This Privacy Policy applies to data processed by RB SERVICOS EM TECNOLOGIA DA INFORMACAO LTDA, a Brazilian company (CNPJ 61.189.543/0001-93, Curitiba/PR, Brazil). It references Brazilian data-protection law (LGPD — Law 13.709/2018). Where mandatorily applicable, data-protection laws of your jurisdiction (such as GDPR in the European Union, PIPEDA in Canada, or CCPA in California) shall prevail over conflicting provisions herein.
Who we are
Bingo Pé Quente is a recreational bingo application (75-ball version) intended for family and social use. This policy describes how we process personal data, in compliance with the Brazilian General Data Protection Law (Law 13.709/2018 — LGPD) and the Brazilian Civil Internet Framework (Law 12.965/2014).
What data we collect
2.1. On the website (bingopequente.com.br)
- Technical access records: IP address, browser type and operating system, page requested and time. They are recorded automatically by the website host (Vercel) when it delivers each page; on the hosting plan we use, these records are deleted after 1 hour. We do not download or keep any copy of them. Legal basis: legitimate interest (art. 7, IX of LGPD), for website security and fixing errors.
- Vercel Analytics: cookieless and anonymous statistical measurement system provided by Vercel Inc. (United States). It does not use cookies, does not assign persistent identifiers to visitors and does not perform individual profiling. Because it is anonymous and cookieless, it is active for all visitors. Legal basis: legitimate interest (art. 7, IX of LGPD).
- Google Analytics (GA4): audience-measurement tool by Google LLC (United States), enabled only after your explicit consent in the cookie banner. When enabled, it uses cookies (_ga, _ga_*) and processes your IP address in anonymized form to understand how the site is used and improve it. Data is processed by Google in the United States (international transfer — art. 33 of LGPD) and retained for up to 14 months. Legal basis: consent (art. 7, I of LGPD), revocable at any time by declining or clearing the site's cookies. If you do not accept, Google Analytics is not loaded and none of its cookies are created.
- The site does not use advertising pixels (Meta, TikTok, Google Ads) or individual profiling tools.
2.2. In the application
- No account and no sign-up: the application does not require login nor collect email, phone, ID, or address. You may enter a name or nickname and choose an avatar to personalize the experience — stored only on your device, never sent to our servers, and which you can leave blank, change, or delete at any time.
- Device data: advertising identifier (AAID), used only for non-personalized ads — see section 4 — and anonymous error reports via Sentry. Legal basis: legitimate interest.
- Internal authentication: the application authenticates calls to internal Edge Functions using the project's public (publishable) key. No personally identifying data is sent to or stored at Supabase.
- Purchases (Party and Grand Bingo): processed by Google Play Billing. We do not have access to your payment data. To confirm the purchase and unlock what was bought, we store on our server the receipt identifier (purchase token) associated with a pseudonymised device identifier — never your name, email or card data. Legal basis: performance of a contract (LGPD, art. 7, V).
- Card scanner: the reading is done on the device itself, by a component that works without a connection. The photo is not sent to our servers or to third parties, is not stored and never leaves your phone.
- Reading the caller's QR code: the camera reads the code shown on the caller's screen to bring the drawn balls and the event to your device. The reading happens on the phone itself; the image is not sent to our servers or to third parties and is not stored.
- Voice number entry (optional): when you tap the microphone to speak a number, the audio is captured and sent to your device's speech recognition service (on Android, usually Google) to convert speech to text. Bingo Pé Quente does not record or store the audio and uses it only to mark the spoken number; depending on the device, the audio may be processed on the speech recognition provider's servers. You can always type the numbers manually. Legal basis: execution of service at the data subject's request (art. 7, V of LGPD).
- Application access log (legal obligation): each time the app is opened, we securely record the date and time of access, your IP address in encrypted form, and your app’s technical identifier (user agent and app version), solely to comply with the mandatory retention of internet application access records required by art. 15 of the Brazilian Civil Internet Framework (Law 12.965/2014). The IP address is encrypted on the server and can only be disclosed under a court order (art. 22 of the same law); we do not use it for profiling or to identify you in ordinary use of the app. Legal basis: compliance with a legal obligation (art. 7, II of LGPD).
- Application usage counts (product funnel): we record, in aggregated form and without any device, person or session identifier, how many devices completed steps such as finishing the welcome screen, finishing a game, using TV Mode, the tiebreaker, an event or Watch Mode, running into a locked feature, opening the Plans screen, watching a video to unlock a feature, or completing a purchase, grouped by day, country and app version. We also count how many devices opened the app again 1, 7 and 30 days after the first time: for this, the date of the first opening is kept only on your device, and the server receives only the range (1, 7 or 30 days), never the date. And we record, in the same aggregated way, how many Scanner card readings were accepted or rejected, to measure recognition quality — never the photo, never its content, never who took it. None of these records allow us to identify you or your device. Legal basis: legitimate interest (art. 7, IX of LGPD), to understand and improve the application.
2.3. Third-party components bundled in the app
- Components that run entirely on your device and transmit nothing: Google ML Kit Text Recognition, which reads the card entirely on the device — it works offline and does not send the image to Google —, the camera's QR code reader, which also reads the code on the device itself, plus the interface, audio and local storage components.
- Components that communicate with servers: Google AdMob (ads, free version only), Google Play Billing (purchases), Google Play (review request and new-version notice, which query the store directly, without going through our servers), Sentry (error reports), Supabase (internal Edge Functions for purchase confirmation, access records and aggregated usage counts), and your device's own speech recognition service if you use voice input. What each of them processes is described in items 2.2 and 3 of this policy.
- The list of open-source components and their licenses is in item 8.1 of the Terms of Use.
International data transfer
The Scanner performs no international data transfer: the card is read on your device and the photo is not sent to any server, in Brazil or abroad. The transfers described below concern the other services of the app and the website.
Other services with possible international transfer:
- Vercel Inc. (United States) — website hosting and Vercel Analytics (cookieless, anonymous measurement, with no cookies or personal identifiers).
- Google LLC (United States) — Google Analytics (GA4), audience measurement enabled only after your explicit consent. When active, it processes browsing data via cookies on Google's servers in the United States.
- Supabase (AWS infrastructure, São Paulo region, Brazil — this data does not leave the country) — the app's internal Edge Functions: purchase confirmation with Google Play, application access records (date, time and encrypted IP, kept for 6 months), and aggregated application usage counts, with no device, person or session identifier, kept for 180 days.
- Google AdMob (United States) — display of ads in the free version.
- Sentry (stored in Germany, European Union) — collection of anonymous error reports.
- Google Play Billing (United States) — purchase processing and receipt verification.
- Device speech recognition service (on Android, usually Google — United States) — used only if you choose voice number entry, to convert speech to text. The audio is not stored by us.
Standard contractual clauses and safeguards
Transfers to operators in countries without an adequacy decision follow art. 33, II of the LGPD and ANPD Resolution CD/ANPD No. 19/2024, which approved the International Data Transfer Regulation and the Brazilian standard contractual clauses. Google already offers these Brazilian clauses in its data processing terms. Sentry (error reports) stores data in Germany, and the European Union's level of protection is recognised as adequate by ANPD (Resolution CD/ANPD No. 32/2026; LGPD, art. 33, I). Vercel (United States) hosts the website: receiving the visitor's IP address is what makes it possible to deliver the page the visitor asked for, so this transfer relies on art. 33, IX, together with art. 7, V, of the LGPD — and the technical logs last 1 hour at most. Vercel Analytics runs on that same hosting: the IP address only passes through it to form a temporary code, discarded within 24 hours, and what is stored are anonymous counts, which are not personal data (LGPD, art. 12). Per-operator detail is recorded in the Records of Processing Activities (RoPA — LGPD art. 37).
Links to third-party sites
The website and the app may contain links and buttons leading to third-party sites — for example, stores and marketplaces (such as Etsy) where we sell printable cards, and our social networks. When you click, you leave our website or app and become subject to the privacy policy and terms of the destination site. We do not control and are not responsible for the privacy practices of these third parties — we recommend reading each one's policy.
To measure where visits come from, some of these links use campaign parameters (UTM) in the address. These parameters are just campaign labels, read by the same measurement tools already described in section 2 (Vercel Analytics and, subject to consent, Google Analytics), and do not collect any additional personal data.
Advertising (only in the free version)
Blocked categories
The free version displays Google AdMob ads: banners, native ads (within the screens), full-screen ads at the end of a round or of a Scanner card-reading session, and rewarded videos, which only play when you choose to watch them — in exchange for an extra card in the game, a period without ads or a feature unlocked until the end of the round. The ad categories gambling, betting, alcohol, and dating are blocked (through category blocking configured in our AdMob account, together with the G content rating, which limits ads to general audiences). Anyone who buys Party or Grand Bingo sees no ads at all.
Ads are always NON-personalized: the advertising identifier (AAID) is not used to build a profile or for behavioural advertising — Google uses it only to cap ad frequency and prevent fraud. Legal basis: legitimate interest (LGPD, art. 7, IX). You can reset or delete this identifier at any time in Android Settings → Privacy → Ads. In the European Economic Area, the United Kingdom and Switzerland, consent is collected through Google's form (UMP) before the first ad — see section 12.
Your rights (LGPD, art. 18)
You may request:
- Confirmation of the existence of processing
- Access to data
- Correction of incomplete or outdated data
- Anonymization, blocking, or deletion of unnecessary data
- Data portability
- Deletion of data processed with consent
- Information about sharing
- Withdrawal of consent
Since the application does not require registration, most data is processed anonymously. To exercise any right, send an email to contato@bingopequente.com.br. Data portability (art. 18, V) can be exercised directly via the Export Data feature, which generates a file with your data.
Retention
- Scanner photos: the reading happens on your own device — the photo is not sent to any server, in Brazil or abroad, and is not stored by us.
- Website logs (Vercel hosting): 1 hour — the host's period on the plan we use; we keep no copy.
- Error reports (Sentry): 30 days.
- Purchases: the receipt identifier (purchase token) and the pseudonymized device identifier are kept for as long as the entitlement lasts — Party and Grand Bingo are permanent, so deleting this record would take away what you already paid for (LGPD, art. 16, I). Accounting/tax records follow their own legal retention periods.
- Application access logs (encrypted IP + date/time): 6 months, as required by art. 15 of the Brazilian Civil Internet Framework (Law 12.965/2014).
- Application usage counts (product funnel, aggregated and with no device, person or session identifier): 180 days.
Security
Technical and organizational measures
We adopt reasonable technical measures (HTTPS, encryption in transit, server-side API key separation) and organizational measures to protect your data. In case of an incident, we will notify ANPD and the affected data subjects within a reasonable period, according to art. 48 of LGPD.
Children and adolescents
Bingo Pé Quente is rated for ages 14+ and is not directed to children under 14. The app does not require sign-up and does not send to our servers personal data of children and adolescents — email, phone, ID, address or any direct personal identifier (LGPD, art. 14). Any name or nickname and avatar chosen to personalize the experience remain only on the device.
Parents and guardians must supervise adolescents' access to the application and website, explicitly authorize any paid purchases processed through Google Play and ensure these Terms of Use are read.
Changes to this policy
This policy may be updated. Significant changes will be announced on the website and within the application. The date of the last update is always at the top of this document.
Contact channel for data subjects and the ANPD
RB SERVICOS EM TECNOLOGIA DA INFORMACAO LTDA (Brazilian Tax ID/CNPJ 61.189.543/0001-93, Curitiba/PR) is a small-scale processing agent and, under art. 11 of ANPD Resolution CD/ANPD No. 2/2022, is exempt from appointing a data protection officer. We keep a direct channel for data subjects and for the ANPD: contato@bingopequente.com.br. Requests from data subjects are answered within 15 days (LGPD, art. 19, II).
Applicable laws and regulations
This policy is governed by Brazilian law, in particular:
- Law 13.709/2018 (LGPD) — Brazilian General Data Protection Law
- Law 12.965/2014 (Brazilian Civil Internet Framework)
- Law 8.078/1990 (Brazilian Consumer Protection Code)
- Law 10.741/2003 (Statute of the Older Adult)
- Law 13.146/2015 (Brazilian Inclusion Act), art. 63 — accessibility of websites and apps, following WCAG 2.1 level AA guidelines
- Decree 5.296/2004 — accessibility for persons with disabilities and reduced mobility
- ANPD Resolution CD/ANPD No. 2/2022 — small-size processing agents
- ANPD Resolution CD/ANPD No. 4/2023 — dosimetry and application of sanctions
- ANPD Resolution CD/ANPD No. 15/2024 — security incident reporting
- ANPD Resolution CD/ANPD No. 18/2024 — duties of the Data Protection Officer
- ANPD Resolution CD/ANPD No. 19/2024 — international data transfers and standard contractual clauses
- ANPD Resolution CD/ANPD No. 32/2026 — recognition of the European Union's adequacy
Users in the European Economic Area, the United Kingdom and Switzerland (GDPR)
This section applies to you if you are located in the European Economic Area (EEA), the United Kingdom or Switzerland. In those territories, Regulation (EU) 2016/679 (GDPR), the UK GDPR and the Swiss Federal Act on Data Protection (nFADP) apply to the processing described in this Policy and prevail over any conflicting provision of the other sections. The controller is RB SERVICOS EM TECNOLOGIA DA INFORMACAO LTDA, Brazilian Tax ID (CNPJ) 61.189.543/0001-93, headquartered in Curitiba/PR, Brazil — contato@bingopequente.com.br.
12.1 Legal basis for each processing activity (GDPR, art. 6)
- Application access log (date, time and encrypted IP): legitimate interests (art. 6(1)(f)) — service security, abuse prevention and incident investigation. Please note: section 2 of this Policy cites art. 15 of the Brazilian Civil Internet Framework as the ground for this log. That is a Brazilian statute and, for you, it does NOT serve as a legal basis — art. 6(3) GDPR requires that a legal obligation derive from Union or Member State law. For you, therefore, the basis is legitimate interests, and you may object to it at any time (art. 21).
- Crash and diagnostic reports: legitimate interests (art. 6(1)(f)) — keeping the app working and fixing failures. No direct personal identifier is involved, and sending your IP address to the diagnostics service is disabled.
- Advertising (free version only): consent (art. 6(1)(a)), collected through Google’s form (UMP) before the first ad and withdrawable at any time via the privacy options button inside the app, as easily as it was given (art. 7(3)).
- In-app purchases: performance of a contract (art. 6(1)(b)) — confirming the receipt with Google and restoring the purchased product when you change devices.
12.2 Your rights under the GDPR
- Access to your data and to this information (art. 15)
- Rectification of inaccurate data (art. 16)
- Erasure (art. 17)
- Restriction of processing (art. 18)
- Portability (art. 20)
- Objection to processing based on legitimate interests (art. 21) — this covers the access log and the diagnostics described in 12.1
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing (art. 7(3))
- Not to be subject to automated decision-making producing legal effects (art. 22) — we make none
To exercise any of them, write to contato@bingopequente.com.br. We reply within one month, extendable by two further months where the request is complex, always with prior notice (art. 12(3)). Exercising your rights is free of charge.
12.3 International transfer to Brazil
The data described in this Policy is processed in Brazil, on infrastructure located in the São Paulo region. Since 26 January 2026, Brazil has been the subject of a European Commission adequacy decision (Implementing Decision (EU) 2026/179, art. 45): transfers from the European Economic Area need no other instrument. The United Kingdom and Switzerland have their own rules and are not covered by that decision; for people there, the transfer relies on the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 (art. 46(2)(c)). In every case we keep supplementary technical measures: the IP address is pseudonymised by a salted hash and encrypted with AES-256-GCM before being stored, and the key is kept outside the database. Where other sections of this Policy state that the data "does not leave Brazil", read: Brazil is the destination of the transfer, not a guarantee that no transfer occurs. You may request a copy of these decisions and safeguards at the contact above.
12.4 Age of consent and advertising
The app is not directed at children under 16 in the EEA, requires no registration, and asks for neither a date of birth nor any data that would allow us to determine your age. Precisely because we cannot determine it — and in order not to process the data of anyone below the age of consent in their country, which art. 8 GDPR sets between 13 and 16 depending on the Member State — every ad request originating in the EEA, the United Kingdom and Switzerland is tagged as "under the age of consent" and receives exclusively NON-personalised ads. We build no profiles, use no advertising identifiers for profiling, and carry out no behavioural advertising.
12.5 Representative in the European Union and right to lodge a complaint
We have not designated a representative in the European Union because we consider the derogation in art. 27(2)(a) GDPR applicable: the processing described here is occasional, does not include special categories of data (art. 9) or data relating to criminal convictions (art. 10), involves neither profiling nor behavioural monitoring, and is unlikely to result in a risk to your rights and freedoms — the app works without an account, without registration and without any direct personal identifier. We will reassess this position if the nature or scale of the processing changes. Regardless, you may lodge a complaint with the supervisory authority in your country (art. 77) — for instance the CNIL in France, the AEPD in Spain, the BfDI in Germany, the CNPD in Portugal, the ICO in the United Kingdom or the FDPIC in Switzerland — without prejudice to contacting us first at the address above.
By using the Bingo Pé Quente website or application, you declare that you have read and understood this Privacy Policy.
