Lounge SecretoLoungeSecreto
Get started

Privacy Policy

Last updated: July 20, 2026

This Privacy Policy describes how ALAS TECHNOLOGY LLC, the data controller, collects, uses and protects your personal data, following international data-protection principles such as lawfulness, transparency, purpose, minimisation and security.

1. Data we collect

We collect the data you provide (such as your name and email at purchase or in the contact form), the content of your support interactions (the messages you write in our support chat and in support tickets, which may include any data you choose to type), the data needed to issue and manage your Pass and its accesses, the transaction data needed to process payment, and the browsing data collected through cookies and similar technologies (such as device identifiers and pages visited). To register the holder with the VIP lounge programme, we also collect, on the activation page, the personal data provided by the holder, detailed in section 10.

2. Purposes of processing

We use the data to process the purchase, register the holder with the VIP lounge programme, issue and activate your Pass, release and manage accesses, provide support and assistance — both through automated support powered by artificial intelligence (our Concierge) and through human support — send service-related communications by email, ensure platform security, comply with legal and compliance obligations, improve the quality of our support and, with your consent, measure the performance of our campaigns.

3. Legal basis for processing

Each processing activity relies on an appropriate basis: performance of the contract, to issue the Pass, deliver accesses and provide the support and assistance you request, including both automated and human support; compliance with legal and compliance obligations, including fraud prevention and registering the holder with the VIP lounge programme; our legitimate interest in protecting the platform and in improving the quality of our support — a basis that supports only the enhancement of the service and never its provision, and to which you may object at any time; and your consent, particularly for analytics and marketing cookies, which you may grant or withdraw at any time.

4. Cookies

We use essential cookies (always active) and, with your consent, analytics and marketing cookies, including advertising-platform pixels. You control these choices at any time. Learn more in our Cookie Policy.

5. Data sharing

We do not sell your data. We may share it with processors that provide services strictly necessary to deliver the service — such as the commercial partners responsible for the technical integration and the card issuance, the payment processor, the VIP-lounge program operator, hosting, analytics and the artificial intelligence provider engaged as a processor, located abroad, which processes the content of support messages to generate our Concierge responses — always under confidentiality obligations and only to the extent necessary for each purpose.

6. Information security

We adopt technical and organisational measures to protect your data against unauthorised access, loss or misuse. Our commitment to security and privacy follows internationally recognised standards, such as those for information-security management (ISO/IEC 27001) and privacy-information management (ISO/IEC 27701).

7. Retention

We keep data only for as long as necessary for the purposes described or to comply with legal and compliance obligations, including those relating to fraud prevention and registering the holder with the VIP lounge programme. The content of support conversations is anonymised after 90 (ninety) days: the text of the messages is irreversibly deleted, and only aggregate statistical data, with no personal content, is retained. Once the applicable period ends, the remaining data is securely deleted or anonymised.

8. Your rights

You may request confirmation, access, correction, portability or deletion of your personal data, object to certain processing and withdraw consents, by contacting us through our Support.

9. International transfers

As we operate globally and rely on processors located outside Brazil and the European Economic Area — among them the artificial intelligence provider that processes the content of our automated support — your data may be transferred to and processed in other countries. For such international transfers, we ensure a level of protection consistent with this policy through standard contractual clauses entered into with our processors and the other safeguards provided for under the Brazilian General Data Protection Law (LGPD), art. 33, and the General Data Protection Regulation (GDPR), Chapter V, applying, where one exists, the adequacy decision of the destination country. You may request information about the safeguards adopted through the contact channels indicated in this policy.

10. Holder registration and data collected at activation

Issuing the pass depends on creating a nominal registration of the holder with the operator of the VIP lounge programme. To carry out that registration and technically enable the virtual card linked to it, we collect, on the activation page (/verificar), the data provided by the holder: (i) full name; (ii) email address, confirmed by a one-time code; (iii) date of birth; (iv) national identification document — the Individual Taxpayer Registry number (CPF), for holders resident in Brazil, or the passport number, for other holders; (v) full residential address, comprising street, complement (where applicable), city, state or province, postal code and country of residence; (vi) telephone number; and (vii) a security question and its answer. This data is used solely to register the holder with the VIP lounge programme and to meet compliance requirements, and is not used for advertising purposes nor sold.

Once the data has been provided and checked, an account is created, linked to the holder's registration, with the commercial partner responsible for the technical enablement and the card issuance, from which a temporary international virtual debit card is generated, intended solely to meet compliance requirements. We are the controller of the registration data provided by the holder and share it with the operator of the VIP lounge programme and with the commercial partners responsible for the technical integration and the card issuance, solely to create and maintain the registration. There is no sharing for advertising purposes nor sale of data. The pass holder may be a person other than the one who made the purchase; in that case, it is the holder who fills in the registration, and the buyer has no access to this data.

We do not store card data on our servers. The registration data provided by the holder and the card-related information remain in the possession, custody and responsibility of the commercial partners responsible for the technical integration and the card issuance, processed solely for the registration and compliance purposes described here, in accordance with the international information-security standards ISO/IEC 27001 and ISO/IEC 27701. The registration data is kept while the pass remains active and for the period necessary to comply with the legal obligations arising from the registration, after which it is deleted or anonymised. Your rights of access, correction, portability and erasure remain intact, provided that the erasure of data subject to a statutory retention period only takes place once that period ends. Requests may be addressed to us through the contact channels indicated in this policy.

11. Automated support and human review

Our support includes a virtual assistant (the Concierge) that responds in an automated way, powered by artificial intelligence. The content of your messages is recorded and, for each response, the recent messages in the conversation are sent to the artificial intelligence provider to generate the reply. This automated support is intended to inform and assist: it does not decide on your rights on its own. Whenever a matter requires assessment — for example, a refund denial — the decision rests with a person. You may request human support at any time; when you do, we open a ticket with a summary of the conversation so that our team can take over. This is how we safeguard your right to human review of automated interactions.

Proof of acceptance of the Terms

When you tick the acceptance boxes to activate your pass, we record proof of that consent. It gathers the date and time, the IP address of the connection, the browser used (user agent), a device identifier, the interface language, the version and cryptographic hash of the documents accepted, the exact wording of each option as it was shown to you, and the confirmed full name of the holder. Together these form the receipt we email you and the evidence we rely on, should the acceptance ever be disputed, to show that it came from you.

At that same step we request your geolocation. Collecting it depends on your express authorisation in the browser's own dialog: without that permission the browser will not provide it. We record latitude, longitude, the accuracy radius reported by the device and the time of the reading. The purpose is single and specific: to strengthen the proof of acceptance. An IP address only indicates the network the connection came from; the coordinate indicates where the device was at the moment of confirmation, which makes the receipt substantially more robust against a chargeback or a dispute over authorship. We do not use this coordinate for advertising, for behavioural profiling, to track you over time, or for any other purpose. It is read once, at the moment you accept, and there is no continuous tracking of your position. You may revoke the permission at any time in your browser settings; revoking it does not erase proof already recorded for an earlier acceptance, for the same reason a signed receipt does not cease to exist.

We process this data to perform our contract with you and to exercise our rights in judicial, administrative or arbitral proceedings (Brazilian Law 13.709/2018, art. 7, items V and VI; equivalent to contractual necessity and legitimate interest in establishing or defending legal claims under the GDPR). Because the proof of acceptance is the record of the contract itself, it is not deleted on request while the periods below are running — which does not affect your other rights as a data subject, described in this Policy.

We keep the proof of acceptance, geolocation included, for 5 years from the end of the contractual relationship, in line with the limitation periods applicable to payment and consumer claims. Once that period ends, the record is deleted.

12. Contact and data protection officer

The data controller is ALAS TECHNOLOGY LLC. To exercise your rights or clarify privacy questions, contact our data protection officer (DPO) through our Support, or directly by email at [email protected].

Privacy Policy — Lounge Secreto