Privacy Policy
Last updated: 2026-05-06
Perfio is a perfume marketplace based in Panama. This policy explains what personal data we collect, how we use it, who we share it with, and what rights you have over it. It is drafted in alignment with Panama's Law No. 81 of 2019 on Personal Data Protection.
1. Data we collect
We only collect the information needed to operate the marketplace. The data we process comes directly from you when you create an account, place an order, or contact us.
Account data: name, email address, phone number (WhatsApp), and hashed password (when applicable).
Shipping data: address, district, neighborhood, and delivery instructions.
Order data: purchase history, products viewed, and cart contents.
Technical data: IP address, session identifiers, browser type, and minimal activity logs for security and fraud prevention.
We do not collect sensitive data (race, health, biometrics) and we do not directly process credit card data: that information goes straight to our payment provider without passing through our servers.
2. How we use your data
Order processing: confirm your purchase, coordinate delivery, and issue receipts.
Transactional communication: send order confirmations, status updates, and notifications via WhatsApp/email.
Customer support: answer your questions and resolve disputes.
Security: prevent fraud, abuse, and unauthorized access.
Legal compliance: respond to lawful requests by competent authorities.
We do not use your data for third-party advertising and we do not sell it to anyone.
6. Data retention
We keep your account while it remains active. You can request closure at any time.
Order, billing, and financial records are retained for the period required by Panamanian tax and commercial law, even after account closure.
Technical records (access logs) are kept for a limited period for security purposes and then deleted or anonymized.
7. Applicable legal framework
This policy is governed by Law No. 81 of March 26, 2019 on Personal Data Protection of the Republic of Panama and related regulations.
The competent authority in Panama is the National Authority for Transparency and Access to Information (ANTAI). If you believe your rights have not been honored, you may file a complaint with this authority.
8. Contact
If you have questions about this policy or want to exercise any of your rights, email soporte@perfio.com.pa or WhatsApp us at the number published on our website.
3. Vendors that process your data
To run Perfio we work with technology vendors that may have limited access to personal data under confidentiality and processing agreements. The main ones are:
- Supabase (United States): database, authentication, and storage. Hosts your account, orders, and marketplace files.
- Vercel (United States): web application hosting. Processes your HTTP requests.
- Yappy (Panama): processes payments when you choose Yappy as the payment method. Payment data is sent directly to Yappy.
- First Atlantic Commerce — FAC (when phase 2 is enabled): credit card payment processor. Card data never touches our servers.
- WhatsApp Business API (Meta): sends transactional notifications via WhatsApp when you provide a phone number.
- Sentry (when monitoring is enabled): captures technical errors. It does not record passwords or sensitive data.
Some vendors are located outside Panama. By using Perfio you accept that your data may be processed in those jurisdictions under reasonable security standards.
5. Your rights as a data subject
Under Law 81 of 2019 you have the following rights over your personal data:
- Access: request a copy of the data we hold about you.
- Rectification: correct inaccurate or outdated data.
- Erasure: ask us to delete your data when it is no longer necessary or you withdraw consent.
- Objection: object to specific processing on legitimate grounds.
- Portability: receive your data in a structured format.
- Restriction: ask us to pause processing while a complaint is being resolved.
To exercise any of these rights, email soporte@perfio.com.pa with the subject "Data request" and we will respond within the legal timeframes.