Privacy
Policy

Last updated: 04/01/2026

 

Protecting your data is very important to us.

This is PagBrasil’s Privacy Policy. Here we explain how we process personal data provided by commercial establishments, through their legal representatives (“Merchants”), and by end users (“Users”) for the purpose of browsing, accessing and/or using the website pagbrasil.com (“Site”) or for the use of the Services (defined below) provided by PAGBRASIL INSTITUIÇÃO DE PAGAMENTO LTDA., a private legal entity enrolled with CNPJ under No. 14.630.124/0001-65, and PAGBRASIL TECNOLOGIA INSTITUIÇÃO DE PAGAMENTO LTDA., a private legal entity enrolled with CNPJ under No. 55.251.092/0001-74, both headquartered in Porto Alegre, State of Rio Grande do Sul, Brazil, at Avenida Carlos Gomes, No. 1,122, Tower A, 11th floor, Três Figueiras, ZIP Code 90470-282 (jointly referred to as “PagBrasil”).

Whenever we refer to “we,” “us,” or “our,” we are referring to PagBrasil. Whenever we refer to “you” or “your,” we are referring to the Merchant or the User (as applicable).

 

1. Who is PagBrasil?

PagBrasil is a payment facilitator that intermediates and processes payment transactions on behalf of domestic or international Merchants (“Services”), in accordance with applicable law and the Agreement entered into with each Merchant.

Our role in personal data processing: with respect to personal data collected through the use of the Site, PagBrasil generally acts as a controller; with respect to personal data collected through the use of the Services, PagBrasil may act as a controller or a processor, depending on the specific flow.

 

2. How we process personal data

Personal data means any information relating to an identified or identifiable natural person, also referred to as the data subject. When information does not allow the identification of a natural person, it is not considered personal data.

PagBrasil adopts internal policies and governance best practices to comply with applicable personal data protection rules, especially Brazil’s General Data Protection Law (LGPD). PagBrasil is committed to the security of information and the personal data of Merchants and Users throughout the process of browsing, accessing and using the Site, submitting support requests, and using the Services.

We process personal data and information shared by Users and Merchants when they access and use the Site or the Services in accordance with the LGPD, this Policy, and the Agreement entered into with each Merchant (when applicable).

PagBrasil’s processing activities follow the principles of purpose limitation, adequacy, necessity, security and transparency, and we adopt technical and administrative measures and a Privacy Program with policies, records and risk assessments. Therefore, the personal data of both Merchants and Users is protected and kept under strict confidentiality and is not sold, traded or disclosed to any third parties, except as expressly set forth in this Policy.

We do not intentionally collect or knowingly request personal data from individuals under 18 (eighteen) years of age. Users under 18 (eighteen) years of age should not submit personal data through our Site. If we become aware that we have collected personal data from an individual under 18 (eighteen) years of age, we will disregard such information and will not keep it in our databases.

 

3. What information and personal data we collect

By accepting the terms of this Policy, Merchants and Users expressly agree to provide only true, current and accurate information and personal data and not to misrepresent their identity or information in any manner when accessing and using the Site and/or the Services.

 

3.1. Data collected when you visit and browse the Site

Even without registration or login, when you visit and browse the Site we may receive technical information from your device (mobile or computer) and browser, such as IP address (Internet Protocol), date and time of access, browser type and version, pages visited, and approximate geolocation, in order to identify Merchants and Users, comply with legal obligations, prevent fraud, detect incidents, and improve the Site and our products.

We may also collect information such as visit duration, navigation paths, campaign attribution and other information about your preferences or activities on the Site when you consent to non-essential cookies and similar technologies, in order to measure the Site’s performance, set User preferences and recognize when the Site is visited by you.

You can change your preferences at any time through the Cookie Settings. However, if you disable certain types of cookies, some Site features may not function properly or may become unavailable, which may affect your browsing experience.

Cookies collected from Users or Merchants who browse our Site without being registered or logged in do not directly disclose personal data. Personal data will only be directly accessed if you choose to share it, such as when registering on the Site, filling out a form or contacting us.

 

3.2. Data collected when a Merchant registers or requests contact

We collect personal data from the Merchant’s legal representative, such as name, CPF (Brazilian taxpayer registry for individuals), email address and phone number, as well as Merchant information such as corporate name, CNPJ (Brazilian taxpayer registry for legal entities), address, website, time in operation and corporate type, when you register on the Site or request contact. Occasionally, we may request financial and economic information such as the balance sheet and profit and loss statement for risk analysis and onboarding..

 

3.3. Data collected for support and complaints

We collect only essential data to contact the Merchant or the User in cases of support requests or complaints, such as name, email address, phone number and address, as well as relevant information related to your support request in order to identify the best way to assist you.

 

3.4. Data processed to provide the Services

Depending on the payment method and the contracted flow, we may receive from Merchants information and/or personal data of Users who purchase their products or services, such as name/corporate name, CPF/CNPJ, email address, address, phone number, card or payment data, and banking details, as applicable, in order to process the payment transaction.

In these cases, PagBrasil generally acts as a processor of Users’ data, and the Merchant, as the controller, is responsible for ensuring that the processing of personal data is aligned with the purposes communicated to Users. If you have any questions, suggestions or complaints regarding the processing of such data, please contact the Merchant directly.

 

4. Purposes for which we use the personal data collected

We process personal data for the purposes listed below, with the respective legal bases, in accordance with the LGPD and other applicable provisions and regulations:

PURPOSE: Operation of the Site and security of the Services, such as prevention of fraud, money laundering and terrorist financing, and improvement of the service..

LEGAL BASES: Legitimate interest, compliance with a legal or regulatory obligation and credit protection.

DATA: Name, CPF, email, address, phone number, card or payment data, and banking data (depending on the type of transaction), when necessary.

 

PURPOSE: Onboarding and performance of the Services, such as payment processing, refunds, sending notifications, carrying out foreign exchange transactions and creating a prepaid payment account in cases of international transactions that require the remittance of funds abroad or the receipt of funds from abroad, when applicable.

LEGAL BASES: Performance of a contract to which the data subject is a party, compliance with a legal or regulatory obligation and credit protection.

DATA: Name, CPF, email, address, phone number, card or payment data, and banking data (depending on the type of transaction).

 

PURPOSE: Handling requests and support.

LEGAL BASES: Performance of a contract to which the data subject is a party, legitimate interest or consent, as applicable.

DATA: Name, CPF, email, address, phone number, card or payment data, and banking data (depending on the type of transaction), when necessary.

 

PURPOSE: Institutional marketing and relationship management (B2B).

LEGAL BASES: Consent or legitimate interest (with the possibility to opt out at any time).

DATA: Name, CPF, email and phone number of the Merchant’s representative.

 

5. Where and for how long we store the data

Personal data collected when accessing or using the Site and/or contracting the Services may be stored in a destination outside Brazil, including through service providers that use cloud technology, with appropriate safeguards and in compliance with the LGPD.

The retention periods for personal data comply with applicable legislation or regulation and the principle of necessity. Access logs to the Site will be stored for at least 6 (six) months, while contractual documents, financial documents and regulatory records will be stored for at least 5 (five) to 10 (ten) years, depending on the category and the applicable legal basis, or for as long as necessary for the full execution of the Services, for judicial, arbitral or administrative defense, to comply with legal and regulatory obligations, to prevent fraud or for credit protection purposes.

 

6. Sharing and international transfer of data

We may share personal data when necessary for the execution of the Services, to comply with legal and regulatory obligations, for credit protection and for defense in judicial, administrative or arbitral proceedings, within the limits and purposes set out in this Policy, both nationally and internationally, in compliance with the LGPD, Resolution No. 19/2024 of the Brazilian National Data Protection Authority (ANPD) and other applicable laws, and with the adoption of appropriate safeguards, including with: (i) the Central Bank of Brazil, and other banks, credit card acquirers, financial and payment institutions, payment arrangements, payment service providers and institutions participating in the transaction, domestic or foreign; (ii) anti-fraud service providers; (iii) infrastructure and storage providers; (iv) competent public authorities when required by law, regulation or order; and (v) third parties upon your authorization or another applicable legal basis.

 

7. Information security

We adopt technical and administrative security measures to protect the information stored in our records, making our best efforts to prevent attempts of breach or unauthorized access to our database. We maintain certifications and controls compatible with our sector, including PCI DSS Level 1. Among the security measures applied are data encryption, access control and logging, the use of firewalls, and software architecture designed to prevent intrusion and the use of HTTPS, with access restricted to authorized professionals.

Despite PagBrasil’s best efforts, we emphasize that the transmission of information over the internet involves risks, including network and operational factors that are beyond PagBrasil’s control, and it is not possible to guarantee the absolute security of information. Any transmission is the sole responsibility of Merchants and Users, who, by agreeing to this Policy and using the Site or the Services, expressly acknowledge and assume such responsibility.

 

8. How to exercise your rights

You may, at any time and upon request, exercise your rights in relation to your personal data, which include:

Confirm and access your personal data: You may request details and/or a copy of your personal data processed by us.

Update or correct your personal data: You may request the amendment or correction of your personal data if you have any reason to believe that it is incorrect or incomplete.

Withdraw consent, delete, block or anonymize your personal data: You may withdraw the consent provided whenever the processing of personal data is based on that legal basis, or also request the deletion, blocking or anonymization of your data. These operations will be carried out whenever PagBrasil acts as the data controller, except where the data is necessary for PagBrasil and/or third parties involved in the provision of the Services for purposes of judicial, arbitral or administrative defense, compliance with legal and regulatory obligations, performance of a contract (if applicable) and credit protection.

Request portability of your personal data: You may request the portability of your data to another provider, subject to trade secrets and confidentiality obligations, whenever PagBrasil acts as the controller of the data.

Understand with whom your data is shared: You may request information about the public and private entities with which PagBrasil has shared your data, subject to trade secrets and confidentiality obligations.

To exercise your rights, or if you have any questions or complaints related to this Privacy Policy, you may: (i) access our support channel, (ii) send an email to support@pagbrasil.com, or (iii) contact our Data Protection Officer, Júlia Fichtner, at dpo@pagbrasil.com.

 

9. Applicable law and jurisdiction

This Privacy Policy shall be interpreted under Brazilian law, in the Portuguese language, and the courts of the city of Porto Alegre/RS are elected to resolve any dispute or controversy involving this document, except where mandatory rules of personal, territorial or functional jurisdiction apply under applicable law.

 

10. Changes to this Policy

PagBrasil reserves the right to amend this Policy at any time to reflect legal, technical or operational changes. In case of material changes, we will inform Users and Merchants through a notice on our Site or by email and, when necessary, we will collect consent again. The current version will always be available on this page.

The use of the Site and the Services demonstrates agreement with the current version of this Policy. If you do not agree, the User or the Merchant must stop using the Site and the Services.

Cookie Policy

We use cookies to improve our website, analyze traffic, enhance the browsing experience and display personalized ads. By clicking "Accept Cookies," you agree to use cookies as outlined above. If you click "Reject," you will decline all non-essential cookies. You can adjust your preferences or manage cookies anytime in the “Cookie Settings” section. For more information, please refer to our Privacy Policy.