This Privacy Notice explains how we process personal data in connection with the Nutrido Affiliate portal at affiliate.nutrido.io and the referral links on go.nutrido.io. It gives the information required by Articles 13 and 14 of the General Data Protection Regulation (GDPR). It covers data you give us and data we receive from other sources.
In short:
- We are VIACHESLAV NIGMATULLIN, a sole trader in Poland (section 1).
- We process account, application and payout data of affiliates, click data of people who open referral links, and install and purchase data of Nutrido app users (section 3).
- We use it to run the Portal and the Affiliate Program, pay commissions, meet our tax duties and keep the service secure. We do not sell your data or use it for advertising (sections 3 and 6).
- We keep most account data until you close your account. Financial, acceptance and purchase records are kept longer (section 8).
- You can access, correct and ask us to delete your data, and you can object to processing based on our legitimate interests (section 9).
1. Who we are
The controller of your personal data is VIACHESLAV NIGMATULLIN, a sole trader registered in Poland.
- Address: ul. Jana Heweliusza, 11/811, 80-890 Gdańsk, Poland.
- NIP: 5833485219
- REGON: 526020120
- Email: hello@nutrido.io
We have not appointed a data protection officer. For any question about your data, email us at the address above.
2. Whose data this notice covers
- Visitors to affiliate.nutrido.io who are not signed in.
- Account holders: people who register, applicants to the Nutrido Affiliate Program and approved affiliates.
- Link visitors: people who open a referral link on go.nutrido.io.
- Nutrido app users: people whose app install is matched to a referral link, and people who make purchases in the Nutrido app. Our purchase-data provider sends us a record of every purchase in the app, so that we can find the purchases that came from referrals.
What the Nutrido app itself does on your device is covered by its own privacy policy at https://nutrido.io/privacy. Accounts of our own staff are not covered by this notice.
3. What we process, why, and on what legal basis
We rely on these legal bases:
- Contract (Art. 6(1)(b) GDPR): to provide the service you asked for, or to take steps you requested before a contract.
- Legal obligation (Art. 6(1)(c) GDPR): Polish tax law, in particular the Tax Ordinance and the income tax and VAT acts, which require us to document payments and keep tax records.
- Legitimate interests (Art. 6(1)(f) GDPR). Our legitimate interests are:
- keeping the Portal and accounts secure;
- preventing fraud and click abuse;
- attributing referrals to the right affiliate and calculating commissions correctly;
- reporting the Nutrido app's revenue and reconciling commissions against all store purchases;
- proving that terms were accepted, and establishing, exercising or defending legal claims.
We do not use consent as a legal basis for any processing in this notice.
Hashes. We store some data only as a hash. A hash is a code calculated from a value, such as an IP address. The same value always gives the same code, but the code cannot be turned back into the value. A keyed hash is also calculated with a secret key, so only we can calculate it and check whether two values match.
3.1 Visitors to affiliate.nutrido.io
| Data | Purpose | Legal basis | Source |
|---|---|---|---|
| IP address and request details (such as page, time and browser information) | Delivering pages over an encrypted connection, and blocking attacks and malicious bots at the network edge | Legitimate interests (security) | Your browser |
| Cookies and similar storage | Sessions, form protection, your language and display settings, and security. See our Cookie Notice | Contract; legitimate interests (security) | Your browser |
| Rate-limit counters for sign-in, registration, password reset and data downloads | Stopping password guessing and abuse | Legitimate interests (security) | Your request |
| Hosting platform logs (time, requested address and response status; they may include your IP address and browser details) | Operating, troubleshooting and securing the service | Legitimate interests (operating the service securely) | Your request |
Most rate-limit counters are stored under a SHA-256 hash of your email address and IP address, or of your IP address alone. After a failed sign-in, the sign-in software also keeps a counter under your email address and IP address in plain form. Sign-in, registration and password-reset counters expire after about one minute. The counter for data downloads is linked to your account and expires after one hour.
3.2 Account holders (applicants and affiliates)
| Data | Purpose | Legal basis | Source |
|---|---|---|---|
| Name, email address, time of email verification, password (stored only as a hash), "Remember me" token, account roles | Creating and running your account, and signing you in | Contract | You |
| Version of our Terms of Use that you accepted and the time you accepted it | Recording the contract for the Portal | Contract; legitimate interests (proof of acceptance) | You |
| Two-factor secret and recovery codes (encrypted), time two-factor was confirmed; passkeys (the name you give, credential ID, public key data, last use) | Securing your sign-in | Contract; legitimate interests (security) | You and your device |
| Affiliate profile: display name, country, preferred language, time zone, status, approval date | Running your participation and showing the Portal in your language | Contract | You, and our decisions |
| Application: promotional channels (platform, handle or URL, label, main channel), audience countries, categories and size, promotion methods and details; submission and review dates, the reason for a rejection and whether you may apply again; status history, reviewer and staff notes | Assessing your application and recording the decision | Contract (steps before a contract); legitimate interests (documenting decisions) | You and our staff |
| Acceptance of the Affiliate Program Terms: version, language, text fingerprint (hash), time, context, the commercial settings shown to you, a keyed hash of your IP address, your full browser user-agent string (up to 255 characters), request ID | Proving which version you accepted and when, and defending legal claims | Legitimate interests (proof and legal claims) | You and your browser |
| Payout recipient and tax details: recipient type, legal name, trading name, postal address, tax residence, country of business establishment, VAT status and country, VAT number, tax identification number | Paying commissions and meeting tax duties | Contract; legal obligation | You |
| Bank details: bank country, account holder, bank name, IBAN or account number, SWIFT/BIC, additional instructions, an optional bank-instructions document (PDF, PNG or JPG, up to 5 MB); review decisions and our requests for information | Paying commissions by bank transfer, and checking the details before paying | Contract | You and our staff |
| Commissions, ledger entries, payouts (amounts, dates, references, withholding, currency conversion), payout statements, receipts and invoices | Calculating and paying commissions, and keeping tax records | Contract; legal obligation | Our records, you, our finance staff |
| Documents and information you send us when we ask for them: proof of identity or of authority to act for a business, a certificate of tax residence, proof of account ownership, invoices or receipts you issue to us, links to or copies of your promotions, evidence about disputed referrals | Checking eligibility, payment and tax documents and compliance with the Program, and handling disputes | Contract; legal obligation (tax documents); legitimate interests (compliance and legal claims) | You |
| Referral links (the address of your main link is a short code made from your initials and random characters), campaign names, link aliases and channels, QR codes, statistics for your links | Providing the dashboard | Contract | You and our systems |
| Notifications in the Portal, and emails to your address (for example verification, password reset, application decisions, commissions, payout and payout-detail updates, tax or bank information requests, account suspension and terms updates), and whether each email was sent | Running your account and the Program | Contract | Our systems |
| Audit log: action, time, account, affected record, request ID, redacted details; for sign-in, sign-out, registration, data export, program-terms acceptance and application submission, also a keyed hash of your IP address | Security, investigating incidents and accountability | Legitimate interests (security, legal claims) | Our systems |
| Messages you send us, such as complaints or requests | Answering you and keeping a record | Contract; legal obligation; legitimate interests | You |
Please note:
- The browser user-agent string is the text your browser sends with each request. It usually shows your browser and operating system and their versions. In terms-acceptance records we store it as your browser sent it.
- The IP hashes in the audit log and in terms-acceptance records use a fixed secret key. This means the same IP address always gives the same hash. They do not store your IP address itself.
- Bank details, your legal name as payout recipient, tax identifiers and address lines are encrypted in our database. The countries, recipient type, trading name, VAT status and type of account identifier are stored unencrypted. The bank-instructions document is stored encrypted. Full bank details are shown to our finance staff only after they re-enter their password, and each such view is logged.
- An uploaded file first waits unencrypted in a private temporary folder in our EU file storage. It is deleted as soon as you save the form, or within about 25 hours if you do not.
- Do not send us identity documents unless we ask for them.
- If you give us data about another person, for example the bank account holder or a representative of your business, please tell them about this notice. We process their data for the same purposes and on the same legal bases as yours.
- We send only service emails. We do not send marketing emails.
3.3 People who open a referral link
When you open a referral link, we record one click with:
- a random click ID, the link, campaign, affiliate and product;
- the platform (iOS, Android, desktop or unknown), guessed from your browser's user-agent string;
- whether the click looks like it came from a person, a known bot or is suspected (see section 5);
- up to five
utm_parameters contained in the link, each shortened to 120 characters; - a language, taken from your browser's language settings (or English if none of our languages matches);
- the time, and an internal request ID;
- a keyed hash of your IP address. The key changes every day, so the same address gives a different hash on different days. We delete the hash after 30 days.
We do not record your IP address itself or your full user-agent string. We read the user-agent string only in memory, to detect the platform and known bots, and then discard it. We do not read the page you came from (the HTTP referrer). Referral links set no cookies of ours and create no session. Only Cloudflare's security cookie may appear (see our Cookie Notice).
Where you go next:
- iOS: we show you an invite page on go.nutrido.io. Where the invite page is not in use, we redirect you straight to the App Store instead and add no click data to that address. On the invite page:
- The button to get Nutrido on the App Store copies an invite link to your device's clipboard when you tap it, and then opens the App Store. Nothing is copied unless you tap this button. A second link on the page opens the App Store without copying anything.
- The invite link contains a signed click token of the same kind as on Android: the random click ID, an expiry time and a signature. It contains no information about you. The token follows the
#sign in the link, a part that browsers do not send to websites, so opening the invite link in a browser does not send the token to us. Opening it only shows the same invite page again and records no new click. We store only a SHA-256 hash of the token, and delete it when the token expires after 30 days. - The App Store address contains no click data.
- The invite link stays on your clipboard until you copy something else. Apps you paste into can see it, and Universal Clipboard may sync it to your other Apple devices.
- Android: we redirect you to Google Play. The address includes a signed click token containing the random click ID, an expiry time and a signature. It contains no information about you. We store only a SHA-256 hash of the token, and delete it when the token expires after 30 days.
- Desktop or unknown: we show a download page on go.nutrido.io with buttons for both stores.
When we redirect you straight to a store, the redirect is immediate, so we cannot show you this notice when you click. It is always available at affiliate.nutrido.io/privacy and is linked from the download page and the invite page.
Each IP address can open referral links up to 120 times a minute. The counter uses the IP hash and expires after about a minute.
Purpose: attributing app installs and purchases to the right affiliate, showing affiliates their click statistics and preventing click abuse. Legal basis: legitimate interests. Source: the request from your browser. We cannot identify you by name from these records.
3.4 Nutrido app users
Matching an install to a referral. After you install the Nutrido app from a referral link, the app may send us a claim. The claim includes a Firebase ID token for your Nutrido app account (a sign-in token issued by Google Firebase). The token contains your app account's user ID and, depending on how you sign in, other account details such as your email address. We read only the user ID and discard the rest. On Android, the app reads the referral information that Google Play kept for your install (the click token described in section 3.3) and sends it with the claim, together with the install and referrer times, the app version and your language. The claim may also include a device integrity token, which we do not store. On iPhone, the app looks at your clipboard only when you first open and set up the app after installing it, and it reads the clipboard at most once. iOS lets the app check whether the clipboard holds a web link without showing it the content. The app reads the clipboard only if it holds a link, and only when you allow this when iOS asks, or when you tap the paste button in the app yourself. Which of the two you see depends on your app version. If you do neither, nothing is read. The app keeps the content only if it is a go.nutrido.io invite link (section 3.3), and sends its click token with the claim, together with the app version. Anything else is discarded and not sent to us. We check the Firebase token with Google's public keys, which we download from Google. We send no data about you to Google.
When the app contacts us, the connection passes through Cloudflare (section 6). We use a keyed hash of your IP address, which expires after about a minute, to limit repeated requests.
We store:
- a keyed hash of your Firebase user ID, never the ID itself, with first-seen and last-seen times;
- an attribution record: affiliate, campaign, click, platform, method, eligibility status, time of original download (where available) and language;
- a record of each claim attempt, with its status and reason, and redacted technical evidence. For Android, this is the referrer and install times, the app version and whether an integrity token was provided. For iOS, it is the store environment, original purchase date and app version; for an iPhone invite link, it is the app version, the platform recorded for the click and the time between the click and the claim. Tokens themselves are never stored;
- records of attribution tokens issued for a click: a hash of each token, when it was issued and expires, and whether it was used.
Purchases. RevenueCat, Inc. (USA), which manages in-app purchases for the Nutrido app, sends us a notification for each purchase event, such as a purchase, renewal, cancellation or refund. The raw notification contains your app user ID and any other IDs linked to it, the store, country and environment, and any subscriber attributes that the Nutrido app sets with RevenueCat. Such attributes can include contact details, such as an email address, or device identifiers. We do not use that information.
We store the raw notification encrypted and blank it 90 days after we received it. Notifications that are still being processed at that point (including ones whose processing failed and is being retried), that could not be processed, or whose purchase we are still checking for a referral are kept until that is resolved and then blanked. We check a new purchase for a referral for up to 48 hours. Notifications about purchases that we cannot match to a referral (most purchases) are therefore also blanked after 90 days.
From each notification we keep:
- keyed hashes of your app user IDs;
- whether your app user ID was an anonymous ID assigned by RevenueCat, which means that the purchase was not linked to a Nutrido app account. We keep only this yes/no flag, not the ID, and use it to detect problems with matching purchases to referrals;
- the store transaction ID and original transaction ID, in plain text (numbers issued by Apple or Google for the purchase);
- the product, store, event type and dates;
- the price and currency, the USD value, the tax and store-fee percentages and any offer code;
- the country code of the purchase;
- the renewal number, refund status and reason for cancellation or expiry.
Purpose: matching purchases to referrals and detecting problems with that matching, checking whether an install from a referral link on Android, or through an iPhone invite link, comes from a new customer (section 5), calculating and correcting commissions (including after refunds), avoiding duplicate commissions, reporting the Nutrido app's revenue and reconciling commissions against all store purchases. Legal basis: legitimate interests (attribution, correct commissions, fraud prevention and revenue reporting); legal obligation where these records support commission payments that we must document. Sources: the Nutrido app, RevenueCat and Google Firebase.
The affiliate whose link you used sees, for their own links only: numbers of clicks and installs and, for each purchase attributed to them, the date, store, product, type of purchase (including the renewal number), amounts, tax and store-fee percentages, and a short customer reference. The reference is the last 6 characters of our internal customer number. It shows when several purchases came from the same person. Affiliates can download these details as a CSV file. They never see your name, email address, account, or app and store IDs.
4. Do you have to give us your data?
- Registration: your name, email address and a password are required to create an account. Without them we cannot create one.
- Application: the required fields are needed to assess your application. Without them we cannot consider it.
- Payout details: these are optional until you are approved. They are required to receive payouts, under our contract and under tax law. Without them we cannot pay you.
- Two-factor authentication and passkeys are optional for affiliates.
- Technical data, such as terms-acceptance evidence and security logs, is collected automatically when you use the Portal. It is needed to use it.
- Link visitors and app users do not give us data directly. Technical data is collected automatically when you open a referral link, or when the Nutrido app sends a claim or a purchase notification is sent to us.
5. Automated processing
Click classification. When a referral link is opened, our server compares the user-agent string with a list of known crawlers and bots. A click from a known bot is labelled "bot". A click without a user-agent string is labelled "suspected". After the click is recorded, a background job labels a click "suspected" if the same IP hash opened the same link more than 12 times within one minute.
The classification never blocks a redirect or the invite page. It has two effects:
- bot and suspected clicks are left out of the filtered click counts that affiliates see;
- an install on Android, or through an iPhone invite link, that is matched to a bot or suspected click is flagged "manual review" (see below).
Attribution and commissions. Matching installs and purchases to referral links, and calculating commissions under the Affiliate Program Terms, are automated. The matching step also sets an eligibility status automatically, and only eligible installs earn commission:
- Android installs. Google Play cannot prove that an install is the first one, so an automated new-customer check decides whether an install from a referral link can earn commission. The check compares a keyed hash of the app user's ID with our pseudonymised (hashed) customer and purchase records (section 3.4). If these records show no purchase or other activity by that customer before the click, the install is marked "eligible"; otherwise it is recorded for statistics only ("analytics only"). An install matched to a bot or suspected click is flagged "manual review" instead. For an eligible install, a purchase earns commission only if the purchase and its subscription both started after the click. Neither "analytics only" nor "manual review" earns commission.
- iPhone installs through an invite link. The App Store cannot prove to us either that such an install is the first one. The same automated new-customer check therefore decides whether it can earn commission, an install matched to a bot or suspected click is flagged "manual review", and a purchase earns commission only if the purchase and its subscription both started after the click. Until we start paying commission for iPhone referrals and announce it to affiliates, no such install earns commission: it is recorded for statistics only ("analytics only"), or flagged "manual review" if it is matched to a bot or suspected click. After that, an install whose app is first opened more than 24 hours after the click is also recorded for statistics only.
- Claims that fail our security checks are rejected.
Applications, reviews of payout details and payouts are decided or approved by people. Commissions reach you only in a payout batch that a person has approved.
Where these automated steps decide whether an affiliate earns a commission, they are necessary to perform our contract with the affiliate (Article 22(2)(a) GDPR). You can ask a person to review any calculation or status, give your view and contest it, using the contact details in section 1. We do not use your data for profiling for marketing or advertising.
6. Who receives your data
Service providers (processors):
- Laravel Cloud (Laravel Holdings Inc., USA): hosting of the application, the PostgreSQL database and the Valkey cache, sessions and queues, in the Frankfurt, Germany (EU) region. Its platform logs are kept for 1 day.
- Cloudflare, Inc. (USA), as part of Laravel Cloud:
- the network edge that all traffic passes through, for encryption (TLS), firewall and bot protection. It processes your IP address and request details and may set a security cookie;
- file storage (R2) in a private bucket with EU jurisdiction. It holds payout documents, bank-instruction files and temporary uploads.
- Hostinger (EU): sends all emails from the Portal.
- Our email provider for the mailbox at hello@nutrido.io: stores the messages you send us.
Other recipients:
- Have I Been Pwned: when you set a password, we send the first 5 characters of the SHA-1 hash of your password to its Pwned Passwords service. We check the answer for known breaches. Your password, the full hash and anything that identifies you are never sent.
- Google Play: if you open a referral link on Android, or choose Google Play on the download page, your browser goes to Google Play with the click token described in section 3.3. The App Store receives no click data from us. On the iPhone invite page, the click token is copied only to your device's clipboard, and we do not send it to Apple. Google and Apple process your visit under their own privacy policies.
- Banks: our bank, the recipient's bank and any intermediary or correspondent banks receive the recipient's name, bank details, amount and reference, to make payouts (see section 7).
- Accountants, tax advisers and lawyers, who are bound by confidentiality.
- Public authorities, such as tax authorities, courts and law enforcement, where the law requires it.
- Affiliates: statistics and purchase details with a short pseudonymous customer reference, for their own links only (section 3.4).
Within our organisation, access is based on roles. Affiliate managers see applications. Finance staff see payout and bank data. Staff must use two-factor authentication to access staff areas.
Sources, not recipients: RevenueCat sends us purchase data. We only download Google's public keys to check Firebase tokens. We send neither of them any data about you.
We do not sell your data or share it for advertising.
7. Transfers outside the European Economic Area
We host your data in the EU: the application, database and cache in Frankfurt, and files in EU storage. Laravel Holdings Inc. and Cloudflare, Inc. are US companies. They may access data from outside the European Economic Area (EEA) for support, maintenance or security. Cloudflare's network handles your connection at a data centre near you, which may be outside the EEA if you are.
For these transfers to the United States, we rely on the EU–US Data Privacy Framework where the provider is certified under it. The European Commission decided on 10 July 2023 that the Framework gives adequate protection. Where a provider is not certified, we rely on the standard contractual clauses approved by the European Commission, which are part of that provider's data processing terms.
Payouts. We pay commissions by bank transfer in US dollars. To make a transfer, the recipient's name, bank details, the amount and the reference go to our bank, the recipient's bank and any intermediary or correspondent banks. These banks can be outside the EEA: for US-dollar payments usually in the United States, and in the recipient's bank's country if it is outside the EEA. Where there is no adequacy decision for that country, the transfer is necessary to perform our contract with you (Article 49(1)(b) GDPR).
You can ask us for more information about these safeguards at hello@nutrido.io.
8. How long we keep data
| Data | How long |
|---|---|
| Account, profile, two-factor and passkey data | While your account exists; replaced or deleted when you close it (see below) |
| Application free text (channels, other category, promotion details) and staff notes | Until you close your account |
| Payout recipient, tax and bank details, and bank-instruction files | Until you close your account, including if your application was rejected or never finished |
| Temporary upload files | Deleted when you save; abandoned files within about 25 hours |
| Notifications in the Portal | Until you close your account |
| Acceptance of our Terms of Use and of the Affiliate Program Terms, including the IP hash and user-agent string | While the agreement lasts and after account closure, as proof of acceptance while claims about the agreement can be raised (under Polish law generally up to 6 years, counted to the end of a calendar year). We do not yet delete these records automatically |
| Audit log | 1,095 days (3 years) |
| Payout statements, earnings statements, receipts and invoices | 3,650 days (10 years) from creation |
| Commissions, ledger, payouts, attributions, customer identity hashes and purchase records | As tax records for as long as tax law requires (generally until 5 years after the end of the year in which the tax was due), and while claims about commissions can be raised (generally up to 6 years, counted to the end of a calendar year). We do not yet delete these records automatically. After an affiliate closes their account, these records no longer show their name or email |
| Referral click records | As long as the attribution and commission records above, because clicks are the evidence for them. We do not yet delete click records automatically. The IP hash is deleted after 30 days |
| Click token hash (Android and iPhone invite links) | Deleted when the token expires, 30 days after the click |
| Raw purchase notifications | Encrypted. Blanked 90 days after receipt. Notifications that are still being processed at that point (including ones whose processing failed and is being retried), that could not be processed, or whose purchase we are still checking for a referral are kept until that is resolved and then blanked |
| Attribution token records | Deleted 90 days after the token expires |
| Attribution claim attempts | 400 days |
| Documents you send us on request | Invoices and receipts: as payout documents above. Other tax and payment documents: as tax records (generally until 5 years after the end of the year in which the tax was due). Everything else: until the check or dispute is closed, then while related claims can be raised |
| Messages, complaints and records of your requests | Until the matter is closed, then while related claims can be raised |
| Password reset links | 60 minutes |
| Sessions | 120 minutes after your last activity |
| "Remember me" sign-in | Up to 400 days, or until you sign out |
| Rate-limit counters | About 1 minute; 1 hour for data downloads |
| Failed background tasks | 14 days |
| Hosting platform logs | 1 day |
| Database backups | Point-in-time recovery for up to 30 days. Monthly encrypted copies, stored offline on storage we control, kept for at least 12 months; we have not yet set a maximum period |
We do not currently delete inactive accounts automatically. You can close your account at any time.
What happens when you close your account. Your name is replaced with "Deleted user" and your email with a placeholder address. Your password, "Remember me" token, two-factor data, passkeys, roles and notifications are removed. Your display name becomes "Closed affiliate", and your application's free text and staff notes are deleted. Campaign names are replaced. Your referral links stop working, but their addresses are kept so that they are never reused, including the address of your main link (a short code made from your initials and random characters). Your bank details, legal and trading names, address, tax identifiers and all countries are erased, and bank-instruction files are deleted. The recipient type, VAT status and our tax and bank review decisions stay with the payout records.
The following survive closure: commissions, ledger, payouts, attributions, clicks and purchase records; payout statements, receipts and invoices, which still show the name and details they were issued with, until their 10-year period ends; terms-acceptance evidence; the audit log for its 3-year period; status history; the structured parts of your application (such as audience countries, promotion methods, dates, the reason for a rejection and whether you may apply again); your referral link addresses; your payout recipient type, VAT status and review decisions; and your profile's country, language and time zone. Deleted data remains in backups until those backups are deleted.
9. Your rights
Your right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. This covers, for example, security and audit records, fraud and click-abuse checks, click and attribution records, purchase records and proof of acceptance. Email hello@nutrido.io and tell us which processing you object to and why. We will stop, unless we show compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims.
Your other rights
You also have the right to:
- access your data and get a copy;
- rectification of inaccurate data;
- erasure of your data;
- restriction of processing;
- data portability for data you gave us that we process under a contract.
Some rights have limits. For example, we cannot erase records we must keep under tax law, or records we need for legal claims.
How to exercise them:
- Download your data: go to Settings → Profile, choose "Download my data" (/settings/data-export) and confirm your password. This needs a verified email address. You get a JSON file with your main account data. Bank details and tax identifiers in it are masked. If you want a full copy of them, or of anything else, such as terms-acceptance evidence, email us and we will send it securely.
- Correct your data: change your name and email in Settings → Profile, or email us.
- Close your account: go to Settings → Profile, choose "Close account" and confirm your password (see section 8). This also needs a verified email address.
- Anything else, or if you cannot use the features above: email hello@nutrido.io, if possible from your account's email address.
We answer within one month. If a request is complex, we may extend this by up to two more months; we will tell you why within the first month. We may ask you to confirm your identity, for example by writing from your account's email address. Exercising your rights is free, unless a request is clearly unfounded or excessive.
Link visitors and app users. We store your app account IDs only as keyed hashes, and we do not store your IP address, so we cannot look you up by name or email. We do keep store transaction IDs in plain text, and raw purchase notifications in encrypted form, generally for 90 days (section 3.4). To use your rights, send us something that lets us find your records, for example your Nutrido app user ID or the transaction or order ID of a purchase. If you only opened a referral link, we usually cannot find your click, because we never store your IP address and we delete its hash after 30 days (Article 11 GDPR).
Complaints. You can complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl. You can also complain to the supervisory authority in the EU country where you live, where you work or where you believe the infringement took place.
10. How we protect your data
- All connections use encryption (HTTPS/TLS).
- Bank details, tax identifiers, address lines and two-factor secrets are encrypted in our database. Bank-instruction documents are encrypted before they are stored.
- Files are kept in private EU storage with no public links.
- In our database, IP addresses are stored only as keyed hashes. App users' Firebase and RevenueCat IDs are stored as keyed hashes, except inside the encrypted raw purchase notifications (section 3.4). Store transaction IDs are stored in plain text. Short-lived sign-in counters are described in section 3.1. Our application does not write raw IP addresses to its logs.
- Access is based on roles, and staff must use two-factor authentication to access staff areas. Viewing full bank details or downloading bank documents requires the password again and is logged.
- Security-relevant actions are recorded in an audit log.
- New passwords must be strong and are checked against known breaches.
11. Cookies
The Portal uses only cookies and browser storage that are strictly necessary or that remember your settings, such as for signing in, form protection, your language and your display settings. There are no analytics, advertising or social-media cookies. Our Cookie Notice lists every cookie and storage key. On go.nutrido.io, the iPhone invite page copies an invite link to your device's clipboard only when you tap its button (section 3.3 and section 3 of our Cookie Notice).
12. Children
The Portal is only for adults aged 18 or over. We do not knowingly create accounts for children. We cannot tell the age of people who open a referral link. The Nutrido app's own policy covers its users.
13. Changes to this notice
The effective date at the top of this page identifies this version. If we make material changes, we will tell account holders by email before the changes take effect.