← tengo.
Privacy Policy
Last updated: 23 July 2026. Tengo is a self-custody spending product, and it is built to hold as little of your data as possible. The most sensitive information — your identity documents and your full card number — never reaches Tengo's servers at all; it is handled inside our regulated partners' own secure components. This policy explains what we do and don't process.
Who we are
The data controller is Novastra Digital Ireland Limited (the "Company"), a company incorporated in Ireland (CRO no. 88541) with its registered office at 25 North Wall Quay, Dublin 1, D01 H104, Ireland, which operates the Tengo application at app.tengo.finance. Its parent, Novastra Holding B.V. (Herengracht 450, 1017 CA Amsterdam, The Netherlands; KvK no. 2074), processes personal data on the Company's behalf under an Intra-Group Data Processing Agreement. For any privacy question, or to exercise your rights, contact privacy@tengo.finance or legal@novastra.ie.
What we collect, and why
- Waitlist: your email, country, and browser language. The email is encrypted at rest and also kept as a one-way hash for de-duplication; country tells us where to launch next. Basis: your consent.
- Sign-in: we authenticate you through Privy. Privy's token is verified in memory and we store only a pseudonymous internal identifier derived one-way from it — we do not store your Privy ID or access token.
- Account: when you set up a card we store your email (encrypted at rest) and your country.
- Wallet address: the public blockchain address of your wallet, so we can show your on-chain positions. This is public on-chain data and is stored in plain form.
- Card & account setup: a small set of identifiers our card partner returns — your virtual card ID, the last four digits of the card, your card account (Safe) address, and your spending currency. We store the KYC status(verified / pending), never the documents.
- Card session: the session token our card partner issues for your account, stored encrypted at rest and expiring automatically.
- Technical: to protect the service from abuse we rate-limit by a one-way hash of your IP address — the raw IP is never stored. Server logs are automatically scrubbed of emails, addresses, phone numbers, and tokens.
What never touches Tengo
The most sensitive data is handled entirely by our regulated partners, inside their own secure components, and is never sent to or stored by Tengo:
- Your identity documents and selfie — captured inside our verification partner's (Sumsub) secure widget and sent directly to them on behalf of the card issuer. Tengo only learns the pass/fail status.
- Your full card number, security code and PIN — rendered inside the card issuer's secure element; Tengo never receives them.
- Your phone number and source-of-funds answers — passed straight to the card issuer for verification; Tengo keeps only the “verified” state.
- Your live balances and transactions — read from the card issuer on demand to show you, and not stored by Tengo.
Who else processes your data
We share data only with the processors needed to run the service, each under a data-processing agreement, and we never sell personal data:
- Privy — sign-in and embedded-wallet provider.
- Gnosis Pay and its licensed card issuer / BIN sponsor (Monavate) — card issuance, the card account, and regulatory obligations.
- Sumsub — identity verification (KYC), on behalf of Gnosis Pay.
- Supabase — database hosting.
- Netlify — application hosting (sees your IP as part of ordinary request routing).
- A blockchain RPC provider — to read public on-chain data.
- Novastra Holding B.V. — our parent company, providing intra-group technical and operational support under an Intra-Group Data Processing Agreement.
How we protect it
Personal data is encrypted at rest with per-column encryption (a sealed-box scheme); systems that only write data cannot read it back. IP addresses are only ever stored as a one-way hash. Logs are scrubbed of personal data. We run no analytics SDKs and no marketing pixels, and set no tracking cookies — the only cookie is the sign-in token set by Privy.
Legal bases (EEA / UK)
- Performance of a contract — operating your account and card.
- Legal obligation — identity verification and anti-money-laundering, required to issue a card.
- Legitimate interests — keeping the service secure (e.g. rate limiting).
- Consent — joining the waitlist.
How long we keep it
Account data is kept for the life of your account. Card-session tokens expire automatically; rate-limit hashes self-delete; waitlist entries are kept until you ask us to remove them. Data held by our card and identity partners is retained under their own policies and applicable law.
Your rights
If you are in the EEA or UK you have the GDPR rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. To exercise any of them, write to privacy@tengo.finance. Some data is held by our card and identity partners for regulatory reasons; we will route your request appropriately.
International transfers
Some processors may handle data outside your country; where they do, transfers rely on appropriate safeguards such as EU Standard Contractual Clauses.
Changes
We will post any changes here and update the date above. Questions: privacy@tengo.finance.