1. Introduction
Your privacy is important to us. This Privacy Policy explains how Chute Certo collects, uses, stores, and protects your personal data in compliance with the General Data Protection Regulation (GDPR).
2. Data Controller
The data controller for your personal data is Chute Certo, based in Portugal. For any questions related to data protection, you can contact us at contacto@chutecerto.pt.
3. Data Collected
We collect the following data: Account data (email, phone, username); Payment data (processed securely by Stripe); Usage data (pages visited, features used); Device data (browser type, operating system, IP address).
4. Legal Basis
We process your data based on: Contract performance (service provision); Legitimate interest (security, fraud prevention, service improvements); Consent (marketing communications, when applicable).
5. Third Parties
We share data with the following service providers: Stripe (payments); Twilio (SMS verification); Resend (transactional emails); PostHog (analytics); OneSignal (push notifications); API-Football (match data); Anthropic (AI processing). All partners are GDPR compliant.
6. Your Rights
Under GDPR, you have the right to: Access your data; Rectify incorrect data; Delete your data (right to be forgotten); Export your data (portability); Withdraw consent at any time; Object to processing; File a complaint with the CNPD.
7. Data Retention
We keep your data as long as your account is active. After account deletion, data is removed within 30 days, except when required by law to retain it longer.
8. Security
We implement technical and organizational measures to protect your data, including encryption in transit and at rest, secure authentication, and continuous security monitoring.
9. Changes
We may update this policy periodically. We will notify you of any significant changes via the email associated with your account or through a notice on the platform.
10. Contact
To exercise your rights or for privacy questions, contact us at contacto@chutecerto.pt. You may also file a complaint with the Portuguese Data Protection Authority (CNPD).