Privacy Policy

Effective Date: September 23, 2026

1. Introduction and Data Controller

We, CodeQuarter, owner Tarkan Gökhan Gökdal, Eekholtesweg 6, 22111 Hamburg, Germany (hereinafter "we", "us", or "Provider"), operate the platform "nutrimio".

We are committed to protecting your privacy. This policy explains how we process personal data in compliance with the EU General Data Protection Regulation (GDPR) and other applicable international data protection laws.

As a company established in Germany, we are directly subject to the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Our own platform runs on servers located in Germany.

2. Data Infrastructure and Storage (EU-Based)

To ensure maximum security and compliance, we host our application and databases on servers located within the European Union (Frankfurt, Germany).

Our infrastructure partners are:

  • Contabo GmbH: Aschauer Straße 32a, 81549 Munich, Germany (Server Infrastructure).
  • Supabase Inc.: 970 Summer St, Stamford, CT 06905, USA. Note: We use the Frankfurt (Germany) region for data storage. Supabase is compliant with GDPR through Standard Contractual Clauses (SCCs).

3. Types of Data Collected (Coaches)

For the purpose of providing our services to Coaches (B2B), we collect the following personal data (Art. 6 (1) (b) GDPR):

  • Identity & Contact: Full name, business email address.
  • Professional Profile: Coach title, stage name/business name, profile picture, slogan/motto.
  • Business Information: Social media handles/links, affiliate partner information and links.
  • Financial Data: Transactional information provided by our payment processor (see Section 5).
  • Sign-in Metadata: The time your email address was confirmed, the time of your last sign-in and any ban expiry date for your account.
  • Support Correspondence and Internal Notes: Messages we send you from our administration console, including the message text actually sent, and notes our staff record about your account – for example about a phone call or a decision taken. See Section 8.1 for details.

3.1 Single Sign-On (SSO) via Google and LinkedIn

To make access to our platform easier and more secure, we offer the option to register and log in using your existing Google or LinkedIn accounts. When you use these third-party services, we do not receive or store your passwords for these accounts.


Google: If you choose to log in via Google, you will be redirected to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We receive your email address, full name, and profile picture from Google strictly to create and authenticate your nutrimio account. More information can be found in Google's Privacy Policy: https://policies.google.com/privacy.


LinkedIn: If you choose to log in via LinkedIn, you will be redirected to LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland). We receive your email address, full name, and profile picture from LinkedIn strictly to create and authenticate your nutrimio account. More information can be found in LinkedIn's Privacy Policy: https://www.linkedin.com/legal/privacy-policy.


Legal Basis: The processing of this data is necessary for the performance of our contract with you (account creation and authentication) according to Art. 6 (1) (b) GDPR.

3.3 Storage Duration

We only store your personal data for as long as is necessary to fulfill the purposes stated in this privacy policy or as required by statutory retention obligations:

  • Account data (name, email, profile): For the duration of your membership + 30 days after account deletion. If you delete your account yourself in the account settings, it is deactivated immediately and your stores are closed; final removal follows 30 days later. Independently of this, we can delete an account immediately and irreversibly through our administration console, without waiting for the 30-day period (see Section 8.1).
  • Transaction data (Mollie): 10 years in accordance with statutory retention obligations (§ 147 AO).
  • Support correspondence and internal notes (Section 8.1): No automatic deletion period is currently set up for these entries. They are also not automatically removed when your account is deleted: the entry is retained in full, including the email address, the subject and the message text; only the link to the account is severed. Please address any erasure request to the address named in Section 7.
  • Log of administrative actions (Section 8.1): The log entry is retained permanently; the technical details about the acting person are removed 180 days after the action.

4. Public Shop Pages (End-Users)

When end-users visit a public shop page hosted on nutrimio, we do not collect personal data that could identify the visitor.

We use anonymized tracking to provide the Coach with business analytics. This includes:

  • Page views (product, category, and bundle pages).
  • Clicks on affiliate links.

This data is processed in a way that it cannot be linked to an identifiable person.

5. Payment Processing (Mollie)

Payments are processed by Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, The Netherlands.

nutrimio does not store your credit card numbers. We only store transactional metadata (e.g., payment status, amount, timestamp) in our Supabase database to manage your subscription. Mollie's privacy policy can be found at https://www.mollie.com/en/privacy.

Transaction data is retained for a period of 10 years to comply with statutory retention obligations under § 147 AO.

6. International Data Transfers

Your data is stored in the EU; the platform is operated and supported by CodeQuarter, based in Hamburg, Germany.

We generally do not transfer your data to third countries. Where individual partner networks transfer data to third countries (see Section 11), this is done on the basis of appropriate safeguards such as Binding Corporate Rules or Standard Contractual Clauses.

7. Your Rights (Global Standard)

Regardless of your location, you have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion of your data ("Right to be forgotten").
  • Portability: Request transfer of your data to another provider.
  • Withdrawal of Consent: Revoke any consent previously given.

To exercise these rights, contact us at: info@nutrimio.app.

7.1 Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority at any time if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR). You may address the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, https://datenschutz-hamburg.de.

8. Data Security

We use industry-standard AES-256 encryption and SSL/TLS protocols for all data transmissions. Within our database, we utilize Row Level Security (RLS) to separate the Coaches' data from one another: through our applications, each Coach can only access their own specific data. RLS does not, however, limit our own administrative access as the operator: our administrative functions run through a server-side interface on a privileged database connection to which RLS does not apply. Section 8.1 describes the access this makes possible.

8.1 Administrative Access by the Operator

To operate the platform, we maintain an internal administration console. It is operated exclusively by persons who run the platform on behalf of CodeQuarter. Access is restricted to accounts that expressly carry the "superadmin" role in our database and that are active and not marked for deletion; this is re-verified on the server for every single request.

Access to data: Through this console we can view the list of all accounts, each with email address, name, role, account status, interface language as well as subscription plan and subscription status; the list is searchable by part of the email address and filterable by role. For an individual account we can additionally view sign-in metadata from authentication, namely the email address held there, the time the email was confirmed, the time of the last sign-in and any ban expiry date, as well as the correspondence and note history kept for that account. Passwords or other credentials are not visible through it.

Actions: Through this console we can change an account's role; disable and re-enable an account, whereby a disabled account can no longer sign in; mark an account for deletion, which at the same time closes all of the account's stores and bans the account; reverse that marking within the 30-day period, whereupon all of the account's stores are reopened – including any you had previously deactivated yourself; delete an account immediately and irreversibly; send you a message to the email address held for your account; and record internal notes about your account.

Messages and notes: Messages from the console are not freely composed. The subject and the frame come from a fixed template rendered in your account's language; only the message text inside that template is freely composed. The sender is always our own sending address and cannot be chosen. The message text actually sent is stored, together with the subject, the template, the time, the acting person and the delivery result, in the correspondence history for your account; internal notes are stored in the same history. Entries in this history cannot be changed afterwards.

Purposes: We use this access to answer support requests and to document that contact, to administer accounts (role, activation, deletion marking), to respond to misuse and violations (disabling an account, closing stores, notice messages) and to fulfil legal obligations, in particular to carry out erasure requests.

Logging: Every action carried out through the console is recorded in a log containing the acting person, the type of action, the account concerned, the time, for changes the previous and the new value of the field changed (such as the role or the deletion marking) and technical details about the acting person – IP address, forwarded IP address, browser identifier and session identifier. The log is set up so that entries can neither be changed nor deleted afterwards; the sole exception is the automatic removal of the IP address, the forwarded IP address and the browser identifier 180 days after the action. The entry itself is retained permanently.

9. Changes to this Policy

We may update this policy from time to time to reflect changes in our practices or global regulations. The "Effective Date" at the top will indicate the latest revision.

10. Reach Analysis with Umami (On-Premise)

We use the Umami analysis tool to statistically evaluate the use of our platform. Umami is a privacy-friendly alternative to traditional analysis tools.

Hosting: The software is operated on our own servers in Germany (on-premise). There is no data transfer to third-party providers.

Anonymization: Umami does not collect IP addresses and does not use cookies. All data is processed anonymously and in aggregate. It is not possible to draw conclusions about individual persons.

Legal Basis: The processing is based on our legitimate interest (Art. 6 (1) (f) GDPR) in optimizing our offer.

11. Use of Affiliate Links

Our platform contains links to affiliate programs. If you click on one of these links, you will be redirected to the respective advertiser's page. Tracking parameters (e.g., affiliate IDs) are transferred in order to technically attribute the sale. This data processing is based on Art. 6 (1) (f) GDPR for the proper billing of advertising services.

Tradedoubler: For recommendation links of brands from the Tradedoubler network (Tradedoubler AB, Stockholm, Sweden), data such as cookie ID, IP address, and order number are processed on click and purchase. Third-party cookies and – subject to consent – cross-device tracking may be used. Tradedoubler acts as a processor for the respective brand; we are involved as a sub-processor. Processing is contractually restricted to the EU/EEA.

Webgains: For brands from the Webgains network, a joint controllership agreement (Art. 26 GDPR) exists between us, Webgains GmbH (Frankenstraße 150c, 90461 Nuremberg, Germany), and the respective brand. On click, the IP address, referrer, browser type, timestamp, program, publisher, event, and reference IDs (including a probabilistic ID), and the order value are processed; for commission settlement, order and billing data are additionally processed. The central contact point for data subject requests is Webgains for sales reporting and the respective brand for click processing – however, you can assert your rights against any of the parties involved, including directly against us.

Rakuten Advertising: For brands from the Rakuten Advertising network (for the EEA: Rakuten Marketing Europe Ltd., London), Rakuten is a separate, independent controller. Subject to consent, Rakuten uses tracking technologies and may also use data for interest-based advertising. Data collected in the EU/EEA may be transferred to the USA and other third countries on the basis of the Rakuten Binding Corporate Rules (https://global.rakuten.com/corp/privacy/bcr/).

We process the transaction data provided by the networks (e.g., order value, commission amount, transaction status, click reference) exclusively to attribute and settle commissions and to provide statistics (Art. 6 (1) (f) GDPR; where data of our own users is concerned, additionally Art. 6 (1) (b) GDPR). For questions or data subject requests regarding affiliate tracking, you can reach us at info@nutrimio.app – we will coordinate the response with the respective network.

12. Reporting Function for Shop Content

On the public shop pages, visitors can report individual products, bundles, and categories – for example in the case of incorrect prices, inaccurate details, or broken links. When they do, we store the reported item, the selected reason for the report, an optional free-text comment, and the IP address from which the report was submitted. You may additionally provide your name and email address on a voluntary basis; these details are optional, are not verified by us, and are used solely so that we can follow up on your report if necessary.

We store the IP address in full, meaning it is neither truncated nor anonymized nor hashed. It serves solely to protect the reporting function against misuse: because the shop pages are accessible without a user account, the IP address is the only characteristic that allows us to limit the number of reports per sender, to fend off automated bulk submissions, and to prevent the same item from being reported repeatedly while a report is still open. We do not use the IP address to analyze usage behavior or to build profiles.

Beyond this, we do not collect any further data as part of the reporting function: no cookies are set, and no session identifiers, device identifiers (fingerprints), or browser details (user agent) are stored.

Recipients: Your report is shown to the coach whose shop the reported item belongs to and is additionally sent by email to our internal support mailbox. A name and email address provided voluntarily are visible there. We do not pass on the IP address: it is neither shown to the coach nor included in the notification to support, nor is it logged.

Legal Basis: The processing is based on our legitimate interest (Art. 6 (1) (f) GDPR) in a functioning reporting facility and in protection against misuse and automated submissions. The data is stored on the EU-based infrastructure described in Section 2.

Retention period: The IP address, together with any name and email address you provided voluntarily, is deleted 90 days after the report has been closed. A report is closed once we have reviewed it and decided on it. If a report is never closed, we delete this data no later than 180 days after the report was submitted. You can therefore calculate your own retention period: it ends 90 days after the decision on your report, and in any event no later than 180 days after you submitted it. The report itself – the reported content, the reason given, any comment, and the decision taken – is retained beyond that in anonymised form so that we can demonstrate our decisions; at that point it no longer relates to an identifiable person. You may request deletion of the data stored in connection with your report before these periods expire (see Section 7).