Privacy Policy
Last updated: 10 March 2026
This Privacy Policy explains how BasedPeps ("we", "us", "our") collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Latvian data protection law.
1. Data Controller
SIA BP Research (trading as BasedPeps)
Latvian Commercial Register No.: 40203736719
Registered office: Anniņmuižas bulvāris 19A-21, Rīga, LV-1067, Latvia
Privacy & GDPR contact: [email protected] (subject: "Privacy Request")
General contact: [email protected] or via the contact form
SIA BP Research is the data controller responsible for your personal data as defined in Article 4(7) GDPR. No Data Protection Officer (DPO) is appointed — we do not carry out processing that requires one under Art. 37 GDPR. For any data-protection questions, contact us directly at [email protected].
2. Legal Basis for Processing
We process personal data under the following legal bases as defined in Article 6(1) GDPR:
- Contract performance (Art. 6(1)(b)) — processing necessary to fulfil orders and provide our services.
- Legitimate interest (Art. 6(1)(f)) — website analytics, fraud prevention, and improving our services.
- Consent (Art. 6(1)(a)) — email newsletter subscription via Mailchimp. Consent may be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)) — compliance with applicable Latvian and EU legal requirements, including tax and accounting obligations.
3. Data We Collect
3.1 Information you provide
- Contact form: name, email address, inquiry type, message content.
- Orders: full name, email address, shipping address, order details, payment reference.
- Newsletter: email address (via Mailchimp subscription form).
3.2 Automatically collected data
- IP address, browser type, operating system, referring URL, pages visited, timestamps.
- This data is collected by our hosting provider for security and performance purposes.
4. Data Processors
We share personal data with the following third-party processors, each bound by data processing agreements compliant with GDPR Article 28:
- Netlify (Netlify Inc., USA) — website hosting, CDN, serverless function execution. Processes IP address, request metadata.
- Supabase (Supabase Inc., USA; EU-region servers in Frankfurt, Germany) — order database, customer records, and backend services. Processes order data, email address, shipping address.
- Resend (Resend Inc., USA) — transactional email delivery (order confirmations, shipping updates). Processes email address, name, order reference.
- NOWPayments (NOWPayments OU, Estonia) — cryptocurrency payment processing. Processes payment reference, order amount, IP address.
- GoAffPro (GoAffPro Inc., Canada) — affiliate programme tracking and management. May process referral source, order value, and email address for commission attribution.
- Sentry (Functional Software Inc., USA) — error tracking and performance monitoring. May process IP address, browser session data, and error stack traces. Personal data is minimised by configuration.
- Plausible Analytics (Plausible Insights OÜ, Estonia) — privacy-friendly website analytics. Processes anonymised page view data; no cookies used, no cross-site tracking. Plausible does not collect personal data as defined by GDPR. Loaded on the basis of legitimate interest (Art. 6(1)(f)) prior to cookie consent as no personal data is processed.
- Mailchimp (The Rocket Science Group LLC, USA) — email newsletter delivery. Processes email address for newsletter subscribers only. Mailchimp participates in the EU-US Data Privacy Framework.
Where data is transferred outside the EU/EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions as applicable.
5. Data Retention
- Contact form submissions: retained for up to 12 months, then deleted unless related to an ongoing order or dispute.
- Order data: retained for 5 years to comply with Latvian accounting and tax requirements.
- Newsletter subscriptions: retained until you unsubscribe. Unsubscribed records are deleted within 30 days.
- Abandoned-cart reminders: if you enter your email at checkout but do not complete the order, your email address and cart contents are stored to send a single reminder, then automatically deleted after 90 days. You can opt out via the unsubscribe link in any reminder email.
- Server logs: automatically purged after 90 days.
6. Your Rights Under GDPR
As a data subject, you have the following rights under GDPR Articles 15-22:
- Right of access (Art. 15) — obtain confirmation of whether we process your data and request a copy.
- Right to rectification (Art. 16) — request correction of inaccurate personal data.
- Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten").
- Right to restriction of processing (Art. 18) — request that we limit how we use your data.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interest, including direct marketing.
To exercise any of these rights, contact us via the contact form or use the erasure form below. We will respond within 30 days as required by GDPR.
6.1 Request Erasure of Your Data
Under Article 17 GDPR, you may request that we erase personal data we hold about you. Submit the form below — we will verify your identity and confirm the erasure within 30 days. Some data may be retained where required by law (for example, invoice records under Latvian accounting law — 5 years).
7. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority in Latvia:
Datu valsts inspekcija (Data State Inspectorate)
Website: www.dvi.gov.lv
Address: Elijas iela 17, Riga, LV-1050, Latvia
8. Cookies and Tracking
In accordance with the EU ePrivacy Directive (2002/58/EC) and its Latvian transposition, we only set non-essential cookies after you give consent via our cookie banner. You can change your choice any time via the Cookie Settings link in the footer.
8.1 What cookies we use
- Strictly necessary: essential for the site to work — shopping cart, login sessions, checkout security, age verification, consent preferences. Always on, no consent required.
- Analytics (on by default, cookieless): privacy-friendly usage metrics (Plausible) processed under legitimate interest — no cookies, no personal data, no cross-site tracking. You can opt out at any time via Cookie Settings.
- Marketing (opt-in): Meta Pixel for ad measurement on Facebook and Instagram. Fires only if you opt in — rejecting means no requests are made to Meta from your browser.
8.2 Managing cookies
Use the Cookie Settings link in the footer to change your choice at any time. You can also control and delete cookies through your browser settings. Disabling strictly necessary cookies may impair website functionality.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. This includes HTTPS encryption, access controls, and regular security reviews.
10. No Sale of Data
BasedPeps does not sell, rent, or trade personal data to any third party for marketing or any other purpose.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes take effect upon publication on this page. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For privacy-related inquiries, please contact us via the contact form on our website.