Legal / Privacy policy
Privacy policy
Last revised
This policy covers personal data Tenza handles as a controller — principally data about you, the merchant operating a workspace. Data about your own customers is handled as a processor on your instructions, and that relationship is governed by the data processing addendum.
Data we collect about you
- Account data — name, email, hashed password, verification and reset tokens, last login time.
- Workspace data — workspace name, slug, plan, status, billing identifiers held by our payment processor.
- Usage data — which admin actions you took and when, recorded in an append-only audit log with actor, target and IP.
- Support data — tickets you open, their messages and any attachments you upload.
- Operational logs — request and job records used to diagnose failures.
How we use it
- To operate your workspace and enforce your plan’s entitlements.
- To authenticate you and to keep other people out of your workspace.
- To bill you, through our payment processor.
- To answer your support tickets, including by reading the logs relevant to your problem.
- To tell you about outages, security matters and material changes to the service.
What we do not do
We do not sell personal data. We do not use your catalog, your customers or your creative assets to train models for anyone else’s benefit. We do not send marketing mail to your customers on our own behalf.
Passwords
Passwords are stored as PBKDF2-SHA256 hashes with a per-user random salt and a per-row iteration count, so the work factor can be raised over time without invalidating existing passwords. We never store or transmit a reversible form of your password, and we cannot tell you what it is.
Subprocessors
We use third parties for hosting and database, transactional and marketing email delivery, payment processing, and AI inference for the creative and diagnostic features. The current list, with the categories of data each receives, is maintained with the data processing addendum.
Retention
- Account and workspace data: for the life of the account, then up to 90 days after deletion.
- Audit log: 24 months, because it is what answers “who changed this”.
- Support tickets and attachments: 24 months from resolution.
- Status probe history: 90 days live, pruned at 100 days.
- Operational logs: 30 days.
Your rights
You can access, correct, export or delete your personal data. Most of it is self-serve in Settings; for anything that is not, ask support and we will action it. If you are in a jurisdiction with specific statutory rights, see the GDPR and CCPA notices.
Security
Data is encrypted in transit and at rest. Supplier and payment credentials are encrypted with a separate key and are never returned to a browser after they are saved. Access to production data is limited to the people who need it and is logged.
Contact
Privacy questions and rights requests go to support, marked as a privacy request.
Contact
Anything in this document that is unclear, or that you need in a different form, goes to support. Mark the ticket as a legal request.