Effective from 9 August 2026. Version 1.0.
This policy explains what personal data vnz.lv processes, why, on what legal basis, and what your rights are. It is prepared in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).
1. Controller
The controller of personal data is Kristaps Ozolins, a self-employed person. Contact for data protection matters: info@vnz.lv.
2. What data we process
- Account data: first and last name, e-mail address, password (hashed), chosen language, registration time.
- Phone number and the fact of its verification — a number is required to publish a listing or to view other users' contact details.
- Listing data: plate, price, description, region, images, status and history.
- Payment data: amount, currency, status, Stripe transaction identifiers. We never see or store payment card data — that is handled by Stripe.
- Usage data: IP address, request times and device information, for security and abuse prevention.
- Contact-reveal log: when a user presses “Show phone”, we record who did so and when.
- Correspondence with us (e-mail to info@vnz.lv).
3. Why we process data and on what basis
- Performance of a contract (GDPR 6(1)(b)): creating and maintaining an account, publishing listings, processing payments, saved-search alerts, service e-mails.
- Legal obligation (GDPR 6(1)(c)): accounting and tax requirements for payments; responding to lawful requests from authorities.
- Legitimate interests (GDPR 6(1)(f)): fraud and abuse prevention, Site security, enforcement of rate limits, statistics to improve the Site. We have balanced these interests against users' rights.
- Consent (GDPR 6(1)(a)): only where separately requested — for example if we offer a newsletter in future. Consent can be withdrawn at any time.
4. Visibility of your phone number
A phone number is never published on a listing page and is not available to search engines or unregistered visitors. It can only be seen by a registered, phone-verified user who presses the “Show phone” button. Every reveal is logged so that bulk harvesting can be detected.
5. Who we share data with
We do not sell data and do not share it for advertising. Data is processed only by the following processors, each under a data processing agreement:
- Supabase — database, authentication and file storage (EU servers).
- Google — sign-in with a Google account, if the user chooses that option (Google is an independent controller in respect of its own account data).
- Vercel — hosting and delivery of the Site.
- Stripe — payment processing (Stripe is an independent controller in respect of payment data).
- Resend — delivery of service e-mails.
- Twilio — SMS verification codes.
- Cloudflare Turnstile — prevention of automated abuse.
- Sentry — error monitoring to keep the Site working.
6. Transfers outside the EU
Some service providers may process data outside the European Economic Area. Where this happens, the transfer is based on a European Commission adequacy decision or on standard contractual clauses (SCCs), ensuring an equivalent level of protection.
7. How long we keep data
- Account data — while the account exists, and 30 days after deletion (to allow recovery from mistaken deletion).
- Listings — while active; after expiry or removal we keep them archived, though price statistics for sold plates may remain public without the seller's identity.
- Payment and accounting data — 5 years, as required by law.
- Security and abuse logs — up to 12 months.
- Correspondence with us — up to 24 months.
8. Your rights
In respect of your data you have the following GDPR rights:
- To access your data and receive a copy of it.
- To rectify inaccurate data (most of it you can correct in account settings).
- To erase data (“to be forgotten”), except where legal obligations such as accounting rules prevent it.
- To restrict processing, or to object to processing based on legitimate interests.
- To receive your data in a portable format.
- To withdraw consent where processing is based on consent.
- To lodge a complaint with the Data State Inspectorate of Latvia (www.dvi.gov.lv) if you believe your data has been processed unlawfully.
9. Cookies
We use only technically necessary cookies: your login session, language choice and security (Turnstile) cookies. We use no advertising or tracking cookies and share no data with ad networks, which is why no cookie consent banner is required.
10. Data security
We apply industry-standard safeguards: encrypted connections (HTTPS), password hashing, database-level access control (row level security policies), phone verification and limits against automated harvesting. No system is perfectly secure, so we encourage you to use a unique password.
11. Children's data
The Site is not intended for persons under 18 and we do not knowingly process their data. If we become aware of such an account, it will be deleted.
12. Changes to this policy
We may update this policy. We give notice of material changes by e-mail or on the Site. The version in force and its date are always shown at the top of this page.
For questions about data processing and to exercise your rights, write to info@vnz.lv. We respond within 30 days.