Baltego

Privacy Policy

Last updated: 30 August 2026

This policy explains what personal data Baltego collects, why we collect it, how long we keep it and what rights you have over it. It covers this website. Baltego is not yet operating a live marketplace, so the data we hold today is limited to what is described below — we will update this policy before any ordering, payment or account features go live.

1. Who controls your data

The data controller is the Baltego operating entity to be completed before launch.

  • Registered address: to be completed before launch
  • Registration number: to be completed before launch
  • Privacy contact: info@baltego.com
  • Data Protection Officer: not appointed — a DPO is not currently required under Art. 37; to be reassessed before launch

2. What we collect, why, and for how long

Each row below is a separate processing activity. We only collect what the activity needs — we do not ask for a name, phone number or address to join the waitlist, because notifying you of a launch does not require them.

Customer waitlist

Applies to: Members of the public who ask to be notified at launch

Data
Email address, selected city, interface language, and how you reached the site (referring page, campaign tags)
Purpose
To send you one notification when Baltego launches in the city you chose, and to understand which cities and campaigns generate interest
Legal basis
Consent (Art. 6(1)(a)) — you asked to be told. The campaign and referrer fields rely on legitimate interests (Art. 6(1)(f)) in understanding demand, and are only captured if you accept analytics cookies
Retention
Until launch in your city plus 6 months, or 24 months if we have not launched, whichever comes first. Deleted immediately on request
Recipients
Our hosting and database providers (see the processor table). Never sold or shared for others' marketing

Marketing consent record

Applies to: Waitlist subscribers and merchant applicants who opted in

Data
Whether you opted in, the timestamp, the form it came from, and the withdrawal timestamp if you later opted out
Purpose
To send general news and offers, and to be able to demonstrate that consent was given — which the GDPR requires us to evidence
Legal basis
Consent (Art. 6(1)(a)); the record itself is kept under legal obligation (Art. 7(1))
Retention
Until you withdraw consent. The record that consent existed and was withdrawn is kept for 3 years afterwards as proof we acted lawfully
Recipients
Our hosting and database providers

Merchant applications

Applies to: People applying on behalf of a food business

Data
Contact name, work email, phone, business name, business type, city and country, and anything you write in the message field
Purpose
To assess your application and contact you about joining Baltego as a merchant
Legal basis
Steps taken at your request prior to a contract (Art. 6(1)(b)); for applications we decline, legitimate interests (Art. 6(1)(f)) in keeping a record of the decision
Retention
24 months from the last contact if the application does not proceed; for the duration of the relationship if it does
Recipients
Our hosting and database providers

Cookie consent

Applies to: All website visitors

Data
Your cookie choices and the policy version they were given against, stored in your browser
Purpose
To remember your choices and to avoid asking again on every page
Legal basis
Legal obligation (Art. 6(1)(c)) — we must be able to show what you consented to
Retention
12 months in your browser, or until you clear it or change your choices
Recipients
Nobody — this stays in your browser and is not transmitted to us

3. What we do not collect

We want to be equally clear about what is not happening yet, because a policy that describes features we have not built would be misleading:

  • There are no customer or merchant user accounts, so we hold no passwords or login history.
  • We do not process payments and never see or store card details. When payments launch they will run through a PCI-compliant provider so card data does not reach our systems.
  • There are no orders or reservations yet, so no purchase history exists.
  • No analytics or advertising scripts are installed. The consent framework described in our Cookie Policy is already in place so that any future analytics is gated behind your consent from the first day.

4. Who processes data on our behalf

We use a small number of service providers (processors). They act only on our instructions under a data processing agreement.

ProviderPurposeDataLocation
Hetzner Online GmbHRuns the website and serves every pageIP addresses and request logs in the ordinary course of serving trafficGermany (EEA)
SupabaseStores waitlist entries, merchant applications and admin accountsAll personal data listed in the activities aboveRegion to be confirmed — verify the project is provisioned in an EU region before launch
GitHub (Microsoft)Builds and deploys the siteNo personal data of website visitors; developer account data onlyUnited States
UnsplashSupplies the imagery used across the siteVisitor IP address is visible to the image host when a photo loadsUnited States

5. Transfers outside the EEA

We aim to keep all personal data within the EEA. Where a provider may process data outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses together with the provider’s supplementary measures. The processor table above records the location for each provider; entries still marked for confirmation are being verified against the provider’s contractual terms before launch.

6. Your rights

Under the GDPR you can:

  • Access a copy of the personal data we hold about you.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data where we have no overriding reason to keep it.
  • Restrict or object to processing based on legitimate interests.
  • Port your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting processing carried out before withdrawal.

The quickest routes: every marketing email carries a one-click unsubscribe link, and cookie choices can be changed at any time through the Cookie settings link in the footer. For anything else, email info@baltego.com and we will respond within one month, as the GDPR requires.

Erasure is not absolute — if a record must be kept for accounting or to defend a legal claim, we will tell you which part we are keeping and why, and erase the rest.

You also have the right to complain to your national supervisory authority: the Data State Inspectorate (Latvia), the State Data Protection Inspectorate (Lithuania), or the Data Protection Inspectorate (Estonia).

7. How we protect data

The site is served over HTTPS only. Personal data is stored in a Postgres database with row-level security enabled: the public website can write a waitlist entry or a merchant application but cannot read either back, so one visitor can never enumerate other people’s data. Reading that data requires an authenticated administrator account. Secrets are held in server-side environment variables and are not present in the browser bundle.

8. Changes to this policy

If we change how we use personal data we will update this page and the date at the top. Where a change relies on your consent, we will ask again rather than assume the earlier answer still applies.

We use cookies 🍪

We use essential cookies to make Baltego work and, with your permission, optional cookies to understand how our website is used and improve your experience.

Learn more: Cookie Policy