Privacy Policy

    Last updated: 23 February 2026

    1. Who We Are

    Daily Diet Online ("we", "us", "our") operates the website dailydiet.online. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

    For enquiries, contact us at: dailydietonline@gmail.com

    2. Information We Collect

    Personal Data You Provide

    • Name and email address (when creating an account or subscribing)
    • Payment information (processed securely via third-party payment processors)
    • Health and dietary preferences (entered into the Health Planner)
    • Any other information you voluntarily submit

    Automatically Collected Data

    • IP address, browser type, operating system
    • Pages visited, time spent, referring URL
    • Cookies and similar tracking technologies (see Section 5)

    3. How We Use Your Information

    • To provide, maintain, and improve our services
    • To personalise your experience (meal plans, coaching, recipes)
    • To process transactions and send related correspondence
    • To send marketing communications (with your consent)
    • To analyse usage and improve our website
    • To comply with legal obligations

    4. Legal Basis for Processing (GDPR — UK & EU)

    We process your personal data on the following legal bases:

    • Consent: When you opt in to marketing emails or accept cookies
    • Contractual necessity: To deliver the services you've signed up for
    • Legitimate interest: To improve our services and prevent fraud
    • Legal obligation: To comply with applicable laws

    5. Cookies & Tracking

    We use cookies and similar technologies. When you first visit our site, a cookie consent banner allows you to accept or decline non-essential cookies.

    Types of Cookies

    • Essential cookies: Required for the website to function (authentication, security)
    • Analytics cookies: Help us understand how visitors use our site (e.g., Google Analytics)
    • Advertising cookies: Used to deliver relevant ads and measure campaign performance (e.g., Google Ads, Meta Pixel)

    You can manage cookie preferences through your browser settings or our consent banner.

    6. Third-Party Services

    We may share data with trusted third parties who assist in operating our website and services:

    • Payment processors (for secure transaction handling)
    • Analytics providers (Google Analytics)
    • Advertising platforms (Google Ads, Meta/Facebook Ads)
    • Email service providers
    • Cloud hosting and infrastructure providers

    These parties are contractually obligated to protect your data and use it only for specified purposes.

    7. Your Rights

    UK & EU Residents (GDPR / UK GDPR)

    • Right to access your personal data
    • Right to rectification of inaccurate data
    • Right to erasure ("right to be forgotten")
    • Right to restrict or object to processing
    • Right to data portability
    • Right to withdraw consent at any time

    California Residents (CCPA)

    • Right to know what personal information is collected
    • Right to delete personal information
    • Right to opt out of the sale of personal information
    • Right to non-discrimination for exercising your rights

    To exercise any of these rights, email dailydietonline@gmail.com.

    8. Data Retention

    We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, or as required by law. Account data is deleted within 30 days of account deletion request.

    9. Biometric & Health Data Protection

    🔒 Our Biometric Data Promise

    We understand that health and biometric data — including weight, body measurements, mood logs, step counts, exercise data, and dietary information — is deeply personal. We hold this data to the highest standard of care.

    • We will NEVER sell your biometric or health data to third parties, advertisers, data brokers, insurance companies, or any other entity — under any circumstances.
    • We will NEVER share identifiable health data with third parties for their own marketing or profiling purposes.
    • Your data is yours. You can export or permanently delete all your health data at any time by contacting us.
    • Encryption at rest and in transit. All biometric and health data is encrypted using industry-standard AES-256 encryption at rest and TLS 1.3 in transit.
    • Minimal access. Only essential systems access your health data to deliver your personalised plans. No human reviews your individual data unless you request support.
    • smart processing is privacy-first. When our platform analyses your mood, behavioural patterns, or nutrition, the processing is used solely to improve your personal experience — never to build advertising profiles.

    Compliance Standards We Follow

    While Daily Diet Online is a wellness platform (not a covered healthcare entity under HIPAA), we voluntarily adopt security practices aligned with recognised standards:

    • HIPAA-aligned safeguards: We implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including access controls, audit logging, and encryption.
    • SOC 2 principles: Our infrastructure follows SOC 2 Trust Service Criteria for security, availability, and confidentiality. Our cloud provider maintains active SOC 2 Type II certification.
    • GDPR & UK GDPR: Full compliance with data subject rights, lawful processing, and data minimisation.
    • CCPA / CPRA: California residents' right to know, delete, and opt out is fully honoured. We do not sell personal information.
    • Illinois BIPA alignment: We do not collect biometric identifiers (fingerprints, facial geometry). The health metrics you voluntarily log are protected under our no-sell guarantee above.

    10. Data Security

    We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3), encryption at rest (AES-256), secure authentication with row-level security policies, and strict access controls. Regular security reviews are conducted to identify and address potential vulnerabilities.

    11. International Transfers

    Your data may be processed in countries outside your country of residence. Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses).

    12. Children's Privacy

    Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

    14. Contact Us

    If you have any questions about this Privacy Policy, please contact us: