Privacy Policy
Last updated: 3 August 2026
This policy explains how tendeta handles personal data when you use our website, create a store or place an order with a store.
Who is responsible
tendeta is responsible for the platform data described in this policy. You can contact us at support@tendeta.io.
Data we collect
We process account details such as your email address and name; store details and product content you choose to publish; order details such as customer name, email, phone number, note, delivery address and chosen delivery method; payment status and provider references; and limited technical data needed to operate and secure the service. tendeta does not receive or store full card numbers.
PDF catalogue conversion
When a PDF catalogue contains usable text, conversion happens in your browser. If a page is a scan or flattened image, a compressed image of that page is sent to Cloudflare Workers AI to identify product details and photo regions. tendeta does not retain the submitted page image. Product-photo crops approved for import are stored temporarily for up to one hour so they can be copied into your store.
For visitors who are not signed in, we store a salted hash derived from the connecting IP address to limit AI-assisted catalogue conversion to three free uses and prevent abuse. We do not store the raw IP address for this limit. Signed-in users are identified by their account instead of this free-use limit.
Why we use it
We use this data to provide the service, authenticate users, publish stores, process and notify store owners about orders, provide support, prevent abuse and meet legal obligations. We process it to perform our contract with you, pursue legitimate interests in operating a safe service, meet legal obligations or, where required, with your consent.
v1 to v2 migration emails
Where permitted by applicable law, we may use the email address of a former tendeta v1 store owner to send a limited number of messages about moving to tendeta v2. For this purpose we use only the contact details needed for the campaign, such as email address, name where available, selected shop language, former subdomain and reservation date. We do not use legacy Airtable credentials for this purpose. Every migration email includes a simple way to stop future marketing broadcasts; this does not stop essential service emails such as sign-in codes or order notifications.
Working migration campaign lists are removed within 90 days after the campaign ends. We keep only the minimal delivery, objection and suppression records needed to demonstrate compliance and make sure we do not contact someone who has opted out.
Who receives it
We use service providers that help us run tendeta, including Cloudflare for hosting, queues and storage, Resend for transactional and migration email, Google for optional sign-in and Stripe for paid subscriptions and optional payments to a store's connected Stripe account. Store owners receive the customer and delivery details submitted through their own store and are responsible for their own handling of that data.
Retention
We retain account and store data while the account is active and for a limited period afterwards where needed for support, security or legal obligations. Order contact and delivery data is retained for the store owner to fulfil and document the order, and can be deleted when it is no longer required, subject to legal retention duties. You can ask us to delete data that we no longer need to retain.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to the use of your personal data, and to request a portable copy. To exercise these rights, contact support@tendeta.io. You may also have the right to complain to your local data protection authority.
Changes
We may update this policy when our service or legal requirements change. We will post the updated version on this page.