status, provider identifier, timestamps). The body of the messages is not stored;
  • marketing consent: explicit record of opt-in and opt-out, with date and time.

From all visitors

  • technical records: IP address, date and time, browser and pages accessed, kept as required by the Marco Civil da Internet;
  • cookies and local storage, described in section 5.

The platform does not deliberately collect sensitive data (art. 5º, II, of the LGPD). Free-text fields, such as CRM notes or reservation remarks, must not be used by the Business to record sensitive data; responsibility for entering them lies with the controller that entered them.

4. What we use data for and on what legal basis

In short

We use data to run reservations, payments and messages (performance of a contract), to comply with the law (legal obligation), to keep the platform secure (legitimate interest) and to send marketing only with your authorization (consent).

  • Performance of a contract (art. 7º, V, LGPD): creating and managing reservations, appointments, queues and waitlists; processing payments and refunds; sending transactional messages (confirmations, reminders, access codes, receipts); operating accounts, cashback and loyalty; providing support; billing Businesses’ subscriptions.
  • Legal or regulatory obligation (art. 7º, II): retention of access records (Marco Civil), tax and accounting records, responding to authorities, the rules of the Pix scheme and the anti money laundering rules applied by the payment providers.
  • Legitimate interest (art. 7º, IX): platform security, fraud and abuse prevention, audit records of sensitive actions, service improvement with aggregated or anonymized data, operational communication with Businesses.
  • Consent (art. 7º, I): marketing communications to the Customer, when they opt in to receive them; optional Google Calendar connection by a Business’s providers.

Where processing relies on legitimate interest, it is preceded by an assessment of the impact on the data subject and limited to the minimum necessary; the data subject may object as described in section 10.

Automated decisions. The platform does not make solely automated decisions producing significant legal effects on data subjects (there is no credit profiling or automatic refusal of registration, for example). Operational automations, such as ordering queues with the priorities of Lei nº 10.048/2000 (priority service law) or routing messages between WhatsApp and email, follow fixed, transparent rules. If a solely automated decision with a significant effect ever exists, the data subject will have the right to review under art. 20 of the LGPD.

5. Cookies and similar technologies

In short

We use only necessary cookies (session, language, theme) and aggregated audience metrics. We do not use advertising cookies.

5.1. The platform uses strictly necessary cookies and local storage: keeping your session authenticated, remembering language and theme, protecting forms and balancing load. Without them the service does not work, which is why they do not depend on consent.

5.2. We measure audience with aggregated metrics and without individual profiling (Vercel Analytics), with no cross-site tracking cookies.

5.3. We do not use advertising cookies and we do not sell browsing data. If that ever changes, this policy will be updated first, with a consent mechanism of its own.

5.4. Each address has its own. Cookies are stored per address: your session on one Business’s storefront (yourbusiness.treebird.app or its own domain) is not shared with another Business’s storefront, nor with the institutional site treebird.com.br. No cookie follows a person from one business to another, and signing in to one storefront tells that Business nothing about the others.

6. Who we share with (subprocessors)

In short

We share data only with the providers that make the platform work, each one named below with its function. We never sell personal data.

6.1. Personal data is shared only to the extent necessary, with the following service providers (subprocessors, when Purple acts as processor):

  • Mercado Pago (Mercado Pago Instituição de Pagamento Ltda., Brazil): processing of Customer payments; receives name, email, CPF when required and transaction data.
  • Stripe (Stripe, Inc., USA, with processing on Brazilian rails): billing of Businesses’ subscriptions; receives legal name, billing email and CNPJ.
  • Meta Platforms (WhatsApp Cloud API, USA): delivery of WhatsApp messages; receives the recipient’s phone number and the message content at the moment of sending.
  • Resend (USA, sending from the São Paulo region): delivery of transactional emails; receives the email address and the message content at the moment of sending.
  • Neon (USA): managed database where the platform’s records are stored.
  • Vercel (USA): hosting and runtime infrastructure of the platform.
  • Upstash (USA): short-lived cache and queues (temporary holds, usage limits).
  • Cloudflare (R2, USA): media storage (logos, venue photos and menus).
  • Google (USA): calendar sync, only for providers of Businesses who connect their own Google Calendar account.
  • Zoho (India/USA): Purple’s corporate mailboxes, used when you write to our contact addresses.
  • NFS-e issuer (NFS-e is the municipal service invoice): when automated tax invoicing is active, the provider contracted at that point will receive the necessary billing data and will be named in this list.

6.2. Besides the providers above, data may be shared: with the Business that controls its Customers’ data; with public authorities, upon legal obligation or valid order; and in corporate transactions involving Purple, in which case the assignee takes on the obligations of this policy.

6.3. Purple does not sell or rent personal data and does not share it for third-party advertising.

7. International transfers

In short

Some providers are outside Brazil. When data leaves the country, it happens with the safeguards of art. 33 of the LGPD, through contractual protection clauses.

7.1. The platform is operated with data resident in Brazil as a guideline; even so, providers listed in section 6 process data in other countries, notably in the United States.

7.2. These transfers take place on the basis of art. 33 of the LGPD, through contractual data protection clauses signed with each provider (data processing agreements, DPAs, incorporating standard clauses), ensuring a level of protection equivalent to this policy and to the LGPD.

7.3. Copies of the applicable safeguards may be requested from the Data Protection Officer (section 14), except for confidential passages.

8. How we protect data

In short

Encryption in transit and at rest, encrypted credentials, permission-based access, no customer passwords stored, and an audit log of sensitive actions.

  • encrypted traffic (TLS) on every surface; data at rest encrypted by the database and storage infrastructure;
  • integration credentials (for example, Mercado Pago tokens) stored encrypted and never written to logs;
  • passwordless authentication for Customers and teams (one-time codes and magic links), which removes the risk of password leaks for those accounts; attempt limits against brute force;
  • minimal internal access, segregated by role; sensitive actions, including support access to a Business’s account, recorded in an audit log;
  • card data outside our environment by architecture (section 3); application secrets kept out of the code;
  • backups and a recovery plan.

No system is immune. In the event of a security incident with relevant risk or damage to data subjects, Purple will notify the ANPD (Brazil’s National Data Protection Authority), the affected controlling Businesses and, where applicable, the data subjects, within the deadlines set by regulation (art. 48 of the LGPD).

9. How long we keep data

In short

We keep data while the account exists. After a business’s contract ends, 90 days for export and then deletion or anonymization, except what the law requires us to keep (tax and financial records, for example).

  • During the contract: data is kept while the Business’s account is active and it remains necessary for the purposes in section 4.
  • After the Business’s contract ends: data is retained for 90 days for export and transition, and then deleted or anonymized.
  • Financial, tax and accounting records (transactions, invoices, receipts, notes): kept for the applicable legal and limitation periods, as a rule 5 years or more, on the basis of legal obligation and the regular exercise of rights.
  • Application access records: at least 6 months, as required by the Marco Civil da Internet.
  • Message metadata: up to 12 months after sending, to prove delivery and account for usage.
  • Audit logs of sensitive actions: up to 5 years, for security and accountability.
  • Consent records (marketing): while the consent is active and for up to 5 years after it is withdrawn, as proof of the processing carried out.

Anonymized data, unable to identify a person, may be kept with no time limit for statistics and service improvement.

10. Your rights as a data subject

In short

Access, correction, deletion, portability, information about sharing and withdrawal of consent. A business’s customer exercises them with the business first; our DPO also handles them.

10.1. Under art. 18 of the LGPD, you may request:

  • confirmation that we process your data, and access to it;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of data that is unnecessary, excessive or processed in breach of the law;
  • portability, in a structured and interoperable format;
  • information about who your data has been shared with;
  • information about the possibility of not giving consent and about withdrawing consent, when that is the legal basis;
  • objection to processing based on legitimate interest, and review of solely automated decisions, where they exist.

10.2. How to exercise them. A Business’s Customer: address the request first to the Business, the controller of your data, through the channels shown on the storefront; the platform gives it the tools to respond (export of your data and deletion). You may also write to our Data Protection Officer (section 14), who will forward the request and follow up on it. Business or team member: write directly to the Data Protection Officer.

10.3. We respond within a timeframe consistent with ANPD regulation: confirmation and access in simplified format immediately where possible, or by a full statement within 15 days, and the remaining requests within a reasonable period, stated on receipt. We may ask for proof of identity in order to protect the data itself.

11. Deletion and anonymization

In short

When you delete your data, what the law requires us to keep (financial records) is kept without your identifiers: the transaction still exists, but it stops pointing to you.

11.1. Deletion requests are met through the mechanism of anonymization with record retention: personal identifiers (name, phone, email, account links) are irreversibly removed or replaced, while the records that the law or a documented legitimate interest requires us to keep (transaction amounts, dates and methods, loyalty entries, tax documents) remain, now without pointing to an identifiable person.

11.2. Surviving deletion, for the periods in section 9: financial and tax records, access records required by the Marco Civil, audit logs and proof of consent. Nothing survives that allows the data subject to be contacted or identified outside those purposes.

11.3. Deleting the sign-in account (login) is not the same as deleting the records a Business keeps about its customer; for the latter, section 10.2 applies.

12. Children and adolescents

In short

The platform is not aimed at anyone under 18. Reservations must be made by adults; each venue’s entry rules belong to the business.

12.1. The platform is not intended for people under 18, and we do not deliberately collect data of children and adolescents. Reservations, appointments and payments must be made by an adult, who may include minors under their responsibility as companions (for example, the number of seats in a reservation).

12.2. Minimum age policies for entry and stay at each venue are defined and enforced by the Business, in accordance with local law.

12.3. If we identify processing of a minor’s data carried out contrary to this policy, the data will be deleted, except where the law requires it to be kept.

13. Marketing and communications

In short

Operational messages (confirmation, reminder, code) are part of the service. Marketing only with a recorded opt-in, and opting out is easy and immediate.

13.1. Transactional messages (reservation confirmations, reminders, access codes, receipts, queue notices) arise from performing the service you requested and do not depend on marketing consent; they carry no promotional content.

13.2. Marketing to the Customer (offers, news from a Business) is only sent with prior, recorded consent (opt-in with date and time), collected in a prominent way. Consent is specific to each Business and managed separately from the transactional flow.

13.3. You may withdraw consent at any time, through your own account, through the Business’s channels or through the Data Protection Officer, taking effect immediately for future sends.

13.4. Purple may send Businesses operational communications about the contracted service (billing, changes, incidents), which are inherent to the contract.

14. Data Protection Officer (DPO) and ANPD

In short

Our Data Protection Officer can be reached at dpo@treebird.com.br. If you prefer, you can also complain directly to the ANPD.

14.1. Purple maintains a Data Protection Officer (Encarregado, DPO), under art. 41 of the LGPD, as the channel between data subjects, Purple and the Autoridade Nacional de Proteção de Dados:

  • Data Protection Officer: Oluwatimilehin Diffu
  • Data Protection Officer email: dpo@treebird.com.br

14.2. Without prejudice to contacting us, the data subject may petition directly to the ANPD (Autoridade Nacional de Proteção de Dados, Brazil’s National Data Protection Authority), under art. 18, § 1º, of the LGPD.

15. Changes to this policy

In short

Material changes are announced in advance; the version in force is always on this page, with the date at the top.

15.1. This policy may be updated to reflect changes in the platform, in the providers or in the law. Material changes will be communicated with reasonable advance notice, by a notice in the Businesses’ dashboard, on the storefront or by email, depending on the audience affected.

15.2. The date of the last update appears at the top of the page. Continued use of the platform after the new version takes effect indicates awareness of it; where the law requires new consent, it will be requested.

15.3. Language. This policy is written in Portuguese, and that is its official and binding version. This English text is offered only for convenience of reading; if there is any divergence in meaning, the Portuguese text prevails.

16. Contact

In short

Official channels to talk about data and privacy.

Controller of the data described in clause 2.1: Purple Engineering Ltda, CNPJ 57.747.444/0001-02, Av. Paulista, 1106, sala 01, andar 16, Bela Vista, São Paulo, SP, CEP 01310-914, Brazil. The Terms of Use complete this document.

Questions about this document? Write to suporte@treebird.com.br. Personal data matters: dpo@treebird.com.br.