Legal
Privacy Policy
This policy describes only what this website actually does today. One contact form, no analytics, no advertising pixels, no cookies for visitors.
Last updated:
1. Who is responsible for your data
The controller of the personal data collected here is Moon, registered under CNPJ 46.700.046/0001-14, based in Votorantim, SP, Brazil.
Data protection officer (encarregado, article 41 of the LGPD): anderson@agenciamoon.com. Representative in the European Union (article 27 of the GDPR): none appointed. Processing here is occasional, limited to the contact details you type into one form, involves no special categories of data and no large-scale monitoring, which is the exemption article 27(2) describes. Write to the address above and it reaches the person responsible.
For anything about your data, write to anderson@agenciamoon.com and it reaches the person responsible.
2. What we collect
There is exactly one place on this site where you give us personal data: the contact form. Nothing else on the site collects information about you.
When you submit that form, this is what gets stored:
- Your name (required)
- Your email address (required)
- Your phone number and the international dial code you selected (required)
- Your company (optional, only if you type it)
- The site or page URL you gave us, which is what the request is about (required)
- Your answers to the qualification questions the form asked, stored together with the questions themselves (required to send the form)
- Your message, on the older single-screen version of the form (optional, only if you typed it)
- Which page of the site the form was sent from, the brand it belongs to (Moon), and the date and time of the submission
3. What we do not collect
The list above is complete. We do not record your IP address, we do not store which pages you visited, we do not build a profile of you, and we do not buy or enrich your data from third parties.
One exception worth stating plainly: if saving your submission fails, our server error log records the email address you typed and the page you were on, so the failure can be diagnosed and your request is not lost. That log is technical and short lived.
Separately from the application, the infrastructure that serves the site keeps standard access logs, which normally include IP addresses. Those are handled by Vercel Inc. (United States) and Neon Inc. (United States).
4. Why we use it, and on what legal basis
We use what you send for one purpose: to read your request, reply to you, and prepare a possible working relationship. That is the pre-contractual basis in article 7, V of the LGPD and article 6(1)(b) of the GDPR.
We also keep a record of contacts received so we can follow up on conversations already started, which rests on legitimate interest under article 7, IX of the LGPD and article 6(1)(f) of the GDPR. You can object to that at any time.
Submitting the form does not subscribe you to any list. The site itself sends no email and runs no automated decision about you.
5. Cookies, analytics and tracking
This site sets no cookies for visitors. There is no Google Analytics, no Google Tag Manager, no Meta pixel, no TikTok pixel, no LinkedIn tag, no heatmap tool and no third-party analytics of any kind loaded on these pages.
One cookie exists in the codebase, named moon_admin. It is set only when the operator of the site logs into the private admin area, it is restricted to that area, and it is never sent to visitors.
The typefaces used here (Inter and JetBrains Mono) are served from our own domain, so your browser makes no request to Google to render this page.
6. Who else has access to the data
Your submission is stored in a Postgres database that is not publicly exposed, and it is read through a password-protected admin area used by the Moon team.
We do not sell your data, we do not trade it, and we do not hand it to advertisers or data brokers.
The infrastructure that hosts the site and the database processes the data on our behalf, as an operator under the LGPD and a processor under the GDPR: Vercel Inc. (United States) and Neon Inc. (United States). If that infrastructure sits outside your country, the transfer happens under the safeguards in articles 33 to 36 of the LGPD and chapter V of the GDPR.
7. How long we keep it
The system has no automatic expiry today: a submission stays in the database until it is deleted, either because you asked or during a cleanup.
The retention period we commit to is 24 meses. You can ask for deletion before that at any moment, and we will do it unless a law requires us to keep a specific record.
8. Your rights under the LGPD (Brazil)
If Brazilian law applies to you, article 18 of the LGPD gives you the right to ask us for:
- Confirmation that we process your data, and access to it
- Correction of data that is incomplete, inaccurate or out of date
- Anonymization, blocking or deletion of data that is unnecessary, excessive, or processed outside the law
- Portability of your data to another provider
- Deletion of data processed with your consent
- Information about the public and private bodies we shared your data with
- Information about the consequences of refusing to provide data
- Withdrawal of consent, whenever consent was the basis
9. Your rights under the GDPR (European Union)
If you are in the European Union or the United Kingdom, you also have the rights in articles 15 to 22 of the GDPR:
- Access to your data and a copy of it (article 15)
- Rectification of inaccurate data (article 16)
- Erasure, the right to be forgotten (article 17)
- Restriction of processing (article 18)
- Portability in a machine-readable format (article 20)
- Objection to processing based on legitimate interest (article 21)
- Not to be subject to a decision based solely on automated processing (article 22). We make no such decisions.
10. How to exercise your rights
Write to anderson@agenciamoon.com from the email address you used in the form, or tell us which address you used. Say what you want, for example access, correction or deletion. We do not charge for this.
We answer within 15 days under the LGPD and within one month under the GDPR, and we tell you if a request needs longer and why.
If you are not satisfied, you can complain to the ANPD, Brazil's national data protection authority, or to the supervisory authority of your country in the European Union.
11. How the data is protected
The form is submitted over an encrypted connection (HTTPS). The database is not publicly reachable. The admin area that reads the leads requires a password, and its session cookie is httpOnly, restricted to the admin path, and expires after eight hours.
No system is perfectly secure. If a breach ever puts your rights at material risk, we notify you and the authorities as required by article 48 of the LGPD and articles 33 and 34 of the GDPR.
12. Children and adolescents
This site is addressed to businesses and to the people who run them. It is not directed at children or adolescents, and we do not knowingly collect their data. If you believe a minor sent us data, write to us and we delete it.
13. Changes to this policy
When this policy changes, the revised version is published on this page with a new revision date at the top. Material changes are described in the text rather than slipped in silently.