Last updated: 28 August 2026
Easy ExtraDollar is operated by Mountain Publish LTDA, registered with CNPJ under number 38.375.288/0001-51, with its registered office at R. Ana de Carvalho Silveira, nº 287, Silveira, Belo Horizonte/MG, CEP 31.140-440, Brazil ("Easy Extra Dollar", "we", "us" or "our").
The site's advertising intermediation and monetisation are provided by Timo Midia LTDA, registered with CNPJ under number 62.179.475/0001-44, with its registered office at Rua Ana de Carvalho Silveira, nº 287, Apto 302, Silveira, Belo Horizonte/MG, CEP 31.140-440, Brazil, which is responsible for the intermediation and monetisation of the programmatic advertising inventory displayed on the site.
This Privacy Policy describes how we collect, use, share and protect the personal data of our visitors and readers, in accordance with the General Law for the Protection of Personal Data (LGPD, Law nº 13,709/2018), the Marco Civil da Internet (Law nº 12,965/2014), the Consumer Protection Code (Law nº 8,078/1990) and, when applicable, the data protection laws of other countries to which we direct content, detailed in the Local Addendum at the end of this document. By accessing or using the website, you declare that you have read, understood and agree with this document.
1. SCOPE OF THE POLICY
This Policy applies to the processing of personal data in the context of this website and the technologies used on it, and, where applicable, in the context of digital properties and advertising inventory operated or monetized by Timo Midia LTDA in connection with the website. It covers activities such as security, measurement, fraud and invalid traffic prevention, performance improvement, advertising delivery and verification, and user support.
This Policy does not apply to third-party websites, products or services, even when accessed through links or advertisements displayed here, nor to environments that expressly indicate another company as the main controller.
Where there is a Local Addendum applicable to your country or relevant jurisdiction, that Addendum will supplement this Policy. In the event of a conflict, the Local Addendum will prevail only to the extent necessary to comply with mandatory local law.
2. NATURE OF THE OPERATION (ADTECH)
Timo Midia LTDA acts as an AdTech specialized in technical infrastructure, digital advertising inventory management, optimization and monetization of advertising spaces for publishers and media outlets. Its activities include the delivery of programmatic advertising, audience measurement, prevention of traffic fraud, bots and technical abuse, as well as email marketing solutions and newsletters to retain its own audience.
3. PRIVACY PRINCIPLES
We adopt technical and administrative controls based on the following principles:
Transparency: provide clear information about the purposes of data processing. Purpose: Process data only for legitimate and informed purposes. Minimization: collect the necessary and proportional data for the operation. Security and prevention: adopt reasonable measures to protect data and mitigate incident risks. Accountability: Accountability for adopting effective compliance measures. Respect for user choices: ensure viable consent and opt-out management mechanisms, when applicable. Limited retention: retaining data only for as long as necessary for legitimate purposes.
4. IMPORTANT DEFINITIONS
Personal data: information that identifies or makes identifiable a natural person, including online identifiers. Technical data: records generated by devices during access, such as logs, network metadata and software characteristics. Aggregated or anonymized data: information subjected to processes that prevent reasonable association with an individual. Cookies: small files stored in the browser to record preferences and technical parameters. Pixels, tags and web beacons: elements used to monitor events, such as advertising delivery or email openings. Programmatic advertising: automated purchase and sale of advertising spaces. Online identifiers: technical codes, such as cookie or advertising IDs, associated with browsers or devices. Invalid Traffic (IVT): Artificially or bot-generated impressions, clicks, or events that distort real metrics, including incentivized or deceptive clicks. Controller: agent that determines the main purposes and means of processing. Operator/Processor: agent who processes data on behalf of and under instructions from the Controller. Independent controller: third-party agent that determines its own processing purposes when interacting with the ecosystem.
5. ROLES AND DIVISION OF DUTIES
5.1 Our role
We are responsible for the editorial operation of this website, for the published content, for the domain, for hosting (unless contracted with Timo Midia LTDA), for our own forms, for the products and services provided and for responding to requests related to this content.
5.2 Role of Timo Midia LTDA
Depending on the technical context of the operation, Timo Midia LTDA can act:
As Controller, when it determines purposes and means of processing, such as in the security management of its own campaigns and in the protection of its infrastructure; As an Operator/Processor, when it provides technology or processes data on our behalf, following our instructions; As a technical monetization partner, working on the infrastructure that connects the website to advertising demand networks; Alongside Independent Controllers, such as Google, SSPs, DSPs, ad exchanges, ad servers and anti-fraud and measurement tools, which can process data under their own policies, legal bases and responsibilities.
5.3 Division of responsibilities
Timo Midia LTDA will not be automatically responsible for editorial content, hosting, domain, legal notice, own forms, commercial service, products, services or commercial promises of this website, when these activities remain under our control. We will not automatically be responsible for the advertising technology layer, programmatic integrations, advertising consent signals, fraud prevention and invalid traffic when these activities remain under the technical control of Timo Midia LTDA.
The exact legal qualification of each party will depend on the purposes of the processing, the means effectively determined by each participant, the technical configuration of the environment and the mandatory standards of the applicable jurisdiction. When necessary, specific instruments may be signed between us and Timo Midia LTDA to regulate roles, responsibilities, joint treatment and cooperation with competent authorities.
6. DATA WE COLLECT
6.1 Technical and navigation data
IP address and approximate geographic location derived from the IP; Date and time of access, pages accessed, referring and exit URLs; Browser, operating system, device type, language, screen resolution and user agent; Cookies and advertising identifiers; Logs, click events, impressions, ad interactions, security signals, and traffic patterns.
6.2 Cookie data and consent
Preferences recorded, consents granted, refused or revoked; Date, time and version of consent; Opt-out options and recognized privacy preference signals when required and technically supported.
6.3 Advertising and monetization data
Ad requests and frequency, viewability and brand safety metrics; Inventory information, aggregate reports and aggregate performance and revenue data; Anti-fraud signals and traffic audit data; Device identifiers, audience segments and advertising preferences managed by the advertising platforms used on the website.
6.4 Data provided voluntarily
Name, email, telephone number and company, when provided in forms, quizzes or contact messages; Content of messages, documents or attachments sent via customer service; Data necessary to validate holder requests.
6.5 Push notification and email marketing data
Device token and notification preferences, collected exclusively with prior and express consent, when the website offers this feature; Email, name (when provided), origin of registration, date and time of registration; Proof of opt-in, communication preferences and history of sending, delivery, opening, clicks, bounces and spam complaints; Unsubscription records and data maintained on a suppression list.
6.6 Sensitive and minor data
We do not seek to collect sensitive data or data from children. Our digital environments are not aimed at children under 18 years of age. If inadvertent collection of data from minors without adequate legal support is identified, we will adopt reasonable measures to delete, anonymize or restrict processing.
7. PURPOSES OF TREATMENT
We process the data collected for: technical operation of the website, stability and performance; security, fraud prevention, combating bots, abusive scraping and invalid traffic (IVT); audience measurement and performance analysis; advertising monetization, delivery, measurement, frequency and optimization of ads; contextual advertising and brand safety maintenance; personalized advertising, when there is a valid legal basis; consent and reporting management; user service and defense of rights in processes or audits; compliance with legal obligations; sending newsletters and communications by email; and managing unsubscribes and suppression lists.
8. LEGAL BASIS FOR TREATMENT
Consent (LGPD Art. 7, I): for non-essential cookies, push notifications, personalized behavioral advertising and sharing of audience matching data (Section 13.2). It can be revoked at any time (LGPD Art. 15), through the channels indicated in Section 25. Legitimate interest (LGPD Art. 7, IX): for technical operation, security, fraud prevention, contextual advertising and aggregate metrics, respecting your rights. Execution of contracts or preliminary procedures (LGPD Art. 7º, V): to respond to requests. Compliance with legal or regulatory obligations (LGPD Art. 7º, II): for retention of logs and compliance with judicial and regulatory determinations. Regular exercise of rights (LGPD Art. 7º, VI): for our legal protection and that of Timo Midia LTDA.
9. COOKIES AND SIMILAR TECHNOLOGIES
The operation may involve cookies, pixels, tags, local storage and session identifiers, organized into:
Necessary: essential for stability, security and consent management — do not depend on consent as they are essential for the website to function; Functional: save basic choices, such as language and region; Measurement: collect technical traffic data in aggregate form; Advertising: used for ad delivery, frequency capping, ecosystem protection and targeted advertising; Security: focused on preventing anomalous activities and fraud.
Preference management can be done through the banner or preference center, when available, or through browser settings. Disabling cookies may affect website functionality. For third-party advertising cookies, you can also visit optout.aboutads.info.
10. PROGRAMMATIC ADVERTISING AND RELATIONSHIP WITH GOOGLE AND PARTNERS
Timo Midia LTDA uses advertising technology platforms, including Google Ad Manager, Google Ad Exchange (AdX), Google AdSense and MCM, and may operate as a Google ecosystem partner, as applicable. These partners may process technical data, online identifiers and navigation information to select ads, measure performance, prevent fraud, limit frequency, protect advertisers, generate reports and enforce their platform policies.
We and Timo Midia LTDA are committed to operating in compliance with the Google Ad Manager/AdSense/AdX program policies, including prohibiting invalid traffic, incentivized clicks, deceptive content, and manipulation of ad units (e.g., ad stacking, pixel stuffing). Failure to comply with these rules by any party could put the entire network's advertising account at risk.
You can personalize the ads you see on Google services and control the information used to personalize them on myadcenter.google.com/home. For more details on how Google processes data on partner sites, see policies.google.com/technologies/partner-sites.
11. CONSENT MODE AND TECHNICAL SIGNAL MANAGEMENT
Where applicable, we have integrated Google Consent Mode, which governs technical signals such as ad_storage, analytics_storage, ad_user_data and ad_personalization as you choose. If you deny or revoke consent, tags operate with restrictions: systems can send signals without cookies, perform aggregate data modeling, or stop using information for personalized advertising.
12. EMAIL MARKETING, NEWSLETTERS AND ELECTRONIC COMMUNICATIONS
When we provide newsletters or email communications, delivery depends on an appropriate legal basis — consent or legitimate interest, depending on the jurisdiction.
Right to unsubscribe: every email contains a clear and functional means of opt-out, respected within the applicable legal deadline. Tracking: When permitted, emails may contain pixels, web beacons or tracking links to measure delivery, opens, clicks and engagement. Suppression list: after unsubscription, the address is kept on the suppression list for the time necessary to prevent new undue shipments, prove fulfillment of the order and protect the operation against undue re-imports.
Complaints about unsolicited communications can be sent to the channels indicated in Section 25.
13. DATA SHARING
13.1 Recipient categories
We may share data, as necessary, with: hosting, CDN and infrastructure providers; cybersecurity and fraud prevention services; analytics and measurement tools (e.g. Google Analytics); CMP and tag management providers; programmatic advertising platforms, SSPs, DSPs, ad exchanges and ad servers; email marketing and push notification providers, when used; consultants and auditors, with safeguards; other digital properties operated by us or the same network, exclusively to recommend relevant products and services; and public authorities, upon legal obligation, court order or valid request.
We do not sell your personal data to third parties. Each partner operates under its own privacy policy and is individually responsible for the processing it carries out.
13.2 Audience matching and conversion measurement
When you fill out a form or quiz and confirm your email with explicit consent, we may share with partner advertising platforms (e.g. Google Ads, via Customer Match and Enhanced Conversions, and Meta, via Conversions API) encrypted versions — SHA-256 hash, one-way and non-reversible — of your email and name, along with campaign and browser identifiers when available (e.g. gclid, fbclid). The purposes are measuring and attributing conversions, building personalized audiences and building suppression audiences to exclude those who requested opt-outs.
We do not send email, name, telephone, address or any other personal data in a readable or reversible format to these platforms — only the hash, which cannot be reversed to recover the original data. The legal basis is free, informed and unequivocal consent (LGPD Art. 7, I), collected at the time of completion through a non-pre-marked consent box, revocable at any time through the channels in Section 25. The hashes remain in the audiences of the partner platforms for the period defined in their respective policies (currently up to 540 days in the case of Google Customer Match, renewable for each interaction) or until the consent is revoked, whichever occurs first.
14. INTERNATIONAL DATA TRANSFERS
Due to the international nature of the internet, cloud computing and programmatic advertising, data may be processed and stored outside of your country of residence — including by US-based providers like Google. We adopt safeguards for these transfers, including standard contractual clauses approved by the National Data Protection Authority (ANPD), in accordance with Art. 33 of the LGPD, and other mechanisms recognized by applicable legislation.
15. DATA RETENTION AND DISPOSAL
We retain data for as long as necessary for the purposes of this Policy, including compliance with legal obligations, consent records, defence of rights, suppression list administration, technical and anti-fraud logs, aggregate reports and email marketing data for as long as there is a legal basis, active relationship or legitimate need. Browsing data and access logs are kept for at least 6 months, as required by Article 15 of the Marco Civil da Internet, and may be retained for an additional period when necessary for the purposes of this Policy or upon legal determination. Once no longer needed, the data is securely discarded or anonymized.
16. HOLDERS’ RIGHTS
You may, at any time, exercise your rights to: confirm the existence of treatment; access to your data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary data or data processed in violation of the law; portability to another supplier, when technically feasible; deletion of data processed based on consent; information about sharing with third parties; revocation of consent; opposition to treatments; and review of automated decisions, when applicable.
To exercise these rights related to editorial content and the website's own functionalities, please contact us through the website channel indicated in Section 25. To exercise these rights specifically in relation to the programmatic advertising layer operated by Timo Midia LTDA — including data processed under Section 13.2 — please contact [email protected].
We may request additional information to verify your identity. We will respond within 15 days, in accordance with Art. 19, II of the LGPD; deadlines for other jurisdictions are set out in the applicable Local Addendum.
You also have the right to lodge a complaint with the National Data Protection Authority (ANPD) if you understand that your rights as a data subject have been violated: gov.br/anpd, Esplanada dos Ministérios, Bloco C, 4th floor, Brasília/DF, CEP 70.297-400.
17. OPT-OUT, DO NOT SELL OR SHARE AND PRIVACY PREFERENCE SIGNALS
When applicable legislation recognizes the right to opt-out of "selling", "sharing" or behavioral/personalized/targeted advertising, we will provide appropriate mechanisms — through the preference center, through the contact channel or through signal recognition such as Global Privacy Control, when technically supported. After opting out of personalized advertising, you may continue to see contextual ads not targeted by profiling.
18. INFORMATION SECURITY
We adopt technical and organizational measures compatible with the risks, including HTTPS connections, encryption in transit, access control with least privilege, audit logs, firewalls, monitoring, bot prevention and anti-fraud tools, seeking alignment with international standards such as ISO/IEC 27001 and 27701. No system connected to the internet is completely immune to risks, external infrastructure failures or incidents caused by third parties.
19. SECURITY INCIDENT RESPONSE PLAN
In the event of a confirmed or suspected security incident under our responsibility, we will act to identify, contain and investigate the threat, adopting mitigation measures. Communication to authorities and holders will occur when required by law — in Brazil, pursuant to Art. 48 of the LGPD — maintaining internal documentation of the measures adopted.
20. AUTOMATED DECISIONS AND PROFILING
Automated signal processing occurs primarily for security, invalid traffic detection, bot prevention, measurement and advertising targeting. We do not seek to make exclusively automated decisions that produce relevant legal effects or similar significant impact on you without a legal basis, transparency and respect for applicable rights.
21. LINKS, ADVERTISEMENTS AND THIRD PARTIES
The site may display third-party advertisements, scripts, integrations, or links. We do not fully control these external environments, which have their own privacy policies and data practices. Clicking on an ad and visiting a partner page does not create a relationship with us — we recommend reviewing the privacy policy of each third-party site before providing information.
22. DIGITAL ACCESSIBILITY
We make reasonable efforts to align the development of our interfaces with the precepts of digital inclusion and web accessibility (WCAG 2.2 AA), when technically feasible. Technical barriers can be reported through the channels indicated in Section 25.
23. LANGUAGES AND VERSIONS
This Policy may be made available in other languages. In case of interpretative divergence, the official version in Brazilian Portuguese prevails, unless mandatory local regulations require otherwise in the user's jurisdiction of residence.
24. UPDATES TO THIS POLICY
This Policy may be revised at any time. The "last updated" date at the top indicates the current version. Relevant changes will be communicated by visible notice on the website, when required by law.
LOCAL ADDENDUM TO THE PRIVACY POLICY
This addendum supplements the Privacy Policy when South African law applies.
Local Addendum – South Africa
When applicable, processing will observe the Protection of Personal Information Act – POPIA and rules from the Information Regulator.
Users in South Africa may exercise rights of access, correction, deletion, objection to processing, objection to direct marketing and complaint before the competent authority.
Direct marketing by electronic means will observe Section 69 of POPIA.
Security incidents involving personal information will be communicated to the Information Regulator and affected data subjects when required by law.
25. CONTACT
Compliance, Privacy and DPO email: [email protected]