Last updated: August 2026
Tenlo is the data controller for personal data collected through this platform. For any privacy-related queries, you can contact us at privacy@tenlo.app.
· Account data: username, email, password (encrypted), optional phone number.
· Verification data (KYC): identity document, required for installment purchases.
· Transaction data: purchase history, payments, withdrawals and wallet movements.
· Usage data: pages visited, device, IP address (for security and fraud prevention).
· Shipping data: name, address, phone when making a purchase.
· Provision of marketplace services and management of installment payments.
· Identity verification (KYC) for regulatory compliance.
· Fraud prevention and platform security.
· Transactional communications (order confirmations, payment reminders).
· Service improvement through usage analysis (anonymized data).
· Contract performance: processing necessary to provide the service.
· Legal obligation: KYC verification and retention of financial and dispute records.
· Legitimate interest: fraud prevention and security.
· Consent: marketing communications (if you have opted in).
We retain your data while you maintain an active account. Transaction and dispute data is retained for 5 years due to legal obligations (tax and financial regulations). If you delete your account, we anonymize your personal data immediately, retaining only the financial records required by law.
· Access: request a copy of your personal data.
· Rectification: correct incorrect data from your profile.
· Erasure: delete your account and data from profile settings.
· Portability: receive your data in a structured format.
· Objection: object to certain processing activities.
· Restriction: request restriction of processing.
To exercise any right, write to us at privacy@tenlo.app. You may also lodge a complaint with your country's supervisory authority.
We use third-party services (Vercel, Railway, Resend, PayPal, Sentry, PostHog) that may process data outside the European Economic Area. All of them have appropriate safeguards in place (standard contractual clauses or equivalent certifications).
We apply technical and organizational measures to protect your data: encryption in transit (HTTPS), bcrypt-hashed passwords, optional two-factor authentication, audit logs for critical actions, and restricted data access.
We only use strictly necessary cookies for platform operation (session, language preferences). We do not use advertising or third-party tracking cookies without your consent.
For any privacy queries or to exercise your rights:
This policy may be updated. We will notify you by email of any significant changes.