Privacy for your Pix operation
- We do not ask for your online banking password.
- We do not sell personal data.
- We use data to authenticate users, provide Pix features, manage access, deliver support and protect the service.
- Bank API credentials and digital certificates are handled only to run integrations selected by the user.
- Data subjects may request access, correction and deletion through the channels described below.
1. Data controller and contact
PAINEL DESENVOLVIMENTO DE SISTEMAS LTDA., trading as Painel Pix, registered in Brazil under CNPJ 62.885.922/0001-80, with its registered address at Passagem São José, 152, Maguari, Ananindeua, Pará, Brazil, determines how account, authentication, service access, support, security, plan payment and platform administration data is handled.
Privacy requests can be sent to painelpixapp@gmail.com. Initial support is also available through WhatsApp at +55 91 99376-9597. To protect the account, we may require identity verification through the registered email address.
2. Scope and processing roles
This policy applies to painelpixapp.com.br, Painel Pix Web, the Painel Pix Android application, related APIs and Painel Pix support channels.
Painel Pix acts as controller for user account, subscription, access period, security and support data. For payer and transaction data viewed by a merchant or professional using the service, that customer generally determines the business purpose and acts as controller, while Painel Pix provides the technical processing required to perform the requested operation. This relationship is further described in the Data Processing Agreement. Banks and Google may act as independent controllers for processing performed in their own environments.
Painel Pix is an independent technology service. It is not a bank, payment institution or direct Pix participant, does not hold payment accounts and does not take custody of funds received by users.
3. Personal data and confidential information we may handle
| Category | Examples | Source and main use |
|---|---|---|
| Account and identity | Name, email address, internal user ID, Firebase UID, Google display name and profile photo when made available. | Provided by the user or received through Google sign-in to create, link and manage an account. |
| Authentication and security | Password hash, session and recovery tokens, login records, IP address, timestamp, browser, operating system and technical identifiers. | Used for authentication, account recovery, abuse prevention, auditing and security. |
| Access and subscriptions | Trial/access period, expiration date, plan, purchase status, order ID, billing response and activation history. | Firebase, Google Play Billing and Pix plan payments used to grant or restrict service access. |
| Pix API credentials | Selected bank, Pix key and type, Client ID, Client Secret/Secret ID, application key, linked account, label and environment. | Provided by the user to authenticate calls to compatible bank APIs. |
| Digital certificates | PKCS#12 file (.p12 or .pfx), file name, SHA-256 fingerprint, upload date and certificate password when required. | Selected by the user for mutual TLS authentication with Efí or Banco Inter. The server copy is isolated and encrypted. |
| Pix charges and receipts | TXID, EndToEndId, QR Code, Pix copy-and-paste payload, amount, payer message, status, date, time and bank identifiers. | Generated or returned by bank APIs to create charges, confirm payments and display statements. |
| Payer data | Name, Brazilian CPF or CNPJ taxpayer ID and payer information, when supplied by the financial institution. | Returned by the bank API and shown to the user for verification, receipts and statements. |
| Painel Pix payments | Plan, amount, duration, Pix charge, TXID, payer, taxpayer ID, status, expiration, payment, cancellation and activation; or purchase information supplied by Google Play. | Used to administer access, reconcile payments, support customers and prevent fraud. |
| Usage and diagnostics | App interactions, app version, device model, OS version, installation identifiers, crashes, stack traces and related technical context. | Firebase Analytics, Firebase Crashlytics and first-party logs used for reliability, operational metrics and troubleshooting. |
| Support | Messages, email address, phone/WhatsApp number, attachments and support history. | Provided by the user to resolve questions and incidents and to exercise rights. |
| On-device data and files | Credentials and preferences in the Android local database, secure certificate references and statement PDFs generated by the user. | Stored on the device. PDFs remain in the selected location until the user deletes them. |
We do not ask for online banking passwords, card PINs or full card numbers. Recurring Android payments are processed by Google Play; Painel Pix receives only the information needed to verify the purchase. Core features do not require precise location, microphone, contact list or message content.
Efí and Banco Inter certificates and secrets remain on the protected backend and device as required by the operation. For compatibility with earlier versions, Banco do Brasil API credentials may also be synchronized to the user's private node in Firebase Realtime Database, in addition to local or Painel Pix Web storage.
4. How data is collected
- Directly from the user during registration, support, payment, charge creation and bank credential setup.
- From the Google account selected by the user through Firebase Authentication and Google Sign-In.
- From Google Play for validation and management of Android subscriptions.
- From Banco do Brasil, Efí and Banco Inter APIs according to the bank and operation selected by the user.
- Automatically through server logs, Firebase Analytics, Firebase Crashlytics, strictly necessary cookies and equivalent technologies.
- From the device when the user selects a certificate or generates a PDF.
5. Purposes and legal bases
| Purpose | Legal basis generally relied upon |
|---|---|
| Create and authenticate accounts, maintain sessions and provide requested features. | Performance of a contract and steps requested before entering into a contract. |
| Validate credentials, connect to banks, create charges, retrieve receipts, confirm Pix payments and generate statements or receipts. | Performance of a contract; legitimate interests in carrying out the requested operation; and legal obligations depending on the user's context. |
| Manage trials, access, Google Play subscriptions, one-time Pix plan payments, cancellation, support and activation history. | Performance of a contract, compliance with legal obligations and establishment, exercise or defense of legal claims. |
| Protect accounts, investigate fraud or abuse, keep logs, fix defects and maintain reliability. | Legitimate interests, fraud prevention, data subject security and legal claims, subject to necessity and proportionality. |
| Respond to data subjects, consumers, authorities and legal proceedings. | Compliance with legal obligations and establishment, exercise or defense of legal claims. |
| Send operational and support communications. | Performance of a contract and legitimate interests. Marketing, if introduced, will use an appropriate legal basis and opt-out mechanism. |
| Use optional technologies not required to provide the service. | Consent where required. As of this version, the public website and Painel Pix Web do not use advertising cookies. |
Consent is not treated as blanket authorization for every activity. Where processing is required to provide the service, comply with law or protect the platform, we rely on the appropriate legal basis. When consent is required, it will be specific and revocable.
6. Service providers and data sharing
We share only what is necessary for the purposes described above:
- Google: Firebase Authentication, Realtime Database, Analytics, Crashlytics, Google Sign-In and Google Play Billing. These services may handle account data, identifiers, app events, purchase information and diagnostics.
- Banco do Brasil, Efí and Banco Inter: credentials, certificates and operation data required for authentication, Pix charge creation, retrieval and confirmation according to the bank selected by the user.
- Infrastructure providers: hosting, databases, storage, network protection, email and technical maintenance.
- Professional advisers: technical support, accounting, auditing and legal advisers where needed and subject to confidentiality duties.
- Public authorities: when required by law, a valid order or the establishment, exercise or defense of legal claims.
We do not sell or rent personal data. Third-party services are also governed by their own privacy terms. Financial institutions retain their own records and legal responsibilities for operations carried out in their environments.
7. International data transfers
Painel Pix does not sell data or make international transfers as an independent commercial purpose. However, Google Firebase Authentication, Realtime Database, Analytics, Crashlytics, Google Play and other infrastructure providers may involve storage, remote support or processing outside Brazil. Those activities are ancillary to providing and securing the service.
Where an international transfer occurs, we rely on the legal basis applicable to the underlying processing and seek to use a transfer mechanism permitted by Article 33 of Brazil's LGPD and ANPD regulations, including ANPD-approved standard contractual clauses incorporated into provider terms where applicable. Additional information about providers, countries or regions and safeguards may be requested through the privacy contact.
8. Cookies, local storage and similar technologies
As of this version, the public website does not set advertising, behavioral profiling or ad-personalization cookies. Painel Pix Web uses a strictly necessary session cookie for authentication and security. Google sign-in uses Firebase local persistence to maintain the session until the user signs out, and the website may locally store that the cookie notice was acknowledged.
External resources such as Google Fonts inherently receive connection metadata such as IP address, time and browser information. The Android app uses installation identifiers and on-device storage; these are not browser cookies but are covered by this policy.
The session cookie and anti-forgery token are strictly necessary. Sign-in persistence, local storage of notice acknowledgment and external presentation resources are limited functional technologies and are not used for behavioral advertising. If optional measurement, marketing or advertising cookies are introduced, they will remain disabled until the user makes a valid choice. See our Cookie and Similar Technologies Notice.
9. Security measures
- HTTPS/TLS transmission across production pages and APIs.
- Painel Pix Web passwords stored as hashes rather than readable text.
- Encryption at rest for bank credentials stored by Painel Pix Web and the Android backend.
- Digital certificates encrypted, randomly named, access-restricted and separated by owner.
- Authentication, authorization, cross-site request forgery tokens and logical separation of user records.
- Error and audit logging designed to limit exposure of secrets.
- Integration review and component updates where needed.
No system is completely secure. Users must protect their devices, email accounts, passwords, Google accounts, API credentials and certificates, restrict employee access and revoke credentials at the bank if compromise is suspected.
10. Retention and deletion
| Data | Retention criterion |
|---|---|
| Account, profile and settings | For the active account lifecycle and afterwards as needed to handle requests, prevent fraud, resolve disputes and meet legal obligations. |
| Credentials and certificates | While registered or required for the integration. They are scheduled for removal when the credential or account is deleted, subject to rotating backups and mandatory retention. |
| Painel Pix charges, subscriptions and payments | For reconciliation, support, tax, accounting and consumer obligations, fraud prevention and legal claims. |
| Logs and diagnostics | For the time required for security, investigation and troubleshooting. Services such as Crashlytics apply their own retention cycles. |
| Recovery and session tokens | Until use, expiration, session termination or replacement. |
| On-device data and PDFs | Until the user deletes the file, clears app data or uninstalls the app, subject to backups configured on the device. |
| Support records | As needed to complete the request, maintain operational history and establish, exercise or defend legal claims. |
Where immediate deletion is not permitted because of law, fraud prevention, legal claims or rotating backups, the data will be blocked, isolated or retained only for the justified purpose until the applicable period expires.
11. Data subject rights
Subject to applicable law, including Brazil's LGPD, a data subject may request:
- confirmation of processing and access to personal data;
- correction of incomplete, inaccurate or outdated data;
- information about sharing and the consequences of withholding consent;
- anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data;
- data portability, subject to applicable regulation and trade secrets;
- withdrawal of consent and deletion of consent-based data, subject to lawful retention;
- objection to unlawful processing and review of solely automated decisions where applicable.
Send requests from the registered email address to painelpixapp@gmail.com. Never send a password, Client Secret or certificate. We may ask for additional information strictly to verify identity and prevent fraud.
12. Account deletion
Users may request deletion of their account and associated data. The Account and Data Deletion page explains the request process, data normally deleted and lawful retention exceptions. Deleting a Painel Pix account does not automatically cancel a recurring Google Play subscription or erase records independently held by banks.
13. Automated decisions
The service automatically checks Google Play subscription status or the Firebase access-period record to grant or restrict features. It may also expire sessions and unpaid charges after a time limit. We do not perform credit scoring or behavioral profiling to decide access. Users may request human review of an apparently incorrect validation.
14. Children
Painel Pix is available only to individuals aged 18 or older for professional or business use and is not directed to children or adolescents. Individuals under 18 may not create an account. If we identify an underage account, we may restrict access, apply risk-appropriate verification measures and delete data that is not required for law, security or legal claims. A legal representative may report an improper registration through the privacy contact.
15. Security incidents
If an incident may create relevant risk or harm to data subjects, we will take containment, investigation and remediation measures and provide notifications required by applicable law and Brazil's data protection authority.
16. Changes to this policy
We may update this policy to reflect changes to the product, integrated banks, providers or law. The version and effective date will be updated on this page. Material changes may also be announced through the website, Painel Pix Web, the Android app or a registered contact channel.