This policy describes how NutriHive handles personal data for the current product.
Effective date: 9 September 2026
Last updated: 11 September 2026
Product: NutriHive (https://nutri-hive.com)
This Privacy Policy explains how NutriHive collects, uses, stores, and shares information when you use our websites, dashboard, admin tools, and related services (together, the “Service”).
Operator: Yaacoub Azzam, Chiyah 212. Privacy contact: privacy@nutri-hive.com.
NutriHive is a practice tool for nutrition professionals. It is not a consumer meal-tracking app.
Two different relationships apply:
If you are a client of a nutritionist who uses NutriHive, this policy still helps you understand what the platform can hold. Your rights requests about your health record should usually go first to that practitioner. You may also contact us, and we will direct the request as the law requires.
When you register or complete onboarding, we store:
Registration can be turned off by an administrator. Google sign-in can also be disabled independently.
Practitioners create and manage client files. Those files can include:
This is health and nutrition information. Under GDPR it is a special category of personal data. Under some US rules it may be treated as health information. We process it only because you put it in the Service to run your practice.
There is no photo or file upload in the current product. Plan PDFs are generated in your browser for download; we do not run a separate document-storage service for those files.
Paid access is billed through Paddle, which acts as merchant of record. Paddle collects payment details (such as card or other payment method, billing address, and tax information) on its checkout.
We store:
We do not store full card numbers.
To keep you signed in and protect accounts, we process:
refreshToken cookie (7 days)We do not currently run product analytics, advertising pixels, session replay, or third-party marketing cookies.
Your browser still sends standard technical data with every request (such as IP address, browser type, and the x-locale language header). Application logs may include request paths and error messages. We do not operate a separate marketing profile from this.
On this device only, the dashboard stores:
en, fr, or ar)These preferences are not used to identify you across other websites.
We send transactional email only:
We do not currently send marketing newsletters.
A shared food catalog can include USDA FoodData Central foundation foods (name and nutrition per 100g, keyed by FDC ID). That catalog is public nutrition data, not your clients’ personal data. Practitioner-created foods are stored on your account.
We use information to:
We do not sell personal information. We do not use client health records for advertising. We do not train public AI models on your client files.
If we ever want to use data for a new purpose that is not compatible with the above, we will update this policy and, where required, ask for consent.
For EU/UK GDPR-style processing, our intended bases are:
| Purpose | Typical basis |
|---|---|
| Running your NutriHive account and paid subscription | Contract (Art. 6(1)(b)) |
| Security, fraud prevention, rate limiting | Legitimate interests (Art. 6(1)(f)) |
| Tax, accounting, and legal requests | Legal obligation (Art. 6(1)(c)) |
| Optional Google sign-in | Consent / contract, depending on how you choose to sign in |
| Client health, allergy, and body-metric records | We process this as your processor. You must have a lawful basis before you enter it — often explicit consent, or another Art. 9 condition that applies to your practice (for example provision of health care, where allowed). |
You are responsible for telling your clients how you use NutriHive and for collecting any consent your profession and local law require.
We share data only as needed to run the Service:
| Recipient | Why | What they receive |
|---|---|---|
| Paddle | Checkout, subscriptions, invoices, tax | Name/email as needed for billing; Paddle collects payment details itself |
| Optional sign-in | Google sees that you authenticated to NutriHive; we receive ID, email, name | |
| Email delivery (SMTP) | Verification, password reset, welcome mail | Recipient email, name, and message content |
| Hosting and infrastructure | Store and run the app | PostgreSQL (app data), Redis (token blocklist and settings cache), RabbitMQ (outbound email queue), application servers |
| Administrators of NutriHive | Support and abuse handling | Account profile fields (not a substitute for your clinical records workflow) |
| Authorities | Only if required by law | Information specified in a lawful request |
USDA FoodData Central is used as a source of public food nutrition data. We do not send your client identities to USDA.
Staff and subprocessors who see personal data are expected to access it only to operate the Service.
We host the application on a virtual private server. We do not publish a specific data-center country. Paddle, Google, and our SMTP provider may process data in the United States, the EEA, or other countries.
By using the Service you understand that personal data may leave your country. Where GDPR or UK GDPR applies to a transfer, we rely on each vendor’s published transfer tools (for example an adequacy decision or Standard Contractual Clauses) as described in that vendor’s privacy policy.
| Data | Current retention |
|---|---|
| Practitioner account and clinic profile | While the account exists. You can permanently delete your account and related data from Settings. Admins can also deactivate an account (blocks login without erasing data). |
| Client files | While you keep them. Archiving hides a client from the active list; it does not erase the record. You can delete individual appointments, body stats, goals, plans, meals, foods, and memberships in the app. |
| Refresh tokens | 7 days, or until logout / admin deactivation |
| Access tokens | About 15 minutes; revoked IDs stay in Redis until expiry |
| Email verification codes | 10 minutes |
| Password-reset tokens | Until used or expired |
| Paddle customer/subscription records | For as long as needed to provide billing and meet tax/accounting rules |
| Webhook event IDs | Stored to prevent duplicate processing |
| Security and application logs | Until ordinary log rotation, or longer if needed to investigate security or abuse |
If you delete your account from Settings, or ask us to delete it, we will erase or anonymize personal data we control unless we must keep it (for example billing records required by tax law, or data needed to resolve a dispute). Client records we hold as your processor are deleted or returned according to your instructions and applicable law.
Depending on where you live (including GDPR, UK GDPR, and CCPA/CPRA), you may have rights to:
How to exercise rights
We will not deny the Service or charge a different price solely because you exercised a privacy right, except as the law allows.
We have not appointed a Data Protection Officer. Privacy requests go to the contact email in section 17.
You can also lodge a complaint with a data protection authority. If you are in the EEA, that is usually the authority in your country (list of EEA DPAs). In the UK: ICO. In Israel: the Privacy Protection Authority.
| Name / storage | Type | Purpose | Duration |
|---|---|---|---|
refreshToken cookie |
Essential | Keep you signed in; HTTP-only, SameSite=Lax, Secure in production |
7 days |
| Access token in local storage | Essential | Authenticate API requests | Until logout or expiry |
locale in local storage |
Preference | Remember language | Until you change it or clear site data |
| Sidebar collapsed flag | Preference | Remember layout | Until you change it or clear site data |
These are needed for the Service to work or to remember display choices. We do not currently set analytics or advertising cookies, so there is no cookie banner for optional trackers. If we add non-essential tracking later, we will ask for consent where the law requires it.
You can delete cookies and local storage in your browser. Clearing the refresh cookie and access token will sign you out.
We take reasonable technical and organizational measures, including:
Secure, HTTP-only)No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify you and regulators as the law requires.
NutriHive accounts are for adult professionals. We do not knowingly offer practitioner accounts to children under 16 (or under 13 where COPPA applies).
Client records may include minors if a practitioner enters a date of birth for a child. There is no age gate on client date of birth in the current product. If you store information about children:
If you believe we have a practitioner account for a child, contact us and we will delete or disable it.
The product does not currently warn you when a client date of birth is under 18. You remain responsible for that check and for any parental or guardian consent the law requires.
If you are a nutrition professional using NutriHive:
Google, Paddle, and any site we link to have their own privacy policies. We are not responsible for their independent practices. Read:
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use sensitive client health data to train advertising models.
If we make material changes, we will update the “Last updated” date and post the new policy at /privacy. Where the law requires it, we will also notify you by email or in-app notice. Continued use after the effective date means you accept the updated policy, except where consent is required.
Privacy requests: privacy@nutri-hive.com
Postal address: Yaacoub Azzam, Chiyah 212
Service: NutriHive, https://nutri-hive.com
We have not appointed a Data Protection Officer. Use the email above.
NutriHive is operated by Yaacoub Azzam from Chiyah 212 (Lebanon). Lebanese law typically governs this policy, without limiting any non-waivable rights you have in your place of residence (including GDPR rights for people in the EEA/UK).