Back

Privacy Policy

Last updated: 03/08/2026

1. Controller and Scope

This Policy describes how Feriados API handles personal data when operating the website and API at https://feriadosapi.com. Under applicable data protection regulations (including LGPD), we act as the data controller for personal data processed on our platform.

2. Data We Collect

2.1 Registration and Authentication Data

  • Email address
  • Password (handled securely by the authentication provider, never stored in plain text)
  • Organization name
  • Social login data (Google/GitHub), when you opt for OAuth

2.2 Billing and Subscription Data

Full credit card details are processed directly by Stripe. We never store full credit card numbers on our servers.

  • Customer/subscription/invoice identifiers on Stripe
  • Contracted plan, subscription status, and billing cycle
  • Payment and invoice history

2.3 Usage and Security Data

  • Accessed endpoints, HTTP methods, and timestamps
  • IP addresses and user-agent headers
  • Quota consumption by organization and plan
  • Technical events for fraud prevention, security monitoring, and auditing

2.4 Cookies and Local Storage

  • Essential cookies for authentication/sessions and active organization context
  • Cookie consent preferences
  • Temporary local data for the onboarding workflow

3. Purposes and Legal Bases

We process personal data to:

  • Perform the contract and provide the service (API, dashboard, billing, and support)
  • Comply with legal and regulatory obligations
  • Prevent fraud, abuse, and security incidents (legitimate interest)
  • Improve product features and website performance (legitimate interest and/or consent where applicable)
  • Operate analytics and non-essential tools only with explicit consent where required

4. Data Sharing

We do not sell personal data. We share personal data only with trusted operators and service providers necessary for our operations, such as:

  • Supabase (authentication and database infrastructure)
  • Stripe (billing, subscriptions, and invoicing)
  • Resend (transactional email delivery, such as team invitations)
  • Google Analytics, Microsoft Clarity, and Vercel Analytics/Speed Insights (metrics and performance monitoring)
  • OAuth providers (Google and GitHub), when utilized by you
  • Public authorities, when required by law or legal order

5. International Data Transfers

Some of our service providers may process data outside of Brazil. In such cases, we adopt standard data protection safeguards, including standard contractual clauses and appropriate technical security measures.

6. Data Retention

  • API access logs: generally up to 90 days
  • Technical webhook logs: up to 30 days
  • Pending team invitations: until expiration, cancellation, or acceptance
  • Account data: while the account remains active and thereafter for the applicable legal retention period
  • Billing data: in accordance with fiscal, legal, and contractual requirements

7. Security

We implement robust technical and organizational measures to protect personal data, including encryption in transit, strict access controls, and security monitoring. While no system is completely immune, we continuously work to mitigate risks.

8. Your Rights

Where applicable under data protection laws (such as LGPD/GDPR), you may request: confirmation of processing, access, rectification, anonymization, blocking, deletion, data portability, information about data sharing, consent revocation, and objection.

To exercise your privacy rights, please contact us at the privacy email below. We will respond within the legally prescribed timeframes.

9. Cookies and Similar Technologies

We use strictly necessary cookies for authentication/session management and non-essential cookies for analytical insights. You can accept or reject non-essential cookies via our consent banner and adjust your preferences by clearing browser cookies and local storage.

Google Analytics operates under Consent Mode, and Microsoft Clarity is activated only after you grant consent for non-essential cookies.

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect legal, regulatory, or operational updates. The effective version will always be posted on this page along with the updated revision date.

11. Contact and Data Protection Officer

For questions regarding privacy, data subject rights, or compliance inquiries:

Your privacy matters to us

Explore our Brazilian holidays API with total transparency

View Plans