1. Who handles your data
The service PaulinhoScripts — which includes the Tribal Wars script package, PS Evolution (multiple accounts) and the Premium Points store — is operated by [FULL NAME OF THE OWNER], an individual / sole trader (MEI), registered under [CPF or MEI CNPJ], with an address in [CITY/STATE, BRAZIL].
For the purposes of the Brazilian General Data Protection Law (Law 13,709/2018) and the European Union General Data Protection Regulation (Regulation EU 2016/679), that person is the controller of the data described here, and also acts as data protection officer (DPO) receiving data subject requests.
Contact for personal data matters: [email protected] or WhatsApp (75) 99179-0412.
2. Who this policy applies to
This policy covers anyone who:
- browses paulinhoscripts.com.br and the pages it serves;
- buys, activates or renews a script licence, in reais, euros or dollars;
- uses the scripts installed in their browser while playing;
- uses PS Evolution (multiple accounts) or buys Premium Points;
- contacts support by WhatsApp or e-mail.
3. Data we collect
We collect only what is needed to sell, deliver and keep the service running. No advertising profiles, no selling of data.
| Category | What it is, in practice | Where it comes from |
|---|---|---|
| In-game identification | Your player name, your numeric player ID and the world/market (br131, pt, en...). This is what ties the licence to your account. | You provide it at checkout; the script reads it from the game screen itself. |
| Contact | E-mail and/or WhatsApp number. | You provide it at checkout or when contacting support. |
| Purchases and licence | Plan purchased, amount, currency, date, coupon, referral code, order status, subscription and customer identifiers at Stripe/Mercado Pago, and the expiry date of each tool. | Generated by the system at the moment of purchase. |
| Access and usage logs | IP address, date and time, browser identification (user-agent), which scripts authenticated and when, and irregular attempts to access the licence. | Recorded automatically by our servers. |
| Settings you create | Build templates, farm targets, per-tool preferences and — if you choose to turn notifications on — the Discord webhook addresses, Telegram bot tokens and WhatsApp contacts you register yourself. | You set them up inside the tools. |
| Loyalty programmes | Loyalty points, redemption history, referral code and referrals made. | Generated by the system as you use it. |
| Support | The content of support conversations, including any screenshots you send. | You send it when asking for help. |
4. Why we process it (legal bases)
Every processing activity here has an explicit legal basis — under the LGPD (art. 7) and the GDPR (art. 6):
| Purpose | Legal basis |
|---|---|
| Creating, activating, renewing and validating your licence; delivering the scripts; providing support. | Performance of a contract — LGPD art. 7, V; GDPR art. 6(1)(b). |
| Processing payments, issuing charges and managing recurring subscriptions. | Performance of a contract — LGPD art. 7, V; GDPR art. 6(1)(b). |
| Keeping application access logs. | Legal obligation — Brazilian Internet Civil Framework (Law 12,965/2014), art. 15; LGPD art. 7, II; GDPR art. 6(1)(c). |
| Keeping tax and financial records of sales. | Legal obligation — Brazilian tax and civil law. |
| Preventing fraud, licence misuse and improper charges; defending against payment disputes. | Legitimate interest — LGPD art. 7, IX; GDPR art. 6(1)(f). See section 6. |
| Notifying you about licence expiry, service outages and tool updates. | Performance of a contract (operational notices) — LGPD art. 7, V. |
| Sending promotions, news and commercial offers. | Consent — LGPD art. 7, I; GDPR art. 6(1)(a). You can withdraw it at any time without affecting the service you purchased. |
5. Payments and card data
We never see and never store your card number. All payment data is captured inside the environment of Stripe (international payments, in euros and dollars) or Mercado Pago (payments in Brazil, including PIX), both certified PCI DSS Level 1.
What stays with us is only the outcome of the transaction: amount, currency, date, status, the last digits and the card brand (when the provider tells us), and the technical identifiers that let us find that payment (for example, the customer ID and the subscription ID at Stripe). That is what allows us to refund, cancel a subscription or prove delivery when you ask.
6. Fraud prevention and payment disputes
When someone disputes a charge with their bank (a chargeback), the acquirer asks us for evidence that the purchase was legitimate and that the service was delivered. To answer that, we process — on the basis of our legitimate interest and the data subject’s own interest in not being charged improperly — the following data:
- the IP address, date and time the purchase was made and the terms were accepted;
- the e-mail and billing details given at checkout;
- the record that the licence was actually released and that the scripts authenticated after the payment;
- the support history relating to that charge.
This data is shared with the payment provider and, through them, with the issuing bank and the card network, solely to support the defence of that specific transaction. We also use Stripe’s own anti-fraud tooling (Stripe Radar), which evaluates device and card signals to block fraudulent transactions before they happen.
You have the right to object to this processing and to request human review of any automated decision that blocks a purchase of yours — just write to the contact in section 16.
7. Who we share it with
We do not sell personal data and we do not hand it over for third-party advertising. We share it only with those the service needs to work:
| Who | What for | What they receive |
|---|---|---|
| Stripe (Ireland / USA) | Processing international payments, managing subscriptions and the cancellation portal. | E-mail, name, player name, world, amount and card data (collected directly by them). |
| Mercado Pago (Brazil) | Processing payments in Brazil (PIX, card, boleto). | Name, contact, amount and payment data (collected directly by them). |
| MongoDB Atlas and Heroku / Salesforce (USA) | Hosting the database and the application. | All the operational data described in section 3, at rest. |
| Meta / WhatsApp | Support channel and expiry notices. | Phone number and the content of the messages exchanged. |
| Discord and Telegram | Internal operational notifications and — if you set them up — alerts from your tools. | Player name, world and the event being notified. The webhooks and tokens are the ones you registered yourself. |
| Google (YouTube and Fonts) | Showing the tutorial videos and loading the page typefaces. | Standard web request data (IP, user-agent) when those resources load. |
| Public authorities | Complying with a court order or legal request. | Only what the order strictly requires. |
8. International transfers
Some of our suppliers are outside Brazil and outside the European Union — mainly in the United States. That means your data may be processed in those countries.
These transfers rely on the standard contractual clauses adopted by those suppliers and on the mechanisms set out in art. 33 of the LGPD and Chapter V of the GDPR, always limited to what is needed to perform the contract with you.
9. How long we keep it
| Data | Period | Reason |
|---|---|---|
| Application access logs (IP, date/time) | At least 6 months | Brazilian Internet Civil Framework, art. 15. |
| Orders, payments and invoices | 5 years after the transaction | Tax and limitation periods (Consumer Protection Code art. 27; Civil Code). |
| Evidence relating to payment disputes | 5 years after the dispute closes | Defence in administrative or court proceedings. |
| Licence, player name, ID and world | For as long as the licence exists + 24 months | Allowing reactivation, name migration and history checks. |
| Tool settings, webhooks and tokens | Until you delete them, or 12 months after the licence expires | There is no point keeping settings for someone who stopped using them. |
| Support conversations | 24 months | Support history and proof of agreements made. |
Once the period ends, the data is deleted or irreversibly anonymised.
10. Your rights
At any time and free of charge, you can require us to:
- Confirm whether we process your data and show you what it is (LGPD art. 18, I and II; GDPR art. 15);
- Correct incomplete, inaccurate or outdated data (LGPD art. 18, III; GDPR art. 16);
- Delete unnecessary, excessive or unlawfully processed data (LGPD art. 18, IV and VI; GDPR art. 17);
- Hand over your data in machine-readable form, to you or to another provider (LGPD art. 18, V; GDPR art. 20);
- Tell you who we share it with (LGPD art. 18, VII);
- Withdraw the consent given for commercial communications (LGPD art. 18, IX; GDPR art. 7(3));
- Object to processing based on legitimate interest (LGPD art. 18, § 2; GDPR art. 21);
- Review automated decisions, such as an anti-fraud block (LGPD art. 20; GDPR art. 22).
How to ask: write to [email protected] or message us on WhatsApp, giving your account name and the e-mail used for the purchase — we need to confirm it is you before touching any data.
Response time: up to 15 days (LGPD art. 19, II) and up to 1 month for data subjects in the European Union (GDPR art. 12(3)).
If you think we handled it badly, you can complain to the ANPD (gov.br/anpd) or, in the European Union, to your country’s data protection authority.
11. Cookies and local storage
Our pages use no advertising cookies and no cross-site tracking. What we do use is:
- Browser local storage (localStorage) — to remember your progress in the install guide, your preferred tab and the tool settings. It stays on your computer only.
- Stripe cookies — during checkout and in the subscription portal, needed for transaction security and fraud detection.
- YouTube cookies — only when you press play on a tutorial video.
You can clear all of this from your browser settings. Clearing local storage resets your tutorial progress, but it does not affect your licence.
12. Security
Measures we keep in place:
- HTTPS/TLS encryption on every page and API call;
- encryption of sensitive contact data (such as phone numbers) at rest in the database;
- end-to-end encryption of the licence data exchanged between the scripts and the server;
- keys and secrets kept out of the code, in environment variables;
- rate limiting on the payment and coupon routes, and logging of irregular access attempts;
- restricted administrative access, protected by a key.
No system is completely immune. If an incident occurs that could pose a relevant risk to you, we will notify you and the ANPD under art. 48 of the LGPD (and, where applicable, under arts. 33 and 34 of the GDPR).
13. Minors
The service is intended for people over 18, since it involves a contract and a payment. We do not knowingly collect children’s data. If you are the guardian of a minor who created an account or made a purchase, write to us: we cancel the subscription, refund the amount and delete the data.
14. Relationship with the game
PaulinhoScripts is an independent project. We are not, do not represent and have no connection to InnoGames GmbH or to the official Tribal Wars operators. We have no access to your game account, your password, or the data the game holds about you. Our tools run in your browser, using the session you already opened.
15. Changes to this policy
When this policy changes, the "last updated" date at the top changes with it. If the change is significant — a new purpose, a new recipient, a longer retention period — we give at least 15 days notice on WhatsApp and in the announcements group before it takes effect.
16. How to reach us
E-mail: [email protected]
WhatsApp: (75) 99179-0412
Support centre: paulinhoscripts.com.br/en/support
Billing, cancellation and refund matters are in the Refund and Cancellation Policy.