| © 2026 Sinatra.

Sinatra, in compliance with the LGPD and ANPD Resolution 18, has appointed its Data Protection Officer, as detailed below:

  • DPO: Data Guide – Consultoria e Soluções em Proteção de Dados
  • Legal representative: Taynara Rodrigues Bernardo
  • Contact: privacidade@sinatra.pro
Terms of ServicePrivacy PolicyLGPD

Backed by

BlustoneCaravelaGR8 VenturesPlug And Play
a16z

Scout Fund

PRIVACY POLICY

1. PURPOSE OF THIS POLICY

We at Sinatra LTDA (Sinatra) are committed to complying with personal data protection laws, guaranteeing the rights of Data Subjects ("You") and the guidelines of the National Data Protection Agency (ANPD). Therefore, we have prepared this Privacy Policy ("Policy") with the aim of clearly and objectively informing you how we collect, process and protect your personal data in the context of the provision of our services.

Thus, to ensure transparency about the processing of personal data carried out by Sinatra, we make this Policy public.

On this website, the person responsible for the processing of the personal data collected is SINATRA LTDA, registered with the CNPJ n. 52.603.308/0001-25, headquartered at Rua Visconde de Pirajá, 414 - Ipanema, Rio de Janeiro - RJ, 22.410-905.

If you have any questions or need more information, please contact us by email: privacidade@sinatra.pro

2. DEFINITIONS

To understand this Policy, we present some definitions below:

National Data Protection Agency (ANPD): is the public administration body responsible for ensuring, implementing, and supervising compliance with the LGPD;

Controller: natural or legal person who is responsible for decisions regarding the processing of personal data.

Operator: natural or legal person, under public or private law, who processes personal data on behalf of the controller.

Personal data: information related to an identified or identifiable natural person.

Sensitive personal data: personal data on racial or ethnic origin, religious belief, political opinion, membership in a union or organization of a religious, philosophical or political nature, data related to health or sex life, genetic or biometric data, when linked to a natural person.

Person in charge of the Processing of Personal Data or "Person in Charge": an individual or legal entity appointed by the controller and operator, to act as a communication channel with the data subjects and the National Data Protection Agency (ANPD).

General Law for the Protection of Personal Data or "LGPD": refers to Law No. 13,708/2018, which provides for the processing of personal data, including in digital media, by an individual or by a legal entity governed by public or private law;

Subject: identified or identifiable natural person to whom the Personal Data processed refers, including leads, customers, service providers and Sinatra employees, depending on the specific case.

Processing: any operation carried out with personal data, such as those referring to the collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination or extraction.

Website: refers to the official website managed and administered by Sinatra, including all of its content, functionality and services made available through this website.

Website user: holder of Personal Data who visits and uses Sinatra's website through the domain https://www.sinatra.pro/pt;

3. WHAT IS SINATRA'S ROLE AS A DATA PROCESSING AGENT?

Sinatra will act as a Personal Data Operator in relation to its customers (Companies that trade online) when hiring Sinatra Software, considering that most of the purposes of use of the personal data processed are under their responsibility, in which case Sinatra will process personal data on behalf of this controller and following its guidelines. In other words, in general, we process data on behalf of Clients and meet the purposes they define.

With regard to website users and suppliers, Sinatra acts as a controller, when it is up to the organization to make decisions regarding the processing of personal data.

4. WHAT ARE YOUR RIGHTS?

In relation to your personal data, you have a number of rights! However, depending on your relationship with us or our Client, you will need to observe the points below:

  • If you are a website visitor, service provider or vendor, we may ask you for specific or additional information to help us confirm your identity and ensure your right to access your personal data (or to exercise your other rights). This is a security measure to ensure that personal data is not disclosed to anyone who does not have the right to receive it.

In this case, these rights may be exercised via e-mail at the following address: privacidade@sinatra.pro

  • If you are a user of the Sinatra Software (employee or representative of our client) and have questions about these issues or want to know how to exercise these rights, we recommend that you contact the company with which you have a relationship directly.

For your knowledge, below are some of these rights:

  • Right of confirmation: confirm whether there is processing of personal data about you by Sinatra;
  • Right of access: access the personal data about you processed by Sinatra;
  • Right to correction: to correct your personal data if it is incomplete, inaccurate or out of date;
  • Right to anonymization, blocking, or deletion: request the anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in violation of the LGPD;
  • Right to portability: if applicable, request the portability of personal data concerning you to another company, upon express request, subject to the limits relating to Sinatra's commercial and industrial secrets;
  • Right to erasure: request the deletion of personal data concerning you processed with your consent, according to the exceptions provided for in article 16 of the LGPD;
  • Right to information on shared use: request information from the public and private companies with which Sinatra has shared personal data;
  • Right to revoke consent: if applicable, revoke the consent given for the processing of personal data by Sinatra, at any time, upon express manifestation;
  • Right to petition the ANPD: petition in relation to personal data concerning you, against Sinatra, before the National Data Protection Agency (ANPD);
  • Right to object: oppose the processing of personal data carried out by Sinatra, based on the hypotheses provided for in articles 7 and 11 of the LGPD, other than consent, in the case of said law;
  • Right to review automated decisions: if applicable, request Sinatra to review decisions made solely with automated processing of data that concerns you and that affect your interests.

Do you have any questions about your rights? Access here and learn about your rights.

5. WHAT DATA AND INFORMATION DO WE PROCESS AND FOR WHAT PURPOSE?

All your data collected and/or provided through our website, other interactions with us, as well as shared by our client will be in compliance with the provisions of data protection legislation, as well as with this Privacy Policy, and will be treated as confidential, using them only for the purposes set forth herein.

The personal data we process are those shared by our customers, service providers or suppliers, as well as the data that you voluntarily enter or submit when accessing and interacting with the functionalities made available, which include:

Personal Data ProcessedCategory of HoldersPurpose of ProcessingLegal hypothesis that justifies the processing
Corporate name and emailSite usersReturn contactLegitimate interest
Name, email, phone, job titleLeadsContact and offer the productLegitimate interest
Name, Email, Phone & LicenseJob CandidatesParticipation in the selection processConsent
Name, address, CPF, e-mail, telephone, CPF and bank detailsService ProvidersHiring the professional and making the paymentContract Execution
Name, CPF and e-mailClient's legal representativeTo draft the contract and send it for digital signatureContract Execution
Name, corporate email and phone numberCustomer Contact or Focal PointFormalize the negotiation and make the delivery of the software operationally viable.Contract Execution
Name, address, CPF, e-mail and IPCustomer ConsumersSo that the software can perform anomaly detection of the customer's e-commerceLegal basis defined by the controller

Eventually, we may use your data for purposes not provided for in this Policy, but these will be within your legitimate expectations. Any use of your data for purposes that do not comply with this prerogative will be done with your prior authorization or other appropriate legal basis.

In addition, other types of data not expressly provided for in this Privacy Policy may be collected, provided that they are provided with the consent of the data subject, or that the collection is permitted or imposed by law, such as the provisions of the Civil Rights Framework for the Internet.

We reiterate that this Policy strictly prohibits Sinatra from selling, renting, transferring, trading, or disclosing Personal Data to unauthorized third parties.

6. DO WE USE COOKIES?

Yes, we use cookies! Cookies are text files sent by the website and stored on your device (computer, mobile phone, for example). These files contain information related to page navigation.

Cookies usually have an expiration date. Some cookies are automatically deleted when you close your browser (so-called session cookies), while others may be stored on your device for longer until they are manually deleted (so-called persistent cookies).

Sinatra uses the following types of cookies on its website:

  • Functionality cookies: These are cookies that memorize your preferences and choices (such as your username and preferred language, for example) for the best functioning of the website;
  • Advertising and marketing cookies: These are cookies that target ads according to your interests and limit the number of times the ad appears.

The use of cookies is based on Sinatra's legitimate interest. Thus, if you wish to refuse the installation of these cookies on your device and/or opt for the removal of cookies, you can manage the use of cookies in the following ways:

Cookie banner: you can choose whether or not to accept the use of cookies (manage your preferences in our cookie banner), except for those strictly necessary for the operation of the website.

Browser settings: You can adjust your browser settings to disable cookies or delete them. To do this, just click on the links below, depending on the browser you use:

  • Firefox
  • Chrome
  • Safari
  • Internet Explorer or Edge

By disabling all cookies in your browser, some functions essential to the functioning of the website may become unavailable.

It is important to clarify that Sinatra is not responsible for the use of cookies by third parties. Please be aware that cookies installed by third parties may continue to monitor your online activities even after you have logged out of our Platform. It is recommended that you clear your browsing data regularly.

7. SHARING OR DISCLOSURE OF PERSONAL DATA

The information collected will be used for the purposes referred to herein.

We will not share your information with third parties unless it is necessary to: 1. comply with legal obligations, including (i) legal process and requirements; (ii) establishing or exercising our legal rights or defense in legal proceedings; or (iii) as required by law; 2. for the hiring of third-party service providers for the purpose of operating the Platform, in which case, the Third Parties only receive your data to the extent necessary for the provision of the contracted services.

8. SECURITY IN THE PROCESSING OF YOUR PERSONAL DATA

The Sinatra website and platform are committed to protecting your privacy by applying technical and organizational measures capable of protecting your personal data from unauthorized access and from situations of destruction, loss, alteration, communication or dissemination of such data.

To ensure safety, solutions will be adopted that take into account: the appropriate techniques; the costs of application; the nature, scope, context and purposes of the processing; and the risks to the rights and freedoms of the holder.

Among the security practices we implement are:

  • Data encryption;
  • Access control based on the principle of least privilege;
  • Segregation of duties;
  • Internal information security policies;
  • Software architecture with intrusion prevention and use of HTTPS;
  • Institutional governance and continuous monitoring of logs;
  • Protection against unauthorized access and regular vulnerability testing.

Despite our best efforts and the measures we take, it is important to remember that due to the nature of the internet, there will always be risks. Elements that are outside of our control can be exploited by malicious actors, making it impossible to completely guarantee that there is no access to or misuse of personal data. This is a risk inherent to the use of computerized systems.

9. INTERNATIONAL TRANSFER

Sinatra is headquartered in Brazil and the personal data processed by Us is subject to Brazilian law.

However, this data may be transferred outside the national territory, because Sinatra uses suppliers that store personal data located in other countries, such as AWS (Amazon Web Service) located in the United States, which implies the International Transfer of Personal Data, as defined in the General Law for the Protection of Personal Data (LGPD) and Resolution CD/ANPD No. 19/2024.

We always prioritize hiring suppliers that adopt the necessary security measures to protect personal data and that carry out international transfers in accordance with the LGPD and the official resolutions and/or guidelines published by the National Data Protection Agency (ANPD) or competent body.

10. STORAGE AND DELETION OF PERSONAL DATA

After its collection and reception by Sinatra, the data is stored on an online server protected against invasions, leaks and deletion of the data.

Each Client has direct access only to its own data, and only Users duly registered by the Client are authorized to access it.

The data will be stored for the period necessary to achieve the purpose for which it was collected or until the end of the processing period. After this period, they will be eliminated in accordance with our Data Retention and Deletion Policy, except in the following cases: (i) when necessary to keep them to comply with legal or regulatory obligations, such as the provisions of article 15 of the Civil Rights Framework for the Internet, article 206 of the Civil Code and article 27 of the Consumer Protection Code; (ii) for the regular exercise of rights, including in contracts and in judicial, administrative or arbitration proceedings or (iii) when the data is anonymized for Sinatra's exclusive use.

The data shared by the customer will be stored and eliminated or returned as provided for in the contract.

11 PERSONAL DATA CONTROLLER OR "DATA PROCESSOR" AND HOW TO CONTACT US

Sinatra, in compliance with the LGPD and Resolution 18 of the ANPD, appointed its Data Officer, as provided below:

  • DPO: Data Guide - Data Protection Consulting and Solutions
  • Legal representative: Taynara Rodrigues Bernardo
  • Contact: privacidade@sinatra.pro

12. CHANGES TO THIS POLICY

We reserve the right to modify this Privacy Policy at any time and as many times as necessary, due to changes in our website, updates in our internal processes, or changes in the legislative scope, in order to ensure more and more security and convenience for you. Therefore, we recommend that you review it whenever possible.

In order to make it easier, we will always indicate at the end of the document the date of the last update.

Thank you for reading our Privacy Policy and we will always be available to assist you. If you have any questions or wish to obtain more information about this Policy, please contact us on the DPO channel: privacidade@sinatra.pro

Last updated: February 05, 2026.