Privacy Policy & LGPD Notice

Last updated: 2026-09-09 · The English version governs; translations are provided for convenience as they become available.

1. Controller

The controller of the personal data described here is Uara Desenvolvimento e Soluções Tecnológicas Ltda. ("Uara Tech", CNPJ 67.797.098/0001-20, NIRE 35250435658), Alameda Rio Negro, 503, Sala 2020, Alphaville, Barueri, SP, 06454-000, Brazil, which operates Synallax (Lei Geral de Proteção de Dados - Lei 13.709/2018 - and, where applicable, the GDPR). Contact for all privacy matters, including requests to the person in charge (encarregado/DPO): contact@synallax.com.

2. What we collect

Account data: name, e-mail address, plan, and hashed credentials (sign-in codes and API keys are stored only as hashes). This covers operators and participants alike: a participant signing in on a storefront gives an e-mail address and, the first time, a name. Early-access list: if you requested early access on synallax.com before the launch, we still hold your e-mail address, the side you chose (buyer or seller), your language and the IP address of the request; the form is closed. Marketplace data: the listings, parameters, offers, acceptances and configuration that operators and participants create - this is the service's content. Billing data: subscription status and Stripe identifiers; card details go directly to Stripe and never reach us, and Stripe receives your e-mail address as the customer of the subscription. Technical data: server logs (IP address, timestamps, requests) kept for security and troubleshooting. Analytics: aggregate, cookieless web statistics on synallax.com and on the console (Umami): pages viewed, referrer, country, browser and device type, and which buttons were clicked. The IP address is hashed with a salt that changes every day and is never stored, and the browser's Do Not Track setting is honoured. There is no analytics on storefronts or embedded widgets.

3. What we deliberately do not collect

No card numbers, no tracking pixels, no advertising identifiers, no sale of personal data - to anyone, ever. Operators see the participants of their marketplace by the name given at sign-in and an internal id, together with their offers by price and quantity; participant e-mail addresses are never shown to operators.

3b. Content uploaded by operators - the operator is the controller

The platform is not designed to store personal data inside marketplace content. Listings, product parameters, descriptions and images should describe things for sale - a room, a court, an hour of service - never identified or identifiable people, and never sensitive data (LGPD art. 5, II). Operators must not upload third parties' personal data into their marketplaces.

If an operator nevertheless chooses to include personal data in the content they upload, the operator - not Synallax - determines the purposes and means of that processing and is therefore its controller under the LGPD, solely responsible for having a legal basis, honouring data subjects' rights, and answering to the ANPD for it; Synallax merely hosts that content as a neutral technical provider (operador). We may remove such content and suspend the account under the Terms of Service. By using the platform, each operator undertakes to comply with the LGPD (and any equivalent law applicable to them) for everything they upload.

4. Purposes and legal bases (LGPD art. 7)

We process data to provide the contracted service (execution of contract), to bill subscriptions (execution of contract and legal obligation), to secure the platform and prevent fraud (legitimate interest), and to send strictly operational e-mails such as sign-in codes and service notices (execution of contract). The early-access list relies on your consent: we use that address only to tell you the platform is open, and you withdraw by writing to us. Any other marketing would require your separate consent, which we do not ask for.

5. Sharing

Data is shared only with the processors needed to run the service: Stripe (subscription payments), GoDaddy (our servers, and the outgoing e-mail that carries sign-in codes and notices) and Umami (the cookieless analytics of section 2). Each acts under its own compliance obligations. We disclose data to authorities only under a valid legal order.

6. International transfers

Our servers are hosted in the United States (GoDaddy, Virginia) and our processors operate there too, so your data is stored outside Brazil and, where the GDPR applies, outside the European Union. Where LGPD or GDPR applies, transfers rely on the safeguards those laws admit, such as the standard contractual clauses of the processors involved.

7. Retention

Account and marketplace data are kept while the account is active and for 30 days after closure (export window), then deleted; closure is requested at contact@synallax.com (Terms, section 12). The journaled record of marketplace activity that other participants relied on (offers, acceptances) may be retained in anonymised or legally required form. Early-access entries are kept until you ask us to remove you or we have told everyone on the list that the platform is open. Billing records are kept for the period tax law requires. Security logs rotate within months.

8. Your rights (LGPD art. 18)

You may request confirmation of processing, access, correction, anonymisation, portability, deletion of unnecessary data, information about sharing, and review of automated decisions - by writing to contact@synallax.com, preferably from the e-mail address on your account so we can confirm it is you. We answer within the legal deadlines. You may also complain to the ANPD (Autoridade Nacional de Proteção de Dados).

9. Security and incidents

Credentials are stored hashed; transport is TLS everywhere on public surfaces; marketplace state is journaled and replayable, which also protects integrity; access to production is restricted to the operating team. If a security incident may cause you relevant risk or harm, we notify the ANPD and you within the deadlines and in the form the LGPD requires (art. 48).

10. Cookies and local storage

We use one strictly necessary session cookie (sx_session, httpOnly) to keep you signed in - on the console and on storefronts alike - plus the anti-forgery token cookie that protects our forms, and the browser's local storage to remember your language. No analytics or advertising cookies: the analytics described in section 2 set none.

11. Children

The service is for businesses and adults; we do not knowingly process children's data.

12. Changes

Material changes to this policy are announced by e-mail or in the console before they take effect.