Last updated: 11 September 2026
This Privacy Policy explains how Basestack processes personal data for the hosted service at https://www.basestack.co, including the Feature Flags and Forms products, related websites, APIs, and product apps.
Basestack is operated from Portugal. Our privacy baseline is the EU General Data Protection Regulation (âGDPRâ). People outside the European Union may also have mandatory privacy rights under their local law, and they can contact us using the details below.
This policy covers Basestack's hosted Service. It does not cover third-party websites, customer websites, customer forms, or third-party integrations after data leaves Basestack at a customer's instruction.
Processor terms are set out in the Data Processing Addendum.
If you subscribe to the Basestack newsletter or ask to receive product updates, we use your email address to send those communications. You can opt out at any time by using the unsubscribe link in the email, where available, or by contacting [email protected]. We do not use Forms submitter data or Feature Flags identity traits for Basestack marketing. We do not sell personal data to third parties.
Where GDPR applies and Basestack acts as controller, we rely on the legal basis that fits each purpose:
When Basestack acts as processor, the customer is responsible for its own legal basis for the underlying data.
Forms submissions are determined by the customer's form design. Customers must not use Forms to collect prohibited data listed in the Acceptable Use Policy. If file uploads are enabled, files are stored with our object-storage sub-processor together with filename, content type, size, and submission link. File limits are currently 5 files per submission and 1 MB per file.
If a form has retention disabled, submissions and uploaded files are not stored. If retention is enabled, submissions and uploaded files remain available until the customer deletes them.
Customer applications may send identity traits, such as an opaque user identifier and attributes chosen by the customer, so Basestack can evaluate flags. Customers must not send special categories of personal data through this channel. Basestack does not actively monitor or control data sent by customers via identity traits.
Forms can use OpenRouter, a third-party AI gateway, to classify form submissions as likely spam or not likely spam. The classifier receives submission field values and the customer account identifier associated with the form. OpenRouter routes this data to an underlying large language model provider (such as OpenAI or Google) to generate the classification, and that provider processes the data under OpenRouter's and its own terms. Uploaded file bytes are not sent for spam classification. The result marks submissions for customer review; it does not delete submissions and does not produce legal or similarly significant effects on submitters. Because this feature sends submission content to a third-party model, customers should not collect special categories of personal data or other data prohibited by the Acceptable Use Policy through Forms.
We use third-party providers for hosting, object storage, CDN, transactional email, billing, analytics, authentication, spam classification, and customer-enabled integrations. The current list is maintained at /legal/sub-processors.
Customer-enabled integrations, such as Google Sheets, receive data only when a customer enables the integration. Those services may also process data under the customer's own relationship with that provider.
Basestack is operated from Portugal. Some providers process data in the United States or on global networks. Where GDPR applies and personal data is transferred outside the EEA, United Kingdom, or Switzerland without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent lawful transfer mechanisms.
We use technical and organisational measures appropriate to the Service, including TLS for public endpoints, access controls, encrypted storage where supported by providers, rate limits, audit logs, backups, and incident processes. No online service can guarantee absolute security.
Depending on where you are and how we process your data, you may have rights to access, correct, delete, restrict, object to, or port your personal data, and to complain to a data protection authority. In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt); if you are located elsewhere, you may also contact your local supervisory authority. If your request concerns data controlled by a Basestack customer, we may refer the request to that customer.
To exercise your rights, contact [email protected]. We will respond within one month, or as otherwise required by law, and may need to verify your identity before acting on the request.
If Basestack or substantially all of its assets are acquired, merged, reorganised, or transferred, personal data may be included in the transferred assets where permitted by law. The recipient must continue to protect personal data in line with this Privacy Policy unless it gives notice of a replacement policy and any rights required by law.
The Service is not directed to children under 16. Customers must not use Basestack to collect personal data from children under 16 or data covered by children's privacy laws unless they have a lawful basis and written permission from Basestack, and must comply with the Acceptable Use Policy regarding children's data.
We may update this Privacy Policy as the Service or law changes. Material changes will be announced through the Service, by email, or on our website where appropriate, and we will provide reasonable notice of material changes that affect your rights.
Basestack Privacy Policy
[email protected]