Last updated: 08.05.2022
Welcome to our privacy policy! It is detailed… but we’d recommend you read it in full so you know exactly what we do with data here at Tandem. If you’re pressed for time, here are the key points:
- We don’t monitor, record or store the contents of your audio calls, video calls or Tandem Party conversations. We do store messages, message information like timestamps and your Topics, but these will not be shared with any third parties unless required by law.
- You can download, edit or permanently delete your personal data at any time. Your personal data is accessed through the “My Profile” tab.
- We keep your data on secured and restricted database servers. We do everything we can to keep your data secure and encrypted between your device and our servers. Tandem is a global community and we may store data on servers outside your home country. Please note that encryption is not supported in China.
- We reserve the right to restrict access to Tandem in the event of misconduct. Providing a safe and friendly community for language learners is our top priority. We therefore take reports of abuse very seriously. Reports of misconduct on Tandem are reviewed by human moderators and can lead to a ban from our app. Please note that you can choose to share messages with our moderators only as part of the reporting process.
PRIVACY POLICY
This statement details how we handle personal data here at Tandem, if you use our mobile apps or website. We are respectful of the data that is shared with us by our members and take protecting it very seriously.
Tandem is made in Germany and as a company based in the European Union we are firmly committed to meeting and often exceeding European data protection standards for all our members wherever possible.
Please take the time to read these details to fully understand how we handle your data and keep it safe.
Tripod Technology GmbH
Represented by Arnd Aschentrup and Tobias Dickmeis
Bölschestr 21
30173 Hannover
Germany
You can reach out to us directly via [email protected].
External Data Protection Officer
ePrivacy GmbH
Represented by Prof. Dr. Christoph Bauer
Große Bleichen 21
20354 Hamburg
For all requests concerning the security of your data, please contact our privacy team and our data protection officer at [email protected].
If you have a particularly sensitive request, please contact our data protection officer by postal mail, as communication by email can always be flawed by security vulnerabilities.
Personal Data
Personal data is all information about identified or identifiable person. This includes the following categories of personal data that we process:
- Your contact details (such as first and last name, address, email address, phone number), Your last name will never be shared with other Tandem members by us,
- Information within your profile (such as your age, gender, city),
- Information you share within your messages (images, voice messages, comments, correction, topics),
- Your correspondence with us,
- Log files with information about your visit to our website and apps,
- Online identifiers (such as cookie IDs, IP addresses, advertising IDs),
- Awards (such as language certificates).
Purposes of Use
Personal data will only be collected by us to the extent and for the purpose for which you provide the data to us, e.g. for registering an account.
We use and store your personal data as part of our services for the following purposes:
- To create a public user profile for you on Tandem;
- To provide a curated community just for language learners, where access is restricted to members only. We take best efforts to prevent abuse and ban offenders, as soon as we are made aware;
- To send information relevant to the service, e.g. via email or push notification (e.g. updates on your membership status, missed calls/messages, new followers);
- To target ads in the app (this can be turned off in settings);
- To find Tandem partners nearby;
- To understand how Tandem is used and optimize the service;
- To help keep our community safe, friendly and accountable in both one-on-one chats, parties and group chats;
- For corresponding with you;
- For processing contracts with you;
- For advertising purposes such as the dispatch of our newsletter;
- On quality assurance and statistics;
- For your participation in our competitions;
- For your participation in our events;
- For your participation in our surveys;
- To consider your application for membership and for community moderation;
- In order to improve our service.
Legal Basis
Your data is processed according to the following legal provisions:
- With regard to data communicated in forms, etc. with your consent, Art. 6(1) (a) GDPR;
- With regard to services you use for the performance of a contract, Art. 6(1) (b) GDPR;
- The fulfilment of legal obligations, Art. 6(1) (c) GDPR),
- With regard to messages you share with your Tandem partners, both in one-on-one chats, Tandem Parties and group chats, based on their legitimate interests, Art 6(1)(f) GDPR.
Otherwise, with particular regard to statistical data and online identifiers based on legitimate interests, Art 6(1)(f) GDPR (see below).
Legitimate Interests
When processing your data, we pursue the following legitimate interests:
- Providing and improving our service;
- Protecting against misuse;
- Statistics and service analytics.
Data Sources
Unless otherwise specified, we obtain the data from you (including via devices used by you).
Data Transfer to Third Countries
Tandem is a worldwide service. Data is transferred to third countries outside your home country and outside the European Union. This is done on the basis of contractual regulations stipulated by law that ensure appropriate protection of your data and that are available for you to view on request.
Retention Period
We retain your data:
- If you have consented to this as part of processing, until such time as you withdraw your consent (e.g. by deleting your account);
- If we need the data to fulfil an agreement, until such time as the contractual relationship with you ceases or legal retention periods expire;
- If we use the data on the basis of a legitimate interest, until such time as your overriding interest obliges us to delete or anonymize them;
- Please note that while your personal data will be deleted if you delete your account, we will retain the messages you’ve sent in your Tandem Partners mailbox;
- If you delete your account, we will continue to store your email address linked to your account so we can handle any conversation deletion requests after you have deleted your account;
- Additionally, we will also continue to store your Tandem ID, and will use this to identify accounts and delete messages for members who sign up with Apple ID and chose not to share their email address with us.
Data Protection
We have taken extensive technical and organizational measures to secure your data against potential risks, such as unauthorized login or access, unauthorized perusal, amendment or distribution, and against loss, deletion or misuse.
In order to protect your personal data against unauthorized access by third parties when being transmitted, we secure data transmissions, if necessary, using SSL and TLS encryption. This is a standard encryption procedure for online and mobile services, particularly for the Internet. Encryption is not supported in China.
Regarding video and audio chats as well as Tandem Parties: we will not monitor, record or broadcast video and audio chat sessions at any time. However, we cannot prevent your chat partners from broadcasting live or recorded chat sessions without your or our permission through third party websites or services. We recommend that you exercise caution in disclosing any information, personal or otherwise, during a video or chat session.
Children under 14 are not allowed to use Tandem. If you are based in the European Economic Area (EEA), you may only use Tandem if you are over the age at which you can provide consent to data processing under the laws of your country or if verifiable parental consent for your use of Tandem has been provided to us. If you are a parent and you learn that your child is using Tandem and you don’t want them to, please contact ([email protected]).
Cookies
Cookies and similar technologies are very small text documents or pieces of code that often contain a unique identification code. When you visit a website or use a mobile application, a computer asks your computer or mobile device for permission to save this file on your computer or mobile device and gain access to information. Information collected through cookies and similar technologies may include the date and time of the visit and how you use a particular website or mobile application.
We need cookies to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the site; (b) provide custom, personalized content and information; (c) to provide and monitor the effectiveness of our Service; (d) to monitor and aggregate metrics such as total number of visitors, traffic, and demographic patterns; (e) to diagnose or fix technology problems; (f) to help you efficiently access your information after you sign in; (g) to keep you logged in; and (h) to keep the Tandem community safe for members.
Switching off or revoking cookie consent:
You can choose to opt-out of all but the necessary cookies. In the settings of the browser, you can change the settings to ensure that cookies will be blocked. Most browsers provide you with an explanation on how to do this in the so-called ‘help-function’. However, if you block the cookies, it is possible that you will not be able to enjoy all the technical features our website has to offer, and it may negatively affect your user experience. You can change your cookie consent on the Tandem website by clicking the “Change your cookie consent” button at the bottom of this page.
Data Recipients
We use your personal information only within the company and forward it only to those companies that are involved in performing the contracts concluded with you or otherwise involved in providing the relevant service.
We forward the following customer data to third parties:
- To analyze how Tandem is used by our members and optimize the service and design, pseudonymous usage and personal data is shared with Google Analytics, Firebase Analytics, New Relic, Rubyspark Labs and Rubylight Limited.
- To communicate information relevant to the service via email or push notification, names, device IDs, email addresses and other personal information may be shared with Amazon Pinpoint (https://aws.amazon.com/pinpoint/), Interable and Sparkpost (https://sparkpost.com). You can control what type of messages you receive in the profile settings, switch off push notifications for Tandem completely in your device settings and unsubscribe from email notifications in each individual email.
- With your explicit consent, in order to make ads more personal, we may share personal but anonymized information, such as age and gender as well as device identifiers with Admob by Google, MoPub and Facebook Audience Network. iOS and Android devices have a resettable advertising identifier that companies can use to target ads based on the apps you use.
- Both iOS and Android devices allow you to opt out of the use of mobile advertising identifiers for purposes of showing you targeted ads. For iOS, go to your iOS device settings and turn on the “limit ad tracking” setting. For Android, turn on “opt out of ads personalization” in your Android device settings.
We create Tandem member profiles based on your login data and also use these profiles and the information they contain, provided by you, for the following purposes:
- We create a public member profile for you on Tandem so that members can find the most relevant language exchange partners to communicate with. While some elements of your profile, including your first name, age, profile picture, language settings, profile answers, current city, time zone and Topics are public, only verified community members can contact you via the Tandem app. We never show your email address, exact location and last name, or any information you have chosen not to share in your profile settings to other members.
- We store applications for membership in the community, including your personal data for a minimum of seven days. After that period, you can permanently delete all personal data from Tandem using the “Delete My Application” button in the app.
- In order to keep Tandem a safe place for language learners, we take violations of our community rules very seriously. Therefore, we may retain anonymous personal identifiers for up to 24 months and might prevent access to the community on this basis during this period.
Otherwise, your personal information will not be forwarded to third parties unless you have given your express consent for this or unless we are obliged to disclose it – for example, at the direction of a court or administrative authority.
To provide the functionality and for usage analytics and marketing purposes, we record information about activities on our apps and websites (e.g. clicks, screens viewed, pages visited).
Registration and Authentication
By registering or authenticating, users allow Tandem to identify them securely and give them access to its services. Depending on what is described below, third parties may provide registration and authentication services. In this case, Tandem will be able to access some data stored by these third-party services for registration or identification purposes, with the user’s explicit consent:
- Facebook Authentication (Meta, Inc.): Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and is connected to the Facebook social network. The personal data collected is various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- Firebase Authentication (Google Inc.): Firebase Authentication is a registration and authentication service provided by Google Inc. To simplify the registration and authentication process, Firebase Authentication can make use of third-party identity providers and save the information on its platform. Personal Data collected: phone number. Place of processing: United States – Privacy Policy.
- Google OAuth (Google Inc.): Google OAuth is a registration and authentication service provided by Google Inc. and is connected to the Google network. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- Weibo (Sina.com): Weibo is a registration and authentication service provided by Sina.com and is connected to the Sina Weibo social network and SDK. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: China – Privacy Policy
- WeChat (Tencent Inc.): WeChat Auth is a registration and authentication service provided by Tencent Inc. and is connected to the WeChat network and SDK. Personal Data collected: various types of Data as specified in the privacy policy of the service. Place of processing: Canada and Hong Kong – Privacy Policy
- Sign in with Apple (Apple Inc.): Sign in with Apple is a registration and authentication service provided by Apple Inc. In cases where Users are required to provide their email address, Sign in with Apple may generate a private relay address on behalf of Users that automatically forwards messages to their verified personal email account - therefore shielding their actual email address from the Owner. Personal Data processed: email address; first name; last name; User ID. Place of processing: United States – Privacy Policy.
Hosting and Backend Infrastructure
This type of service has the purpose of hosting data and files that enable Tandem to run and be distributed, as well as providing a ready-made infrastructure to run specific features or parts of Tandem. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where personal data is stored.
- Amazon Web Services (AWS) (Amazon Web Services, Inc.): Amazon Web Services is a hosting and backend service provided by Amazon.com Inc. A wide range of Personal Data, including sign-in data, images and message content is stored on AWS infrastructure as Tandem’s main hosting and infrastructure provider. Place of processing: Germany and the United States – Privacy Policy.
- Google Cloud Platform (Google Inc.): Google Cloud Platform is a hosting and backend service provided by Google Inc. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- CDS Global Cloud (Beijing CapitalOnline Data Service): CDS Global Cloud is a specialized international provider of hosting services. At Tandem we use CDS to optimize the speed and reliability of data transmission from or to Mainland China. Place of Processing: European Union - Privacy Policy.
Handling Payments
Payment processing services enable Tandem to process payments. To ensure greater security, Tandem does not process or store credit card details, and uses only the information necessary to execute the transaction with the financial intermediaries handling the transaction.
Some of these services may also enable the sending of timed messages to you, such as emails containing invoices or notifications concerning the payment.
- Payments processed via the Apple App Store (Apple Inc.): Tandem uses a payment service provided by Apple Inc. that allows the Owner to offer the purchase of the app itself or in-app purchases. Personal Data processed to complete the purchases are processed by Apple, as described in the privacy policy for the App Store. Personal Data processed: payment data. Place of processing: United States – Privacy Policy.
- Payments processed via the Google Play Store (Google Ireland Limited): Tandem uses a payment service provided by Google Ireland Limited that allows the Owner to offer the purchase of the app itself or in-app purchases. Personal Data processed to complete the purchases are processed by Google, as described in the privacy policy for the Google Play Store. Personal Data processed: payment data. Place of processing: Ireland – Privacy Policy.
Infrastructure Monitoring
This type of service allows Tandem to monitor the use and behavior of its service components, so its features, performance, operation, maintenance and troubleshooting can be improved. Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of Tandem.
- Crashlytics (Google Inc.): Crashlytics is a monitoring service provided by Google Inc. to enable Tandem to improve the stability of the app and reduce app crashes. Personal Data collected: geographic position, unique device identifiers for advertising (Google Advertiser ID or IDFA, for example) and various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- Firebase Crash Reporting (Google Inc.): Firebase Crash Reporting is a monitoring service provided by Google, Inc. to improve the stability of the app and reduce app crashes. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- Firebase Performance Monitoring (Google Inc.): Firebase Performance Monitoring is a monitoring service provided by Google, Inc. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- New Relic (New Relic Inc.): New Relic is a monitoring service provided by New Relic Inc. The way New Relic is integrated means that it filters all traffic of Tandem, i.e., communication between the Application and the User’s browser or device, while also allowing analytical data on Tandem to be collected. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
This type of service makes it possible to communicate with users outside of the app, e.g. via push notifications and email. They may manage a database of email contacts, phone contacts or any other contact information to communicate with the user. These services may also collect data concerning the date and time when the message was viewed by the user, as well as when the user interacted with it, such as by clicking on links included in the message.
- Firebase Cloud Messaging (Google Inc.): Firebase Cloud Messaging is a message sending service provided by Google, Inc. Firebase Cloud Messaging allows the Owner to send messages and notifications to Users across platforms such as Android, iOS, and the web. Messages can be sent to single devices, groups of devices, or specific topics or User segments. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- SparkPost (Message Systems, Inc.): SparkPost is an email address management and message sending service provided by Message Systems, Inc. Personal Data collected: email address and various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- Iterable (Iterable, Inc.): Iterable is a User Communications and database management service provided by Iterable, Inc. Personal Data processed: email address; Tracker; various types of personal data. Place of processing: United States – Privacy Policy..
- Vonage (Vonage Holdings Corp.): Vonage is global communications platform and software services provider. Tandem uses the Vonage video and voice communication API to provide global high audio- and video-calling functionality across our mobile and web applications. The content of video and audio calls on Tandem are private and will not be monitored or moderated. Personal Data processed: pseudonymous user identifiers, call metadata. Place of processing: United Kingdom, the European Economic Area, the United States and in other jurisdictions – Privacy Policy.
- Agora (Agora Lab, Inc): Agora is a real-time engagement platform. Tandem uses the Vonage video and voice communication API to provide global high audio- and video-calling functionality across our mobile and web applications. Agora Lab Inc. only collects Internet Protocol (IP) addresses and operational information necessary for providing their services. Place of processing: United States – Compliance & Privacy.
Web and Mobile Analytics
The services contained in this section enable us to monitor and analyze web and mobile traffic and can be used to keep track of how Tandem is used by users.
- Analytics collected directly (Tandem): Tandem uses an internal analytics system that does not involve third parties. Personal data collected: cookies and usage data.
- Google Analytics (Google Inc.): Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the data collected to track and examine the use of Tandem, to prepare reports on its activities and share them with other Google services. Google may use the data collected to contextualize and personalize the ads of its own advertising network. Personal Data collected: cookies and usage data. Place of processing: United States – Privacy Policy – Opt Out.
- Google Analytics for Firebase (Google Inc.): Google Analytics for Firebase or Firebase Analytics is an analytics service provided by Google Inc. In order to understand Google’s use of data, Google’s partner policy. Firebase Analytics may share data with other tools provided by Firebase, such as Crash Reporting, Authentication, Remote Config or Notifications. The user may check this privacy policy to find a detailed explanation about the other tools used by the owner. Tandem uses identifiers for mobile devices (including Android Advertising ID or Advertising Identifier for iOS, respectively) and technologies similar to cookies to run the Firebase Analytics service. Users may opt out of certain Firebase features through applicable device settings, such as the device advertising settings for mobile phones or by following the instructions in other Firebase related sections of this privacy policy, if available. Personal Data collected: cookies, unique device identifiers for advertising (Google Advertiser ID or IDFA, for example) and usage data. Place of processing: United States – Privacy Policy.
- Adjust (Adjust GmbH): Adjust is an analytics and ad attribution service provided by Adjust GmbH. Personal data collected: Cookies, Device Identifiers and Usage Data. Place of processing: Germany – Privacy Policy – Opt Out.
- Facebook Ads conversion tracking (Facebook, Inc.): Facebook Ads conversion tracking is an analytics service provided by Facebook, Inc. that connects data from the Facebook advertising network with actions performed on Tandem. Personal Data collected: cookies and usage data. Place of processing: United States – Privacy Policy.
- TestFlight (Apple Inc.): TestFlight is an analytics service provided by Apple Inc. Personal Data collected: Cookies, email address and usage data. Place of processing: United States – Privacy Policy.
Location-based Services
Tandem may collect, use, and share user location data in order to provide location-based services. Most browsers and devices provide tools to opt out from this feature by default. If explicit authorization has been provided, the user’s location data may be tracked in order for Tandem to show Tandem partners nearby or on a city map, with city-by-city granularity. Tandem will never show your precise location to other members. Personal data collected: geographic position.
Our customer support platform allows us to manage support and contact requests received via email or by other means, such as the contact form. The personal data processed depends on the information provided by the user in the messages and the means used for communication (e.g. email address).
- Zendesk (Zendesk, Inc.): Zendesk is a support and contact request management service provided by Zendesk Inc. Personal Data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- HelloNext (HelloNext, Inc.): HelloNext is a service used to collect user feedback and feature requests provided by Hellonext, Inc. Data collected: logs, analytic, cookies and other tracking technologies. Place of Processing: Safe Harbor Privacy Principles agreed upon by the U.S, the European Union and Switzerland - Privacy Policy.
Advertising
Ads (e.g. banners and native ads) help us to earn money and continue to provide most features of Tandem for free.
When we share your age, gender and location with advertisers, the ads you see on Tandem are more relevant to you and we earn more from them. We share your personal Information only with your explicit consent and if you don’t want your information to be shared, you can revoke your consent off at any time.
Also, this does not mean that all personal data is used for this purpose. Information and conditions of use are shown below.
Some of the services listed below may use cookies or mobile advertising identifiers to identify users or they may use the behavioral retargeting technique, i.e. displaying ads tailored to the user’s interests and behavior, including those detected outside Tandem. For more information, please check the privacy policies of the relevant services.
In addition to any opt-out offered by any of the services below, the user may opt out of a third-party service’s use of cookies by visiting the Network Advertising Initiative opt-out page. Another option for disabling ad personalization is the preference management of YourOnlineChoices https://youronlinechoices.com.
- AdMob (Google Inc.): AdMob is an advertising service provided by Google Inc. In order to understand Google’s use of data, consult Google’s partner policy. Personal Data collected: cookies, unique device identifiers for advertising (Google Advertiser ID or IDFA, for example) and usage data. Place of processing: United States – Privacy Policy – Opt Out.
- DoubleClick for Publishers (Google Inc.): DoubleClick for Publishers is an advertising service provided by Google Inc. that allows the owner to run advertising campaigns in conjunction with external advertising networks that the owner, unless otherwise specified in this document, has no direct relationship with. In order to opt-out from being tracked by various advertising networks, Users may make use of Youronlinechoices. In order to understand Google’s use of data, consult Google’s partner policy. This service uses the “Doubleclick” Cookie, which tracks use of Tandem and User behavior concerning ads, products and services offered. Users may decide to disable all the Doubleclick Cookies by clicking on: google.com/settings/ads/onweb/optout?hl=en. Personal data collected: Cookies and Usage Data. Place of processing: United States – Privacy Policy.
- Facebook Audience Network (Facebook, Inc.): Facebook Audience Network is an advertising service provided by Facebook, Inc. In order to understand Facebook’s use of Data, consult Facebook’s data policy. Tandem may use identifiers for mobile devices (including Android Advertising ID or Advertising Identifier for iOS, respectively) and technologies similar to cookies to run the Facebook Audience Network service. One of the ways Audience Network shows ads is by using the User’s ad preferences. The User can control this in the Facebook ad settings. Users may opt out of certain Audience Network targeting through applicable device settings, such as the device advertising settings for mobile phones or by following the instructions in other Audience Network related sections of this privacy policy, if available. Personal data collected: cookies, unique device identifiers for advertising (Google Advertiser ID or IDFA, for example) and Usage Data. Place of processing: United States – Privacy Policy– Opt Out.
Content Performance and Features Testing (A/B testing)
The services contained in this section allow the Tandem to track and analyze the user response concerning web traffic or behavior regarding changes to the structure, text or any other component of Tandem.
- Firebase Remote Config (Google Inc.): Firebase Remote Config is an A/B testing and configuration service provided by Google Inc. Personal data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
- Google Optimize (Google Inc.): Google Optimize is an A/B testing, website testing, and personalization tool provided by Google Inc. Personal data collected: various types of data as specified in the privacy policy of the service. Place of processing: United States – Privacy Policy.
Your Rights
As a Tandem user, you have the right to access, rectification, right to object, to complaint, erasure and blockage with regard to your personal data. More specifically:
- You have the right to request information about whether and which personal data is processed by our company. You also have the right to demand that your personal data is rectified or amended.
- Under certain circumstances, you have the right to request that your personal data should be deleted, e.g. by tapping “Delete Account” in My Profile/Settings.
- Under certain circumstances, you have the right to demand that the processing of your personal data should be restricted.
- You can withdraw your consent to the processing and use of your data completely or partially at any time with future application.
- You have the right to obtain your personal data in a common, structured and mechanically readable format, e.g. via the “Download My Data” button in My Profile/Settings.
- If you have any questions, comments, complaints or requests in connection with our statement on data protection and the processing of your personal data, you can also contact our data protection officer in detail.
- You also have the right to complain to the responsible supervisory authority if you believe that the processing of your personal data is in violation of the legislation.
You reach us as follows:
Tripod Technology GmbH
Bölschestr 21
30173 Hannover
Germany
or at [email protected].
We undertake to reply to questions relating to data protection within five business days.
Requirement or obligation to provide data
Insofar as this is not expressly stated, when data is collected, the provision of data is neither required nor obligatory.
Date of issue of this data privacy statement
08.05.2022
We reserve the right to make amendments at any time to this data privacy statement for future effect.