Privacy at Tentora

Privacy notice

This notice explains which personal data Tentora processes when you use the website, create an account, save a route, or join the app waiting list.

Last updated: 30 July 2026 · version 1.0

1. Controller

Tentora is operated in Belgium by Alexander Hoogsteyn, who is the controller of the personal data described in this notice.

Send privacy questions or requests to privacy@tentora.app.

2. Data we process

UseDataPurpose and legal basis
Website and securityIP address, time, URL, referrer, browser, device, and technical logs.Deliver the site, prevent abuse, and investigate errors. Legitimate interests and technical necessity.
AccountSupabase user ID, email, display name, and data received from Google or Apple.Create, authenticate, and manage your account. Performance of the requested service.
Favourites and routesSelected places, route name, activity, points, coordinates, geometry, and distance.Save and display favourites and routes. Performance of the service.
Route calculationRoute points and coordinates you select.Calculate routes through BRouter and temporarily cache reusable route legs. Performance of the service.
Waiting listEmail, source, and signup date.Send news about the Tentora app. Consent, which you may withdraw.
ContributionsInformation you publish through GitHub, including your GitHub profile.Review location reports. You voluntarily choose to contribute through GitHub.
Vercel Web AnalyticsPage, referrer, time, filtered query parameters, country or region, browser, operating system, and device type.Understand aggregate use and improve the site. Legitimate interests; see section 4.
Google AnalyticsPage views, interactions, browser and device data, broad location, and analytics identifiers.Measure visits when you consent. Consent.

3. Sources of data

Most data comes directly from you or your browser. When you sign in, we receive limited profile data from your chosen identity provider, Google or Apple. Tentora does not buy or sell personal data.

4. Analytics

Tentora uses Vercel Web Analytics. Vercel states that the service uses no cookies and measures visits with aggregate data. A daily hash derived from the incoming request counts unique visitors within one day; stored data points are not associated with an IP address, and visitor identification resets after 24 hours.

Tentora also uses Google Analytics. It may use cookies such as _ga and _ga_<container-id> and process measurement data about site use. For EEA visitors, Google states that IP addresses are used for broad geolocation and discarded before storage. Consent is the legal basis, and Google Analytics may only activate after your cookie-banner choice. We do not send sensitive data, email addresses, or saved route coordinates to Google Analytics.

5. Providers and recipients

  • Vercel: hosting, network security, logs, and privacy-focused web analytics.
  • Supabase: database, accounts, authentication, and sessions.
  • Google and Apple: identity providers when you select that sign-in method.
  • Google Analytics: visitor measurement after consent.
  • BRouter: route calculation; selected coordinates are sent server-side.
  • OpenFreeMap and underlying map providers: map display; your browser requests tiles and shares normal connection data.
  • GitHub: public reports and contributions that you submit there.

6. Transfers outside the EEA

Some providers may process data outside the EEA. Where relevant, we rely on an adequacy decision, the EU–US Data Privacy Framework for certified organisations, European Commission Standard Contractual Clauses, or another valid safeguard.

7. Retention

  • Account, favourites, and saved routes: until you delete them or close the account, subject to short technical backups and legal duties.
  • Waiting list: until you withdraw consent or no later than twelve months after the announced app becomes generally available.
  • Google Analytics: user and event data for no more than two months; aggregate reports may remain available longer.
  • Vercel Web Analytics: visitor identification resets after 24 hours; aggregate reports remain within the active Vercel plan’s reporting window.
  • Technical and security logs under Tentora’s control: normally no more than 90 days, unless needed for an incident, legal duty, or claim.
  • Rights requests and consent evidence: as long as needed to handle the request and demonstrate compliance.

8. Your rights

Depending on the circumstances, the GDPR gives you rights of access, correction, deletion, restriction, portability, and objection. You may withdraw consent at any time without affecting earlier lawful processing. We normally respond within one month and may reasonably verify your identity.

9. Security and choices

We use access controls, encrypted connections, per-user database policies, and restricted administrator rights. No system is completely secure. Do not put sensitive information in account or route-name fields.

You can reject analytics cookies without losing Tentora’s core functions. Necessary authentication and security cookies remain required when you sign in.

10. Children and changes

Tentora does not knowingly seek to collect children’s data. Contact us if you believe a child shared personal data without appropriate permission.

We may update this notice when the service or law changes. The date and version above identify the current text; material changes will be communicated appropriately.