Privacy
What Radar CNPJ keeps about the people who use it, for how long, which infrastructure it shares, and how to request access or deletion.
Who processes the data
Radar CNPJ is run by the same house as the other products listed in the footer. Requests about personal data go to contato@radar-cnpj.com and are answered by e-mail.
What this product keeps
- Searches and CNPJ lookups go into a usage log with the term, the filters, the latency, the country and a salted hash of the IP address — never the raw IP.
- Monitoring: the watches linked to this browser's temporary visitor, to the linked account or to the agent's credit wallet, with the CNPJ being followed and the history of detected changes. The email alert goes to the account's verified email, read from the account at each send.
- Prepaid credit: the balance and the statement of each code — purchases and reveals, with the revealed CNPJ —, linked to a hash of the code, never to the code. The code stays only in your browser.
- Data reveal: revealed phone numbers, email and partner names appear only in the open tab and are not kept in your browser or in an account.
- USDC payments: the paying wallet address, the amount and the transaction, which the Base network itself already makes public.
- Support and contact: the message and a hash of the source IP.
- Account: e-mail, password, passkeys, sign-in codes and sessions are kept by the account system shared by our products, in its own database — this product keeps only the account id next to what is yours. Without an account, a signed guest token stored in your browser owns what you create; signing in moves it to your account.
- Pay-per-call payments (x402) settle on the Base network, which is public by design; here we keep the transaction reference and the amount for reconciliation and accounting.
- Prepaid credit: the token is stored only as a SHA-256 hash with its balance and movements; whoever holds the token holds the credit, and it cannot be recovered by e-mail.
- Contact: your message, the e-mail you give and the reply go through Amazon SES to the product mailbox.
For how long
- Watches and alerts stay linked to this browser's temporary token until the person claims them in the account; a watch beyond the quota is suspended, not deleted.
- The usage log serves to operate and measure the service and is aggregated per day.
- Sign-in codes expire within minutes; the account session ends when you sign out or when it expires.
- Per-network rate-limit counters (guest, contact, sign-in code) expire on their own within minutes or hours.
- Payment and credit records stay as long as accounting requires.
- Visit steps stay 7 days on the product server; the copy kept for analysis, without IP or account, stays on our data server.
Infrastructure and third parties
- Servers we operate run the service and store your data. Cloudflare provides DNS only.
- Amazon Web Services (SES) sends transactional e-mail on behalf of the product.
- Interface libraries (Bootstrap) are served from the product's own domain, not from a third-party CDN.
- Google Analytics 4 measures pages and events only after the first interaction (tap, click or key), with ad storage denied and no sale or sharing for advertising.
- PayAI (x402 facilitator) verifies and settles payments on the Base network; the paying wallet is yours, and its address is public on-chain.
- Each company's record comes from the open CNPJ data of Receita Federal (Brazil's Federal Revenue), including the partner list, as the source publishes it.
Cookies and browser storage
- When you sign in, the account session lives in an HttpOnly cookie on this domain; without an account, the guest token stays in your browser and identifies what you created.
- Screen preferences (theme, filters) stay in the browser's local storage and never leave it.
- To learn where a visit stops (pages opened, offer seen, payment started or completed), we keep a random id for this browser and the session in local storage, and send those steps only to our own server — no IP, e-mail, account or typed text. With Global Privacy Control or "Do Not Track" on, none of it is kept.
- There is no advertising cookie and no cross-site tracking.
IP address
To limit abuse, the IP address goes into a hash with a secret salt. The approximate country and city come from a geolocation database (MaxMind GeoLite2) looked up on our server, without sending the address to anyone. The raw IP is not stored, except where this page says otherwise.
Your rights
You can request access, correction or deletion of what exists about you by writing to contato@radar-cnpj.com. We answer within the terms of the Brazilian data protection law (LGPD) and, where it applies, the GDPR. Data from public sources (official registries) stays at the source; only the copy here is removed.
Last updated: September 23, 2026.