Skip to content

Privacy policy

How StarUp collects, uses, stores and protects personal data on this website, under Brazil's data protection law (LGPD).

Version of September 28, 2026

This is a courtesy translation. If there is any difference, the Portuguese version prevails.

This policy explains how StarUp Software Ltda ("StarUp"), Brazilian company registration (CNPJ) 51.090.626/0001-77, based in Belo Horizonte/MG, Brazil, handles personal data on the starup.srv.br website, under Brazil's General Data Protection Law (Law No. 13,709/2018, "LGPD").

1. Who the controller is

StarUp is the controller of the personal data processed on this website. For any privacy matter, email us at [email protected].

2. What data we collect

When you fill in a form (free trial request or contact), we collect:

  • name and email (required);
  • WhatsApp, company, product of interest and message (optional);
  • the language and the page you were on, and the date and time of your consent.

When you browse the website, our servers and Cloudflare, which protects and speeds up the site, log technical request data such as IP address, date and time, page visited, browser and operating system. These logs are used for security, abuse prevention and legal compliance.

Audience metrics. We use Cloudflare Web Analytics, which measures visits in aggregate, without cookies and without identifying you individually.

We do not collect sensitive data through the website, we do not use advertising cookies and we do not sell personal data.

3. Why we use data and on which legal basis

Purpose Data Legal basis (LGPD)
Reply to your trial or contact request form data consent (art. 7, I) and pre-contractual steps (art. 7, V)
Protect the site from attacks, spam and fraud, including the anti-bot check (Cloudflare Turnstile) technical browsing data legitimate interest (art. 7, IX)
Keep the access logs required by Brazil's Internet Civil Framework IP, date and time legal obligation (art. 7, II)
Understand, in aggregate, which pages are most visited non-identifying metrics legitimate interest (art. 7, IX)

When you subscribe to a product, the data needed for the subscription and billing will be processed to perform the contract (art. 7, V), under each product's terms.

4. Who we share data with

Only with providers the website needs to work, who process data on our behalf and under our instructions:

  • Cloudflare: content delivery, security, anti-bot checks and metrics;
  • Amazon Web Services (AWS): server hosting in the São Paulo region, and email delivery;
  • Mercado Pago: payment processing, when you subscribe to a plan.

We may also share data when required by law or a court order.

5. International transfers

Some providers, such as Cloudflare, operate servers in other countries. In those cases, transfers follow art. 33 of the LGPD, with providers that adopt contractual clauses and security measures compatible with Brazilian law.

6. How long we keep data

  • Trial and contact requests: while we are handling them and for up to 24 months after the last contact, unless you ask us to delete them sooner.
  • Access logs: for the minimum of 6 months required by Brazil's Internet Civil Framework (Law No. 12,965/2014, art. 15); then they are deleted.
  • Customer data: for the duration of the contract and the legal periods after it (for example, tax).

7. Your rights

Under the LGPD (art. 18), you may request, at any time and free of charge:

  • confirmation that we process your data, and access to it;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
  • data portability;
  • deletion of data processed based on your consent, and withdrawal of that consent;
  • information about the entities we share your data with.

To exercise any right, email [email protected]. We reply within 15 days. You may also file a complaint with Brazil's National Data Protection Authority (ANPD).

8. Privacy contact

The contact channel for data subjects and for the ANPD is [email protected].

9. Security

We use encrypted connections (HTTPS), restricted access to data, backups and continuous system updates. No system is completely immune to failures; if a security incident may pose a relevant risk to you, we will notify you and the ANPD, as the law requires.

10. Children and teenagers

The website is aimed at businesses and professionals. We do not knowingly collect data from anyone under 18.

11. Cookies

The public website sets no cookies of its own. See the details in our cookie policy.

12. Changes to this policy

We may update this policy. The version date appears at the top of the page, and important changes will be highlighted on the website.