Basket Privacy Policy
Effective date: 18 August 2026 Last updated: 9 September 2026 Version: 1.1
1. Introduction
This Privacy Policy explains how BASK3T International B.V. ("Basket", "we", "us" or "our") collects, uses, shares and protects personal data when you use the Basket mobile applications for iOS and Android, our website at https://bask3t.app, and any related features and services (together, the "Services").
Basket is a shopping layer for the internet. It helps you discover, save, organise, compare and buy products across online stores. To do that, we necessarily process some information about you and about the products you save. This document sets out exactly what we process, why, and what control you have.
We have written this policy to be readable. Where a term has a specific legal meaning under the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), we use it in that sense.
If you do not agree with this Privacy Policy, please do not use the Services.
2. Who is responsible for your data (data controller)
For the purposes of the GDPR and equivalent laws, the data controller for the personal data described in this policy is:
| Legal entity | BASK3T International B.V. |
| Registered address | Lingedijk 85, 4247 EG Kedichem, the Netherlands |
| Company registration number | 85149683 (Dutch Chamber of Commerce / KVK) |
| Country of establishment | the Netherlands |
| General privacy contact | [email protected] |
| Data Protection Officer (if appointed) | We have not appointed a Data Protection Officer. Privacy matters are handled at [email protected] |
| EU/UK representative (if applicable) | Not applicable. BASK3T International B.V. is established in the Netherlands, within the European Union |
3. Summary at a glance
| What we do | Short answer |
|---|---|
| Do we sell your personal data? | No. We do not sell personal data, and we do not share it with third parties for their own independent advertising purposes. |
| Do we need an account? | Yes. The Basket apps require an account (email and password). The public website can be browsed without one. |
| Do we track you across other companies' apps and websites? | No. We do not track you across apps and websites owned by other companies. |
| Can you delete everything? | Yes. You can delete your account and associated personal data from within the app and via [email protected]. |
| Where is your data stored? | The European Union (Amsterdam), with the transfer safeguards described in Section 10 where a provider is established outside the EEA. |
4. The personal data we collect
We collect personal data in three ways: data you give us, data generated when you use the Services, and data we receive from third parties.
4.1 Data you provide to us
| Category | Examples | Applies when |
|---|---|---|
| Account data | Email address; display name; password (stored only as a salted cryptographic hash); profile photo, if you add one | You create an account with email and password |
| Content you create | Baskets, saved products, product notes, lists, tags, collections and any text or images you add | You use the core features |
| Sharing data | The recipients you share a basket with and any accompanying message | You share a basket |
| Preference data | Notification and price-alert settings, language, currency, categories of interest, and (where you choose to provide them) size or style preferences | You configure the app |
| Support and correspondence data | Messages, attachments and contact details you send us by email, in-app support or other channels | You contact us |
| Merchant/retailer contact data | Business contact name, business email, company name, role, and the store domain being claimed | A retailer registers for or claims a merchant profile |
4.2 Data generated when you use the Services
| Category | Examples | Notes |
|---|---|---|
| Usage and interaction data | Screens viewed, features used, items saved, searches performed within Basket, comparison actions, session start and end times, referral source | Used to operate and improve the product |
| Device and technical data | Device model, operating system and version, app version, language and region settings, time zone, mobile network or connection type, crash and diagnostic logs, and a resettable app or device identifier | Standard mobile app telemetry |
| Approximate location | Country or region, derived from IP address | Used for currency, availability and language — not precise GPS location. Basket does not request access to precise device location |
| Log data | IP address, request timestamps, requested URLs on our own systems, error codes | Retained for security and troubleshooting |
| Product graph data | Which products are saved, compared, or price-tracked, and the stores they come from | Used in aggregated and de-identified form for price intelligence and comparison quality (see Section 6.4) |
We do not collect your general browsing history. Basket's apps do not read the websites you visit outside the Basket app. We only receive information about a product page when you deliberately save or share it with Basket — for example through the system share sheet or by pasting a link.
4.3 Data we receive from third parties
- Product and retailer data sources — primarily Shopify Inc. (including the Shopify Global Catalog and merchant storefronts via the Universal Commerce Protocol) and the online stores whose products you view or save. This is product data (titles, prices, availability, images and links), not personal data, but it becomes associated with you once you save an item.
- Infrastructure providers — hosting and related technical processing as listed in Section 9.
4.4 Data we do not collect
We do not knowingly collect special categories of personal data under GDPR Article 9 (such as data revealing health, religious beliefs, political opinions, trade union membership, sexual orientation, or biometric data used to identify you). Please do not include such information in basket names, notes or support messages.
We do not collect payment card data. Basket does not currently process payments — see Section 12.
We do not collect Sign in with Apple or Google sign-in identifiers. Accounts are created with email and password only.
5. Account requirement
The Basket mobile apps require an account. There is no guest mode: you cannot create baskets, sync content or receive alerts without registering. You may browse the public website at https://bask3t.app without an account; in that case we still process the limited device, technical and log data described in Section 4.2 and any cookies covered by Section 8.
6. Why we use your data, and our legal basis
Under the GDPR we must have a lawful basis for each purpose. The table below sets these out. Where we rely on legitimate interests (Article 6(1)(f)), we have carried out a balancing assessment and you may object at any time (Section 11).
6.1 To provide the Services — legal basis: performance of a contract (Art. 6(1)(b))
Creating and authenticating your account; storing and syncing your baskets and saved products; enabling sharing; providing search, comparison and price information; providing customer support.
6.2 To send you the alerts and notifications you ask for — legal basis: performance of a contract (Art. 6(1)(b)), or consent (Art. 6(1)(a)) for the device permission
Price-drop alerts, back-in-stock alerts and other notifications about items you have saved. Push notifications require your operating system permission, which you can withdraw at any time in device settings.
6.3 To keep the Services secure and prevent abuse — legal basis: legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
Detecting and preventing fraud, spam, scraping, credential stuffing and other misuse; enforcing our Terms; protecting our users and systems. Our legitimate interest is the security and integrity of a service that many people rely on.
6.4 To improve, measure and develop the Services — legal basis: legitimate interests (Art. 6(1)(f)), or consent where required by local law for analytics
Understanding which features are used and where users encounter problems; diagnosing crashes; measuring the performance of new features; improving product matching, price accuracy and recommendation quality. Wherever it is possible to do so without loss of accuracy, we use aggregated or de-identified data for this purpose.
6.5 To produce aggregated retailer insights — legal basis: legitimate interests (Art. 6(1)(f))
We provide retailers with aggregated and statistical insight into demand for their products — for example, how often a product is saved or compared. No insight is shown to a retailer unless it is derived from at least 50 distinct users
We do not provide retailers with your identity, your email address, your individual baskets, or any information that identifies you as an individual, unless you have given separate, explicit consent.
6.6 To communicate with you — legal basis: performance of a contract (Art. 6(1)(b)) for service messages; consent (Art. 6(1)(a)) or legitimate interests (Art. 6(1)(f)) for marketing, depending on your country
Service messages (security alerts, changes to these documents, account notices) are not optional while you hold an account. Marketing emails are sent only where permitted, and every marketing message contains an unsubscribe link.
6.7 To comply with law — legal basis: legal obligation (Art. 6(1)(c))
Responding to lawful requests from authorities, meeting accounting and tax obligations, and handling data subject requests.
6.8 Automated decision-making and profiling
Basket uses automated processing to rank, group, match and recommend products, and to decide which alerts to send you. This is profiling in the GDPR sense, but it does not produce legal effects concerning you or similarly significantly affect you within the meaning of GDPR Article 22. We do not use automated decision-making to make credit, pricing, employment, insurance or eligibility decisions about you, and prices shown in Basket are not personalised to your individual profile.
7. Advertising and paid placements
Basket does not currently display advertising. If we introduce sponsored or promoted placements in future, they will be clearly labelled as such, they will never alter the neutrality of our rankings or price comparisons, and this Privacy Policy will be updated before any such feature goes live
We do not use your personal data to build advertising profiles for third parties, and we do not participate in real-time bidding or data broker arrangements.
8. Cookies, analytics and similar technologies
8.1 On our website
Our website uses cookies and similar technologies:
| Type | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Session management, security, load balancing, remembering your cookie choices | No |
| Functional | Remembering language, region and display preferences | Yes, in the EU/EEA and UK |
| Analytics | Measuring page views and traffic sources to improve the site | Yes, in the EU/EEA and UK |
| Marketing | We do not use marketing or retargeting cookies | — |
Where consent is required, we ask for it through our cookie banner before any non-essential cookie is set, and you can change or withdraw your choices at any time via https://bask3t.app/cookies. Details of individual cookies, their providers and their lifespans are listed at https://bask3t.app/cookies#overview.
8.2 In our mobile apps
Our apps do not use browser cookies. They use device-level storage for session tokens, preferences and similar functional data. The shipping apps do not currently include third-party analytics or crash-reporting SDKs. If we add such SDKs later, we will update this policy and the App Store / Play privacy labels before release.
8.3 Apple App Tracking Transparency
Basket does not track you across apps and websites owned by other companies, and therefore does not request permission under Apple's App Tracking Transparency framework. If we ever enable advertising-identifier collection or cross-app tracking, we will request ATT permission where required and update this policy.
8.4 Do Not Track
Our website does not currently respond to browser "Do Not Track" signals, because no common standard for interpreting them has been agreed. We do honour Global Privacy Control signals where legally required
9. Third-party services and recipients of your data
We share personal data only with the following categories of recipients, and only to the extent necessary.
9.1 Processors acting on our instructions
These providers process personal data on our behalf under a written data processing agreement that meets GDPR Article 28. They may not use your data for their own purposes.
| Provider | Role | Data involved | Location | Safeguard |
|---|---|---|---|---|
| DigitalOcean, LLC | Application hosting (App Platform), managed PostgreSQL database, and S3-compatible object storage when used for media | All service data processed by the backend and website | European Union (Amsterdam, ams3) | Data hosted in the EEA under DigitalOcean's Data Processing Agreement; Standard Contractual Clauses where the provider is US-established |
We do not currently use a separate third-party transactional email provider, push-notification delivery provider, customer-support platform, or crash/error monitoring SDK. Account, alert and support messages are handled by Basket systems or by direct email to our @bask3t.app addresses. When we introduce any of those processors, we will add them to this table before they process personal data.
This table must stay accurate. Apple and Google compare the third-party SDKs in the app binary against this policy and the store privacy labels. A mismatch is a common rejection reason.
9.2 Independent controllers
- Apple Inc. and Google LLC act as independent controllers for app store distribution and the platform services they provide when you download or use Basket through the App Store or Google Play. Their handling of your data is governed by their own privacy policies.
- Shopify Inc. and online stores / retailers. When Basket retrieves catalogue data from Shopify or another merchant, and when you follow a link from Basket to a retailer's website or app (including checkout), you deal with that party as an independent controller and its own privacy policy applies to the data it processes. Basket has no control over, and accepts no responsibility for, the data practices of third-party stores.
9.3 Other disclosures
We may disclose personal data where necessary to: comply with a legal obligation, court order or valid request from a public authority; establish, exercise or defend legal claims; protect the rights, safety or property of Basket, our users or the public; or enforce our Terms and Conditions.
9.4 Corporate transactions
If Basket is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a materially different privacy policy, and you will retain the right to delete your account.
10. International data transfers
Our primary hosting region is the European Union. Some of our providers are established outside the European Economic Area, including in the United States.
Where personal data is transferred outside the EEA or the UK, we rely on one or more of the following safeguards under Chapter V of the GDPR:
- an adequacy decision of the European Commission for the destination country, or the UK equivalent;
- the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where relevant, supported by a transfer impact assessment; or
- certification under the EU–US Data Privacy Framework and its UK extension, where the recipient participates.
You can obtain a copy of the safeguards we rely on, with commercially confidential terms redacted, by writing to [email protected].
11. Your rights
Subject to the conditions and exceptions in applicable law, you have the following rights.
| Right | What it means | How to use it |
|---|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your data and receive a copy of it | In-app: Settings → Account → Delete account · or email [email protected] |
| Rectification (Art. 16) | Correct inaccurate or incomplete data | Edit your profile in the app, or email us |
| Erasure (Art. 17) | Have your data deleted — the "right to be forgotten" | See Section 13 |
| Restriction (Art. 18) | Ask us to pause processing while a dispute is resolved | Email [email protected] |
| Data portability (Art. 20) | Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible | In-app export: Settings → Account → Delete account · or email us |
| Object (Art. 21) | Object to processing based on our legitimate interests, and object at any time to direct marketing | Email [email protected] · marketing: use the unsubscribe link |
| Withdraw consent (Art. 7(3)) | Withdraw consent at any time, without affecting processing that already took place | Device settings for notifications; cookie settings for cookies; email us for anything else |
| Not be subject to solely automated decisions (Art. 22) | See Section 6.8 | Email [email protected] |
| Lodge a complaint (Art. 77) | Complain to a supervisory authority | the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the authority where you live or work |
Our response times. We respond to requests without undue delay and in any event within one month of receipt. Where a request is complex or you have made several requests, we may extend this by up to two further months and will tell you why within the first month.
Verification. To protect your data, we may need to verify your identity before acting on a request. We will not ask for more information than is necessary to do so.
Cost. Exercising your rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if that ever happens.
11.1 Additional rights for residents of certain jurisdictions
If you are a California resident, you have rights under the California Consumer Privacy Act as amended, including rights to know, delete, correct, and to opt out of the "sale" or "sharing" of personal information. Basket does not sell or share personal information as those terms are defined under the CCPA, and does not knowingly do so for consumers under 16. We do not discriminate against you for exercising your rights.
If you are in another jurisdiction with comparable legislation, we will honour equivalent rights to the extent that law applies to us. Basket launches first for users in the European Union / EEA and comparable European markets. If we expand to jurisdictions that require additional disclosures (for example Brazil's LGPD, Canada's PIPEDA, or further US state privacy laws beyond the CCPA statement above), we will update this section before that launch.
12. Payments and subscriptions
Basket is currently free to use and does not charge consumers. We do not process, store or have access to payment card details.
If we introduce paid features in future, purchases made through the iOS or Android apps will be processed by Apple or Google under their own terms, and we will receive only the transaction confirmation and subscription status necessary to activate your entitlement — never your full payment card number. This Privacy Policy will be updated before any paid feature launches.
Retailers and merchants who enter into a paid agreement with us are handled under a separate commercial contract. We do not currently use a third-party billing processor for merchant invoicing; if we introduce one, we will name it in Section 9 before it processes personal data.
13. Data retention and deletion
We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires.
| Data | Retention period |
|---|---|
| Account data and content (baskets, saved products) | For as long as your account is active |
| Account data after you request deletion | Deleted from live systems within 30 days; removed from encrypted backups within 90 days |
| Inactive accounts | Accounts with no activity for 24 months are notified by email and deleted 30 days later if there is still no activity |
| Analytics and usage data | 14 months (first-party product usage records we store ourselves) |
| Server and security logs | 90 days |
| Support correspondence | 24 months after the case is closed |
| Records required for tax, accounting or legal defence | As required by the law of the Netherlands — typically seven years for fiscal records (Article 52 of the Dutch General State Taxes Act) |
| Aggregated and de-identified data | Indefinitely, as it no longer identifies you |
13.1 How to delete your account
You can permanently delete your Basket account and its associated personal data:
- In the app — open Settings → Account → Delete account and confirm. This route is available in both the iOS and Android apps, as required by Apple App Store Review Guideline 5.1.1(v).
- By email — write to [email protected] from the address associated with your account.
Deletion removes your profile, your baskets and saved products, your preferences and your alert subscriptions. We may retain a minimal record of the deletion itself, and any data we are legally required to keep, as set out above. Deletion cannot be undone.
14. How we protect your data
We implement appropriate technical and organisational measures under GDPR Article 32, including:
- encryption of data in transit using TLS, and encryption of data at rest;
- passwords stored only as salted hashes using a modern password-hashing algorithm — never in plain text;
- role-based access control and the principle of least privilege for employee access;
- logging and monitoring of access to production systems;
- segregation of production, staging and development environments;
- regular backups, with restore testing;
- security review of code changes and of third-party dependencies;
- contractual security obligations on all processors.
No system can be guaranteed to be completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required (GDPR Art. 33) and inform affected users without undue delay where the risk is high (GDPR Art. 34).
15. Children's privacy
The Services are not directed to children. You must be at least 16 years old to create a Basket account.
- In the EU/EEA, the GDPR sets the age of consent for information society services at 16, with Member States permitted to lower it to no less than 13. In the Netherlands the applicable age is 16.
- In the United States, our minimum age is 13, in line with the Children's Online Privacy Protection Act.
We do not knowingly collect personal data from children below the applicable age. If we become aware that we have done so, we will delete the data promptly. If you believe a child has provided us with personal data, contact [email protected].
Basket is not submitted to Apple's Kids Category or Google Play's Designed for Families. If that ever changes, this section will be rewritten before release.
16. Links to other websites and services
The Services contain links to retailers, brands and other third-party websites and apps. Following such a link takes you outside Basket. We do not control those destinations, and this Privacy Policy does not apply to them. We encourage you to read the privacy policy of any site you visit.
17. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, to our data practices, or to the law. When we do:
- we will update the "Last updated" date at the top of this page;
- we will keep the previous version available at https://bask3t.app/privacy-policy/archive;
- where the change is material — for example a new purpose of processing, a new category of recipient, or a change in legal basis — we will notify you in advance by email or through an in-app notice, and where the law requires it we will ask for your consent.
Continued use of the Services after a change takes effect means you have read the updated policy.
18. How to contact us
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | [email protected] |
| Data Protection Officer | No DPO appointed — write to [email protected] |
| Postal address | BASK3T International B.V., Lingedijk 85, 4247 EG Kedichem, the Netherlands |
| Security disclosures | [email protected] |
You also have the right to lodge a complaint with your local data protection supervisory authority at any time. In the Netherlands this is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.
Prepared for BASK3T International B.V. Not legal advice. Before App Store submission, have qualified Dutch counsel review this policy against the shipping build, App Store privacy labels, and signed processor agreements.