What data we process
Identification and contact data, the financial and asset data needed to assess credit, and site navigation data. The name, e-mail address, telephone number and message sent through the site's forms are stored encrypted to handle your request. We collect only what each step requires.
Why we use it
To simulate, assess and formalise credit operations with the partner financial institutions, to meet legal and regulatory obligations and to prevent fraud.
Site and campaign measurement
We use Cloudflare Web Analytics for aggregate performance and navigation metrics, without cookies or individual identification. Meta measurement starts automatically when you access the site unless it was disabled through Measurement preferences or the browser sends a Global Privacy Control signal. The Meta Pixel may record page views, interest in the simulator, clicks to start a WhatsApp conversation, and leads accepted by our system in the browser. When a form is accepted, CifraCred may also send the same event from the server to Meta's Conversions API to measure and deduplicate the conversion. This transmission may include the IP address, browser identification (user agent), fbp and fbc identifiers, and SHA-256 hashes of the e-mail address and telephone number submitted. These hashes are cryptographic summaries, not the original contact-data text. Meta processes these data under its own policies. Your preference is stored in this browser and can be changed at any time through Measurement preferences in the footer.
Who we share it with
With the financial institution responsible for each operation and with strictly necessary providers (analysis, biometrics, fraud prevention), always under confidentiality and within the purpose.
Your rights
You may confirm the processing, access, correct, port and request the deletion of your data, among other LGPD rights. To exercise them, contact our Data Protection Officer.
Data Protection Officer (DPO)
Privacy questions and requests can be sent to dpo@cifracred.com.br.
Security and retention
We apply technical and organisational measures to protect the data, including encryption of the stored contact and the Cloudflare Turnstile anti-bot check on the forms. The contact of a request that does not become an operation is deleted within twelve months of submission; that of an ongoing operation follows the operation's lifecycle. Otherwise we keep data only for as long as the purposes and legal obligations require.