Privacy Policy
Last updated: February 19, 2026
This privacy policy is prepared in accordance with GDPR (General Data Protection Regulation) and Latvian Personal Data Processing Law.
1. Data Controller
The website autopase.lv is operated by Baltic Oranges, an information platform for used car search and verification in Latvia.
- Name: Baltic Oranges (SIA) [Example — replace with actual data]
- Registration number: [To be filled with LR Company Register number]
- Legal address: [To be filled with address]
- Contact: info@autopase.lv
- DVI: Data State Inspectorate of Latvia — dvi.gov.lv
ℹ️ We do not sell personal data and do not perform automated decision-making that would significantly affect you (GDPR Article 22).
2. What Data We Process and Why
2.1 Analytics Data
- Data: Page views, device type, browser, country (anonymized IP), session duration
- Purpose: Website improvement, error detection, usage statistics
- Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) — understanding user needs
- Service provider: PostHog (EU instance) — privacy policy
- Retention: 90 days (anonymized history up to 2 years)
2.2 Email Addresses
- Data: Email address, selected alert filters (brand, price, etc.)
- Purpose: Price alerts, newsletter updates
- Legal basis: Consent (GDPR Art. 6(1)(a))
- Service provider: Railway Postgres (EU/US), email sending via Vercel Functions
- Retention: Until you unsubscribe or request deletion
2.3 VIN Numbers
- Data: Entered VIN number, check timestamp
- Purpose: Vehicle history checks, CSDD data queries
- Legal basis: Contract performance / service provision (GDPR Art. 6(1)(b))
- Service provider: carVertical, carVertical (if integrated), CSDD public API
- Retention: 7 days (session data), purchased report history up to 2 years (accounting)
2.4 Telegram Bot Data
- Data: Telegram user ID, selected filters (brand, price, region)
- Purpose: Car notifications, VIN checks via bot
- Legal basis: Consent (GDPR Art. 6(1)(a))
- Service provider: Telegram Bot API (Telegram Inc.), Railway Postgres (EU)
- Retention: Until you unsubscribe from bot or delete subscription (/stop command)
2.5 Listing Data
- Data: Publicly available used car listings from ss.lv, auto.lv, etc.
- Purpose: Information aggregation, price analysis, market reports
- Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) — public data collection
- Service provider: Railway Postgres (EU), Vercel (global CDN)
- Retention: Up to 6 months after listing removal from source
2.6 Cookies
We use cookies for language preference, session identification, and analytics. More details: Cookie Policy.
3. Who We Share Your Data With
3.1 Third-Party Service Providers
| Service | Purpose | Location |
|---|---|---|
| PostHog | Analytics | EU (Frankfurt) |
| Vercel | Hosting, CDN | Global (primary EU) |
| Railway | Database (Postgres) | EU or US (region-dependent) |
| Stripe | Payment processing (VIN reports) | Global (GDPR compliant) |
| carVertical / carVertical | VIN checks | EU (Poland / Lithuania) |
| Telegram | Bot API | Global |
ℹ️ All third-party service providers process data with appropriate agreements (Data Processing Agreements) and security measures in accordance with GDPR requirements.
3.2 Legal Requirements
We may disclose your data if required by law, court order, or other lawful requests (e.g., law enforcement inquiries).
4. Data Retention
- Analytics data: 90 days (recent events), anonymized up to 2 years
- Email subscriptions: Until unsubscribe or 2 years of inactivity
- VIN checks: 7 days (session data), payment history 7 years (legal requirement)
- Telegram subscriptions: Until /stop command or 1 year of inactivity
- Listing data: Up to 6 months after removal from source
After the retention period ends, data is automatically deleted or anonymized.
5. Your Rights Under GDPR
5.1 Right to Access Your Data (Article 15)
You have the right to request a copy of all your personal data we hold. We will respond within 30 days (free of charge).
5.2 Right to Rectification (Article 16)
If your email address or other data is incorrect, you can request corrections.
5.3 Right to Erasure (Article 17 — "Right to be Forgotten")
You can request deletion of your data if:
- Data is no longer necessary for the original purpose
- You withdraw your consent (email subscriptions, Telegram bot)
- You object to processing and there are no overriding legitimate grounds to continue
⚠️ Exception: If data is required for legal obligations (e.g., payment history for accounting).
5.4 Right to Restrict Processing (Article 18)
You can request to suspend data processing (but not delete) if you contest the accuracy or lawfulness of the data.
5.5 Right to Data Portability (Article 20)
You can request to receive your data in a structured, machine-readable format (JSON, CSV) and transfer it to another service.
5.6 Right to Object (Article 21)
You can object to data processing based on legitimate interests (e.g., analytics). We will assess whether we have compelling legitimate grounds to continue.
5.7 Right to Lodge a Complaint
If you believe we violate GDPR, you can file a complaint with the Data State Inspectorate of Latvia:
- Address: Elijas Street 17, Riga, LV-1050
- Phone: +371 67 22 31 31
- Email: info@dvi.gov.lv
- Website: www.dvi.gov.lv
6. How to Exercise Your Rights
To exercise any of the above rights, write to:
- Email: info@autopase.lv (subject: "GDPR Request")
- Specify your email address or Telegram ID (for identification)
- Describe your request (access / deletion / correction, etc.)
We will respond within 30 days. If verification is needed, we may request a copy of your photo ID (for data protection purposes).
7. Children's Privacy
Our services are not intended for persons under 16 years old. We do not knowingly collect personal data from children without parental consent. If you discover that a child has provided us with data, please contact us — we will delete it.
8. Security
We use industry-standard security measures:
- HTTPS encryption for all connections
- Database encryption at rest
- Access control (only authorized employees)
- Regular security audits and updates
⚠️ However, no internet transmission method is 100% secure. We cannot guarantee absolute security.
9. International Data Transfers
Some of our service providers (Vercel, Railway) may process data outside the European Economic Area (EEA). In such cases:
- We use only GDPR-compliant services
- Standard Contractual Clauses (SCC)
- Data Processing Agreements (DPA)
10. Telegram Bot
By using our Telegram bot (@autopase_lv_bot), you agree to:
- Storage of your Telegram user ID (required for sending messages)
- Storage of your selected filters (brand, price, region)
- Receiving notifications about new listings or VIN checks
To stop: send /stop command to the bot. Your data will be deleted within 7 days.
11. Changes to This Privacy Policy
We may periodically update this privacy policy. Changes take effect from the moment they are published on this page. Significant changes will be notified via email (if you subscribe to updates) or through the Telegram bot.
Latest changes: February 19, 2026 — GDPR compliance improvements, added cookie policy, detailed third-party list.
12. Contact
For questions about privacy or data processing:
- Email: info@autopase.lv
- Subject: "GDPR Request" or "Privacy"
Related documents: Terms of Service • Cookie Policy