← Back to Tenderal

Privacy Policy

Last updated: April 2026

Plain-English summary. We collect the minimum personal data needed to run Tenderal: your account email, your saved searches and favourites, and your payment information (handled by Stripe — we never see your card number). We never sell your data. You can export or delete it at any time.

1. Who is the data controller

Tenderal ("we", "us") is the controller of your personal data under GDPR (EU/EEA users), UK GDPR (UK users), and equivalent laws in other jurisdictions. Contact: info@tenderal.com.

2. What we collect

CategoryExamplesWhy
Account dataEmail, name, company, country, password hashSign-in, support, invoicing
Profile preferencesSaved searches, favourites, alert rules, declared sectorsPersonalise the product
Billing dataStripe customer ID, plan, invoice history, billing addressProcess payments, tax receipts
Usage dataPages viewed, search terms, clicks, device/browser info, IP addressImprove the product, detect abuse
Support messagesEmails, chat logs, attachments you send usAnswer your questions
CookiesSession, preferences, and (optional) analytics cookiesKeep you signed in; measure usage

We do not collect: payment card numbers (Stripe does), government ID, biometric data, or special-category data (race, religion, health, etc.).

3. Legal bases (GDPR Art. 6)

4. Who we share data with

We never sell or rent your personal data.

5. International transfers

Some providers (Stripe, Cloudflare) may process data in the United States or other jurisdictions. We rely on Standard Contractual Clauses (SCCs) and each vendor's certifications (e.g. Data Privacy Framework) as the legal basis for those transfers.

6. Retention

7. Your rights

You have the right to: access your data, correct it, delete it, port it to another provider, object to processing, restrict processing, and withdraw consent at any time. Email privacy@tenderal.com to exercise any of these. We respond within 30 days.

EU/EEA users may also lodge a complaint with your national data protection authority. UK users: ICO.

8. Cookies

We use a small number of cookies:

9. Security

We use TLS 1.2+ for all traffic, bcrypt-hashed passwords, least-privilege database access with row-level security, and encrypted backups. No system is 100 % secure; if we detect a breach that affects you, we will notify you within 72 hours as required by GDPR.

10. Children

Tenderal is a B2B tool for procurement professionals and is not directed to anyone under 18. We do not knowingly collect personal data from minors. If you believe we have such data, email privacy@tenderal.com and we will delete it.

11. Changes

We may update this policy to reflect product or legal changes. Material updates will be announced by email at least 14 days before they take effect.

12. Contact

Privacy questions or data-subject requests: privacy@tenderal.com. General contact: info@tenderal.com.