Privacy Policy

Last updated: July 21, 2026

Your privacy matters to us. This Privacy Policy explains how Angular e-Commerce LTDA ("Angular e-Commerce", "we", "us") collects, uses, shares and protects personal data in connection with our management platform for bookings and e-commerce, and with our own website. We comply with the Brazilian General Data Protection Law (LGPD, Law No. 13.709/2018) and, where applicable, with the EU General Data Protection Regulation (GDPR).

How Our Platform Works — and Why It Matters for Your Privacy

Angular e-Commerce provides a management platform to fitness and wellness businesses such as boutique studios, gyms, sports clubs and clinics (our "Clients"). There is no single "Angular app" and no single storefront: each Client operates its own website and, optionally, its own branded mobile app, both powered by our platform. Data may also be collected at the Client's front desk (through our management dashboard), at self-service kiosks, and at access-control turnstiles at the Client's facility. All of these surfaces provide the same functionality and therefore collect the same categories of data.

This Policy applies to the processing carried out by Angular e-Commerce on all of those surfaces, whatever brand they carry, as well as to our own website (angulare.com).

Our Two Roles: Controller and Processor

We process personal data in two distinct capacities:

  • As a controller — for data whose purposes we decide: visitors of angulare.com (contact forms, cookies, analytics) and the account, billing and support data of our business Clients and their staff.
  • As a processor ("operador" under the LGPD) — for the personal data of our Clients' end customers ("End Users": the members, students and patients of each business). For that data, the Client is the controller: it decides why and how End User data is used. We process it on the Client's behalf, under contract, strictly to deliver the platform's features.

If you are an End User (for example, a member of a studio that runs on our platform), the business you have a relationship with is your primary point of contact for privacy matters and data-subject requests. We support our Clients in answering those requests, and we offer you a direct self-service path for anonymization (see "Your Rights" below).

Information We Collect

Depending on how each Client configures the platform, we process the following categories of End User data:

  • Identification and contact: name, date of birth, national ID / taxpayer number (e.g. CPF), e-mail, phone, address, photo.
  • Account and usage: login credentials, plans and credit packages, bookings and waiting-list entries, attendance and check-in history, class and spot preferences, activity logs, device data (IP address, device type, error reports) and notification tokens.
  • Purchases and payments: order history, invoices and receipts, payment status. Card data is tokenized by our payment partners; full card numbers are not stored on our platform.
  • Communications: messages and campaign interactions (push, e-mail, SMS, WhatsApp) sent by the Client through the platform, and support interactions.
  • Health-related data (sensitive), where the Client enables it: physical-activity readiness questionnaires (PAR-Q) and, for clinics, clinical records maintained by the Client's professionals. Processed strictly so the Client can deliver its services safely, with restricted, role-based access.
  • Biometric data (sensitive), only in one specific scenario: see the dedicated section below.

From visitors of angulare.com we collect only what you submit through our contact form (name, e-mail, phone/WhatsApp, business details, message) and the cookie and analytics data described in our Cookie Policy.

Biometric Data

Facial biometric data is collected and processed only when a Client has enabled both its branded app and biometric access-control turnstiles at its facility. In that case:

  • biometric data is used exclusively for communication with the turnstile, to control physical access at the Client's facility;
  • it is not used for any other purpose — no profiling, no advertising, no data enrichment — and is never shared with third-party integrations;
  • it is collected on the basis of the End User's specific, informed consent, obtained by the Client as controller;
  • it is deleted when the Client disables the feature, when the End User's registration is anonymized, or upon a valid deletion request.

Purposes and Legal Bases

We process personal data for the following purposes, under the legal bases of the LGPD (articles 7 and 11) and the GDPR (articles 6 and 9):

  • Delivering the platform — bookings, purchases, check-in, payments, member communications: performance of a contract (ours with the Client, and the Client's with the End User).
  • Safety and quality of service — PAR-Q and clinical records where enabled: protection of health in a procedure carried out by the Client's professionals and, where required, the End User's specific consent obtained by the Client.
  • Biometric access control — the End User's specific consent, obtained by the Client.
  • Security, fraud prevention and platform improvement — legitimate interest, using aggregated or minimized data wherever possible.
  • Compliance with legal obligations — tax, accounting and consumer-protection records.

How Personal Data Is Shared

We do not sell personal data. Data is shared only as follows:

  • With the Client (the controller): End User data is available to the business the End User belongs to — that is what the platform is for.
  • With integrations the Client activates: if the Client connects third-party systems — for example Spivi, RD Station, Wellhub (Gympass), TotalPass, ClassPass, OMIE, WeHelp, or other tools via our API and webhooks — the End User data required by each integration is shared with that provider. Activating an integration is a decision made by the Client in its capacity as controller, and each provider processes data under its own privacy policy.
  • With service providers that help us run the platform (sub-processors): hosting, communication delivery (push, e-mail, SMS, WhatsApp) and payment processing — currently including Pagar.me, Asaas, Stripe, Google Payments and Apple Pay — all bound by contractual data-protection obligations.
  • For legal reasons: to comply with a law, regulation, judicial or administrative order, or to establish, exercise or defend legal claims.
  • In business transfers: if we are part of a merger, acquisition or asset sale, personal data may be included in the transferred assets; this Policy will continue to apply to it.

International Data Transfers

Personal data is stored and processed in Brazil, and may also be processed in the United States and Germany where we or our sub-processors maintain facilities. Integrations chosen by Clients may involve providers located in other countries. Whenever personal data is transferred internationally, we rely on the safeguards of chapter V of the LGPD and, where the GDPR applies, on adequacy decisions or appropriate safeguards such as the European Commission's standard contractual clauses.

How Long We Keep Personal Data

We keep End User personal data while the Client maintains its relationship with the platform and the End User's registration is active, and afterwards only for as long as necessary to comply with legal obligations — for example, Brazilian tax and accounting rules require transactional records (purchases, invoices) to be kept for up to five years. Data that is no longer required is deleted or anonymized.

Security

We apply technical and organizational measures appropriate to the risk: encryption in transit, role-based access control, payment-card tokenization, segregated environments, logging and monitoring. No method of electronic storage is 100% secure; we work continuously to protect the data entrusted to us, and we will notify controllers and the competent authorities of security incidents as required by the LGPD and the GDPR.

Your Rights — Including Self-Service Anonymization

Under the LGPD (article 18) and the GDPR (articles 15–22), you may request: confirmation that we process your data; access to it; correction of incomplete, inaccurate or outdated data; portability; deletion or anonymization of unnecessary or excessive data; information about sharing; restriction of or objection to certain processing; and review of automated decisions. Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of prior processing. We will never discriminate against you for exercising your rights.

Self-service anonymization: End Users can request the anonymization of their personal data directly in the Client's app or website. The request is fulfilled automatically when the End User has made no purchase and received no service in the previous 12 months. This window exists because transactional records must, by law, be retained for tax and accounting purposes. Anonymization is not the same as cancelling a membership: any active contract must first be terminated with the Client.

If you are inside the 12-month window, or wish to exercise any other right, contact the business you have a relationship with — the controller of your data. You may also contact our privacy team (see "Data Protection Officer and Contact" below), and we will route and answer your request together with the Client. You always have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD) or, in the European Union, with your local supervisory authority.

Children and Dependents

The platform supports family plans and dependent registrations, which may include minors. Personal data of minors is processed in the minor's best interest and is registered by a parent or legal guardian — typically the financially responsible person on the account — who provides the consent required by article 14 of the LGPD and, where applicable, article 8 of the GDPR. Guardians may exercise all of the rights described above on behalf of their dependents.

Cookies

Our own website uses cookies as described in our Cookie Policy and managed through our consent banner; analytics on angulare.com runs without cookies until you consent. Client websites and apps may set their own cookies and similar technologies, under the Client's responsibility as controller.

Data Protection Officer and Contact

Angular e-Commerce LTDA has appointed a Data Protection Officer ("encarregado", article 41 of the LGPD) as the channel for data subjects, Clients and the authorities:

Alessandro Reichert
[email protected]

Changes to This Policy

We may update this Policy to reflect changes in the platform, in our practices or in the law. The "last updated" date on this page always identifies the current version. Material changes will be communicated to our Clients, who are responsible for informing their End Users where required, and, when the law demands it, we will seek renewed consent.