Privacy Policy
Last updated: 5 May 2026
This Privacy Policy explains how Kitelost ("we", "us", "our") collects, uses, and protects your personal data when you use our website at kitelost.com and related services (together, the "Platform").
We take your privacy seriously. We try to collect as little personal data as we reasonably can, we tell you what we do with it, and we give you clear control over it.
If you only have a minute, here's the short version:
- We collect what we need to run a gear registry, a lost & found network, and a marketplace — nothing more.
- We never sell your personal data.
- You can access, export, correct, or delete your data at any time.
- Your gear's serial number, your location for lost & found reports, and your username are public when you choose to make them public — and we'll always make that clear before you do.
The full version is below.
1. Who we are
Kitelost is operated by:
Niels Dercksen, trading as Kitelost (eenmanszaak) Servaes Noutsstraat 6, 1074 ED Amsterdam, The Netherlands The Netherlands
For all privacy-related questions, including requests to access, correct, or delete your data, please contact:
We are the "data controller" of your personal data under the EU General Data Protection Regulation (GDPR) and Dutch privacy law (UAVG).
2. What this Policy covers
This Policy applies to everyone who uses Kitelost: private riders, shops, schools, and visitors who don't have an account.
It covers all data we collect through:
- The Kitelost website and any subdomains
- Account creation, gear registration, marketplace ads, lost & found reports, transfers, reviews, and messaging
- Emails we send you (transactional and marketing)
- Cookies and similar technologies (see Section 12)
It does not cover third-party websites we link to. Those have their own privacy policies, and we're not responsible for them.
3. What data we collect
We collect data in three ways: (a) data you give us directly, (b) data we generate when you use the Platform, and (c) data we receive from third parties.
3.1 Data you give us
When you create an account:
- Email address
- Username
- Password (stored hashed — we never see it in plain text)
- Account type (private, shop, or school)
When you complete your profile:
- Display name and/or business name
- Country and approximate location (city / postal code)
- Optional profile picture
- For shops and schools: business details such as company name, address, KvK / VAT number (when provided)
When you register gear:
- Brand, model, type, size, year
- Serial number
- Photos of the gear and the serial number sticker
- Optional notes (purchase date, where it was bought, condition)
When you create marketplace ads:
- Listing details (price, description, photos, location)
- Shipping or pickup preferences
When you report gear lost or stolen:
- Approximate location of the loss
- Date and circumstances
- Any details you choose to share publicly to help recovery
When you transfer gear:
- The recipient's email address
- A snapshot of the gear and transfer details (price, date)
When you message other users:
- The content of your messages and any images you attach
- Read/delivery timestamps
When you leave reviews:
- Your rating and written feedback after a completed transfer
When you contact us:
- Your email and the content of your message
If DAC7 tax reporting becomes applicable in the future (sellers only — see Section 4.1):
If, in the future, Kitelost becomes a "reporting platform operator" under EU Directive 2021/514 (DAC7), Dutch tax law will require us to collect and verify additional information about sellers who cross certain thresholds (currently more than 30 sales per calendar year, or more than €2,000 in total proceeds). This includes:
- Full legal name
- Primary residential address (or registered office address, for businesses)
- Date of birth (individuals)
- Tax Identification Number (TIN) — for Dutch residents this is your BSN; for residents of other EU countries, the equivalent national TIN
- VAT identification number, where applicable
- Business registration number (KvK), where applicable
- The financial account where proceeds are paid (typically IBAN)
- Country of tax residence
This does not apply today. We're flagging it now so you know what to expect if and when it becomes relevant.
3.2 Data we generate when you use the Platform
- Login and security data: IP address, device type, browser, login times, password reset events, email verification status
- Activity data: gear added, ads created, serials verified, reports filed, transfers initiated/accepted, messages sent, login frequency
- Notification data: notifications sent to you and whether you've read them
- Onboarding milestones: timestamps for when you first added gear, verified a serial, or created an ad (used to send relevant onboarding emails)
3.3 Data we receive from third parties
- Geocoding data (from Google Maps): when you enter a postal code or city, we use Google's geocoding service to convert it into approximate coordinates so the location can be shown on a map.
- Email engagement data (from Loops.so): whether you've opened or clicked our emails — used to improve our communications and stop sending to inactive addresses.
- Analytics data (from Google Analytics): anonymized website usage data — see Section 12.
- Image hosting metadata (from Cloudflare Images): basic technical info about uploaded images.
4. Why we collect it (and the legal basis)
Under GDPR, we need a legal reason to process your data. Here's what we do, why, and on what basis:
| What we use your data for | Legal basis |
|---|---|
| Running your account, gear registry, ads, transfers, messaging, and reviews | Performance of contract (Article 6(1)(b)) — we can't provide the service without it |
| Verifying your email, preventing spam and fraud, blocking abuse | Legitimate interest (Article 6(1)(f)) — keeping the Platform safe for everyone |
| Showing your gear, ads, lost reports, reviews, and username publicly when you choose to make them public | Performance of contract + your action — you decide what to publish |
| Sending transactional emails (verification, password reset, transfer notifications, etc.) | Performance of contract |
| Sending onboarding and marketing emails | Legitimate interest, with an easy unsubscribe in every email — or your consent where required by law |
| Processing payments for shop subscriptions and per-transfer fees (when applicable) | Performance of contract |
| Verifying business identity for shops and schools (KYC, when applicable) | Legal obligation (Article 6(1)(c)) and performance of contract |
| Collecting, verifying and reporting seller data under DAC7 (future — see Section 4.1) | Legal obligation (Article 6(1)(c)) |
| Complying with legal requests, tax obligations, and law enforcement | Legal obligation |
| Improving the Platform with analytics | Consent (you can decline analytics cookies) |
| Defending our legal rights | Legitimate interest |
If you ever want more detail on the balancing test for any "legitimate interest" use, email us and we'll explain it.
4.1 Tax reporting under DAC7 (future)
EU Directive 2021/514 ("DAC7"), implemented in the Netherlands as the Wet implementatie EU-richtlijn gegevensuitwisseling digitale platformeconomie, requires certain platform operators to report data about sellers to the Dutch Tax Administration (Belastingdienst).
Today. Kitelost is currently operated as a sole proprietorship (eenmanszaak) and is not yet a "reporting platform operator" under DAC7. We do not currently collect DAC7-specific tax data, and we do not make DAC7 reports to the Belastingdienst.
In the future. If Kitelost incorporates as a legal entity (e.g. a BV), or otherwise becomes a reporting platform operator, DAC7 will apply. We're including the information below now so you know what to expect when that happens. We will update the "Last updated" date at the top of this Policy and notify you in advance before any DAC7 collection or reporting begins.
Who this would apply to. You would be a "reportable seller" under DAC7 if, in a given calendar year, you cross either threshold for sales of goods on the Platform:
- More than 30 sales transactions, or
- More than €2,000 in total proceeds
This applies to both individuals and businesses. It applies regardless of whether you make a profit.
What we'd ask you for. When you approach or cross the threshold, we'd ask you to provide and confirm:
- Full legal name
- Date of birth (individuals)
- Primary residential address or registered office address
- Tax Identification Number (BSN for Dutch residents; the equivalent national TIN for residents of other EU member states)
- VAT number, where applicable
- Business registration / KvK number, where applicable
- The financial account (IBAN) where proceeds are paid
What we'd report. Once you're a reportable seller, we'd report the following to the Belastingdienst:
- The identification data listed above
- The total proceeds you received per quarter and per calendar year
- The number of relevant transactions
- Any fees, commissions, or taxes we charged you
- The financial account details where proceeds were paid
This would be reported annually, by 31 January, for the previous calendar year. You would receive a copy of the data we report about you, and you'd have the right to ask us to correct any errors.
If you don't provide the information. DAC7 requires us, after two reminders and a 60-day period, to either close the seller's account or suspend their ability to receive payments until they provide the requested information.
Retention. When DAC7 applies, we'd keep DAC7-related data for the periods required by Dutch tax law (currently 7 years, plus the year of reporting). Even if you delete your account, we would be legally required to retain this data for the full retention period.
Verification. We may use third-party services to verify the validity of TINs, VAT numbers, or KvK numbers (for example, by checking against EU VIES or the Dutch KvK register).
The legal basis for all of this would be Article 6(1)(c) GDPR — legal obligation.
5. What's public, what's private
Kitelost is part-marketplace, part-community, part-registry. Some things you do are deliberately visible to other users — but we always make this clear before you publish.
Always public (visible to anyone, including non-registered visitors):
- Your username
- Marketplace ads you create (including photos, price, and approximate location)
- Lost & stolen reports you choose to publish, including the approximate location of the loss
- Reviews you give and receive
- Your overall rating
- For shops and schools: business name and verified business badge
Visible only to logged-in users:
- Your profile page
- Your gear inventory (only the items you choose to show)
Visible only to specific users:
- Messages you send (visible only to the participants in that conversation — see note below on moderation)
- Transfer requests (visible only to sender and recipient)
Never public:
- Your password (we never see it either)
- Your home address or exact location
- Your private notes on gear
- Serial numbers of gear that hasn't been reported lost or stolen
Visible only if you switch it on (contact visibility settings):
- Your email address and phone number are private by default. In your profile settings you can choose to make them visible so that someone who finds your gear (or checks its serial number before buying it) can reach you directly. If you enable this, anyone who looks up the serial number of an item you registered can see the contact details you chose to share. You can switch this off again at any time.
- Shops and schools that fill in business contact details (phone, address, VAT/chamber-of-commerce number) show them on their public business profile — that's the point of a business profile.
A note on serial numbers: when gear is reported lost or stolen, the serial number becomes searchable on the Platform so the community can flag it if it shows up for sale. This is the entire point of the lost & found network. By using Kitelost, you understand and accept this.
A note on searching serial numbers: if you look up or try to register a serial number that belongs to gear with an open lost or stolen report, we alert the owner that their item was searched. That alert contains the date and time, how the lookup happened, and an approximate location derived from your IP address (city/region level). We never share your IP address itself, and if you're not logged in the alert contains nothing else about you.
6. Moderation and access to private content
We take the privacy of your messages and other private content seriously. We don't read messages for fun, we don't scan them to train algorithms, and we don't use them for advertising.
But there are limited situations where a Kitelost team member may need to look at private content — including messages, transfer details, or reported gear:
- When you or another user reports abuse, fraud, or a policy violation — for example, a spam report, a harassment complaint, a suspected scam, or a report that someone is trying to sell stolen gear. We may review the relevant messages or content to assess what happened and decide on action.
- When we detect suspicious activity automatically — such as patterns that look like spam, scams, or attempts to take transactions off-platform — and a human review is needed to confirm.
- When required by law — for example, in response to a valid request from law enforcement or a court order.
- When essential to fix a technical problem — for example, debugging a delivery failure or recovering data after an incident. In these cases, we look at the minimum needed and only with the right access controls in place.
When we do review private content, we:
- Limit access to the specific conversation or item under review — not your full history
- Limit access to authorized team members only
- Keep a record of who accessed what and why
- Use the information solely to handle the report or issue at hand
When you submit a report (bug report, user report, or ad report), the contents of that report — including any details you provide and the reported content — are forwarded to our internal handling tools (currently Notion, and in the future possibly Slack for operational alerts) so we can triage and act on them. See Section 7.2 for details on these processors.
The legal basis for this is our legitimate interest in keeping the Platform safe, honest, and free of abuse — and in some cases a legal obligation (for example, when responding to law enforcement). If you'd like more detail on the balancing test we apply, email us.
If we take action on a report (warning, suspension, account closure), we'll generally explain why — unless doing so would compromise an investigation or another user's safety.
7. Who we share your data with
We don't sell your data. Ever.
We share data only with the parties below, and only as far as needed to run the Platform.
7.1 Other Kitelost users
When you publish ads, reports, reviews, or send messages, the relevant data is shared with the users you're interacting with — as described in Section 5.
7.2 Service providers ("data processors")
We use trusted third-party services to run the Platform. They process your data on our behalf, under data processing agreements, and only for the purposes we've agreed with them.
| Provider | What it does | Where it processes data |
|---|---|---|
| Xano | Backend / database / API | EU (Frankfurt, Germany) |
| Cloudflare | Website hosting, image hosting and CDN | Global (with EU SCCs) |
| Google (Maps & Geocoding) | Converting addresses/postcodes to map coordinates | Global (with EU SCCs) |
| Google Analytics | Website usage analytics (only with your consent) | Global (with EU SCCs) |
| OCR.space | Reading serial numbers from photos you upload | EU |
| Loops.so | Sending transactional and marketing emails | USA (with EU SCCs) |
| Notion | Internal handling of bug reports, user reports, and ad reports | USA (with EU SCCs) |
| Slack (when active) | Internal operational alerts (e.g. new reports, account events) | USA (with EU SCCs) |
| Stripe (when active) | Payment processing for shop subscriptions and per-transfer fees | Global (with EU SCCs) |
For transfers outside the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) to make sure your data stays protected.
7.3 Authorities and legal requests
We may share data with police, regulators, or courts if we're legally required to — for example, in connection with a stolen-gear investigation or a tax audit. We push back on overly broad requests and only share the minimum needed.
Future routine reporting to the Dutch Tax Administration (Belastingdienst). If and when DAC7 becomes applicable to Kitelost, we will be required to make annual reports to the Belastingdienst about reportable sellers on the Platform. This is not happening today. See Section 4.1 for details.
7.4 Business transfers
If Kitelost is ever sold or merged into another company, your data may be part of that transfer. We'll let you know in advance if this happens, and the new owner will be bound by this Policy or a similar one.
8. How long we keep your data
We don't keep data longer than we need to. Roughly:
- Account data: as long as your account is active. After deletion, most data is removed within 30 days.
- Gear records and transfers: kept after deletion as anonymized records, because the gear's history matters to future owners and to the lost & found network.
- Lost & stolen reports: kept indefinitely (this is the whole point) but unlinked from your personal account if you delete it.
- Messages: kept for as long as both participants have an account, then deleted.
- Reviews: kept after deletion, but shown as "Deleted user" — because removing reviews would let people erase negative feedback.
- Financial records (invoices, payments): kept for 7 years, as required by Dutch tax law.
- DAC7 data (when applicable in future): when DAC7 reporting applies to us, the data covered by it must be kept for 7 years from the end of the reporting year, as required by Dutch tax law. This applies even if you delete your account.
- Server logs and security data: 30–90 days.
- Analytics data: anonymized and aggregated; retained per Google Analytics defaults.
If you'd like a more specific answer for your data, email us at privacy@kitelost.com.
9. Your rights
Under GDPR, you have the following rights over your personal data:
- Right to access — get a copy of the data we hold about you
- Right to rectification — correct data that's wrong or incomplete
- Right to erasure — ask us to delete your account and personal data
- Right to restriction — ask us to limit how we use your data
- Right to data portability — get your data in a portable, machine-readable format
- Right to object — object to processing based on legitimate interest, or to direct marketing (always)
- Right to withdraw consent — where we rely on your consent, you can withdraw it at any time
- Right not to be subject to automated decision-making — we don't make legal or significant decisions about you automatically
To exercise any of these, email privacy@kitelost.com. We'll respond within 30 days. We may need to verify your identity first.
Limits on these rights. Some of your rights are limited where we have a legal obligation to keep data — for example, financial records under Dutch tax law (7 years). When DAC7 becomes applicable to Kitelost, the same will apply to DAC7-reported data. We'll always tell you when this applies and explain why.
If you think we're handling your data wrongly and we can't resolve it together, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
10. Security
We protect your data with:
- HTTPS encryption for everything in transit
- Hashed passwords (we never store or see them in plain text)
- Access controls so only authorized systems can read your data
- Regular backups
- Security monitoring on our backend
No system is perfectly secure, so we also ask you to help: use a strong, unique password, don't share your login, and let us know immediately if you suspect anything's wrong.
If we ever discover a data breach that could affect you, we'll notify you and the Dutch DPA within 72 hours, as required by law.
11. Children
Kitelost is not intended for users under 16. We don't knowingly collect data from anyone under 16. If you believe a child has created an account, email us and we'll delete it.
12. Cookies
We use cookies and similar technologies for three things:
- Strictly necessary cookies — to keep you logged in, remember your preferences, and run the site. These can't be turned off.
- Analytics cookies — Google Analytics, only with your consent. Used to understand how the site is used so we can improve it.
- Functional cookies — to remember things like your language preference.
We don't currently use advertising cookies or social tracking pixels.
You can manage your cookie preferences through the cookie banner shown when you first visit, or at any time via the cookie settings link in our footer.
A more detailed cookie list is available in our Cookie Policy (coming soon).
13. Marketing emails
When you sign up, we may send you a short series of onboarding emails to help you get started. These are sent through Loops.so and are tailored to your account type (private, shop, or school).
You can unsubscribe at any time using the link in any email, or by emailing privacy@kitelost.com. Unsubscribing from marketing emails won't stop transactional emails (verification, password reset, transfer notifications) — those are necessary to use the Platform.
14. Changes to this Policy
We may update this Policy from time to time — for example, when we add new features or use new service providers. The "Last updated" date at the top will always tell you when.
If we make a material change, we'll let you know by email or through a notice on the Platform before it takes effect.
15. Questions?
For any privacy question, large or small:
We read everything and aim to reply within a few working days.
Kitelost is currently in beta. We're a small team and we genuinely care about getting this right. If anything in this Policy is unclear or feels off, tell us — we'd rather hear it.