Privacy Policy
PRIVACY
POLICY
GDPR • UK GDPR • CASL • CCPA • CAN-SPAM
Compliant
Last Updated: March 22, 2026
1. Who We
Are
Gut Logic ("we," "us," or
"our") is an educational platform dedicated to providing
science-backed information about gut health and the microbiome. We are
committed to protecting your privacy and being transparent about how we
collect, use, and protect your personal information.
Contact Email: hello@gut-logic.com
Physical Location: Edmonton, AB, Canada
We will respond to all data protection
inquiries within 30 days of receipt.
2.
Information We Collect
We collect different types of information
depending on how you interact with our website and services:
Information
You Provide Directly
When you sign up for our newsletter, download
resources, or contact us, we may collect:
- Email address (required for newsletter signup)
- Name (optional)
- Any information you include in messages to us
Information
Collected Automatically
When you visit our website, with your consent
where required, we may automatically collect:
- IP address (used to determine general geographic location)
- Device information (browser type, operating system, device type)
- Cookie identifiers and similar tracking technologies
- Browsing behavior (pages visited, time on site, click patterns)
- Referral source (how you found our website)
- Email engagement data (opens and clicks, if you are a subscriber)
3. How We
Use Your Information
We use your personal information for the
following purposes:
- Email Marketing & Communication: To send you newsletters, educational content, and occasional
promotional emails about gut health topics you signed up to receive.
- Content Delivery: To
deliver lead magnets, guides, and other resources you have requested.
- Website Analytics: To
understand how visitors use our website, improve user experience, and
optimize our content.
- Advertising Optimization: To
measure the effectiveness of our advertising campaigns and show you
relevant content.
- Purchase Event Processing: If
you purchase a product through one of our affiliate links, we may process
limited transaction data (your email address and transaction identifiers
such as order ID, product name, and transaction date) to ensure you
receive relevant post-purchase content and are no longer sent promotional
emails for a product you already own. This processing occurs through our
automation platform (Zapier) and email marketing platform (Kit) and is
based on our legitimate interest in providing a relevant subscriber experience
(GDPR Article 6(1)(f)). Transaction metadata used for this matching
process is cleared from our email marketing platform within 7 days of
processing. Your email address is the only personal data actively
collected in this process; names are not collected unless you have
voluntarily provided yours through our preference center or direct
correspondence.
- Compliance & Legal Obligations: To maintain records required by law and respond to legal requests.
- Customer Support: To
respond to your inquiries and provide assistance.
4. Legal
Basis for Processing (GDPR)
For visitors from the European Union, United
Kingdom, and other jurisdictions that require a legal basis for processing
personal data, we rely on the following:
- Consent (Article 6(1)(a)): For
email marketing communications, cookie-based tracking (analytics and
advertising pixels), and processing any special category data. You may
withdraw consent at any time.
- Legitimate Interest (Article 6(1)(f)): For basic website functionality, security, and server logging
necessary to operate our website; and for purchase event processing to
match affiliate purchases to subscriber records, ensuring relevant
post-purchase content delivery and suppression of redundant promotional
emails. Our legitimate interest is balanced against your rights and does
not override your fundamental freedoms. For purchase event processing
specifically, the impact on data subjects is minimal (email address only,
no marketing sent to non-subscribers, temporary records deleted within 24
hours).
- Contract (Article 6(1)(b)): To
deliver resources and services you have specifically requested.
- Legal Obligation (Article 6(1)(c)): To comply with applicable laws and regulations, including
maintaining consent records.
5. Who We
Share Your Information With
We share your personal information with the
following categories of third parties, each of which has committed to data
protection standards:
Email
Marketing Platform: Kit (formerly ConvertKit), Inc.
Data shared: Email
address, name (if provided), signup timestamp, IP address, consent records,
email engagement metrics (opens, clicks), signup source tracking data
Purpose: Email
marketing, automation, landing pages, and delivery of lead magnets
Location: Boise,
Idaho, USA. Kit is certified under the EU-US Data Privacy Framework (DPF) and
includes Standard Contractual Clauses (SCCs) and the International Data
Transfer Agreement (IDTA) in its Data Processing Addendum (DPA).
Privacy Policy: https://kit.com/privacy
DPA: https://kit.com/dpa
(incorporated into Kit's Privacy Policy)
Advertising
Platform: Meta Platforms Ireland Ltd
Data shared: Cookie
identifiers, browsing behavior, device information, conversion events
Purpose:
Advertising optimization, retargeting, conversion measurement
Location: Ireland
(EU) with transfers to USA
Privacy Policy: https://www.facebook.com/privacy/policy
Advertising
Platform: Pinterest Europe Ltd
Data shared: Cookie
identifiers, browsing behavior, device information, conversion events
Purpose:
Advertising optimization, conversion tracking
Location: Ireland
(EU) with transfers to USA
Privacy Policy: https://policy.pinterest.com/privacy-policy
Analytics:
Google Ireland Ltd (Google Analytics 4)
Data shared:
Anonymized/aggregated browsing data, page views, session information
Purpose: Website
analytics, content performance measurement
Location: EU data
storage enabled (data stored in Europe)
Privacy Policy: https://policies.google.com/privacy
Consent
Management: Cybot A/S (Cookiebot)
Data shared:
Hashed/anonymized IP address, consent choices, timestamps
Purpose: Cookie
consent management, compliance audit trail
Location: Denmark
(EU)
Privacy Policy: https://www.cookiebot.com/en/privacy-policy
Affiliate
Platform: Digistore24 GmbH
Data shared:
Transaction data for purchases made through our affiliate links
Purpose: Affiliate
commission tracking and payment processing
Location: Germany
(EU)
Note:
Digistore24 acts as an independent data controller for purchase transactions
Privacy Policy: https://www.digistore24.com/info/privacy
Automation
Platform: Zapier, Inc.
Data shared: Email
address and transaction identifiers (order ID, product name, transaction date)
for purchases made through our affiliate links. Email is the only personal data
processed; transaction identifiers are operational metadata that cannot
identify a natural person independently.
Purpose: Automated
purchase event processing — connecting affiliate purchase data from Digistore24
to our email marketing platform (Kit) to ensure subscribers receive relevant
post-purchase content and are not sent redundant promotional emails for
products they already own.
Legal basis: Legitimate
interest (Article 6(1)(f)) — improving subscriber experience by matching
purchase events to subscriber records.
Data retention: Transaction data passes through Zapier in near-real-time. Zapier
retains Zap Content (data transferred in and out of Zaps) for 7 days in logs,
29–69 days in the Zapier account, and up to 4 months in backups. Zap run
metadata (Zap name, timestamps, and status — not personal data) is retained in
Zapier's non-production analytics database for product improvement purposes.
Transaction metadata stored in our email marketing platform for the manual
review process is cleared within 7 days. Any subscriber records temporarily
created during this process for individuals who are not existing subscribers
are deleted within 24 hours without any marketing communication being sent.
Location: San
Francisco, California, USA. Zapier maintains SOC 2 Type II certification, is
certified under the EU-US Data Privacy Framework (DPF), and includes Standard
Contractual Clauses (SCCs) in its Data Processing Addendum (DPA). We have
submitted an opt-out from Zapier's Derived Data program to prevent any
de-identified data from being used for AI model training.
Privacy Policy: https://zapier.com/privacy
DPA:
https://zapier.com/dpa (incorporated into Zapier's Terms of Service; standalone
signed copy available on request)
Tag
Management: Google Ireland Ltd / Google LLC (Google Tag Manager)
Data shared: IP address
(in standard HTTP request logs only, generated when your browser loads the GTM
container script). GTM does not set cookies, does not collect personally
identifiable information, and its Use Policy explicitly prohibits uploading
data that personally identifies an individual.
Purpose: Tag
management infrastructure — deploying and managing our consent management
platform (Cookiebot) and consent-gated tags (analytics, advertising pixels) via
a centralized container system. GTM loads before any consent-gated tags fire,
ensuring that tracking scripts are properly blocked until you provide consent.
Legal basis: Legitimate
interest (Article 6(1)(f)) — necessary technical infrastructure for safe and
functioning operation of our website's consent management and tag deployment
systems.
Data retention: HTTP request logs are deleted within 14 days. Google also collects
aggregated diagnostics data about tag firing (containing no IP addresses or
individual identifiers) with no stated deletion timeline. Google states that
GTM does not otherwise collect, retain, or share any information about
visitors.
Location: Ireland
(EU) with transfers to USA via Google infrastructure. Google is certified under
the EU-US Data Privacy Framework (DPF) and includes Standard Contractual
Clauses (SCCs) in its Data Processing Addendum (Google Ads Data Processing
Terms). Google Tag Manager holds ISO 27001 certification.
Privacy Policy: https://policies.google.com/privacy
DPA: Google Ads
Data Processing Terms (accepted in GTM Account Settings)
Website
Hosting: Google LLC (Blogger)
Data shared: Server
logs including IP addresses, page requests
Purpose: Website
hosting and content delivery
Privacy Policy: https://policies.google.com/privacy
Domain
Registration & Business Email: Hostinger International Ltd
Data shared: Contact
information, email content, sender/recipient metadata
Purpose: Domain
registration, business email hosting (hello@gut-logic.com), and DNS management
Location: Lithuania
(EU). Data stored in EU locations (Netherlands, Lithuania, Cyprus, UK).
Privacy Policy: https://www.hostinger.com/privacy-policy
We do not sell your personal information to
third parties. We only share data as described above or when required by law.
6.
International Data Transfers
Some of our third-party service providers are
located outside of your country of residence. When we transfer your personal
data internationally, we ensure appropriate safeguards are in place:
- EU-US Data Privacy Framework (DPF): Kit (email marketing), Zapier (purchase event automation), Google
(tag management via GTM), Meta, and Pinterest are certified under the
EU-US Data Privacy Framework, providing adequate protection for EU
personal data transferred to the United States. Kit additionally includes
Standard Contractual Clauses (SCCs) and the International Data Transfer
Agreement (IDTA) in its Data Processing Addendum. Zapier and Google
additionally include Standard Contractual Clauses (SCCs) in their
respective Data Processing Addendums.
- Standard Contractual Clauses (SCCs): Where DPF certification is not available, we rely on EU-approved
Standard Contractual Clauses to protect your data.
- EU Data Storage: For
Google Analytics 4, we have enabled EU data storage, ensuring EU visitor
data is processed and stored within the European Union.
7. How Long
We Keep Your Information
We retain your personal data only as long as
necessary for the purposes described:
Data Type Retention
Period
Email subscriber data Until you unsubscribe +
30 days
Website analytics (GA4) 14 months
Advertising cookies (Meta, 180 days (platform
default) Pinterest)
Cookie consent records 12 months
Affiliate transaction records 7 years
(legal/tax requirement)
Server logs Per Google Blogger and Hostinger
policies
Purchase processing metadata Transaction
metadata cleared from (order ID, product name, email marketing platform within
7 transaction date) days. Automation platform (Zapier) retains Zap Content for
7 days in logs, 29–69 days in account, up to 4 months in backups.
Auto-created non-subscriber Deleted within 24
hours. No records (purchase processing) marketing communications sent.
Tag
management logs (GTM) HTTP request logs deleted within 14 days. No PII
collected.
When data is no longer needed, we securely
delete it or anonymize it so it can no longer be associated with you.
8. Your
Privacy Rights
For EU/UK
Residents (GDPR Rights)
If you are located in the European Union or
United Kingdom, you have the following rights under the General Data Protection
Regulation:
- Right of Access (Article 15): You
can request a copy of the personal data we hold about you.
- Right to Rectification (Article 16): You can ask us to correct any inaccurate or incomplete personal
data.
- Right to Erasure (Article 17): You
can request that we delete your personal data in certain circumstances
(also known as the "right to be forgotten").
- Right to Restriction (Article 18): You can ask us to limit how we use your data while we address
concerns you have raised.
- Right to Data Portability (Article 20): You can request to receive your data in a structured, commonly
used format, or have it transferred to another controller.
- Right to Object (Article 21): You
can object to processing based on legitimate interests or for direct
marketing purposes.
- Right to Withdraw Consent (Article 7): Where we rely on consent, you can withdraw it at any time without
affecting the lawfulness of prior processing.
For
California Residents (CCPA Rights)
If you are a California resident, the
California Consumer Privacy Act (CCPA) provides you with additional rights:
- Right to Know: You
can request information about the categories and specific pieces of
personal information we have collected about you.
- Right to Delete: You
can request that we delete your personal information, subject to certain
exceptions.
- Right to Opt-Out of Sale: You
have the right to opt out of the "sale" of your personal
information. However, we do not sell personal information as defined under
the CCPA.
- Right to Non-Discrimination: We
will not discriminate against you for exercising any of your CCPA rights.
"DO NOT SELL MY PERSONAL
INFORMATION": Gut Logic does NOT sell personal information
to third parties. The sharing of data with our advertising partners (Meta,
Pinterest) for targeted advertising purposes does not constitute a
"sale" under CCPA when Limited Data Use is enabled, which we have
implemented.
For
Canadian Residents (CASL/PIPEDA Rights)
Canadian residents have the right to access,
correct, and withdraw consent for the use of their personal information.
Commercial electronic messages require express consent, which you provide when
signing up for our newsletter. You may unsubscribe at any time, and we will
process your request within 10 business days as required by CASL.
9. How to
Exercise Your Rights
To exercise any of your privacy rights, you
may:
- Email us at: hello@gut-logic.com
- Use the unsubscribe link in any marketing email
- Adjust your cookie preferences using the cookie banner on our
website
When you contact us with a request, we will:
- Verify your identity to protect your privacy
- Respond within 30 days (or 45 days for complex requests)
- Provide the requested information free of charge (one request per
12-month period)
- Explain any reasons if we cannot fulfill your request
10. Cookies
and Tracking Technologies
We use cookies and similar tracking
technologies to enhance your experience on our website. A cookie is a small
text file stored on your device that helps us recognize you and remember your
preferences.
Cookie
Categories
- Necessary Cookies:
Essential for website functionality (session management, security). These
cannot be disabled as they are required for the site to work.
- Preference Cookies:
Remember your settings and choices (language, display preferences).
Default: OFF until you consent.
- Statistics Cookies: Help
us understand how visitors interact with our website through analytics
(Google Analytics 4). Default: OFF until you consent.
- Marketing Cookies: Used
to deliver relevant advertisements and measure ad campaign effectiveness
(Meta Pixel, Pinterest Tag). Default: OFF until you consent.
Managing
Your Cookie Preferences
When you first visit our website, you will see
a cookie consent banner. You can choose to accept all cookies, reject all
non-essential cookies, or customize your preferences by category. You can
change your preferences at any time by clicking the cookie settings link in our
website footer.
We use Cookiebot as our Consent Management
Platform. Tracking scripts (Meta Pixel, Pinterest Tag, Google Analytics) are
automatically blocked until you provide consent for the relevant category.
11.
Advertising Pixels Explained
Meta Pixel
(Facebook/Instagram)
The Meta Pixel is a piece of code that allows
us to measure the effectiveness of our advertising by understanding the actions
people take on our website. With your consent, the pixel collects:
- Pages you visit on our website
- Actions you take (such as signing up for our newsletter)
- Device and browser information
- Referral information
This data helps us show relevant content to
people who have expressed interest in gut health topics. The pixel only fires
after you consent to Marketing cookies. You can learn more about Meta's data
practices at: https://www.facebook.com/privacy/policy
Pinterest
Tag
The Pinterest Tag works similarly, helping us
measure the effectiveness of ads on Pinterest and show relevant content to
interested users. It only activates with your consent and collects similar
browsing and conversion data. Learn more: https://policy.pinterest.com/privacy-policy
12. Right
to Lodge a Complaint
If you believe we have not handled your
personal data properly, you have the right to lodge a complaint with a
supervisory authority. We encourage you to contact us first so we can address
your concerns.
Email us at: hello@gut-logic.com
13.
Children's Privacy
Our website and services are not directed at
children under the age of 16 (or 13 in the United States). We do not knowingly
collect personal information from children. If you are a parent or guardian and
believe your child has provided us with personal information, please contact us
immediately at hello@gut-logic.com, and we will take steps to delete such
information.
14. How We
Protect Your Information
We implement appropriate technical and
organizational measures to protect your personal data against unauthorized
access, alteration, disclosure, or destruction:
- SSL/TLS Encryption: All
data transmitted to and from our website is encrypted using
industry-standard SSL/TLS protocols.
- Secure Service Providers: We
only work with reputable service providers who maintain strong security
practices and are compliant with applicable data protection regulations.
- Access Controls:
Access to personal data is limited to authorized personnel who need it to
perform their duties.
- Two-Factor Authentication: We
use 2FA on all administrative accounts to prevent unauthorized access.
- Regular Reviews: We
periodically review our data collection, storage, and processing practices
to ensure ongoing security.
While we strive to protect your personal
information, no method of transmission over the Internet or electronic storage
is 100% secure. We cannot guarantee absolute security but are committed to
protecting your data to the best of our ability.
15.
Affiliate Disclosure
Gut Logic participates in affiliate marketing
programs. This means that some links on our website and in our emails are
affiliate links. If you click on an affiliate link and make a purchase, we may
earn a small commission at no additional cost to you.
We only recommend products that we believe may
genuinely benefit our audience based on research and alignment with our
educational mission. Affiliate relationships do not influence our editorial
content or recommendations.
Our primary affiliate partner is Digistore24,
a Germany-based platform that handles all transaction processing according to
EU compliance practices. When you make a purchase through our affiliate links,
Digistore24 acts as the data controller for that transaction.
16. Health
& Medical Disclaimer
IMPORTANT: The
content provided by Gut Logic is for educational and informational purposes
only. It is not intended to be a substitute for professional medical advice,
diagnosis, or treatment.
Always seek the advice of your physician or
other qualified healthcare provider with any questions you may have regarding a
medical condition. Never disregard professional medical advice or delay in
seeking it because of something you have read on our website or in our
communications.
If you think you may have a medical emergency,
call your doctor or emergency services immediately. Gut Logic does not
recommend or endorse any specific tests, physicians, products, procedures,
opinions, or other information that may be mentioned on our website.
17. FDA
Disclaimer
FDA NOTICE: The
statements made on this website have not been evaluated by the Food and Drug
Administration. Any products mentioned or discussed are not intended to
diagnose, treat, cure, or prevent any disease.
The information provided is not intended to
replace consultation with a qualified medical professional. Individual results
may vary. Please consult your healthcare provider before starting any
supplement or wellness program.
18.
Platform Independence Statement
Gut Logic is an independent educational
platform. We are not affiliated with, endorsed by, or sponsored by any of the
following companies or platforms:
- Meta Platforms, Inc. (Facebook, Instagram)
- Google LLC (YouTube, Google, Blogger)
- Pinterest, Inc.
- Any social media platform
- Any supplement manufacturer (unless explicitly stated)
Any trademarks, service marks, or logos used
on our website are the property of their respective owners and are used for
identification purposes only.
19. Changes
to This Privacy Policy
We may update this Privacy Policy from time to
time to reflect changes in our practices, technologies, legal requirements, or
other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify email subscribers of significant changes
- Display a notice on our website for a reasonable period
We encourage you to review this Privacy Policy
periodically to stay informed about how we protect your information.
20. Contact
Us
If you have any questions, concerns, or
requests regarding this Privacy Policy or our data practices, please contact
us:
Email:
hello@gut-logic.com
We aim to respond to all inquiries within 30
days.
──────────────────────────────────────────────────
© 2026 Gut Logic. All rights reserved.
This Privacy Policy was last reviewed and
updated on March 22, 2026