1. Data controller
The controller of your personal data is Brindi, operated by [Legal name, RUT and domicile]. You can contact us about privacy matters at [contact email, e.g. privacy@brindi.cl].
2. Data we collect
We collect the following data, depending on how you use the platform:
- Restaurant account data: the admin user's name, email and login credentials.
- Restaurant data: business name, logo, products, storefront settings and payment-account details.
- Purchase data: the buyer's and recipient's name and email, amount, product and an optional gift message.
- Payment data: handled by MercadoPago. Brindi receives the transaction result but does not store full card details.
- Technical data: IP address, browser/device type and usage logs, collected for security and service operation.
3. Purpose of processing
We use your data to:
- Issue, deliver and enable redemption of gift cards.
- Process payments and, where applicable, handle refunds.
- Send transactional communications (purchase confirmation, gift-card delivery, redemption notifications).
- Operate, maintain and improve the platform, and prevent fraud and abuse.
- Comply with legal, accounting and tax obligations.
4. Legal basis
We process your data on the basis of the performance of the contract (the purchase and delivery of the gift card), your consent where applicable, our legitimate interest in operating and securing the platform, and compliance with legal obligations.
5. Third parties and processors
To provide the service we share data with providers acting as processors, under confidentiality and security agreements. These providers may process data outside Chile:
- Supabase — database and authentication (hosting of the platform's data).
- MercadoPago — payment and refund processing.
- Resend — delivery of transactional emails (gift-card delivery and notifications).
- The issuing Restaurant — receives the data needed to manage and redeem the gift card it sold.
6. Cookies and similar technologies
We use cookies and local storage that are strictly necessary for the site to work (for example, keeping you signed in and remembering your language preference). We do not use third-party advertising cookies. You can configure your browser to block cookies, although some features may then stop working correctly.
7. Data retention
We keep personal data for as long as it is necessary for the purposes described and to comply with legal obligations (for example, accounting and tax periods). When it is no longer needed, we securely delete or anonymize it.
8. Security
We apply reasonable technical and organizational measures to protect your data, including encryption in transit, access control and tokenized handling of payment information. No system is 100% foolproof, but we work to keep your data protected.
9. Your rights
Under Law No. 19.628 you have the right to access your data, rectify it, delete (cancel) it and object to its processing in the cases the law allows. To exercise these rights, write to us at [contact email]. We will respond within the legal timeframes and may ask to verify your identity.
10. Minors
Brindi is not directed to minors. We do not knowingly collect data from minors without the authorization of their legal representative.
11. Changes to this Policy
We may update this Policy to reflect changes in the service or in applicable law. We will publish the current version on this page, indicating the last-updated date.
12. Contact
If you have questions about this Policy or about the processing of your data, write to us at [contact email, e.g. privacy@brindi.cl].