Pasar al contenido principal

Privacy policy

This is a translation. The German version (Datenschutzerklärung) is legally binding.

This policy explains which personal data we process on TandemCafe, for what purpose and on what legal basis. TandemCafe shows no advertising, uses no analytics or tracking tools, and does not pass on or sell your data to third parties.

1. Controller

E-mail: E-mail address (image)
For data protection questions: E-mail address for data protection questions (image)

2. Hosting and server logs

TandemCafe runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. Hetzner processes the data on our behalf (Art. 28 GDPR).

With every request the web server stores technical data: IP address, date and time, the address requested, the amount of data transferred, browser and operating system. This is necessary to deliver the site and to detect attacks (Art. 6(1)(f) GDPR). The logs are deleted after 14 days.

The application itself also keeps a log: the application log holds the last 1,000 entries (such as logins, pages not found, errors) with IP address and account; older entries are deleted automatically. To protect against password attacks we remember failed logins with the IP address for 1 hour and per account for 6 hours. Forms submitted by spam programs are kept with the IP address for a few minutes. The legal basis is Art. 6(1)(f) GDPR (secure operation, protection against abuse).

3. Account and profile

For an account we need: e-mail address, user name, password (stored only as a hash, not readable), display name, native language(s), age group, city or the option “online only”, and your confirmation that you are at least 18 years old. Optionally you can add your gender, a photo, texts about yourself, your hobbies and how you like to practise.

Nobody but us sees your e-mail address and user name. Only logged-in members can see your profile; age group, gender and photo never appear in public ads. The legal basis is your use of TandemCafe under our terms of use (Art. 6(1)(b) GDPR).

4. Signing in with Google, Apple, Facebook or Microsoft

Instead of an e-mail address and password you can also sign in with an account at Google, Apple, Facebook or Microsoft. This only happens when you click the corresponding button: we then forward you to the provider, you sign in there and allow the data to be passed on. The provider sends us your name, your e-mail address, an identifier of your account and, depending on the provider, further profile details such as a link to your profile picture or your age range; we do not use or store these further details. We store the identifier so we recognise you next time, and use your name (only the first name as display name) and e-mail address to create your TandemCafe account or connect it to an existing account with the same e-mail address. We do not store the providers’ access tokens or profile pictures, neither in your account nor in your session. We only connect a sign-in to an existing account if the provider confirms that the e-mail address belongs to you (Google, Apple); we then send you an e-mail about it. No provider scripts are loaded on our pages.

The providers are Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland; Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. What the providers process when you sign in is described in their privacy policies; data may also be transferred to their parent companies in the USA (basis: EU-US Data Privacy Framework). The legal basis is Art. 6(1)(b) GDPR – you choose this way of signing in yourself. We delete the connection to the provider together with your account.

5. Ads

Tandem ads are public and can be found by search engines. They show your display name, the languages or topics, your city (if you want to meet in person) and your text. An ad stays online for one year; shortly before, we remind you by e-mail and you can extend it. We review texts containing links or e-mail addresses before they appear, to prevent spam.

6. Messages, blocking and reporting

We store messages between members on our server so that you can write to each other. Only the people in the conversation can read them. We only look at messages if one is reported to us or if this is necessary to prevent abuse. We notify you of new messages by e-mail; you can switch this off in your account.

If you block someone, we store this so that you no longer see or write to each other. If you report something, we store the report with the reason, your text and your account until we have dealt with it. New accounts can only start a limited number of new conversations in their first week; for this we count the conversations started. The legal basis is Art. 6(1)(b) and (f) GDPR (protecting members from spam and harassment).

7. E-mails

We send you e-mails about your registration, resetting your password, deleting your account, new messages and the expiry of your ads. We send the e-mails through Gmail by Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). For this, Google processes your e-mail address and the content of the e-mail on our behalf (Art. 28 GDPR); data may also be transferred to Google LLC in the USA (basis: EU-US Data Privacy Framework).

8. Search and places

Search runs on our own search server (Apache Solr) on our server. The radius search uses a list of cities (GeoNames) that is also stored on our server. We never ask for your device’s location.

9. Cookies and browser storage

We set only one cookie: the session cookie. It is created when you log in, and briefly also without logging in when we show you a message (for example after registering). For the session we store your IP address on the server. The cookie is technically necessary (§ 25(2) no. 2 TDDDG) to keep you logged in and lasts up to 23 days or until you log out. In your browser’s storage we remember whether you have closed the hint about the language of the site and – if you clicked “Show map” – your consent to the map for the current browser session. We serve fonts, scripts and styles ourselves. Content from other servers is only loaded when you switch on the map: then the map images from OpenStreetMap (see section 8).

10. Deletion

You can delete your account yourself at any time. We then immediately delete your profile, your ads, your conversations including all messages, your blocks, the reports made by you and about you, and the connections to Google, Apple, Facebook or Microsoft. Backups may still contain data for up to 14 days (we back up daily) before they are overwritten.

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). Just write to us at the address above.

You can also lodge a complaint with a data protection supervisory authority, for example the authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Last updated: September 2026