Legal

Privacy Policy

Last updated: 8 September 2026

This policy explains what personal data Tezly collects, why we collect it, how long we keep it and what rights you have. It covers the Tezly app and the tezly.app website.

1. Who we are

The controller of your personal data is:

Tezly OÜ Registry code: 17571405 Pärnu mnt 139b, Kesklinna linnaosa 11317 Tallinn, Harju maakond, Estonia Email: [email protected]

We have not appointed a data protection officer. Privacy questions can be sent to [email protected].

2. What Tezly does

Tezly is a platform that connects people who want to send an item with travellers willing to carry it. We do not transport items, handle payments between users, or take part in the agreements users make with each other. This shapes what data we hold: we hold what is needed to run the platform, and little beyond it.

3. What data we collect

You give us:

DataWhen
Name, email address, phone numberRegistration
Profile photoIf you choose to add one
Identity document and a selfieIdentity verification
Listings: routes, dates, item descriptions, pricesWhen you post
Messages you send to other usersIn-app chat
Pickup photos and delivery recordsAt handover and delivery
Ratings and reviewsAfter a delivery
Reports and support requestsWhen you contact us

Collected automatically:

DataPurpose
Device type, operating system, app versionMaking the app work, fixing errors
IP addressSecurity and fraud prevention
Push notification tokenSending you notifications

Locations you enter. Routes and handover points are the addresses and cities you type in. The app does not track your location in the background.

We do not collect: your payment card details. Credits are sold through Apple and Google, and card data goes to them, not to us.

4. Why we use it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and running your accountPerformance of a contract, Art. 6(1)(b)
Matching Senders and Carriers, showing listingsPerformance of a contract, Art. 6(1)(b)
Identity verificationLegitimate interest in platform safety, Art. 6(1)(f)
Selling Credits and keeping transaction recordsContract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)
Fraud prevention and platform securityLegitimate interest, Art. 6(1)(f)
Reviewing reports and moderating contentLegal obligation, Art. 6(1)(c)
Responding to your questionsContract, Art. 6(1)(b)
Accounting and tax recordsLegal obligation, Art. 6(1)(c)
Push notificationsConsent, Art. 6(1)(a)
Establishing or defending legal claimsLegitimate interest, Art. 6(1)(f)

You can withdraw consent for notifications at any time in your device settings. This does not affect anything done before you withdrew it.

5. What other users see

Other users can see your first name, your profile photo, your verification status, your ratings and reviews, and the details of any listing you post.

They cannot see your email address, your phone number, your identity document, or your full address unless you share it with them yourself in a message.

Verification status only shows that a check was carried out. It does not reveal the document you used.

6. Messages and content moderation

We do not generally monitor user communications and are under no obligation to do so. We may use automated tools, and may review content that is reported to us, for safety, fraud prevention, legal compliance and enforcement of our Terms.

Where content is reported or a dispute arises, we may read the messages relating to it.

7. Who we share data with

We do not sell your data and we do not share it for advertising.

WhoWhat they receiveWhere
Hostinger (hosting)All platform data: accounts, listings, messages, delivery recordsFrankfurt, Germany
Cloudflare (file storage, content delivery, security)Photos and voice messages you upload; traffic metadataEuropean Union and global network
Didit (identity verification)Identity document, selfie, verification resultEuropean Union
Google (push notifications, address search)Push token and notification content; addresses you type when searchingOutside the EEA, under Standard Contractual Clauses
RevenueCat (purchase validation)Purchase records and your account identifierOutside the EEA, under Standard Contractual Clauses
Resend (email delivery)Your email address and the content of the emailOutside the EEA, under Standard Contractual Clauses
Twilio and Infobip (SMS verification)Your phone number and the verification codeOutside the EEA, under Standard Contractual Clauses
Apple / Google (in-app purchases)Purchase recordsTheir own infrastructure
Other usersSee section 5—
AuthoritiesOnly where the law requires it, or to report a serious crime—

Apple and Google process purchase data as independent controllers under their own privacy policies.

8. Where your data is stored

Your data is stored on servers located in Frankfurt, Germany, within the European Union.

Some of our providers are part of international groups. Where personal data is transferred outside the European Economic Area, that transfer is made under the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

Users in Azerbaijan and Türkiye should note that their data is processed in the European Union.

9. How long we keep it

WhatHow long
Account and profile dataUntil you delete your account, then 30 days
Listings, messages, delivery recordsUntil you delete your account, then 30 days
BackupsOverwritten within 90 days of deletion
Transaction and accounting records7 years, as required by Estonian law
Records relating to an open dispute or legal claimUntil the matter is closed
Limited record of accounts terminated for breach3 years, to prevent re-registration
Reports about content or conduct3 years
Identity verification dataHeld by Didit under its own retention policy

Ratings and reviews you gave to others remain visible after deletion but are anonymised.

See our Account Deletion page for the full process.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • correct data that is wrong or incomplete;
  • delete your data, where we are not required to keep it;
  • restrict how we use your data while a question about it is resolved;
  • object to processing based on legitimate interest;
  • portability — receive your data in a machine-readable format;
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, write to [email protected] from the address linked to your account. We respond within one month. If a request is complex we may extend this by two months and will tell you if we do.

There is no charge, unless a request is manifestly unfounded or excessive.

Complaints. If you are not satisfied with how we handle your data, you may complain to:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39, 10134 Tallinn, Estonia aki.ee

You may also complain to the data protection authority in the country where you live.

11. Cookies

The tezly.app website does not use cookies. No cookie is set when you visit the site, and no consent banner is shown because there is nothing to consent to.

The language you select is stored in your browser's local storage under the name tezly-locale, so that the site opens in the same language next time. This value never leaves your browser and is not sent to us.

We do not use analytics, advertising or tracking technologies on the website or in the app.

The app does not use cookies either. It stores your login session and your settings locally on your device.

12. Security

We protect your data with encryption in transit, access controls limiting who on our side can see what, and the security measures provided by our infrastructure provider.

No system is completely secure. If a data breach occurs that is likely to put your rights at risk, we will tell you and notify the Estonian Data Protection Inspectorate as the law requires.

13. Children

Tezly is not for anyone under 18. We do not knowingly collect data from children. If we learn that a user is under 18, we close the account and delete the data.

14. Automated decisions

We do not make decisions about you by automated means alone that produce legal effects or similarly significant effects. Automated tools may flag content or activity for review, but a person decides what happens next.

15. Changes to this policy

We may update this policy. If a change is material, we will tell you in the app or by email before it takes effect. The date at the top shows when it was last updated.

16. Contact

Tezly OÜ Registry code: 17571405 Pärnu mnt 139b, Kesklinna linnaosa 11317 Tallinn, Harju maakond, Estonia

Email: [email protected]