
Tenner
Trade software
Privacy
Privacy Policy
This policy explains how GRAFT SOFTWARE LTD, trading as Tenner, collects, uses and protects personal data.
Operator
GRAFT SOFTWARE LTD, trading as Tenner
Company number
16920446
Registered office
Hillcrest West Hanningfield Road, Great Baddow, Chelmsford, England, CM2 7SY
Contact
support@tennerapp.co.ukLast updated
3 July 2026
1. Who controls your data
For account, billing, website, support and service administration data, GRAFT SOFTWARE LTD trading as Tenner is the controller.
For customer, worker, job, quote, invoice, photo, document and contact data that a trade business enters into Tenner, the trade business is usually the controller and Tenner acts as a processor or service provider. The trade business is responsible for having a lawful basis to collect and use that data.
2. Personal data we collect
We may collect and process the following categories of data:
- account data: name, email, login provider, business name and user ID;
- profile data: phone, address, logo, VAT settings, bank details and preferences;
- subscription data: billing provider, Stripe customer/subscription IDs, Apple transaction IDs, subscription status, trial dates and cancellation status;
- business data: contacts, customers, workers, subcontractors, jobs, quotes, invoices, notes, photos, files, forms and certificates;
- communications data: support messages, contact form submissions, emails and notification preferences;
- technical data: IP address, device, browser, operating system, logs, security events, cookies and session data;
- integration data: data you choose to import from or send to connected providers such as accounting platforms.
3. How we use data
We use personal data to:
- create, authenticate and manage Tenner accounts;
- provide jobs, quotes, invoices, contacts, diary, forms, teams, follow-ups and integrations;
- process subscriptions, trials, renewals, cancellations and billing status;
- send service emails, support replies, security notices and account updates;
- send optional product updates or offers where permitted;
- secure, monitor, debug, maintain and improve Tenner;
- comply with legal, tax, accounting, fraud prevention and regulatory obligations.
4. Lawful bases
We rely on the following lawful bases where applicable:
- Contract: to provide Tenner, manage accounts and process subscriptions.
- Legitimate interests: to secure, improve and operate Tenner, prevent fraud and respond to support requests.
- Legal obligation: to keep billing, accounting, tax and compliance records where required.
- Consent: for optional marketing or non-essential cookies where consent is required.
5. Processors and third parties
We use trusted providers to operate Tenner. Depending on the features you use, these may include:
- Supabase for authentication, database, storage and backend services;
- Stripe for website payments, card setup, subscriptions and fraud prevention;
- Apple for in-app subscriptions and Apple account billing;
- Resend or similar providers for transactional email;
- Xero, QuickBooks, Sage or other accounting providers where you connect them;
- address lookup, hosting, analytics, error monitoring and infrastructure providers where used.
We only share data where needed to provide, secure, improve or support Tenner, comply with law, or operate integrations you choose to connect.
6. International transfers
Some providers may process data outside the UK. Where this happens, we rely on appropriate safeguards such as adequacy regulations, standard contractual clauses, processor terms, or other lawful transfer mechanisms.
7. How long we keep data
We keep data only for as long as reasonably needed. Typical periods are:
- account and business data: while your account is active;
- deleted account data: deleted or anonymised where possible, subject to backups and legal retention;
- billing, subscription, tax and accounting records: up to 6 years where required for business records;
- support emails and contact requests: usually up to 3 years after the last interaction;
- security, diagnostic and server logs: usually up to 24 months unless needed longer for security or legal reasons;
- marketing preferences: until you unsubscribe or your account is deleted.
8. Account deletion
If you delete your account, we will take steps to delete or anonymise account data and app data. Some information may remain temporarily in backups or logs, and some records may be kept where required for legal, billing, tax, fraud prevention, security or dispute purposes.
9. Marketing and service messages
You can opt out of optional marketing or product update emails. We may still send service messages about your account, security, subscription, payments, support, legal updates or important changes to Tenner.
10. Cookies
We use cookies and similar technologies as explained in our Cookie Policy.
11. Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing of your personal data, request portability, and withdraw consent where consent is the lawful basis.
To exercise your rights, contact support@tennerapp.co.uk. You also have the right to complain to the UK Information Commissioner’s Office.
12. Security
We use technical and organisational measures designed to protect data, including authentication, access controls, provider security tools, encrypted connections and operational monitoring. No system is completely secure, so you must also protect your login details and devices.
13. Children
Tenner is business software and is not intended for children. You must not create an account if you are not legally able to enter into these terms or act on behalf of the business using Tenner.
14. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will be available on this page.