How Treebird processes personal data of businesses and of businesses’ customers, under the Lei Geral de Proteção de Dados (LGPD), Brazil’s data protection law.
Last updated: August 6, 2026
In short
Treebird is operated by Purple Engineering Ltda. For your company’s data (registration, billing), Purple is the controller; for the data of a Business’s customers (reservations, contacts, spending), the Business is the controller and Purple is the processor, handling everything under its instructions. We collect what the service needs, such as name, phone and email for reservations and messages, and CPF (Brazilian taxpayer number) when payment requires it; card data never passes through our servers, and the content of the messages sent is not stored, only delivery metadata.
We do not sell personal data: we share it only with the providers that make the platform work, named in this policy. You can request access, correction, deletion and portability. A Business’s customer talks to the Business first, which is the controller of their data, or writes to our Data Protection Officer at dpo@treebird.com.br. This English text is a convenience translation of the Portuguese original, which is the official version and prevails over it.
The summary is there to help you read; what is legally binding is the full text below.
In short
This policy covers both sides of the platform: the companies that hire Treebird and the people who use those companies’ storefronts.
1.1. This Privacy Policy describes how Purple Engineering Ltda (“Purple”, “we”), operator of the Treebird platform, processes personal data in Brazil, in compliance with Lei nº 13.709/2018 (LGPD, Brazil’s data protection law), the Marco Civil da Internet (Lei nº 12.965/2014, Brazil’s Internet Civil Framework) and other applicable rules.
1.2. Purple and Treebird are not the same. Purple Engineering Ltda is the legal entity that processes the data and answers for it in the roles described in section 2. Treebird is the brand and the software platform through which Purple provides the service; it is not a legal entity of its own. When this policy says “Treebird”, the processing agent behind it is always Purple.
1.3. It applies to:
1.4. This policy complements the Terms of Use. Capitalized terms not defined here have the meaning given there.
1.5. Which addresses it covers. Treebird uses two addresses with different roles, and this policy covers both:
1.6. It does notcover a Business’s own sites, social networks and systems outside the platform, even when linked from the storefront, nor the sites of the providers named in section 6, which have policies of their own.
In short
Data of the contracting company: Purple decides and answers for it (controller). Data of a Business’s customers: the Business decides (controller) and Purple carries it out (processor). This split defines who you go to in order to exercise your rights.
2.1. Purple as controller. For the data of Businesses and their representatives (registration, contacts, billing data, team access records, communications with our support), Purple defines the purposes and is the controller, under art. 5º, VI, of the LGPD.
2.2. Purple as processor. For the data of a Business’s Customers (identification, contact, reservations, spending history, loyalty balances, preferences), the Business is the controller and Purple is the processor (art. 5º, VII), processing that data solely to provide the contracted service and in line with the Business’s lawful instructions, documented in the Terms of Use.
2.3. The practical consequence: data subject requests about data processed on a Business’s storefront must be addressed to the Business first, which is the party that decides on them. Purple helps the Business respond and, when contacted directly, forwards the request to the Business, without prejudice to acting in the cases where the law imposes an obligation of its own.
2.4. In limited situations Purple processes Customer data as controller: compliance with its own legal obligations (tax, accounting, security), defense in proceedings and fraud prevention on the platform.
2.5. The relationship between the Business (controller) and Purple (processor) is governed by documented instructions, as set out in art. 39 of the LGPD: section 22 of the Terms of Use governs security, subprocessors, assistance to the controller, incident notification and what happens to the data at the end of the contract.
In short
Name, phone and email for reservations and accounts; CPF when payment requires it; spending and loyalty data inside the storefront; technical access records. Card data is tokenized in your browser and never reaches our servers.
The platform does not deliberately collect sensitive data (art. 5º, II, of the LGPD). Free-text fields, such as CRM notes or reservation remarks, must not be used by the Business to record sensitive data; responsibility for entering them lies with the controller that entered them.
In short
We use data to run reservations, payments and messages (performance of a contract), to comply with the law (legal obligation), to keep the platform secure (legitimate interest) and to send marketing only with your authorization (consent).
Where processing relies on legitimate interest, it is preceded by an assessment of the impact on the data subject and limited to the minimum necessary; the data subject may object as described in section 10.
Automated decisions. The platform does not make solely automated decisions producing significant legal effects on data subjects (there is no credit profiling or automatic refusal of registration, for example). Operational automations, such as ordering queues with the priorities of Lei nº 10.048/2000 (priority service law) or routing messages between WhatsApp and email, follow fixed, transparent rules. If a solely automated decision with a significant effect ever exists, the data subject will have the right to review under art. 20 of the LGPD.
In short
We share data only with the providers that make the platform work, each one named below with its function. We never sell personal data.
6.1. Personal data is shared only to the extent necessary, with the following service providers (subprocessors, when Purple acts as processor):
6.2. Besides the providers above, data may be shared: with the Business that controls its Customers’ data; with public authorities, upon legal obligation or valid order; and in corporate transactions involving Purple, in which case the assignee takes on the obligations of this policy.
6.3. Purple does not sell or rent personal data and does not share it for third-party advertising.
In short
Some providers are outside Brazil. When data leaves the country, it happens with the safeguards of art. 33 of the LGPD, through contractual protection clauses.
7.1. The platform is operated with data resident in Brazil as a guideline; even so, providers listed in section 6 process data in other countries, notably in the United States.
7.2. These transfers take place on the basis of art. 33 of the LGPD, through contractual data protection clauses signed with each provider (data processing agreements, DPAs, incorporating standard clauses), ensuring a level of protection equivalent to this policy and to the LGPD.
7.3. Copies of the applicable safeguards may be requested from the Data Protection Officer (section 14), except for confidential passages.
In short
Encryption in transit and at rest, encrypted credentials, permission-based access, no customer passwords stored, and an audit log of sensitive actions.
No system is immune. In the event of a security incident with relevant risk or damage to data subjects, Purple will notify the ANPD (Brazil’s National Data Protection Authority), the affected controlling Businesses and, where applicable, the data subjects, within the deadlines set by regulation (art. 48 of the LGPD).
In short
We keep data while the account exists. After a business’s contract ends, 90 days for export and then deletion or anonymization, except what the law requires us to keep (tax and financial records, for example).
Anonymized data, unable to identify a person, may be kept with no time limit for statistics and service improvement.
In short
Access, correction, deletion, portability, information about sharing and withdrawal of consent. A business’s customer exercises them with the business first; our DPO also handles them.
10.1. Under art. 18 of the LGPD, you may request:
10.2. How to exercise them. A Business’s Customer: address the request first to the Business, the controller of your data, through the channels shown on the storefront; the platform gives it the tools to respond (export of your data and deletion). You may also write to our Data Protection Officer (section 14), who will forward the request and follow up on it. Business or team member: write directly to the Data Protection Officer.
10.3. We respond within a timeframe consistent with ANPD regulation: confirmation and access in simplified format immediately where possible, or by a full statement within 15 days, and the remaining requests within a reasonable period, stated on receipt. We may ask for proof of identity in order to protect the data itself.
In short
When you delete your data, what the law requires us to keep (financial records) is kept without your identifiers: the transaction still exists, but it stops pointing to you.
11.1. Deletion requests are met through the mechanism of anonymization with record retention: personal identifiers (name, phone, email, account links) are irreversibly removed or replaced, while the records that the law or a documented legitimate interest requires us to keep (transaction amounts, dates and methods, loyalty entries, tax documents) remain, now without pointing to an identifiable person.
11.2. Surviving deletion, for the periods in section 9: financial and tax records, access records required by the Marco Civil, audit logs and proof of consent. Nothing survives that allows the data subject to be contacted or identified outside those purposes.
11.3. Deleting the sign-in account (login) is not the same as deleting the records a Business keeps about its customer; for the latter, section 10.2 applies.
In short
The platform is not aimed at anyone under 18. Reservations must be made by adults; each venue’s entry rules belong to the business.
12.1. The platform is not intended for people under 18, and we do not deliberately collect data of children and adolescents. Reservations, appointments and payments must be made by an adult, who may include minors under their responsibility as companions (for example, the number of seats in a reservation).
12.2. Minimum age policies for entry and stay at each venue are defined and enforced by the Business, in accordance with local law.
12.3. If we identify processing of a minor’s data carried out contrary to this policy, the data will be deleted, except where the law requires it to be kept.
In short
Operational messages (confirmation, reminder, code) are part of the service. Marketing only with a recorded opt-in, and opting out is easy and immediate.
13.1. Transactional messages (reservation confirmations, reminders, access codes, receipts, queue notices) arise from performing the service you requested and do not depend on marketing consent; they carry no promotional content.
13.2. Marketing to the Customer (offers, news from a Business) is only sent with prior, recorded consent (opt-in with date and time), collected in a prominent way. Consent is specific to each Business and managed separately from the transactional flow.
13.3. You may withdraw consent at any time, through your own account, through the Business’s channels or through the Data Protection Officer, taking effect immediately for future sends.
13.4. Purple may send Businesses operational communications about the contracted service (billing, changes, incidents), which are inherent to the contract.
In short
Our Data Protection Officer can be reached at dpo@treebird.com.br. If you prefer, you can also complain directly to the ANPD.
14.1. Purple maintains a Data Protection Officer (Encarregado, DPO), under art. 41 of the LGPD, as the channel between data subjects, Purple and the Autoridade Nacional de Proteção de Dados:
14.2. Without prejudice to contacting us, the data subject may petition directly to the ANPD (Autoridade Nacional de Proteção de Dados, Brazil’s National Data Protection Authority), under art. 18, § 1º, of the LGPD.
In short
Material changes are announced in advance; the version in force is always on this page, with the date at the top.
15.1. This policy may be updated to reflect changes in the platform, in the providers or in the law. Material changes will be communicated with reasonable advance notice, by a notice in the Businesses’ dashboard, on the storefront or by email, depending on the audience affected.
15.2. The date of the last update appears at the top of the page. Continued use of the platform after the new version takes effect indicates awareness of it; where the law requires new consent, it will be requested.
15.3. Language. This policy is written in Portuguese, and that is its official and binding version. This English text is offered only for convenience of reading; if there is any divergence in meaning, the Portuguese text prevails.
In short
Official channels to talk about data and privacy.
Controller of the data described in clause 2.1: Purple Engineering Ltda, CNPJ 57.747.444/0001-02, Av. Paulista, 1106, sala 01, andar 16, Bela Vista, São Paulo, SP, CEP 01310-914, Brazil. The Terms of Use complete this document.
Questions about this document? Write to suporte@treebird.com.br. Personal data matters: dpo@treebird.com.br.