LGPD Privacy Policy

LGPD Privacy Policy / Política de Privacidade LGPD

Effective Date / Data de Vigência: July 23, 2025
Last Updated / Última Atualização: July 23, 2025

1. Introduction / Introdução

Refurbr.in ("Company," "we," "us," "our") is committed to protecting your personal data in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados - LGPD), Law No. 13.709/2018.

This Privacy Policy explains how we collect, use, store, process, share, and protect your personal data when you use our refurbished electronics marketplace platform.

2. Data Controller and Data Protection Officer / Controlador e Encarregado

Data Protection Officer (Encarregado de Proteção de Dados)

Email: info@refurbr.in

You may contact our DPO for any questions about your personal data or to exercise your rights under LGPD.

3. Personal Data We Collect / Dados Pessoais que Coletamos

3.1 Data You Provide Directly / Dados Fornecidos Diretamente

Registration and Account Data

  • Full name (Nome completo)
  • CPF (Cadastro de Pessoas Físicas)
  • Email address (Endereço de e-mail)
  • Phone number (Número de telefone)
  • Date of birth (Data de nascimento)
  • Postal address (Endereço)

Transaction Data

  • Payment information (credit/debit card, PIX keys)
  • Banking details (for sellers)
  • Purchase and sales history
  • Device information (brand, model, condition, IMEI)

Business Data (for Professional Sellers)

  • CNPJ (Cadastro Nacional da Pessoa Jurídica)
  • Company name and trade name
  • State and municipal registrations
  • Tax information

3.2 Data Collected Automatically / Dados Coletados Automaticamente

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Access logs and timestamps
  • Cookies and similar technologies
  • Approximate location (based on IP)
  • Navigation patterns and preferences

3.3 Sensitive Personal Data / Dados Pessoais Sensíveis

We do not intentionally collect sensitive personal data as defined by LGPD (racial or ethnic origin, religious beliefs, political opinions, health data, genetic data, biometric data, sexual life, or sexual orientation).

4. Legal Bases for Processing / Bases Legais para Tratamento

We process your personal data based on the following legal bases under Article 7 of LGPD:

4.1 Consent (Consentimento)

  • Marketing communications
  • Newsletter subscriptions
  • Optional profile features

4.2 Contract Performance (Execução de Contrato)

  • Account creation and management
  • Processing buy/sell transactions
  • Payment processing
  • Shipping and delivery

4.3 Legal or Regulatory Obligation (Obrigação Legal ou Regulatória)

  • Tax reporting and fiscal obligations
  • Anti-money laundering compliance
  • Consumer protection requirements
  • Court orders and legal requests

4.4 Legitimate Interests (Interesses Legítimos)

  • Fraud prevention and security
  • Platform improvement and analytics
  • Customer support
  • Business operations

4.5 Protection of Life or Physical Safety (Proteção da Vida)

  • Emergency situations
  • Safety investigations

4.6 Credit Protection (Proteção ao Crédito)

  • Credit analysis for payment methods
  • Default prevention

5. Purpose of Data Processing / Finalidade do Tratamento

We process your personal data for the following specific purposes:

  1. Marketplace Operations

    • Enable buying and selling of refurbished electronics
    • Process payments and refunds
    • Facilitate communication between buyers and sellers
    • Manage product listings and inventory
  2. Identity Verification and Security

    • Verify user identities
    • Prevent fraud and unauthorized access
    • Ensure marketplace integrity
    • Comply with KYC (Know Your Customer) requirements
  3. Customer Service

    • Respond to inquiries and complaints
    • Provide technical support
    • Send transaction notifications
    • Manage warranties and returns
  4. Legal Compliance

    • Comply with tax obligations
    • Meet regulatory requirements
    • Respond to legal requests
    • Maintain required records
  5. Marketing and Communications (with consent)

    • Send promotional offers
    • Inform about new features
    • Conduct market research
    • Personalize user experience
  6. Platform Improvement

    • Analyze usage patterns
    • Improve user interface
    • Develop new features
    • Optimize performance

6. Data Sharing / Compartilhamento de Dados

6.1 Categories of Recipients

We may share your personal data with:

  1. Service Providers (Operadores)

    • Payment processors (PagSeguro, Mercado Pago, PIX operators)
    • Shipping companies (Correios, transportadoras)
    • Cloud hosting providers
    • Customer support tools
    • Analytics services
  2. Business Partners

    • Device inspection services
    • Warranty providers
    • Insurance companies
    • Marketing platforms
  3. Other Users

    • Limited information visible in transactions
    • Public seller profiles
    • Reviews and ratings
  4. Government Authorities

    • Tax authorities (Receita Federal)
    • Law enforcement agencies
    • Regulatory bodies
    • Courts and judicial authorities
  5. Financial Institutions

    • Banks and payment institutions
    • Credit protection agencies
    • Anti-fraud services

6.2 International Data Transfers

Your data may be transferred to countries outside Brazil, particularly to India where our servers are located. We ensure adequate protection through:

  • Standard contractual clauses
  • Appropriate safeguards as required by LGPD
  • Compliance with ANPD regulations on international transfers

7. Your Rights Under LGPD / Seus Direitos sob a LGPD

Under LGPD, you have the following rights:

7.1 Confirmation and Access (Confirmação e Acesso)

Right to confirm whether we process your data and access it

7.2 Correction (Correção)

Right to correct incomplete, inaccurate, or outdated data

7.3 Anonymization, Blocking, or Deletion (Anonimização, Bloqueio ou Eliminação)

Right to request anonymization, blocking, or deletion of unnecessary or excessive data

7.4 Portability (Portabilidade)

Right to transfer your data to another service provider

7.5 Deletion (Eliminação)

Right to delete personal data processed with your consent

7.6 Information about Sharing (Informação sobre Compartilhamento)

Right to know with which public and private entities we share your data

7.7 Information about Consent (Informação sobre Consentimento)

Right to be informed about the possibility of denying consent and consequences

7.8 Revocation of Consent (Revogação do Consentimento)

Right to revoke consent at any time

7.9 Opposition (Oposição)

Right to oppose processing when carried out in violation of LGPD

7.10 Review of Automated Decisions (Revisão de Decisões Automatizadas)

Right to request review of decisions made solely based on automated processing

8. How to Exercise Your Rights / Como Exercer Seus Direitos

To exercise your rights, contact us through:

Email: privacidade@refurbr.in
Phone: 0800-XXX-XXXX
Online Form: www.refurbr.in/lgpd-rights
Mail: [Address]

Verification Process

We will verify your identity to protect your data:

  • Request confirmation of CPF
  • Security questions about your account
  • Email or SMS verification

Response Timeline

  • Immediate response for simple requests
  • Up to 15 days for complex requests
  • We will inform you if we need additional time

9. Data Retention / Retenção de Dados

We retain your personal data for:

Data Type Retention Period Legal Basis
Account data Active account + 5 years Legal obligations
Transaction records 10 years Tax and consumer law
Tax documents 5 years Tax obligations
Customer support 2 years after resolution Legitimate interest
Marketing data Until consent withdrawal Consent
Access logs 6 months Security

10. Data Security / Segurança dos Dados

We implement technical and administrative measures to protect your data:

Technical Measures

  • Data encryption in transit and at rest
  • Secure servers with firewall protection
  • Regular security updates and patches
  • Access control and authentication
  • Intrusion detection systems

Administrative Measures

  • Employee training on data protection
  • Confidentiality agreements
  • Access on a need-to-know basis
  • Privacy by design principles
  • Regular security audits

Incident Response

In case of a security incident, we will:

  • Notify affected users within 72 hours
  • Report to ANPD as required
  • Take measures to minimize damage
  • Investigate and document the incident

11. Children and Adolescents / Crianças e Adolescentes

Under 12 Years

Our service is not directed to children under 12. We do not knowingly collect data from children under 12.

12-18 Years (Adolescents)

Adolescents may use our service with parental supervision. We process adolescent data only:

  • With parental consent when required
  • In their best interest
  • With enhanced protection measures

Parents may exercise rights on behalf of their children by contacting our DPO.

12. Cookies and Similar Technologies

Types of Cookies We Use

  1. Essential Cookies

    • Required for platform functionality
    • Cannot be disabled
  2. Analytics Cookies

    • Help us understand usage patterns
    • Improve user experience
  3. Marketing Cookies

    • Personalize advertisements
    • Measure campaign effectiveness
  4. Preference Cookies

    • Remember your choices
    • Customize your experience

Cookie Management

You can manage cookies through:

  • Browser settings
  • Our cookie preference center
  • Email preferences

13. Automated Decisions / Decisões Automatizadas

We use automated processing for:

  • Fraud detection
  • Product recommendations
  • Risk assessment
  • Price suggestions

You have the right to:

  • Request human review
  • Contest automated decisions
  • Understand the criteria used

14. Data Protection Impact Assessment / Relatório de Impacto

For high-risk processing activities, we conduct Data Protection Impact Assessments (RIPD) to:

  • Identify and minimize risks
  • Ensure compliance with LGPD
  • Protect your rights and freedoms

15. Updates to This Policy / Atualizações desta Política

We may update this policy to reflect:

  • Changes in our practices
  • New legal requirements
  • ANPD guidance

We will notify you of material changes through:

  • Email notification
  • Platform announcement
  • Website banner

16. Contact Information / Informações de Contato

Privacy Team

Email: info@refurbr.in
Address: 209, B UNIT, SONA UDYOG PREMISES CO-OP. SOCIETY
LTD., ANDHERI EAST, MUMBAI, Mumbai City, Maharashtra,
400069

National Data Protection Authority (ANPD)

For complaints or more information:
Website: www.gov.br/anpd
Email: encarregado@anpd.gov.br

17. Governing Law / Lei Aplicável

This Privacy Policy is governed by Brazilian law, particularly:

  • Lei Geral de Proteção de Dados (Law 13.709/2018)
  • Consumer Protection Code (Law 8.078/1990)
  • Brazilian Civil Code (Law 10.406/2002)

Any disputes shall be resolved in the courts of [City], Brazil.


Acceptance / Aceitação

By using Refurbr.in, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Esta Política de Privacidade está disponível em português mediante solicitação através do e-mail privacidade@refurbr.in.