Skip to main content
TenTrust

Last updated: 14 March 2026

Privacy Policy

TenTrust GmbH ("TenTrust", "we", "us") is committed to protecting your personal data. This policy explains what we collect, why, and your rights under the GDPR (Regulation (EU) 2016/679).

1. Who we are

TenTrust GmbH is the data controller for personal data processed through the TenTrust platform (tentrust.com and associated mobile applications). Our registered address and Data Protection Officer contact details are available at privacy@tentrust.com.

2. Data we collect

  • Account data: name, email address, password (hashed with Argon2id), locale preference.
  • Profile data: display name, profile photo, bio, trust rank, dining history.
  • Location data: GPS coordinates at check-in time only. We do not track your location continuously.
  • Review content: scores, text, photos, dish tags you submit.
  • Usage data: pages visited, features used, device type — collected via privacy-respecting EU-hosted analytics (if you consent).
  • KYC data: identity documents, processed by our KYC provider under a Data Processing Agreement. Required for specific features only.
  • Payment data: processed by our payment processor. We do not store full card numbers.

3. Legal basis for processing

  • Contract performance (Art. 6(1)(b)): account creation, check-ins, reviews, reservations.
  • Legitimate interest (Art. 6(1)(f)): fraud prevention, platform security, trust scoring.
  • Consent (Art. 6(1)(a)): analytics cookies, marketing communications, birthday deals.
  • Legal obligation (Art. 6(1)(c)): GDPR data subject requests, tax records.

4. How we use your data

  • Providing and personalising the TenTrust platform
  • Computing Trust Ranks and weighted venue scores
  • Sending transactional emails (verification, reservations, challenges)
  • Fraud detection and platform integrity (risk sidecar, velocity checks)
  • Complying with legal obligations (GDPR, Luxembourg law)

We never sell your personal data. We do not share individual taste profiles, no-show records, location history, or private messages with third parties.

5. Data retention

Active account data is retained for the duration of your account. On account deletion, personal data is anonymised within 30 days (GDPR Article 17 grace period). Audit logs are retained for 7 years for legal compliance. Anonymised, aggregated analytics data may be retained indefinitely.

6. Your rights

Under the GDPR, you have the right to:

  • Access (Art. 15): request a copy of your data via Settings → Export my data.
  • Rectification (Art. 16): correct inaccurate data via your profile settings.
  • Erasure (Art. 17): delete your account via Settings → Delete account.
  • Portability (Art. 20): download your data in JSON format from Settings.
  • Objection (Art. 21): opt out of legitimate interest processing.
  • Withdraw consent: withdraw analytics consent at any time via cookie settings.

To exercise any right, contact privacy@tentrust.com. You may also lodge a complaint with the Luxembourg data protection authority (CNPD) or your local supervisory authority.

7. Cookies

See our Cookie Policy for full details. Essential cookies cannot be disabled. Analytics cookies require your consent.

8. Changes to this policy

We will notify you of material changes by email and by displaying a banner in the app at least 14 days before changes take effect. Continued use after the effective date constitutes acceptance.

TenTrust GmbH · Luxembourg City, Luxembourg · privacy@tentrust.com

Privacy Policy | TenTrust