Privacy Policy
Last updated: 30 August 2026
This policy explains what personal data Baltego collects, why we collect it, how long we keep it and what rights you have over it. It covers this website. Baltego is not yet operating a live marketplace, so the data we hold today is limited to what is described below — we will update this policy before any ordering, payment or account features go live.
1. Who controls your data
The data controller is the Baltego operating entity to be completed before launch.
- Registered address: to be completed before launch
- Registration number: to be completed before launch
- Privacy contact: info@baltego.com
- Data Protection Officer: not appointed — a DPO is not currently required under Art. 37; to be reassessed before launch
2. What we collect, why, and for how long
Each row below is a separate processing activity. We only collect what the activity needs — we do not ask for a name, phone number or address to join the waitlist, because notifying you of a launch does not require them.
Customer waitlist
Applies to: Members of the public who ask to be notified at launch
- Data
- Email address, selected city, interface language, and how you reached the site (referring page, campaign tags)
- Purpose
- To send you one notification when Baltego launches in the city you chose, and to understand which cities and campaigns generate interest
- Legal basis
- Consent (Art. 6(1)(a)) — you asked to be told. The campaign and referrer fields rely on legitimate interests (Art. 6(1)(f)) in understanding demand, and are only captured if you accept analytics cookies
- Retention
- Until launch in your city plus 6 months, or 24 months if we have not launched, whichever comes first. Deleted immediately on request
- Recipients
- Our hosting and database providers (see the processor table). Never sold or shared for others' marketing
Marketing consent record
Applies to: Waitlist subscribers and merchant applicants who opted in
- Data
- Whether you opted in, the timestamp, the form it came from, and the withdrawal timestamp if you later opted out
- Purpose
- To send general news and offers, and to be able to demonstrate that consent was given — which the GDPR requires us to evidence
- Legal basis
- Consent (Art. 6(1)(a)); the record itself is kept under legal obligation (Art. 7(1))
- Retention
- Until you withdraw consent. The record that consent existed and was withdrawn is kept for 3 years afterwards as proof we acted lawfully
- Recipients
- Our hosting and database providers
Merchant applications
Applies to: People applying on behalf of a food business
- Data
- Contact name, work email, phone, business name, business type, city and country, and anything you write in the message field
- Purpose
- To assess your application and contact you about joining Baltego as a merchant
- Legal basis
- Steps taken at your request prior to a contract (Art. 6(1)(b)); for applications we decline, legitimate interests (Art. 6(1)(f)) in keeping a record of the decision
- Retention
- 24 months from the last contact if the application does not proceed; for the duration of the relationship if it does
- Recipients
- Our hosting and database providers
Cookie consent
Applies to: All website visitors
- Data
- Your cookie choices and the policy version they were given against, stored in your browser
- Purpose
- To remember your choices and to avoid asking again on every page
- Legal basis
- Legal obligation (Art. 6(1)(c)) — we must be able to show what you consented to
- Retention
- 12 months in your browser, or until you clear it or change your choices
- Recipients
- Nobody — this stays in your browser and is not transmitted to us
3. What we do not collect
We want to be equally clear about what is not happening yet, because a policy that describes features we have not built would be misleading:
- There are no customer or merchant user accounts, so we hold no passwords or login history.
- We do not process payments and never see or store card details. When payments launch they will run through a PCI-compliant provider so card data does not reach our systems.
- There are no orders or reservations yet, so no purchase history exists.
- No analytics or advertising scripts are installed. The consent framework described in our Cookie Policy is already in place so that any future analytics is gated behind your consent from the first day.
4. Who processes data on our behalf
We use a small number of service providers (processors). They act only on our instructions under a data processing agreement.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Hetzner Online GmbH | Runs the website and serves every page | IP addresses and request logs in the ordinary course of serving traffic | Germany (EEA) |
| Supabase | Stores waitlist entries, merchant applications and admin accounts | All personal data listed in the activities above | Region to be confirmed — verify the project is provisioned in an EU region before launch |
| GitHub (Microsoft) | Builds and deploys the site | No personal data of website visitors; developer account data only | United States |
| Unsplash | Supplies the imagery used across the site | Visitor IP address is visible to the image host when a photo loads | United States |
5. Transfers outside the EEA
We aim to keep all personal data within the EEA. Where a provider may process data outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses together with the provider’s supplementary measures. The processor table above records the location for each provider; entries still marked for confirmation are being verified against the provider’s contractual terms before launch.
6. Your rights
Under the GDPR you can:
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data where we have no overriding reason to keep it.
- Restrict or object to processing based on legitimate interests.
- Port your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting processing carried out before withdrawal.
The quickest routes: every marketing email carries a one-click unsubscribe link, and cookie choices can be changed at any time through the Cookie settings link in the footer. For anything else, email info@baltego.com and we will respond within one month, as the GDPR requires.
Erasure is not absolute — if a record must be kept for accounting or to defend a legal claim, we will tell you which part we are keeping and why, and erase the rest.
You also have the right to complain to your national supervisory authority: the Data State Inspectorate (Latvia), the State Data Protection Inspectorate (Lithuania), or the Data Protection Inspectorate (Estonia).
7. How we protect data
The site is served over HTTPS only. Personal data is stored in a Postgres database with row-level security enabled: the public website can write a waitlist entry or a merchant application but cannot read either back, so one visitor can never enumerate other people’s data. Reading that data requires an authenticated administrator account. Secrets are held in server-side environment variables and are not present in the browser bundle.
8. Changes to this policy
If we change how we use personal data we will update this page and the date at the top. Where a change relies on your consent, we will ask again rather than assume the earlier answer still applies.