Skip to content

Privacy policy

17 September 2026

This policy explains data use on the Cantim Café website. Public pages do not require an account. The restricted dashboard uses Google sign-in to verify staff access and record access to protected information.

Who is responsible

Cantim Café is responsible for the data handled on this site. For any question or request about personal data, write to cantimcafe@gmail.com.

What we collect

Until you accept, no analytics tool is loaded and no browsing data is sent for analytics. The map is an exception: it loads only if you click to open it, as explained in the Cookie policy.

If you accept, we use Google Analytics to understand how the site is used: pages visited, language chosen, whether you arrived through the QR code on the machine, and clicks on links such as Google and Instagram. This is browsing data. It does not identify you by name. The survey opens an external Google Form, which has its own privacy information.

Map

The map shown on this site uses OpenStreetMap data. Map © OpenStreetMap contributors. When you open Google's map, your browsing data is sent to Google.

What stays in your browser

We store your analytics and diagnostics choice and theme preference in your browser. Google sign-in also keeps the dashboard session in this browser until you sign out.

Why we collect it

To know what works on the site and what does not. How many people arrive by QR code, which pages get read, in which language. None of it is used for advertising.

Legal basis

Optional analytics and diagnostics reports depend on your consent. You can withdraw it at any time without losing access to the website or dashboard.

Who we share it with

Google, which operates Google Analytics, and only if you have accepted. Google handles that data under its own policies.

With your permission, we also use Sentry to diagnose technical failures. We send the error type, its code location and the page identifier. We remove free-form messages, user data, tokens, screen contents and financial figures from reports. We do not record sessions. Connecting to the service involves your IP address and technical browser information; the ingestion destination is in the United States. Retention depends on the Sentry project settings.

How long we keep it

Browsing data stays in Google Analytics for the retention period configured there. The choices stored in your browser stay until you clear or change them.

Your rights

Brazilian law gives you the right to confirm processing, access, correct, anonymise, block and delete data, and to withdraw consent. To exercise any of them, write to cantimcafe@gmail.com.

One honest note: the analytics data we collect is browsing data and does not identify you. In practice that means we cannot look up “your data” from a name or an email, not because we refuse, but because that link does not exist. What you can always do is withdraw consent, and we stop collecting.

How to withdraw consent

Use “Cookie preferences” in the website or dashboard footer. This clears your previous choice and stops new analytics and diagnostics reports. Reports already sent remain subject to the service retention period.

Children

This site is not directed at children, and we do not knowingly collect data from minors.

Changes

If this policy changes, the date at the top changes with it. Significant changes will be flagged on the site.

Support tickets and notifications

By sending, you request support. We use your report and contact only to handle this ticket. Authorized staff access this data in the admin panel. Data is stored in Firebase (Google) and deleted within 90 days after resolution; the audit record excludes the report and contact. Do not send passwords or payment details.

Submitting a ticket requests support independently of your analytics choice. The report and contact are available only to authorized staff while the ticket is open and for up to 90 days after resolution. We retain minimal audit metadata without the text or contact. To prevent abuse, submission limits use identifiers derived from the IP address, without saving the IP in the ticket. Admins may opt into notifications through Firebase Cloud Messaging (Google): the browser stores a subscription and the server stores its device identifier for up to 30 days, renewed when the support inbox is visited. Notifications contain neither the report nor contact details. Signing out disables alerts in this browser. You can request access, correction or deletion using your reference and the privacy contact on this page.

Contact

Questions about privacy and personal data: cantimcafe@gmail.com.

© 2026 Cantim Café. All rights reserved.
Images and videos used on this site and in marketing materials are for illustration only.