Back to home

Privacy Policy

Effective 7 September 2026· Tendie Terminal

This notice explains what Tendie Terminal collects, why we collect it, who processes it on our behalf, and how to get it exported or deleted. It is written to satisfy the GDPR and the CCPA/CPRA, and to be readable in one sitting.

01 / Collection

What we collect

We collect the minimum needed to run an authenticated, billed product:

  • Account and identity data, handled by Clerk: your email address, authentication tokens, session records, and any profile fields you supply. Passwords and OAuth credentials are held by Clerk; we never see or store them.
  • Billing telemetry from our payment processor: subscription status, plan, renewal dates, and the last four digits and brand of the card. Full card numbers are never transmitted to or stored by us.
  • Session and usage data: pages loaded, features used, timestamps, IP address, browser and device type, and error diagnostics — collected to keep the platform reliable and to detect abuse.
  • Cookies, limited to what the product needs: a session cookie set by Clerk to keep you signed in, and a local preference for your colour theme. We do not run advertising or cross-site tracking cookies.
  • Content you create in the platform: watchlists, saved scanner configurations, filters, and similar settings, stored against your account so they persist between sessions.

02 / Use

How we use it

Data is used to authenticate you, provision the access your plan entitles you to, operate and secure the platform, diagnose faults, and administer billing. We also use it to send service communications — security notices, billing events, and material changes to this policy.

We do not sell personal data to third parties, and we do not share it with advertisers or data brokers. We do not use your data to train models offered to anyone else.

Our lawful bases under the GDPR are performance of a contract (providing the Service you subscribed to), legitimate interests (security, abuse prevention, and reliability), and legal obligation (tax and accounting records). Under the CCPA/CPRA we do not sell or share personal information as those terms are defined, and we have not done so in the preceding twelve months.

03 / Processors

Security and sub-processors

Traffic is served over TLS, access to production systems is restricted and authenticated, and secrets are held outside the source tree. No system is perfectly secure, so we also keep the amount of personal data we hold small by design.

We rely on the following sub-processors, each under its own data processing terms:

  • Clerk — identity, authentication, and session management.
  • Our payment processor, acting as merchant of record — payment collection, subscription billing, invoicing, and tax handling.
  • Namecheap — domain and email routing for our correspondence addresses.
  • Resend — delivery of transactional email such as account and billing notices.
  • Our hosting and infrastructure providers, which store application data and operational logs.

04 / Retention & rights

Your data, and getting it back or removed

We keep account data for as long as your account is active. On deletion, profile and application data are removed within 30 days, except records we must retain for legal, tax, or fraud-prevention reasons, and operational logs which age out on their own retention schedule.

You may request access to, correction of, export of, or deletion of your stored profile data, and may object to or request restriction of certain processing. Where processing rests on consent, you can withdraw it at any time. We do not discriminate against anyone who exercises these rights.

To make a request, email us from the address on your account so we can verify it. We respond within 30 days. If you are in the EEA or UK you may also complain to your local supervisory authority.

The Service is not directed at children under 16, and we do not knowingly collect their data.