Skip to main content

Privacy Policy

This Privacy Policy explains how we collect, use, share, and protect personal information when you visit nextbasket.com and contact us through this website. We serve customers globally, including in the United States. This policy addresses US state privacy laws — starting with the California Consumer Privacy Act, as amended by the CPRA (together, the "CCPA") — and, because our operating company is established in the Netherlands, the EU General Data Protection Regulation (GDPR).

Effective date: 23 July 2026

Document version: Version 1.0 — effective 23 July 2026

1. Who we are (the business / data controller)

The business responsible for your personal information under this policy — the "controller" under the GDPR and the "business" under the CCPA — is Next Basket Platform B.V. (trading as NEXT BASKET AI), a Besloten Vennootschap (B.V.) — a private limited company under the laws of the Netherlands. We have not established that the CCPA or another US state privacy law applies to us by its thresholds, and publishing this policy is not an admission that any such statute applies. As a voluntary baseline we extend the core rights described here — access, correction, and deletion — to California and other US residents wherever reasonably possible.

Legal entity
Next Basket Platform B.V.
Brand
NEXT BASKET AI is a trade name of Next Basket Platform B.V.
Registered office
Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands
Company register
Netherlands Chamber of Commerce (Kamer van Koophandel, KVK), no. 84479493
General contact
office@nextbasket.com
Data protection / privacy contact
privacy@nextbasket.com — dedicated privacy / data-protection intake, monitored by our Privacy & Compliance Lead. No individual is publicly designated as a statutory Data Protection Officer at this stage, and no GDPR Article 27 EU representative is required because the controller is established in the Netherlands.

2. Scope of this policy

This policy covers personal information processed through the nextbasket.com marketing website — the pages you browse here and the enquiry, demo-request, and newsletter forms you may submit. Our audience is primarily businesses, but our forms may be used by individuals, so this policy is written to protect individuals as well.

The NEXT BASKET AI merchant platform (used by store operators at my.nextbasket.shop) and the personal information of shoppers on stores we host for merchants are governed by separate agreements. Where we host a merchant’s store, the merchant is the controller/business and we act as its processor/service provider.

For the marketing website, Next Basket Platform B.V. is the controller (business) for visitor, lead, and newsletter data. For the merchant platform, the merchant is the controller (business) for its shopper and merchant-customer data, and we act as its processor (service provider) under our Data Processing Addendum — except for our own account, security, billing, and legal-compliance data, for which we act as controller.

3. What personal information we collect

  • Contact and enquiry data you submit through our forms: your name, work email, company/store name, phone number (optional), and the content of your message.
  • Newsletter data: your email address, when you subscribe.
  • Technical data collected automatically: your IP address and standard request metadata (used for security, rate-limiting, and abuse prevention).
  • Analytics data (only when analytics is enabled for the build): pseudonymous usage data such as pages viewed and approximate, IP-derived location, via Google Analytics 4. This runs in a cookieless mode — it sets no cookies, stores nothing on your device, anonymizes your IP, and its events never carry your form data.

We do not ask for sensitive or special-category data (for example government IDs, precise geolocation, health, biometric, racial, religious, or political data) through this website, and we ask that you do not include such data in free-text message fields.

4. Why we process your data, and (for the EEA/UK) our legal bases

Purpose, data used, and — for EEA/UK visitors — the GDPR Article 6 legal basis

PurposeData usedLegal basis (GDPR)
Respond to enquiries, demo requests, and quotesName, email, company, phone, messageSteps at your request prior to a contract (Art. 6(1)(b)); consent (Art. 6(1)(a))
Send the newsletter / marketing you subscribed toEmail addressConsent (Art. 6(1)(a)) — withdrawable at any time
Security, anti-spam, and abuse preventionIP address, request metadata, Turnstile signalLegitimate interests in protecting our service (Art. 6(1)(f))
Measure and improve the website (cookieless analytics)Pseudonymous, cookieless usage data (GA4), when enabledLegitimate interests (Art. 6(1)(f)) — GA4 runs cookieless with no device storage and advertising features disabled, so limited measurement relies on legitimate interests, not consent

Because our analytics is configured with no analytics cookies or device storage, advertising features disabled, no form data in events, and IP protections, we rely on legitimate interests for this limited measurement rather than consent. If we ever introduce non-essential storage, an advertising feature, a user identifier, or cross-site tracking, it will stay disabled until prior consent and the necessary consent controls are in place.

In all of this processing we follow the data-protection principles of GDPR Art. 5: we process personal data lawfully, fairly, and transparently; collect it only for the specific purposes set out above and do not further process it in a way incompatible with those purposes; limit it to what those purposes require (data minimisation); keep it accurate and up to date; store it no longer than the retention periods in this policy; and protect its integrity and confidentiality with appropriate security measures — and we remain accountable for demonstrating all of this.

5. Who we share data with (recipients, processors / service providers)

We do not sell your personal information for money. We disclose it only to the service providers (processors) that help us run this website and respond to you, each under a data processing / service-provider agreement and only for the purposes above. See the California and other-state sections below for how "sale" and "sharing" are defined under US law and the choices you have.

Service providers / sub-processors used for this website

RecipientRoleData sharedLocationTransfer safeguard
OdooCRM — stores and manages your enquiry as a leadName, email, company, phone, messageEuropean Economic AreaProcessed within the EEA — no third-country transfer requiring safeguards
HubSpotCRM synchronisation, where enabledName, email, company, phone, messageEuropean Economic Area / United StatesData-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate
ResendTransactional email — delivers our notification and response emails (Brevo is not used)Email address and message metadataUnited StatesData-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate
CloudflareCDN, edge hosting, and Turnstile anti-bot protectionIP address, request metadata, Turnstile challenge dataGlobal edge networkData-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate
Fly.ioHosting for the backend that receives form submissionsAll submitted form data in transit and at restEuropean Economic Area (primary application region, where configured)Data-processing agreement and EU Standard Contractual Clauses for any processing outside the EEA, with supplementary measures where appropriate
Google (Analytics 4)Website analytics — only when enabled; cookieless modePseudonymous, cookieless usage data; no form dataEuropean Economic Area / United StatesData-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate
StripePayment processing (platform checkout / subscriptions) — PCI DSS Level 1Payment/card and billing data — handled by Stripe, not stored by usEuropean Economic Area / United StatesData-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate

We may also disclose personal information when required by law, to enforce our terms, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honor this policy).

Our current service providers for this website are Cloudflare (CDN, WAF, and Turnstile anti-bot), Fly.io (hosting for the form backend), Resend (transactional email; Brevo is not used), Odoo (CRM and lead management) and HubSpot (CRM synchronisation, where enabled), Google Analytics 4 (only when analytics is enabled in production), and Stripe (only for platform checkout and subscriptions, not for this marketing website). Processing may take place in the European Economic Area, the United States, or globally, as shown in the table above.

6. International data transfers

Some providers above may process personal information outside the European Economic Area (for example in the United States). Where that happens, we rely on the provider’s executed data-processing agreement and the European Commission’s Standard Contractual Clauses, together with supplementary security measures where appropriate. We do not rely on a generic "SCCs and/or Data Privacy Framework" statement: a provider’s EU–US Data Privacy Framework certification is cited only where we have verified it against the current DPF registry.

For each provider that processes personal information outside the EEA, the mechanism we rely on is that provider’s data-processing agreement and the EU Standard Contractual Clauses, with supplementary measures where appropriate. Where a provider processes only within the EEA, no third-country transfer safeguard is required.

7. How long we keep your data

We keep personal information only for as long as necessary for the purposes described above, and then delete or anonymise it. We determine retention by the type of data, why we hold it, and any legal obligation to keep it.

Retention schedule by data category.

Data categoryRetentionWhat sets the period
Enquiry / lead records (name, email, company, phone, message)24 months after the last meaningful contact, then deletion or anonymisation — unless the record is converted into a customer record.Sales follow-up need and applicable limitation periods; owner-set 24-month follow-up window.
Newsletter subscription (email)Until you unsubscribe; minimal consent and suppression evidence is then retained for 5 years.Your consent — kept until withdrawn; a minimal post-unsubscribe suppression record proves the opt-out and honours it.
Marketing-consent record (proof the checkbox was ticked + wording version)5 years (retained with the newsletter consent / suppression evidence).Accountability under GDPR Art. 7(1) and CAN-SPAM — evidence of what consent was given, in which wording, and when.
Security / IP / request logsOrdinary logs: 90 days, then deletion. Incident-specific records: retained up to 12 months.Fraud- and abuse-prevention need; the shortest window that still lets us investigate incidents.
Cookieless analytics data (GA4, when enabled)14 months, then automatic expiry (the GA4 data-retention maximum).The GA4 data-retention configuration, set to 14 months; GA4 expires events automatically at that horizon.
Privacy-request records (verification and handling of your request)3 years.Proof that we received, verified, and responded to your request, as our accountability obligations require.
Contracts, invoices, and tax / accounting records7 years, or the applicable statutory period where longer.Mandatory retention under Dutch tax and accounting law and equivalent obligations.

Where a legal obligation requires us to keep certain records for longer — for example contracts, invoices, and tax or accounting records — we retain those records for the applicable statutory period and then delete them.

8. Your California privacy rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this policy. It uses terms defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

Categories of personal information (Cal. Civ. Code § 1798.140) — collected in the last 12 months

Statutory categoryExamplesCollected on this site?
A. IdentifiersName, work email, phone number, IP address, online identifiersYes
B. Customer records (§ 1798.80(e))Name, phone number (and any address you provide)Yes
C. Protected classificationsAge, sex, race, etc.No — not collected
D. Commercial informationRecords of products/services you enquired about or requested a demo ofYes (limited)
E. Biometric informationFingerprints, faceprints, etc.No
F. Internet / network activityPages viewed and interactions, via cookieless analytics (only when enabled)Yes (limited)
G. Geolocation dataApproximate, IP-derived location — NOT precise geolocationYes (approximate only)
H. Sensory dataAudio, visual, thermalNo
I. Professional / employment informationCompany/store name; that you contact us in a business capacityYes
J. Education informationEducation recordsNo
K. InferencesProfiles drawn from the aboveNo — we do not draw inferences or profiles from this data
Sensitive personal information (§ 1798.140(ae))Government IDs, precise geolocation, account log-ins, contents of private messages, etc.No — not intentionally collected; do not submit it in free-text fields

Sources. We collect personal information directly from you (when you complete a form), automatically from your device and our servers (IP and request metadata, cookieless analytics), and from our service providers (for example our anti-bot provider).

Business and commercial purposes. We use the categories above to respond to your enquiries and provide requested information or demos; to secure the site and prevent fraud and abuse; to measure and improve the site; to send communications you asked for; and to comply with law. We do not use sensitive personal information to infer characteristics.

Sale and sharing. We do not sell your personal information for monetary consideration, and we do not "share" it for cross-context behavioral advertising (we run no advertising or ad-personalization technologies — our analytics is cookieless with ad features disabled). We do not sell or share the personal information of consumers we know to be under 16. Even so, we offer a privacy-choice request route — see the "Your Privacy Choices" section below.

We have not established that we meet the CCPA applicability thresholds, and this policy is written to comply as a precaution regardless of whether the statute strictly applies. We do not sell personal information, and we do not share it for cross-context behavioural advertising: this website runs no advertising or ad-personalisation technologies, and its analytics is cookieless with advertising features disabled.

Your California rights. Subject to the CCPA’s conditions, you have the right to:

  • Know / access — the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients (12-month lookback).
  • Delete — the personal information we collected from you, subject to legal exceptions.
  • Correct — inaccurate personal information we hold about you.
  • Opt out of sale/sharing — direct us not to sell or share your personal information (see "Your choices").
  • Limit use of sensitive personal information — although we do not collect sensitive personal information to infer characteristics.
  • Non-discrimination — we will not discriminate or retaliate against you for exercising these rights.

How to exercise. Submit a request by emailing privacy@nextbasket.com (subject line "California Privacy Request"). We will verify your identity by matching the information you give us against our records, and may ask for additional information to confirm you are the person the data relates to (or their authorized agent). We will respond within the timeframes the CCPA requires.

Authorized agents. You may use an authorized agent to submit a request. We may require the agent to provide proof of your written permission and may still verify your identity directly.

Financial incentives. We do not offer financial incentives or price/service differences in exchange for your personal information.

California "Shine the Light" (Civ. Code § 1798.83). We do not disclose personal information to third parties for those third parties’ own direct-marketing purposes.

Request methods. You may submit a California privacy request by email as described above; we may add a webform, but a webform is not a condition of making a request. Because we operate online and B2B, email is our primary channel and we do not designate a US toll-free privacy line. We verify your identity proportionately using information we already hold and do not ask for a government ID unless strictly necessary.

Categories in the last 12 months. Collected: identifiers and contact data; professional and company data; limited commercial enquiry data; IP and request-security data; and limited website-usage data when analytics is enabled. Disclosed for business purposes: to our hosting, security, CRM, communications, analytics, and payment providers, as applicable. Sold: none. Shared for cross-context behavioural advertising or targeted advertising: none. Sensitive personal information is not intentionally collected through this marketing website.

9. Other US state privacy rights

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), or another US state with a comprehensive consumer-privacy law (as such laws take effect), you have rights that mirror those above, subject to each law’s conditions:

  • Confirm whether we process your personal data and access it.
  • Correct inaccuracies in your personal data.
  • Delete personal data we hold about you.
  • Obtain a portable copy of personal data you provided.
  • Opt out of (a) targeted advertising, (b) the sale of personal data, and (c) certain profiling with significant effects — noting we do not sell personal data, do not conduct targeted advertising, and do not carry out such profiling through this website.

To exercise these rights, email privacy@nextbasket.com. If we decline your request, you may appeal by replying to our decision; we will respond to the appeal within the period your state law allows and, if we still decline, tell you how to contact your state Attorney General. You may exercise these rights free of charge, and we will not discriminate against you for doing so.

10. Your Privacy Choices

As explained above, we do not sell your personal information and do not share it for cross-context behavioural advertising or targeted advertising. Because there is no sale or share to opt out of, we do not publish a "Do Not Sell or Share" toggle; instead, to make your choice easy to exercise, we offer the privacy-choice request route below.

  • Your Privacy Choices — email privacy@nextbasket.com with the subject "Privacy Choice" and we will apply your preference.
  • Universal opt-out signals — because we do not sell or share personal information or conduct targeted advertising, no browser-based opt-out signal (such as Global Privacy Control) is currently required to exercise a choice here, and we make no claim that such a signal is detected today. If our practices ever change, we will implement and honour recognised opt-out signals before doing so.
  • Marketing email — use the unsubscribe link in any marketing email, or email us, to stop marketing messages (see the CAN-SPAM section).

Our current intake mechanism for a privacy choice is email; we may add a linked webform or a preference control in future. We do not present any browser-based opt-out signal as an implemented control unless and until it is technically detected and honoured.

11. Your rights (EEA / UK — GDPR)

If you are in the European Economic Area or the UK, then under the GDPR, and subject to its conditions, you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Have inaccurate data corrected (Art. 16).
  • Have your data erased in certain circumstances (Art. 17).
  • Restrict processing in certain circumstances (Art. 18).
  • Be told which recipients we have disclosed your data to, where you asked us to correct, erase, or restrict it (Art. 19).
  • Receive your data in a portable format (Art. 20).
  • Object to processing based on our legitimate interests, and object at any time to processing for direct marketing — in which case we stop that processing for marketing purposes (Art. 21).
  • Withdraw consent at any time, without affecting processing already carried out (Art. 7(3)).

To exercise any of these rights, contact us at privacy@nextbasket.com. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).

Our lead supervisory authority is the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), because our controlling entity is established in the Netherlands. You may also complain to the supervisory authority in your own EEA country or, in the UK, the Information Commissioner’s Office, where that applies to you. To exercise any right, email privacy@nextbasket.com.

12. Automated decision-making and profiling

We do not carry out automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22), and we do not conduct profiling with significant effects under US state laws, through this website. Our anti-bot check (Cloudflare Turnstile) scores requests to protect our forms from abuse; it does not make decisions about you as an individual.

This holds for all processing connected to this website: we do not draw inferences or behavioural profiles, and we do not use lead scoring or other automated processing to make legal or similarly significant decisions about you. Ordinary CRM prioritisation and our anti-bot and security scoring are not used to make consequential decisions about individuals. Any automated processing on the NEXT BASKET platform is governed by our platform terms.

13. Marketing emails (CAN-SPAM)

  • Our marketing emails identify Next Basket Platform B.V. as the sender, use accurate "from" and subject lines, and include our postal address (Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands).
  • Every marketing email includes a working unsubscribe link. You can also opt out by emailing us. We honor opt-out requests promptly (within 10 business days, as CAN-SPAM requires) and do not sell or transfer your address to others after you opt out.
  • Transactional or relationship messages — for example, our reply to an enquiry you sent us — are not marketing and may still be sent after you opt out of marketing.

The postal address shown in our marketing-email footers is our Netherlands registered office (Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands). We do not currently designate a US postal address or US registered agent; US establishment is planned for a later phase.

14. Children’s privacy (COPPA)

This website and our services are directed to businesses and adults, not to children. We do not knowingly collect personal information from children under 13 (as defined by the US Children’s Online Privacy Protection Act, COPPA), and we do not knowingly sell or share the personal information of consumers under 16. If you believe a child has provided us personal information, please contact us and we will delete it.

15. Cookies and similar technologies

This website is designed to set no non-essential cookies. Only strictly necessary / security technologies (provided by Cloudflare) may be used, and our analytics runs in a cookieless mode. Details of each category are set out in our Cookie Policy.

16. How we protect your data

  • Data is transmitted over encrypted connections (TLS/HTTPS).
  • Form submissions are protected by anti-bot verification (Cloudflare Turnstile), per-IP rate limiting, and honeypot fields.
  • Payment card data (on the platform) is handled by Stripe, a PCI DSS Level 1 certified provider; we do not store full card numbers.
  • Access to lead data is limited to the people and systems that need it to respond to you, and the people authorised to process it are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay, as the GDPR requires (Art. 33). Where the breach is likely to result in a high risk to you, we will also inform you without undue delay and describe the measures we have taken or propose to take (Art. 34) — unless an applicable exception applies, for example where the affected data was already protected by appropriate technical measures such as encryption, where we have since taken measures that make the high risk unlikely to materialise, or where individual notice would involve disproportionate effort (in which case we will make a public communication instead).

17. How to make a privacy request (our process)

You can exercise any of the rights described above — under the CCPA/CPRA, the other US state laws, or the GDPR — by contacting us. This section explains the single process we follow so every request is handled consistently, whichever law applies to you.

Where to send it. Email us at privacy@nextbasket.com with "Privacy Request" in the subject line, and tell us what you would like us to do (know/access, delete, correct, opt out, or receive a portable copy). Email is our live request route; we may add a web request form in future, but it is not required to make a request.

  • Acknowledge — we confirm we received your request.
  • Verify your identity — we match the details you give us against our records and may ask for limited additional information to confirm the request truly comes from you (or your authorized agent). We use that information only to verify the request.
  • Respond within the legal deadline — for GDPR requests, within one month, extendable by up to two further months only for complex or numerous requests (we tell you within the first month if we need the extension); for US state requests we handle voluntarily, we target 45 days with one permitted extension, and any appeal response within 45 days where the applicable law allows. Where a specific law sets a different deadline, that statutory deadline controls.
  • No charge, no retaliation — we handle requests free of charge, save for the narrow exceptions the law permits, and we never discriminate or retaliate against you for exercising a privacy right.
  • Authorized agents — you may use an authorized agent; we may require proof of your written permission and may still verify your identity directly.
  • If we decline — we tell you why and how to appeal: US state residents may appeal by replying to our decision (see our U.S. State Privacy Notice at /us-state-privacy-notice/) and may contact their state Attorney General; EEA/UK residents may complain to a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).

For the simplest choices — unsubscribing from marketing, or asking us not to sell or share your information (we do neither) — see Your Privacy Choices (/privacy-choices/). State-specific details are set out in our U.S. State Privacy Notice (/us-state-privacy-notice/).

Our live intake route is the privacy@nextbasket.com mailbox; a web request form may be added later. We verify your identity proportionately and document how we did so, and we follow the statutory response and appeal deadlines set out above for each applicable law.

18. AI training and use of your data

We are transparent about how personal information relates to our artificial-intelligence features. We do not use merchant content, shopper personal data, or website lead data to train general-purpose AI models unless the customer has expressly opted in through a separate written agreement.

This website itself runs no AI features on your enquiry data — your form submissions are used only to respond to you and for the purposes described in this policy. The AI features of the NEXT BASKET platform are governed by our AI Features Terms (/ai-terms/), which set out the no-training commitment above, the limits of AI output, and your controls.

We do not use website lead or newsletter data — or, on the platform, merchant content or shopper personal data — to train or fine-tune general-purpose AI models, unless the relevant customer gives a separate, explicit written opt-in. The platform’s AI Features run on our own in-house trained AI agents, so your data is not shared with third-party foundation-model vendors for training. If we ever engaged an external model provider for a feature, we would first configure its business or API terms so it does not use submitted data for general model training, and list it at /subprocessors/ before enablement.

19. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you.

20. How to contact us

If you have questions about this policy or how we handle your data, or to exercise any privacy right, contact Next Basket Platform B.V., Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands, or email privacy@nextbasket.com.