Summary: TakeFirst does not sell personal data, does not show third-party advertising, and does not use personal data for cross-app tracking. Location and notifications are optional. Payments are processed by Stripe; TakeFirst does not receive or store full card numbers or card security codes.
1. Who controls your data
The data controller for the TakeFirst mobile application, website, marketplace, and related customer services is:
- Legal entity
- Take first, MB
- Company code
- 308075748
- Registered address
- Trakų g. 20, LT-76288 Šiauliai, Lithuania
- Privacy contact
- info@takefirst.lt
In this policy, “TakeFirst”, “we”, “us”, and “our” refer to Take first, MB. Sellers offering surprise baskets through TakeFirst are separately responsible for any personal data they independently process for food preparation, collection, legal compliance, or customer service.
2. Scope
This policy applies when you browse or use the TakeFirst mobile application for iOS and Android, visit takefirst.lt, create or manage an account, reserve or buy a surprise basket, receive notifications, contact support, or otherwise interact with TakeFirst as a buyer.
Seller and administrator data may also be processed to operate the marketplace, but business users may receive additional notices relevant to their relationship with TakeFirst.
3. Personal data we process
Account and contact data
- First and last name, email address, telephone number, preferred language, account identifier, account status, and email-verification status.
- A securely hashed form of your password. We do not store your plain-text password.
- The date and version of the Terms you accepted.
Orders, reservations, and payments
- Selected basket and seller, quantity, price, currency, pickup branch and window, reservation and order status, pickup code, purchase history, and refund or support status.
- Stripe transaction identifiers and limited payment-method metadata such as payment type, card brand, last four digits, and expiry month/year where available.
- Full card details and card security codes are entered into Stripe-controlled payment interfaces and are not stored by TakeFirst.
Location data
- If you grant location permission, the app uses your device’s foreground location to show nearby offers, distances, and your position on the map.
- If you choose location-based offer notifications, your most recently supplied latitude, longitude, and update time may be associated with your account to determine whether an offer is nearby.
- You can instead select a city manually. Location permission is not required to browse TakeFirst.
Notifications and device data
- If you enable notifications, we process an Expo push token, device platform, app version, environment, installation identifier, and token activity date.
- We maintain an in-app notification inbox, including notification content, related basket or order, sent date, and read status.
Security, technical, and support data
- Session and verification identifiers, login-attempt data, IP address and request/security logs where generated by our systems, and information necessary to prevent fraud, abuse, or technical failures.
- Your messages, attachments, order references, and contact details when you request support or exercise a privacy right.
- If you choose card scanning, camera access is used for that action through the payment interface; TakeFirst does not store photographs from the card scan.
The TakeFirst app currently contains no advertising SDK and does not use personal data for third-party advertising or cross-app tracking.
4. Why we process data and our legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create and secure your account; verify email; provide login and password reset | Account, contact, session, and security data | Performance of a contract and steps requested before entering a contract; legitimate interests in account security |
| Display offers, calculate distance, and provide maps or directions | Selected city and, if enabled, foreground location | Your device permission/consent; performance of requested app functionality |
| Reserve, charge for, fulfil, support, and record orders | Account, order, pickup, payment metadata, and seller information | Performance of a contract; compliance with accounting, tax, and consumer-law obligations |
| Send optional offer and transactional notifications | Push token, notification location, order and notification data | Your consent for optional notifications; performance of a contract for essential order communications where applicable |
| Answer questions, investigate complaints, prevent fraud, and defend legal claims | Support, transaction, security, and technical data | Legitimate interests in operating and protecting the service and users; legal obligations |
| Maintain, troubleshoot, and improve reliability without advertising profiling | Limited technical and error information | Legitimate interests in providing a secure and reliable service |
Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations. Where processing is based on consent, you can withdraw consent at any time without affecting processing that occurred before withdrawal.
6. International data transfers
Some service providers may process data outside Lithuania or the European Economic Area. Where a destination is not recognised by the European Commission as providing adequate protection, we use an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required. You may contact us for more information about safeguards relevant to your data.
7. How long we retain data
We keep personal data only for as long as needed for the purpose collected and for applicable legal, accounting, tax, fraud-prevention, dispute, and security requirements. The main criteria are:
- Account profile: while your account is active. When you delete the account in the app, the account is disabled, direct profile identifiers are anonymised, active sessions are revoked, and historical order snapshots are anonymised.
- Orders and payment records: for the statutory accounting/tax period and as needed for refunds, chargebacks, consumer claims, fraud prevention, and legal claims. Records retained after account deletion are minimised or anonymised where possible.
- Reservations: for the operational period and a limited period needed to resolve payment, inventory, security, and support issues.
- Push tokens and notification location: notification delivery and location-based selection stop when the account is deleted or the feature is disabled. Token records may remain until the token is removed, becomes invalid, or is removed through operational cleanup, but deleted accounts are excluded from notification delivery.
- Authentication and security data: until the relevant token/session expires or is revoked, plus a limited period required to investigate abuse or protect the service.
- Support correspondence: for as long as needed to resolve the request and retain evidence of its handling.
- Backups: until overwritten under our protected backup-rotation cycle.
Some auxiliary records, such as saved card-display metadata, prior notification records, or security references, may temporarily remain linked only to a pseudonymous internal identifier after profile anonymisation. They are no longer available through or used to contact a deleted account and are removed when their operational or legal retention purpose ends. Deletion may otherwise be delayed where retention is legally required or necessary for a legal claim; in those cases, the data is restricted to that purpose.
8. Your controls and choices
- Location: deny or revoke location access in iOS Settings or Android Settings (Settings > Apps > TakeFirst > Permissions > Location) and choose a city manually in TakeFirst.
- Notifications: disable notifications in the TakeFirst settings and/or in iOS Settings or Android Settings (Settings > Apps > TakeFirst > Notifications). Location-based notifications can be disabled independently by removing the notification location.
- Account details: review or update your name, email, phone number, and preferences in Profile > Settings.
- Saved payment metadata: remove a saved payment method from the Payments settings where available.
- Account deletion: open Profile > Settings > Account > Delete account and confirm. You may also contact info@takefirst.lt.
9. Your data-protection rights
Subject to the GDPR and applicable limitations, you may request access to your personal data, correction, deletion, restriction, portability, or objection to processing based on legitimate interests. You may withdraw consent at any time. You also have the right not to be subject to a solely automated decision that produces legal or similarly significant effects; TakeFirst does not currently make such decisions about buyers.
Email info@takefirst.lt with the subject “Privacy rights request”. We may ask for information reasonably necessary to verify your identity and protect your account. We normally respond within one month, subject to lawful extensions for complex or numerous requests.
10. Security
We use technical and organisational safeguards designed for the sensitivity of the data, including encrypted network connections, hashed passwords, access controls, protected credentials, least-privilege practices, logging, and service monitoring. No service can guarantee absolute security. Please use a unique password and contact us promptly if you suspect unauthorised access.
11. Children
TakeFirst is not directed to children under 16, and we do not knowingly create buyer accounts for them. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.
12. Changes, contact, and complaints
We may update this policy when our service, providers, or legal obligations change. We will publish the new version here, update the date above, and provide additional notice where a change materially affects your rights or requires consent.
For questions or rights requests, contact Take first, MB at info@takefirst.lt or by post at Trakų g. 20, LT-76288 Šiauliai, Lithuania.
You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate, L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania, or through vdai.lrv.lt. You may complain to another competent supervisory authority where the GDPR permits.
