Privacy Policy
Last updated 24 September 2026. In force from 24 September 2026.
This policy explains what personal data we collect when you visit this website or buy a course, why we collect it, who else processes it and how you can exercise your rights. It is written to meet the Brazilian General Data Protection Law (LGPD, Law 13.709/2018), the EU General Data Protection Regulation (GDPR), the UK GDPR and, for California residents, the California Consumer Privacy Act (CCPA).
Who is responsible for your data
The controller of your personal data is:
| Seller | Lucas Henrique de Melo Machado, trading as Glowence Spa |
|---|---|
| Legal status | Individual trader (pessoa física) resident in Brazil |
| Tax number | CPF 239.943.488-97 |
| Address | Av. Luiz Rodrigues Mendes, 729, Pq. R. V. Verde, 14806-860 Araraquara - SP, Brazil |
| support@glowencespa.com | |
| Telephone | +55 16 98179-5880, Monday to Friday, 9:00 to 18:00 Brasília time (UTC−3) |
| Website | https://glowencespa.com |
| Card statement descriptor | GLOWENCESPA |
Please send any privacy request to privacy@glowencespa.com. Because of the size of this business we have not appointed a formal Data Protection Officer; Lucas Henrique de Melo Machado handles these requests personally.
What we collect and why
| Data | Purpose | Legal basis | How long we keep it |
|---|---|---|---|
| Name, email address and billing country | To process your order, deliver the course, send your access link and answer you | Performance of a contract (GDPR art. 6(1)(b); LGPD art. 7, V) | 5 years after the purchase |
| Payment details: amount, currency, date, card brand, last four digits, Stripe reference | To take payment, issue refunds, handle disputes and keep tax records | Contract and legal obligation (GDPR art. 6(1)(b) and (c); LGPD art. 7, II and V) | 5 years |
| Proof of your checkout choices: acceptance of the terms and request for immediate delivery, with date and time | To show that the purchase and immediate delivery were requested by you | Legal obligation and legitimate interest (GDPR art. 6(1)(c) and (f); LGPD art. 7, II and IX) | 5 years |
| Messages you send us, including through the contact form | To answer and keep a record of what was agreed | Contract, or our legitimate interest in answering you | 2 years |
| Technical logs: IP address, browser, date and page requested | Security, fraud prevention and fixing faults. Brazilian Law 12.965/2014, article 15, requires us to keep access logs | Legal obligation and legitimate interest | 6 months |
| Measurement and advertising data, only if you accept them in the cookie banner | To see which pages work and whether our adverts lead to purchases | Your consent (GDPR art. 6(1)(a); LGPD art. 7, I) | As set by each provider, never more than 13 months |
We do not ask for, and do not want, any health data or other sensitive data. Please do not include it in messages to us.
What we never do
- We never see or store your full card number. Stripe handles it.
- We do not sell or rent personal data, and we do not share it for other companies' marketing.
- We do not make automated decisions that have legal or similarly significant effects on you.
- We do not load advertising or measurement scripts unless you accept them in the cookie banner.
Who processes data for us
| Provider | What it does | Location |
|---|---|---|
| Stripe, Inc. and its affiliates | Payment processing, refunds and fraud prevention. Stripe is also an independent controller for its own legal and fraud prevention duties | United States, Ireland and other countries |
| Vercel Inc. | Hosting of this website and its server functions, technical logs | United States, with worldwide delivery network |
| Resend (Plus Five Five, Inc.) | Sending the delivery email and replies to your messages | United States |
| Our email mailbox provider | Receiving and storing the messages you send us | Varies |
Each provider may only use your data to provide its service to us, under a data processing agreement.
International transfers
We are based in Brazil and some of our providers are in the United States, so your data is transferred between countries. Transfers from the European Economic Area and the United Kingdom rely on the European Commission's standard contractual clauses, the UK addendum or the EU-US Data Privacy Framework where the provider is certified. Transfers from Brazil rely on the mechanisms in LGPD article 33, including standard contractual clauses. You can ask for a copy at privacy@glowencespa.com.
Emails we send
After a purchase we send transactional emails: the access link, the receipt and important notices about the course you bought. They are part of the service, so you cannot unsubscribe from them. We only send occasional news about new courses if you have agreed, and every such email includes a one-click unsubscribe link.
Your rights
Wherever you live, you can ask us to:
- confirm whether we hold your data and give you a copy;
- correct inaccurate or incomplete data;
- delete data we no longer need, or anonymise or block it;
- restrict or object to a particular use;
- give you your data in a portable format;
- tell you who we have shared it with;
- withdraw a consent you gave, at any time, and explain the consequences of not giving it.
California residents also have the right to know, to delete and to correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the CCPA, unless you accept advertising cookies.
Send your request to privacy@glowencespa.com from the email address you used to buy. We answer within 15 days, as LGPD requires, and in any case within the one month allowed by the GDPR. It is free unless a request is clearly excessive. If you ask us to delete your data, we can no longer confirm your purchase or resend your access link, and records we must keep by law, such as tax records, will be kept until the legal period ends.
Complaints
If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to a supervisory authority: in Brazil the Autoridade Nacional de Proteção de Dados (gov.br/anpd), in the European Union the data protection authority of your country, and in the United Kingdom the Information Commissioner's Office (ico.org.uk).
Security
The site uses HTTPS on every page. Access links are digitally signed so they cannot be guessed or altered. Card data never reaches our servers. Access to our Stripe, hosting and email accounts is protected by two-factor authentication. If a data breach creates a risk to you, we will notify the authorities and affected customers within the time the law requires.
Children
Our courses are sold only to adults. We do not knowingly collect data from anyone under 18. If you believe a minor has sent us personal data, write to privacy@glowencespa.com and we will delete it.
Changes to this policy
If we change this policy in a way that matters to you, we will tell customers by email before the change takes effect. The date at the top of this page shows the current version.