Skip to content

Privacy Policy

Privacy and Cookie Policy — effective and last updated: October 6, 2026.

This Policy explains how Grandma Naoca, at recipes.vonaoca.com.br, handles information when you read our recipes and crochet guides or contact us. It describes collection, purposes, recipients, retention, and privacy choices. Our editorial audience is in the United States; the operator is based in Brazil. Rights depend on applicable law and the circumstances of processing.

1. Who is responsible

Vó Naoca Empreendimentos Ltda., CNPJ 56.433.321/0001-34, owns and operates the website. Registered address: PSG Brasília, 8, Telégrafo Sem Fio, Belém, Pará, CEP 66115-430, Brazil. Visit Contact Us for the available contact methods. Identify Grandma Naoca and recipes.vonaoca.com.br in a request.

2. Information collected and its sources

  • Contact and request information: your name if provided, reply details, message, article URL, attachments you choose to send, and records of our response. The source is you or a person authorized to act for you.
  • Technical and browsing information: IP address, browser, device, operating system, approximate location, referring page, pages visited, search terms used on the site, access times, errors, and security events. Our infrastructure and providers may receive these automatically.
  • Analytics information: cookie or similar identifiers, clicks, scrolling, page interactions, and events used to understand how the website works.
  • Advertising information: identifiers, ad views or clicks, browsing activity, and interests inferred by advertising technology for measurement or personalization where permitted.

We do not ask readers to send payment-card details, Social Security numbers, passwords, precise location, medical records, or an individual health history. A recipe question does not require a diagnosis. Do not include sensitive information in a site search or ordinary message. Dietary content is not a request for health information.

3. Why information is used

We use information to deliver and secure the website, answer questions, investigate recipe corrections, address accessibility problems, prevent abuse, understand readership, measure advertising, support publishing revenue, handle privacy choices, and meet legal obligations. Contact correspondence is not a marketing subscription and is not intended for advertising targeting.

4. Cookies, analytics, advertising, and other services

Cookies, tags, pixels, and similar technology may support essential functions, preferences, traffic measurement, advertising auctions, and personalized advertising. Google Tag Manager and Cloudflare tools may help deliver integrations. A first-party-looking script address does not necessarily mean the information stays only with us.

Google Analytics and Google advertising

We use Google Analytics and Google advertising, including AdSense and monetization partners participating in Google advertising inventory. Google and ad vendors may receive page URLs, IP addresses, identifiers, and interaction information. Advertising vendors may use cookies to serve ads based on visits to this and other sites, subject to applicable choices.

Read how Google uses information from partner sites, Google’s Privacy Policy, and Google’s U.S. display-advertising notice.

Microsoft Clarity

Clarity helps us understand clicks, scrolling, heatmaps, and session playback. It can record page structure and interaction events. Its masking features address certain sensitive fields; this is not a guarantee that every piece of information you enter is anonymous. Read Clarity’s data-collection information and the Microsoft Privacy Statement.

Criteo and advertising technology

Criteo technology may process browser or device identifiers, browsing activity, and ad interactions to support advertising, audience matching, and measurement. See Criteo’s Privacy Policy and its browser opt-out instructions. Advertising auction, recommendation, and performance-measurement providers may also receive technical information as part of delivering or measuring commercial content. Ad vendors and availability can vary by browser, location, and auction.

Infrastructure, messages, avatars, and external content

Hosting, delivery, security, and email providers process information needed to operate their services. Cloudflare supports delivery, security, and performance; see Cloudflare’s Privacy Policy. Author portraits are served through Gravatar, which receives the browser request needed to display the image; see Automattic’s Privacy Policy.

Correspondence may remain in the operator’s receiving mailbox and relevant service records. Visit Contact Us for the currently available method. If a Contact Form 7 form is provided there, its default functionality sends a message rather than maintaining its own WordPress inbox; mailbox or separately configured storage can retain a copy.

Linked videos and external websites have their own practices. Following a YouTube link opens a separate service; an embedded player, if used, may receive device and interaction data when it loads. A link and an embedded player do not collect information in the same way.

5. Recipients and advertising disclosures

Information may be disclosed to hosting, security, communications, analytics, advertising, ad-auction, and performance-measurement providers for the purposes above; advisers when needed; authorities when lawfully required; or a successor in a legitimate business transfer subject to applicable protections. A provider’s role may be processor, service provider, or independent controller depending on the agreement and activity.

Disclosures of identifiers, browsing activity, or inferred interests for advertising may qualify as a “sale,” “sharing,” or targeted advertising under some U.S. state laws, even without payment for an individual record. We do not describe all advertising data flows as exempt from those definitions.

6. Your Privacy Choices — opt-out

Do Not Sell or Share My Personal Information / Opt Out of Targeted Advertising: visit Contact Us for the available request method and identify your request as an advertising opt-out. No account, purchase, or payment is required. This is a request channel, not a control that instantly turns off every third-party tag. We will explain any information reasonably needed to implement a choice.

These provider and U.S. industry resources offer additional controls:

Controls have different scopes. They may depend on a browser, device, or account and may need renewal after cookies are cleared. They do not necessarily remove ads or stop essential processing, and an industry opt-out does not replace a statutory request to the operator.

Manage cookies with official instructions for Chrome, Firefox, Safari, or Microsoft Edge. Blocking essential cookies can affect functionality.

Browser privacy signals

Global Privacy Control (GPC) communicates certain statutory opt-outs and is distinct from the older Do Not Track (DNT) setting. Applicable law can require a covered business to honor recognized signals. See California’s GPC guidance and Colorado’s universal opt-out guidance. Our integrations have not all been independently verified to respond to GPC. Contact us for confirmation or help with an opt-out; DNT alone is not represented as a universal technical opt-out.

7. How long information may be kept

Our ordinary policy is to retain contact correspondence for 9 months after the matter is closed, extending up to 18 months only for necessary follow-up, an unresolved matter, or a documented operational need. Information should be deleted or anonymized sooner when no longer needed. These are operator retention rules, not a claim that every provider automatically uses the same schedule.

Operational and security records under our direct control are reviewed within 9 months and ordinarily retained no longer than 18 months. Shorter provider periods may apply. Incident, legal-hold, dispute, and privacy-request compliance records may require a different period. Where California’s request-record requirement applies, privacy-request and response records are kept for at least 24 months, restricted to compliance purposes. A record is kept longer only when necessary for its purpose or required by applicable law; restricted backups remain until their normal secure rotation.

  • Microsoft Clarity: ordinary playback is retained for 30 days; click/heatmap data and labeled or favorited sessions for 9 months, according to Microsoft’s retention documentation.
  • Standard Google Analytics user/event controls offer 2 or 14 months. The actual period depends on the property setting; aggregated reports and some other records are treated differently. The property’s setting has not been independently audited here. See Google Analytics retention details.
  • For certain advertising logs, Google describes removing part of IP addresses after 9 months and cookie information after 18 months. This is not a universal deletion deadline for every Google record. See Google’s retention policy.
  • Criteo and other advertising providers set purpose-specific periods under their own policies and applicable law. Ask through Contact Us about a particular record; our 9–18 month operational range does not override those rules.

8. U.S. privacy rights and requests

Depending on your state, a law’s coverage, and applicable exceptions, you may have rights to access, correct, delete, receive a portable copy, or opt out of sale, sharing, targeted advertising, or certain consequential profiling. Some laws provide rights concerning sensitive information, authorized agents, appeals, and non-discrimination. We do not use recipe readership to make employment, credit, housing, or similar eligibility decisions.

Visit Contact Us, identify the right and relevant interaction, and provide a way to respond. Identity verification may be needed for access or deletion to protect records; an opt-out does not require account creation or unnecessary identity documents. An authorized agent may submit a request with appropriate evidence of authority. We respond within the applicable legal period, generally 30 or 45 days for many access/deletion laws, and explain any permitted extension or exception. Opt-outs may have shorter deadlines. To appeal where available, identify the earlier decision and say “Privacy appeal.” You may also contact your state attorney general or privacy regulator.

See the California Attorney General’s CCPA guidance. Rights apply when legal coverage conditions are met; not every visitor or small publisher is covered identically. The information above identifies our current collection categories, sources, purposes, and recipient categories; it is not a claim that every possible historical record was audited.

9. Children

Grandma Naoca is intended for general adult home-cooking and craft readership, not children under 13. We do not knowingly seek personal information from children under 13. If a child has supplied information, contact us so we can investigate and take appropriate deletion or other steps. We do not knowingly authorize sale or sharing of personal information of children under 16. Read the FTC’s children’s privacy guidance.

10. International processing and security

Information may be processed in Brazil, the United States, and other countries where providers operate. Laws can differ. We use reasonable organizational and technical safeguards and applicable contractual protections; no online system guarantees absolute security. Incidents are assessed under applicable notification requirements. Brazilian privacy law may also apply based on its territorial rules. Visiting the site is not blanket consent to every international transfer or optional tracking use.

11. Changes and questions

We update this Policy when practices or requirements materially change and show the current date above. Additional notice will be provided where required. For privacy questions, requests, corrections, or consent withdrawal where relevant, visit Contact Us. Our Terms of Use and Disclaimer provide additional information about the website.

Explore Grandma Naoca