← tengo.

Privacy Policy

Last updated: 23 July 2026. Tengo is a self-custody spending product, and it is built to hold as little of your data as possible. The most sensitive information — your identity documents and your full card number — never reaches Tengo's servers at all; it is handled inside our regulated partners' own secure components. This policy explains what we do and don't process.

Who we are

The data controller is Novastra Digital Ireland Limited (the "Company"), a company incorporated in Ireland (CRO no. 88541) with its registered office at 25 North Wall Quay, Dublin 1, D01 H104, Ireland, which operates the Tengo application at app.tengo.finance. Its parent, Novastra Holding B.V. (Herengracht 450, 1017 CA Amsterdam, The Netherlands; KvK no. 2074), processes personal data on the Company's behalf under an Intra-Group Data Processing Agreement. For any privacy question, or to exercise your rights, contact privacy@tengo.finance or legal@novastra.ie.

What we collect, and why

What never touches Tengo

The most sensitive data is handled entirely by our regulated partners, inside their own secure components, and is never sent to or stored by Tengo:

Who else processes your data

We share data only with the processors needed to run the service, each under a data-processing agreement, and we never sell personal data:

How we protect it

Personal data is encrypted at rest with per-column encryption (a sealed-box scheme); systems that only write data cannot read it back. IP addresses are only ever stored as a one-way hash. Logs are scrubbed of personal data. We run no analytics SDKs and no marketing pixels, and set no tracking cookies — the only cookie is the sign-in token set by Privy.

Legal bases (EEA / UK)

How long we keep it

Account data is kept for the life of your account. Card-session tokens expire automatically; rate-limit hashes self-delete; waitlist entries are kept until you ask us to remove them. Data held by our card and identity partners is retained under their own policies and applicable law.

Your rights

If you are in the EEA or UK you have the GDPR rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. To exercise any of them, write to privacy@tengo.finance. Some data is held by our card and identity partners for regulatory reasons; we will route your request appropriately.

International transfers

Some processors may handle data outside your country; where they do, transfers rely on appropriate safeguards such as EU Standard Contractual Clauses.

Changes

We will post any changes here and update the date above. Questions: privacy@tengo.finance.