Privacy Policy

PRIVACY POLICY

GDPR • UK GDPR • CASL • CCPA • CAN-SPAM Compliant

Last Updated: March 22, 2026

1. Who We Are

Gut Logic ("we," "us," or "our") is an educational platform dedicated to providing science-backed information about gut health and the microbiome. We are committed to protecting your privacy and being transparent about how we collect, use, and protect your personal information.

Contact Email: hello@gut-logic.com

Physical Location: Edmonton, AB, Canada

We will respond to all data protection inquiries within 30 days of receipt.

2. Information We Collect

We collect different types of information depending on how you interact with our website and services:

Information You Provide Directly

When you sign up for our newsletter, download resources, or contact us, we may collect:

  • Email address (required for newsletter signup)
  • Name (optional)
  • Any information you include in messages to us

Information Collected Automatically

When you visit our website, with your consent where required, we may automatically collect:

  • IP address (used to determine general geographic location)
  • Device information (browser type, operating system, device type)
  • Cookie identifiers and similar tracking technologies
  • Browsing behavior (pages visited, time on site, click patterns)
  • Referral source (how you found our website)
  • Email engagement data (opens and clicks, if you are a subscriber)

3. How We Use Your Information

We use your personal information for the following purposes:

  • Email Marketing & Communication: To send you newsletters, educational content, and occasional promotional emails about gut health topics you signed up to receive.
  • Content Delivery: To deliver lead magnets, guides, and other resources you have requested.
  • Website Analytics: To understand how visitors use our website, improve user experience, and optimize our content.
  • Advertising Optimization: To measure the effectiveness of our advertising campaigns and show you relevant content.
  • Purchase Event Processing: If you purchase a product through one of our affiliate links, we may process limited transaction data (your email address and transaction identifiers such as order ID, product name, and transaction date) to ensure you receive relevant post-purchase content and are no longer sent promotional emails for a product you already own. This processing occurs through our automation platform (Zapier) and email marketing platform (Kit) and is based on our legitimate interest in providing a relevant subscriber experience (GDPR Article 6(1)(f)). Transaction metadata used for this matching process is cleared from our email marketing platform within 7 days of processing. Your email address is the only personal data actively collected in this process; names are not collected unless you have voluntarily provided yours through our preference center or direct correspondence.
  • Compliance & Legal Obligations: To maintain records required by law and respond to legal requests.
  • Customer Support: To respond to your inquiries and provide assistance.

4. Legal Basis for Processing (GDPR)

For visitors from the European Union, United Kingdom, and other jurisdictions that require a legal basis for processing personal data, we rely on the following:

  • Consent (Article 6(1)(a)): For email marketing communications, cookie-based tracking (analytics and advertising pixels), and processing any special category data. You may withdraw consent at any time.
  • Legitimate Interest (Article 6(1)(f)): For basic website functionality, security, and server logging necessary to operate our website; and for purchase event processing to match affiliate purchases to subscriber records, ensuring relevant post-purchase content delivery and suppression of redundant promotional emails. Our legitimate interest is balanced against your rights and does not override your fundamental freedoms. For purchase event processing specifically, the impact on data subjects is minimal (email address only, no marketing sent to non-subscribers, temporary records deleted within 24 hours).
  • Contract (Article 6(1)(b)): To deliver resources and services you have specifically requested.
  • Legal Obligation (Article 6(1)(c)): To comply with applicable laws and regulations, including maintaining consent records.

5. Who We Share Your Information With

We share your personal information with the following categories of third parties, each of which has committed to data protection standards:

Email Marketing Platform: Kit (formerly ConvertKit), Inc.

Data shared: Email address, name (if provided), signup timestamp, IP address, consent records, email engagement metrics (opens, clicks), signup source tracking data

Purpose: Email marketing, automation, landing pages, and delivery of lead magnets

Location: Boise, Idaho, USA. Kit is certified under the EU-US Data Privacy Framework (DPF) and includes Standard Contractual Clauses (SCCs) and the International Data Transfer Agreement (IDTA) in its Data Processing Addendum (DPA).

Privacy Policy: https://kit.com/privacy

DPA: https://kit.com/dpa (incorporated into Kit's Privacy Policy)

Advertising Platform: Meta Platforms Ireland Ltd

Data shared: Cookie identifiers, browsing behavior, device information, conversion events

Purpose: Advertising optimization, retargeting, conversion measurement

Location: Ireland (EU) with transfers to USA

Privacy Policy: https://www.facebook.com/privacy/policy

Advertising Platform: Pinterest Europe Ltd

Data shared: Cookie identifiers, browsing behavior, device information, conversion events

Purpose: Advertising optimization, conversion tracking

Location: Ireland (EU) with transfers to USA

Privacy Policy: https://policy.pinterest.com/privacy-policy

Analytics: Google Ireland Ltd (Google Analytics 4)

Data shared: Anonymized/aggregated browsing data, page views, session information

Purpose: Website analytics, content performance measurement

Location: EU data storage enabled (data stored in Europe)

Privacy Policy: https://policies.google.com/privacy

Consent Management: Cybot A/S (Cookiebot)

Data shared: Hashed/anonymized IP address, consent choices, timestamps

Purpose: Cookie consent management, compliance audit trail

Location: Denmark (EU)

Privacy Policy: https://www.cookiebot.com/en/privacy-policy

Affiliate Platform: Digistore24 GmbH

Data shared: Transaction data for purchases made through our affiliate links

Purpose: Affiliate commission tracking and payment processing

Location: Germany (EU)

Note: Digistore24 acts as an independent data controller for purchase transactions

Privacy Policy: https://www.digistore24.com/info/privacy

Automation Platform: Zapier, Inc.

Data shared: Email address and transaction identifiers (order ID, product name, transaction date) for purchases made through our affiliate links. Email is the only personal data processed; transaction identifiers are operational metadata that cannot identify a natural person independently.

Purpose: Automated purchase event processing — connecting affiliate purchase data from Digistore24 to our email marketing platform (Kit) to ensure subscribers receive relevant post-purchase content and are not sent redundant promotional emails for products they already own.

Legal basis: Legitimate interest (Article 6(1)(f)) — improving subscriber experience by matching purchase events to subscriber records.

Data retention: Transaction data passes through Zapier in near-real-time. Zapier retains Zap Content (data transferred in and out of Zaps) for 7 days in logs, 29–69 days in the Zapier account, and up to 4 months in backups. Zap run metadata (Zap name, timestamps, and status — not personal data) is retained in Zapier's non-production analytics database for product improvement purposes. Transaction metadata stored in our email marketing platform for the manual review process is cleared within 7 days. Any subscriber records temporarily created during this process for individuals who are not existing subscribers are deleted within 24 hours without any marketing communication being sent.

Location: San Francisco, California, USA. Zapier maintains SOC 2 Type II certification, is certified under the EU-US Data Privacy Framework (DPF), and includes Standard Contractual Clauses (SCCs) in its Data Processing Addendum (DPA). We have submitted an opt-out from Zapier's Derived Data program to prevent any de-identified data from being used for AI model training.

Privacy Policy: https://zapier.com/privacy

DPA: https://zapier.com/dpa (incorporated into Zapier's Terms of Service; standalone signed copy available on request)

Tag Management: Google Ireland Ltd / Google LLC (Google Tag Manager)

Data shared: IP address (in standard HTTP request logs only, generated when your browser loads the GTM container script). GTM does not set cookies, does not collect personally identifiable information, and its Use Policy explicitly prohibits uploading data that personally identifies an individual.

Purpose: Tag management infrastructure — deploying and managing our consent management platform (Cookiebot) and consent-gated tags (analytics, advertising pixels) via a centralized container system. GTM loads before any consent-gated tags fire, ensuring that tracking scripts are properly blocked until you provide consent.

Legal basis: Legitimate interest (Article 6(1)(f)) — necessary technical infrastructure for safe and functioning operation of our website's consent management and tag deployment systems.

Data retention: HTTP request logs are deleted within 14 days. Google also collects aggregated diagnostics data about tag firing (containing no IP addresses or individual identifiers) with no stated deletion timeline. Google states that GTM does not otherwise collect, retain, or share any information about visitors.

Location: Ireland (EU) with transfers to USA via Google infrastructure. Google is certified under the EU-US Data Privacy Framework (DPF) and includes Standard Contractual Clauses (SCCs) in its Data Processing Addendum (Google Ads Data Processing Terms). Google Tag Manager holds ISO 27001 certification.

Privacy Policy: https://policies.google.com/privacy

DPA: Google Ads Data Processing Terms (accepted in GTM Account Settings)

Website Hosting: Google LLC (Blogger)

Data shared: Server logs including IP addresses, page requests

Purpose: Website hosting and content delivery

Privacy Policy: https://policies.google.com/privacy

Domain Registration & Business Email: Hostinger International Ltd

Data shared: Contact information, email content, sender/recipient metadata

Purpose: Domain registration, business email hosting (hello@gut-logic.com), and DNS management

Location: Lithuania (EU). Data stored in EU locations (Netherlands, Lithuania, Cyprus, UK).

Privacy Policy: https://www.hostinger.com/privacy-policy

We do not sell your personal information to third parties. We only share data as described above or when required by law.

6. International Data Transfers

Some of our third-party service providers are located outside of your country of residence. When we transfer your personal data internationally, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework (DPF): Kit (email marketing), Zapier (purchase event automation), Google (tag management via GTM), Meta, and Pinterest are certified under the EU-US Data Privacy Framework, providing adequate protection for EU personal data transferred to the United States. Kit additionally includes Standard Contractual Clauses (SCCs) and the International Data Transfer Agreement (IDTA) in its Data Processing Addendum. Zapier and Google additionally include Standard Contractual Clauses (SCCs) in their respective Data Processing Addendums.
  • Standard Contractual Clauses (SCCs): Where DPF certification is not available, we rely on EU-approved Standard Contractual Clauses to protect your data.
  • EU Data Storage: For Google Analytics 4, we have enabled EU data storage, ensuring EU visitor data is processed and stored within the European Union.

7. How Long We Keep Your Information

We retain your personal data only as long as necessary for the purposes described:


Data Type Retention Period


Email subscriber data Until you unsubscribe + 30 days

Website analytics (GA4) 14 months

Advertising cookies (Meta, 180 days (platform default) Pinterest)

Cookie consent records 12 months

Affiliate transaction records 7 years (legal/tax requirement)

Server logs Per Google Blogger and Hostinger policies

Purchase processing metadata Transaction metadata cleared from (order ID, product name, email marketing platform within 7 transaction date) days. Automation platform (Zapier) retains Zap Content for 7 days in logs, 29–69 days in account, up to 4 months in backups.

Auto-created non-subscriber Deleted within 24 hours. No records (purchase processing) marketing communications sent.

Tag management logs (GTM) HTTP request logs deleted within 14 days. No PII collected.

When data is no longer needed, we securely delete it or anonymize it so it can no longer be associated with you.

8. Your Privacy Rights

For EU/UK Residents (GDPR Rights)

If you are located in the European Union or United Kingdom, you have the following rights under the General Data Protection Regulation:

  • Right of Access (Article 15): You can request a copy of the personal data we hold about you.
  • Right to Rectification (Article 16): You can ask us to correct any inaccurate or incomplete personal data.
  • Right to Erasure (Article 17): You can request that we delete your personal data in certain circumstances (also known as the "right to be forgotten").
  • Right to Restriction (Article 18): You can ask us to limit how we use your data while we address concerns you have raised.
  • Right to Data Portability (Article 20): You can request to receive your data in a structured, commonly used format, or have it transferred to another controller.
  • Right to Object (Article 21): You can object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent (Article 7): Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

For California Residents (CCPA Rights)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You can request that we delete your personal information, subject to certain exceptions.
  • Right to Opt-Out of Sale: You have the right to opt out of the "sale" of your personal information. However, we do not sell personal information as defined under the CCPA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

"DO NOT SELL MY PERSONAL INFORMATION": Gut Logic does NOT sell personal information to third parties. The sharing of data with our advertising partners (Meta, Pinterest) for targeted advertising purposes does not constitute a "sale" under CCPA when Limited Data Use is enabled, which we have implemented.

For Canadian Residents (CASL/PIPEDA Rights)

Canadian residents have the right to access, correct, and withdraw consent for the use of their personal information. Commercial electronic messages require express consent, which you provide when signing up for our newsletter. You may unsubscribe at any time, and we will process your request within 10 business days as required by CASL.

9. How to Exercise Your Rights

To exercise any of your privacy rights, you may:

  • Email us at: hello@gut-logic.com
  • Use the unsubscribe link in any marketing email
  • Adjust your cookie preferences using the cookie banner on our website

When you contact us with a request, we will:

  • Verify your identity to protect your privacy
  • Respond within 30 days (or 45 days for complex requests)
  • Provide the requested information free of charge (one request per 12-month period)
  • Explain any reasons if we cannot fulfill your request

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website. A cookie is a small text file stored on your device that helps us recognize you and remember your preferences.

Cookie Categories

  • Necessary Cookies: Essential for website functionality (session management, security). These cannot be disabled as they are required for the site to work.
  • Preference Cookies: Remember your settings and choices (language, display preferences). Default: OFF until you consent.
  • Statistics Cookies: Help us understand how visitors interact with our website through analytics (Google Analytics 4). Default: OFF until you consent.
  • Marketing Cookies: Used to deliver relevant advertisements and measure ad campaign effectiveness (Meta Pixel, Pinterest Tag). Default: OFF until you consent.

Managing Your Cookie Preferences

When you first visit our website, you will see a cookie consent banner. You can choose to accept all cookies, reject all non-essential cookies, or customize your preferences by category. You can change your preferences at any time by clicking the cookie settings link in our website footer.

We use Cookiebot as our Consent Management Platform. Tracking scripts (Meta Pixel, Pinterest Tag, Google Analytics) are automatically blocked until you provide consent for the relevant category.

11. Advertising Pixels Explained

Meta Pixel (Facebook/Instagram)

The Meta Pixel is a piece of code that allows us to measure the effectiveness of our advertising by understanding the actions people take on our website. With your consent, the pixel collects:

  • Pages you visit on our website
  • Actions you take (such as signing up for our newsletter)
  • Device and browser information
  • Referral information

This data helps us show relevant content to people who have expressed interest in gut health topics. The pixel only fires after you consent to Marketing cookies. You can learn more about Meta's data practices at: https://www.facebook.com/privacy/policy

Pinterest Tag

The Pinterest Tag works similarly, helping us measure the effectiveness of ads on Pinterest and show relevant content to interested users. It only activates with your consent and collects similar browsing and conversion data. Learn more: https://policy.pinterest.com/privacy-policy

12. Right to Lodge a Complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. We encourage you to contact us first so we can address your concerns.

Email us at: hello@gut-logic.com

13. Children's Privacy

Our website and services are not directed at children under the age of 16 (or 13 in the United States). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at hello@gut-logic.com, and we will take steps to delete such information.

14. How We Protect Your Information

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • SSL/TLS Encryption: All data transmitted to and from our website is encrypted using industry-standard SSL/TLS protocols.
  • Secure Service Providers: We only work with reputable service providers who maintain strong security practices and are compliant with applicable data protection regulations.
  • Access Controls: Access to personal data is limited to authorized personnel who need it to perform their duties.
  • Two-Factor Authentication: We use 2FA on all administrative accounts to prevent unauthorized access.
  • Regular Reviews: We periodically review our data collection, storage, and processing practices to ensure ongoing security.

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.

15. Affiliate Disclosure

Gut Logic participates in affiliate marketing programs. This means that some links on our website and in our emails are affiliate links. If you click on an affiliate link and make a purchase, we may earn a small commission at no additional cost to you.

We only recommend products that we believe may genuinely benefit our audience based on research and alignment with our educational mission. Affiliate relationships do not influence our editorial content or recommendations.

Our primary affiliate partner is Digistore24, a Germany-based platform that handles all transaction processing according to EU compliance practices. When you make a purchase through our affiliate links, Digistore24 acts as the data controller for that transaction.

16. Health & Medical Disclaimer

IMPORTANT: The content provided by Gut Logic is for educational and informational purposes only. It is not intended to be a substitute for professional medical advice, diagnosis, or treatment.

Always seek the advice of your physician or other qualified healthcare provider with any questions you may have regarding a medical condition. Never disregard professional medical advice or delay in seeking it because of something you have read on our website or in our communications.

If you think you may have a medical emergency, call your doctor or emergency services immediately. Gut Logic does not recommend or endorse any specific tests, physicians, products, procedures, opinions, or other information that may be mentioned on our website.

17. FDA Disclaimer

FDA NOTICE: The statements made on this website have not been evaluated by the Food and Drug Administration. Any products mentioned or discussed are not intended to diagnose, treat, cure, or prevent any disease.

The information provided is not intended to replace consultation with a qualified medical professional. Individual results may vary. Please consult your healthcare provider before starting any supplement or wellness program.

18. Platform Independence Statement

Gut Logic is an independent educational platform. We are not affiliated with, endorsed by, or sponsored by any of the following companies or platforms:

  • Meta Platforms, Inc. (Facebook, Instagram)
  • Google LLC (YouTube, Google, Blogger)
  • Pinterest, Inc.
  • Any social media platform
  • Any supplement manufacturer (unless explicitly stated)

Any trademarks, service marks, or logos used on our website are the property of their respective owners and are used for identification purposes only.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify email subscribers of significant changes
  • Display a notice on our website for a reasonable period

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

20. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: hello@gut-logic.com

We aim to respond to all inquiries within 30 days.

──────────────────────────────────────────────────

© 2026 Gut Logic. All rights reserved.

This Privacy Policy was last reviewed and updated on March 22, 2026


Popular posts from this blog

Your Gut Bacteria May Be Influencing Your Weight More Than Your Diet

The Oral-Gut Connection: How the Bacteria in Your Mouth Affect Your Entire Digestive System

The Gut-Skin Axis: Why Your Skin Problems Might Start in Your Digestive Tract