Tenerife Premium Card
Experiences
Hotels & Accommodation
Find accommodationAre you a property owner?Real Estate · Real estate
Services
Health & ParapharmaciesBeauty & CareHome & RepairsCar & AssistancePaperwork & ConsultingTourist ServicesPets
See all services
The Heart
Prices
View all plans
Preview
Discover
Trip Planner
Videos
Blog
Business
Dashboard
Distribution
Commercial Partners
Platinum
Dashboard
Get your card
Experiences
Find accommodationAre you a property owner?Real Estate · Real estate
Health & ParapharmaciesBeauty & CareHome & RepairsCar & AssistancePaperwork & ConsultingTourist ServicesPetsSee all services
The Heart
View all plansPreview
Trip PlannerVideosBlog
DashboardHub BusinessDistributionCommercial Partners
Platinum
⚙ Admin
Get your card→

Legal

Privacy Policy

Last updated: 6 September 2026

1. Data controller

Data controller: TPCARD, S.L., NIF B93881506. Email: info@tpcard.es. For the full address and LSSI identifying details, see the Legal Notice.

2. Data we collect

We collect name, email, phone and payment data when purchasing a card or making a booking.

3. Purpose of processing

Your data is used to manage your purchase, process bookings and send you information.

4. Legal basis

Processing is based on contract performance, consent and legitimate interest.

5. Data retention

We retain your data for the duration of your card and for up to 3 years afterwards.

6. Your rights

You have the right to access, rectify, delete, restrict and port your data. Write to us at info@tpcard.es.

7. Cookies

We use technical cookies and, with your consent, analytical ones. Manage them through your browser.

8. Tracking technologies

With your explicit consent (Art. 6(1)(a) GDPR), we use the following tracking technologies for traffic analysis and digital marketing:

  • Google Analytics 4 — Analysis of traffic and user behaviour on the website. Anonymised and aggregated data. Provider: Google LLC (USA), subject to EU Standard Contractual Clauses.
  • Meta Pixel (Facebook / Instagram) — Conversion measurement and personalised advertising. Active only if configured by the controller. Provider: Meta Platforms Ireland Ltd.
  • TikTok Pixel — Conversion measurement and advertising on TikTok. Active only if configured by the controller. Provider: TikTok Technology Limited.
  • LinkedIn Insight Tag — Conversion measurement and advertising on LinkedIn. Active only if configured by the controller. Provider: LinkedIn Ireland Unlimited Company.

Right to object: You may withdraw consent at any time by disabling cookies via the cookie banner or your browser settings. Withdrawal of consent does not affect the lawfulness of prior processing.

9. Exercise of GDPR rights (Arts 12–22 GDPR)

You may exercise your rights of access, rectification, erasure, restriction and portability directly from your account at /mioaccount. For manual requests, write to info@tpcard.es stating your email address and the right you wish to exercise.

  • Acknowledgement of receipt of the request: 10 working days.
  • Resolution of the request: 30 days (extendable by a further 60 days in complex cases, with prior notice).
  • We may require identity verification (copy of DNI/NIE or equivalent document) before fulfilling the request.
  • If you consider that processing is not compliant with the GDPR, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).

10. Recipients of data (Art. 28 GDPR)

Your data may be disclosed to the following processors, all bound by a data processing agreement compliant with Art. 28 GDPR:

  • Stripe, Inc. — Payment processing. Registered office: USA. International transfer covered by Standard Contractual Clauses (SCC) approved by the European Commission.
  • Google LLC (Google Analytics 4) — Anonymised web traffic analysis. Registered office: USA. Transfer covered by SCC.
  • Meta Platforms, Inc. — Digital advertising (Meta Pixel). Registered office: USA. Transfer covered by SCC.
  • TikTok Technology Limited — Digital advertising (TikTok Pixel). Registered office: USA. Transfer covered by SCC.
  • LinkedIn Ireland Unlimited Company — Digital advertising (LinkedIn Insight Tag). Registered office: Ireland (EU).
  • Supabase, Inc. — Database hosting and file storage. Registered office: USA. Transfer covered by SCC. Data hosted on AWS servers in the EU region (Frankfurt).

11. Security measures (Art. 32 GDPR)

We implement appropriate technical and organisational measures to ensure a level of security proportionate to the risk:

  • Encryption in transit via SSL/TLS for all communications with the website.
  • Secure authentication with one-time session tokens (OTP) and protected HttpOnly cookies.
  • Payment processing via Stripe (PCI-DSS Level 1): we do not store card data in our systems at any time.
  • Encrypted backups with controlled retention in accordance with legal obligations.
  • Audit and logging of administrative access for the detection of unauthorised access.

12. Right to object to direct marketing (Art. 21 GDPR)

You have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to such marketing. To exercise this right, write to info@tpcard.es with subject line Marketing objection. We will cease processing your data for that purpose immediately and without requiring justification.

13. Consent and tracking technologies (Art. 6(1)(a) GDPR)

In accordance with Art. 6(1)(a) GDPR, third-party tracking technologies (Google Analytics 4, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag) are loaded only after the user has given explicit consent via the cookie banner displayed on the first visit to the site.

Without consent, no third-party analytics or advertising pixels or scripts are executed in your browser. You may modify or withdraw consent at any time via the cookie banner accessible in the site footer.

14. Data processors (DPA — Art. 28 GDPR)

To provide our services we rely on the following processors (Art. 28 GDPR), all bound by DPA (Data Processing Agreement) contracts compliant with European data protection law.

ProviderServiceCountryLegal basis for transferDPA
Supabase Inc.PostgreSQL database + Auth + StorageUSA (California)SCC + Art. 46 GDPRView DPA
Stripe Payments Europe Ltd.Card paymentsIreland (EU)Art. 6(1)(b) GDPR (performance of contract)View DPA
Resend (Reform.io Inc.)Transactional emailsUSASCC + Art. 46 GDPRView DPA
Vercel Inc.Hosting + CDN + serverlessUSASCC + Art. 46 GDPRView DPA
Hangzhou DeepSeek Artificial Intelligence Co., Ltd.AI assistant (chatbot)China (People's Republic of China)Explicit consent of the data subject (Art. 49(1)(a) GDPR)View DPA
Google LLC (reCAPTCHA + Analytics)Anti-spam + opt-in analyticsUSASCC + Art. 46 GDPR + user consentView DPA
Cloudflare Inc.DNS + DDoS protection (if active)USASCC + Art. 46 GDPRView DPA
Functional Software, Inc. (Sentry)Error monitoring and technical diagnosticsUSA (data in EU, Germany)SCC + Art. 46 GDPRView DPA

In accordance with Art. 30 GDPR, we maintain an up-to-date Record of Processing Activities (RAT) documenting each operation carried out by the processors listed above. You may request the updated list and signed DPAs at privacy@tpcard.es.

14.2 International transfers (Arts 44–50 GDPR)

Some processors are established outside the European Economic Area (EEA). In such cases, international transfers take place with the following safeguards:

  • Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914), entered into with each processor outside the EEA.
  • Art. 49 GDPR — additional safeguards through the user's explicit opt-in consent for analytics and marketing purposes before any transfer.
  • Transfer impact assessments (TIA) documented and reviewed periodically to verify that the level of protection in the destination country is substantially equivalent to that of the EEA.

Right to object: You have the right to object to the international transfer of your data by contacting privacy@tpcard.es. Objection may result in functional limitations in certain services whose provision depends on providers outside the EEA.

Privacy questions: info@tpcard.es

Tenerife Premium Card™

TPCARD, S.L.

NIF B93881506

info@tpcard.es+34 922 150 311+34 624 615 845

Support: Mon-Sun 9:00-20:00 · Chatbot 24/7

VISAMASTERCARDAMEXAPPLE PAYGOOGLE PAY🔒 STRIPE

Explore

ExperiencesPricesFAQContactAbout us
Explore
ExperiencesPricesFAQContactAbout us

Partner

Work with us
Partner
Work with us

Legal

Card rulesCommercial Partner ProtocolPrivacyCookieTermsLegal notice
Legal
Card rulesCommercial Partner ProtocolPrivacyCookieTermsLegal notice
© 2026 Tenerife Premium Card™ · Tenerife, Canary IslandsEU dispute resolution