Privacy Policy (LGPD)
Lanzinha respects user privacy and processes personal data under the Lei Geral de Protecao de Dados (LGPD, Law 13.709/2018). This policy explains what data we collect, why, how we keep it safe, who we share it with, and how you can exercise your rights as a data subject.
Controller: Lanzinha [operator legal name, CNPJ pending], Brazil
Data Protection Officer (DPO): [email protected]
1. Who we are and when this applies
Lanzinha is operated by [operator legal name, CNPJ pending] in Brazil. This policy applies to anyone who visits the Lanzinha website, signs up for an account, tops up a wallet, opens a room, or joins a room as a player. For LGPD purposes, Lanzinha is the data controller for account, billing, support, security, and operational data.
2. Data we collect
Account: email address, display name, Firebase Authentication identifier, language preference, optional Minecraft username, optional Discord webhook URL. Service: room and session timestamps, world identifiers, server-side log lines necessary to debug your session, IP address when you sign in, agent telemetry such as CPU, memory, disk usage, and bytes sent or received during a session. Payments: payment-provider transaction identifier (InfinitePay for Pix/card; on-chain transaction hash for crypto), top-up amount, payment status, and timestamp. Support: messages you send to support and any context you choose to provide. We do not collect credit-card data, banking credentials, or Pix keys, since InfinitePay handles the card/Pix payment surface; crypto payments are recorded on public blockchains by design.
3. How we use the data
We use personal data to operate your account and rooms, charge for compute usage, prevent fraud and abuse, secure the platform, comply with legal and tax obligations, send service-availability and account-status notifications, and provide support. We do not sell personal data, do not use personal data to train artificial-intelligence models we own, and do not run third-party advertising trackers.
4. Legal bases (LGPD art. 7)
Operating your account and rooms relies on execution of contract. Billing, fraud prevention, and security rely on legitimate interest and legal obligation. Storing wallet-ledger entries for fiscal record-keeping relies on legal obligation. Service-availability emails rely on legitimate interest. Optional features that require user opt-in, such as Discord webhooks or push notifications, rely on consent that you can withdraw at any time from your account settings.
5. Sharing and subprocessors
We share data with subprocessors only as necessary to operate, secure, bill, monitor, and support the service. The current subprocessor list, including purpose, data categories, and region, is available at /legal/subprocessors. We update it when providers change.
6. International transfer
Most processing happens in the southamerica-east1 region of Google Cloud (Sao Paulo, Brazil). Some operations by Google Cloud or InfinitePay (CloudWalk) may occur outside Brazil for support, monitoring, or fraud-prevention purposes; both providers commit to data-protection safeguards consistent with the LGPD, including isolation, encryption in transit and at rest, and access logging.
7. Cookies, local storage, and telemetry
We use first-party cookies and localStorage for authentication, session security, language and theme preference, and short-lived user-interface state. We use Sentry for error reporting and performance monitoring; sensitive payload fields are redacted before transmission, and session replay, if enabled in the future, will mask text, inputs, and media by default. We do not use third-party advertising cookies, third-party analytics that build cross-site profiles, or tracking pixels.
8. Security
Data in transit uses TLS 1.2 or higher. Data at rest uses Google Cloud encryption. Production access is limited to engineers strictly required to operate the service; access is logged, secrets are stored in Google Secret Manager, and credentials rotate on a regular schedule. We back up Firestore data through Google-managed daily exports and world snapshots through Cloud Storage object versioning.
9. Retention and deletion
Account, room, session, and telemetry data are kept while your account is active and for twenty-four months after closure for fraud, dispute, audit, and legal-defense purposes. Wallet ledger entries and payment records are kept for five years as required by Brazilian fiscal regulations. World snapshots associated with a deleted account are erased no later than ninety days after account closure. Anonymized aggregate statistics with no link to an individual may be kept longer.
10. Your rights (LGPD art. 18)
You may request confirmation that we process your data, access to that data, correction of incomplete or out-of-date data, anonymization, blocking, or deletion of unnecessary data, portability, information about with whom we have shared your data, review of automated decisions if applicable, and revocation of consent. Send your request to [email protected]. We respond within fifteen days. Some requests cannot be fully honored when retention is required by law (for example, fiscal records); we will explain the basis in those cases.
11. Children and adolescents
Lanzinha is directed to users at least eighteen years old who can authorize payment. Minors may participate in a room opened by an account holder as players, including children under twelve, with consent and supervision of a parent or legal guardian. Account holders are responsible for ensuring that any minors who play on their rooms have appropriate supervision. If you become aware that a minor has created an account on Lanzinha without the consent of a parent or legal guardian, contact [email protected] so we can remove the account and erase the associated personal data.
12. Changes and contact
We may update this policy as the product, law, or our subprocessors change. Material changes are announced by email and reflected here with a new last-updated date. Continued use after the effective date means the updated policy applies. For privacy questions, contact [email protected].
13. Complaints to the ANPD
If you believe your rights under the LGPD are not being respected, you may also file a complaint with the Autoridade Nacional de Protecao de Dados at anpd.gov.br.