Privacy Policy
Sundial Privacy Policy (Updated on 09/04/2025)
This website is maintained and operated by Sundial, a private law legal entity.
This website collects and uses some personal data belonging to those who use it. In doing so, the company acts as the controller of such data, and is subject to the provisions of Federal Law No. 13,709/2018 (General Personal Data Protection Law - LGPD).
The company respects your privacy and the protection of your Personal Data. Personal Data is used within legal and ethical limits and to provide greater care, all measures adopted to protect it were taken by Cartpanda Pay. And as a way of making the care taken transparent, we provide this privacy policy, which contains important information about:
- Who should use the site;
- What data is collected and how it is used;
- Your rights in relation to your personal data; and
- How to contact us.
- Who should use our website
This website should only be used by people over eighteen years of age. Therefore, children and teenagers should not use it.
- Data we collect and reasons for collection
This website collects and uses some personal data of users, in accordance with the provisions of this section.
- Personal data expressly provided by the user
The following personal data is collected that users expressly provide when using the website:
- Full Name;
- CPF;
- Address;
- Cell phone and/or landline;
- CEP;
- E-mail;
This data is collected at the following times:
- When the user registers on the website/payment system;
- When the user uses the contact form;
The data provided by our users is collected for the following purposes:
- So that the customer can access the company's platform;
- So that the customer can contact our Customer Service;
- So that our Customer Service can contact the customer.
- For the Company to offer exclusive offers, promotions and discounts to the customer.
- Sensitive data
Sensitive data will not be collected from our users, as defined in articles 11 et seq. of the Personal Data Protection Law. Therefore, there will be no collection of data on racial or ethnic origin, religious beliefs, political opinions, membership of a trade union or organization of a religious, philosophical or political nature, data relating to health or sexual life, genetic or biometric data, when linked to a natural person.
- Collection of data not expressly provided for
Eventually, other types of data not expressly provided for in this Privacy Policy may be collected, provided that they are provided with the user's consent, or, further, that the collection is permitted based on another legal basis provided for by law.
In any case, the collection of data and the processing activities resulting from it will be informed to the users of the website.
- Storage
Data is stored directly on the Cartpanda Pay platform, since all collection is done on this payment platform which we use on our website.
- Sharing personal data with third parties
We do not share your personal data with third parties. However, we may do so to comply with a legal or regulatory requirement, or to comply with an order issued by a public authority.
- How long will your personal data be stored?
Personal data collected by the website are stored and used for a period of time that corresponds to that necessary to achieve the purposes listed in this document and which consider the rights of their owners, the rights of the website controller and the applicable legal or regulatory provisions.
Once the personal data storage periods have expired, they are removed from our databases or anonymized, except in cases where there is the possibility or need for storage due to legal or regulatory provisions.
- Legal bases for the processing of personal data
A legal basis for the processing of personal data is nothing more than a legal basis, provided for by law, that justifies it. Therefore, each personal data processing operation must have a corresponding legal basis.
We process our users' personal data in the following cases:
- With the consent of the holder of the personal data;
- For the regular exercise of rights in judicial, administrative or arbitration proceedings;
- For the execution of a contract or preliminary procedures related to a contract to which the data subject is a party, at the request of the data subject.
- Consent
Certain personal data processing operations carried out on our website will depend on the user's prior consent, which must be expressed freely, in an informed and unequivocal manner.
The user may revoke their consent at any time, and if there is no legal hypothesis that allows or requires the storage of data, the data provided with consent will be deleted.
Furthermore, if desired, the user may not agree to any personal data processing operation based on consent. In these cases, however, it is possible that they will not be able to use some functionality of the website that depends on that operation. The consequences of the lack of consent for a specific activity are informed prior to the processing.
- Contract execution
In order to execute the contract eventually signed between the website and the user, other data related to or necessary for its execution may be collected and stored, including the content of any communications held with the user.
- User rights
The website user has the following rights, granted by the Personal Data Protection Law:
- Confirmation of the existence of treatment;
- Access to data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary, excessive data or data processed in non-compliance with the provisions of the law;
- Portability of data to another service or product provider, upon express request, in accordance with the regulations of the national authority, observing commercial and industrial secrets;
- Deletion of personal data processed with the consent of the holder, except in cases provided for by law;
- Information on public and private entities with which the controller shared data;
- Information about the possibility of not providing consent and the consequences of refusal;
- Revocation of consent.
It is important to highlight that, under the LGPD, there is no right to delete data processed based on legal grounds other than consent, unless the data is unnecessary, excessive or processed in a manner that does not comply with the law.
- How the holder can exercise his rights
To ensure that the user who intends to exercise his/her rights is, in fact, the holder of the personal data subject to the request, we may request documents or other information that may assist in his/her correct identification, in order to protect our rights and the rights of third parties. This will only be done, however, if absolutely necessary, and the applicant will receive all related information.
- Security measures in the processing of personal data
We employ technical and organizational measures capable of protecting personal data from unauthorized access and from situations of destruction, loss, misplacement or alteration of such data.
The measures we use take into account the nature of the data, the context and purpose of the processing, the risks that a possible violation would generate for the user's rights and freedoms, and the standards currently used in the market by companies similar to ours.
Among the security measures adopted by us, we highlight the following:
- Password storage using cryptographic hashes;
- Restrictions on access to databases;
- Monitoring physical access to servers;
- Limiting permissions to system modules.
- Use of secure website.
Even if we take all possible steps to prevent security incidents, it is possible that a problem may occur caused exclusively by a third party - such as in the case of hacker or cracker attacks, or even in cases of exclusive fault of the user, which occurs, for example, when the user transfers his/her data to a third party. Therefore, although we are generally responsible for the personal data we process, we are exempt from liability in the event of an exceptional situation such as these, over which we have no control.
In any case, if any type of security incident occurs that may generate risk or relevant damage to any of our users, we will notify those affected and the National Data Protection Authority about the incident, in accordance with the provisions of the General Data Protection Law.
- Complaint to a supervisory authority
Without prejudice to any other administrative or judicial remedy, holders of personal data who feel harmed in any way may file a complaint with the National Data Protection Authority.
Cookies
We use cookies on our website to collect information about the behavior of our visitors and customers. Cookies are small text files that are stored on your device when you access our platform. They allow us to recognize and monitor information about your activities and preferences while browsing our website.
These cookies are intended to:
- Analyze and monitor how our website and applications are used.
- Help us understand how visitors and customers use the Platform.
- Assist in the continuous improvement of the website, applications and communications to ensure we can deliver interesting and relevant content.
Cookies collect information including, but not limited to:
- Pages visited.
- Time spent on each page.
- Products or services viewed.
- Navigation behavior.
- Language preferences.
- Device used.
- Approximate geographic location.
By continuing to use our website, you consent to the use of cookies in accordance with this policy. If you do not wish cookies to be used, you can disable them in your browser settings, although this may affect the functionality of the website.
- Changes to this policy
This version of this Privacy Policy was last updated on: October 10, 2023
We reserve the right to modify these rules at any time, especially to adapt them to any changes made to our website, whether by making new features available or by deleting or modifying existing ones.
Whenever there is a modification, our users will be notified about the change.
By making a purchase on our website, you agree to our refund policy. Hefestus reserves the right to change this policy at any time, and we recommend that you review it periodically.