1. Who controls your data
BAZI is operated by BAZI TECNOLOGIA LTDA (CNPJ 68.967.065/0001-44, the Brazilian company tax ID), which is the controller of your data.
For any privacy matter, including contacting the Data Protection Officer (DPO), write to suporte@baziapp.co.
2. What data we collect
Data you provide
- Registration: name, email, profile photo and, when you sign in with Google or Apple, the account identifier.
- Purchase: the data needed to issue the ticket.
- CPF, at events with a per-person limit: some organizers limit how many tickets each person can buy. To apply that limit we ask for your CPF (the Brazilian taxpayer number) once. We don't keep the full number. From it we generate a scrambled code, from which it isn't possible to get back to the CPF, and it's that code that stays on your account — along with the last 4 digits, which exist only so that you can recognize, in settings, which document you registered. The code serves two purposes: preventing the same person from using several accounts to get around the limit, and counting your tickets at those events. The code stays as long as your account exists and is deleted along with it. The organizer receives neither the number nor the code.
- Communications: messages you send us by email or through the support channels.
Data generated by the wallet and by invites
- Wallet: entries for bonuses, cashback, balance used in purchases, reversals and expirations. The history is kept because it is the very proof of your balance — deleting an entry would leave the statement inconsistent.
- Invites: we record that an account was created from someone else's link and the identifier of the device used at the moment the bonus is released, only to prevent fraud in the referral program. Whoever invites does not have access to the identity of whoever joined through the link — they only see aggregate numbers.
Data collected automatically
- Usage: pages and events visited, clicks, the source of the visit and actions on the platform.
- Organizer metrics: we record which events you visited and which ones you clicked to buy, and we show those numbers added up to the organizer of that event — it's their performance report. Just like in the referral program, they see quantities, never who visited or who clicked. The individual record — that it was you who saw it — is deleted after 180 days; what remains is only the event's count, which doesn't identify anyone.
- Access log: we keep the date and time you sign in to the app, the method used (Apple, Google or email), the platform and the app version. It serves to keep the account secure and to help us understand how the product is used. The individual record is deleted after 180 days; only the date of your last access remains, for as long as the account exists.
- Technical: IP address, device type, browser, operating system and session identifiers.
- Approximate location: only to sort events by proximity, and only with your permission on the device.
Data we don't collect
We don't store your full card number or the security code. That data goes encrypted straight to the payment processor; we only get back the card brand, the last four digits and the transaction status.
2.1. Contacts from your address book
The app has an optional feature for finding people you already know: BAZI compares your address book with people who already have an account here and suggests them for you to follow. It ships off, only works after you allow it, and the app works in full without it.
These are two separate switches, and one does not turn on the other
- Sync my contacts: this is you uploading your address book to find people who already have an account. It ships off and only turns on with your consent, on the Privacy screen of the app.
- Appear to people who have my contact: this is the opposite — someone who already has your phone number or your email in their address book may get your profile as a suggestion. This one ships on, because it is what lets your friends find you, and you can turn it off whenever you want on the same screen.
Neither depends on the other: you can upload your address book without appearing to anyone, and you can be found without ever having uploaded an address book.
What leaves your device, and what stays on it
When you turn syncing on, the app sends the phone numbers and emails from your address book over the encrypted connection, and our server immediately converts them into a scrambled code — generated with a secret that exists only on the server and stored as a short fragment. That code is what we keep. The phone number and the email themselves are not stored, neither as text nor in any form that allows going back to them without our secret.
What never goes up: your contacts' names, and also photo, nickname, company, birthday, notes, address and any other address-book field. None of it leaves the device. When a suggestion shows up with the name you gave that person, that name was read from the address book on your own phone as the screen was drawn — it did not come from us, because we don't have it.
A contact is someone else's data
Your address book has people who don't use BAZI and decided nothing about this. That's why the feature was built to keep the least possible and to do nothing else with that data:
- the code serves one comparison and nothing beyond it: it finds accounts that already exist;
- if your contact has no BAZI account, the code matches no one — it does not become a record, does not become a list and does not tell us who they are;
- we never send a message, email, SMS or invitation to the contacts in your address book, and we never tell anyone that you have them in yours;
- that code does not feed advertising, is not sold and is not shared with organizers or with any other company;
- the suggestion runs in one direction only. You see who you have in your address book; never the list of who has you — showing that would be handing you other people's address books;
- anyone with an account who doesn't want to be found this way turns off “appear to people who have my contact” and stops coming up as a suggestion, even if they are already in many people's address books.
How long we keep it
- while syncing is on, the codes are refreshed at every sync;
- if you stop syncing and don't come back, everything is deleted on its own and the switch is turned off with it. The period in force appears on the Privacy screen of the app and, by the way the system is built, it never exceeds two years;
- if the text of this consent changes, we stop using your address book at that same moment and ask for your permission again; without it, whatever was stored is deleted within 7 days;
- if you delete your account, the codes from your address book, the key that let people find you and these preferences are deleted along with it.
How to erase it, at any time
On the Privacy screen of the app, “Remove synced contacts” erases every code from your address book off our servers and turns syncing off. The preference belongs to the account, not to the device: it takes effect on every device where you use BAZI. Simply turning syncing off there has the same effect — the stored address book is erased right away, with no waiting period. You don't have to ask anyone, and you lose nothing beyond that suggestion.
Legal basis: your consent (art. 7, I of the LGPD, the Brazilian data protection law) to send and use your address book, recorded with the date and the version of the text you read, together with legitimate interest (art. 7, IX) in connecting people who already know each other — handled with the minimization described above. You withdraw your consent on the same screen where you gave it.
3. What we use it for, and on what legal basis
- Performing the contract (art. 7, V of the LGPD): creating your account, processing payments, issuing and validating tickets, providing support.
- Complying with legal obligations (art. 7, II): keeping access logs for the period required by the Marco Civil, Brazil's internet civil framework, and preventing fraud and money laundering. Tax invoicing of the ticket is not covered here: BAZI intermediates the sale, and the ticket invoice is the organizer's.
- Legitimate interest (art. 7, IX): platform security, aggregate usage metrics and product improvement, always with an impact assessment and the possibility of objecting.
- Ticket limit per person (art. 7, IX): when the organizer limits the purchase, we generate and keep a scrambled code derived from your CPF — never the number. It's what allows us to apply the limit and prevent the same person from using several accounts to get around it. Without that code there's no way to tell ten new accounts from ten different people.
- Consent (art. 7, I): marketing communications, promotional push notifications, use of location and advertising cookies. You can withdraw your consent at any time.
4. Who we share it with
- Event organizers: when you buy a ticket, the organizer of that event starts to see your name, your @ and your account email, along with the ticket type, the purchase date and the check-in status. They can also export that list to check entry outside the app. It's the ticketing market standard, and it's what allows them to run the door and talk to the people going to their event.
What the organizer does not receive: your CPF, your phone, your date of birth and your ticket code — the last one is your entry credential and never leaves your app.
The legal basis is performance of the purchase contract: without knowing who bought, there's no way to let you in. From the moment they receive that data, the organizer acts as an independent controller — whatever use they make of it, including promoting future events, is their responsibility, and it's with them that you ask to be taken off the list. - Payment processors: Asaas (ticket purchases and payouts to organizers), Stripe (Clube BAZI and organizer plan subscriptions) and Apple or Google, when the subscription is purchased inside the app.
- Infrastructure: Supabase (database and authentication), Vercel (hosting and analytics), Google Firebase (push notifications).
- Meta Platforms (Facebook/Instagram), with your consent: the Meta Pixel records the pages you visit on this site and the purchase confirmation (amount, currency and event bought) so we can measure the results of our ads. We don't send your name, email or CPF.
- OpenAI: when you use the support assistant on this help page. What you write is sent so that it can understand the problem and draft the answer — see item 4.1.
- Authorities: upon a court order or valid legal request.
We never sell your personal data.
4.1. Support assistant
In the Help center there's an assistant that answers your questions on the spot. It's optional: the list of frequently asked questions and email support keep working without it. To answer, what you write is sent to OpenAI, which operates in the United States — an international transfer supported by art. 33 of the LGPD, with contractual safeguards.
- What we send: the message you wrote and the previous ones in the same conversation. When the question depends on a purchase of yours, we also send a summary of your latest orders — event, date, status, quantity and amount. We don't send your name, email, phone, CPF, card details or your ticket code.
- What is kept: from the use of the assistant, our servers record only counts, cost and response time — the content of your messages is not stored there. The conversation stays on your screen and disappears when you leave the page.
- If a support request is opened: then yes, what you wrote is kept, because it becomes the support history our team will read and reply to. You follow that history in “My support requests”.
- Decisions: the assistant doesn't decide refunds, cancellations or anything that affects your order. It answers questions and, when the case needs a person, opens a support request for our team.
Since you write freely, avoid including sensitive data or third-party data in the conversation — describe the problem; there's no need to repeat card numbers or passwords (we never ask for those).
5. International transfers
Some vendors process data outside Brazil. In those cases we require contractual protection clauses compatible with the level required by the LGPD, under arts. 33 and 34.
6. How long we keep it
- Active account: for as long as you keep the account.
- Purchase order: the order record itself (event, amount, status) is kept for as long as it's needed for the platform's history and to comply with legal obligations.
- Buyer data linked to the order: kept for 1 year from the transaction, because that's the window in which a charge can be disputed and we need to be able to prove and resolve the purchase. After that the order remains, without identifying you.
- Access logs: 180 days, meeting the 6-month minimum of the Marco Civil da Internet, Brazil's internet civil framework.
- After you delete your account: we anonymize or delete the data we don't need to keep because of a legal obligation within 30 days.
7. Your rights
The LGPD guarantees that you can, at any time:
- confirm that processing exists and access your data;
- correct incomplete, inaccurate or outdated data;
- request anonymization, blocking or deletion of unnecessary data or data processed in breach of the law;
- request portability to another provider;
- withdraw consent and object to specific processing;
- know which public and private entities we share your data with.
To exercise any of them, write to suporte@baziapp.co. We reply within 15 days.
8. Security
We use encryption in transit (TLS) and at rest, role-based access control, per-user data isolation in the database (RLS), audit logging and periodic permission reviews. No system is 100% infallible — if there's an incident with relevant risk, we notify you and the ANPD, Brazil's data protection authority, within the legal deadlines.
9. Cookies and similar technologies
We use cookies to:
- Essential: keep you signed in and protect checkout. They can't be turned off.
- Analytics: understand which pages and events generate interest, in aggregate.
- Advertising: the Meta Pixel, to measure the results of our ads on Facebook and Instagram. It only loads after you accept in the cookie banner — before that, no Meta tag runs.
Your choice is stored in this browser and can be changed at any time under “Cookie preferences”, in the footer. You can also block cookies in your browser settings, bearing in mind that the essential ones are needed to buy tickets.
10. Children and teenagers
The platform is intended for people 18 and over. We don't intentionally collect data from minors without a legal guardian's consent. If we identify such a case, we remove the data.
11. Changes to this policy
We may update this document. The update date is at the top of the page and relevant changes are communicated by email or inside the app. See also the Terms of use.