Privacy Policy
Last updated: 20 July 2026
1. Data Controller
HitMacros (Inhaber: Ivica Kopcalija)
Warnemünder Str. 7
13059 Berlin, Germany
Email: [email protected]
2. Data We Collect
When you place an order for a personalized meal plan through our order form, we collect the following information:
- Name, email address, and order language
- Sex, age, weight (kg), height (cm), and optional body fat percentage
- Goal, goal pace, activity level, protein preference, and selected food/category exclusions
- Plan values calculated from those details (for example BMR, TDEE, calorie and protein targets), together with plan, access, and generation identifiers
- Order and payment evidence, including amount, currency, discount/referral attribution, order status, and payment references received from Stripe; we do not store card details
- Evidence of your acceptance of the terms displayed at purchase, including acceptance time, version, language, the displayed notice or its checksum, and the IP address and browser/device identifier (User-Agent) used for the acceptance
- Technical data: IP address, browser/device identifier (User-Agent), access time, and action may be recorded in server, plan-access, and referral-link logs
3. Purpose of Processing
We use your data exclusively for the following purposes:
- Calculating, creating, delivering, and providing time-limited access to your personalized meal plan
- Performing an offered one-time plan adjustment that you request during the access period
- Processing your payment through Stripe
- Communicating about your order (confirmation email, follow-up questions)
- Protecting plan access, preventing abuse and fraud, and retaining evidence for payment disputes
- Meeting legal record-keeping obligations (tax and commercial law)
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligation), and Art. 6(1)(f) GDPR (legitimate interest in business operations).
Insofar as the combination of details you enter (in particular sex, age, weight, height, body-fat percentage, and goal) qualifies as health data within the meaning of Art. 9 GDPR, we process it on the basis of your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR). It is used to create and provide your plan and to perform an offered adjustment that you request. You may withdraw your consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal or transaction records that we must retain by law.
4. Payment Processing (Stripe)
We use Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin 2, Ireland) as our payment processor. When you place an order, you are redirected to a secure Stripe Checkout page.
Stripe processes your payment data (card number, expiry date, CVC) as an independent data controller. We only receive confirmation that the payment was successful — no card data is stored on our servers.
More information: Stripe Privacy Policy.
5. Data Retention
- Temporary PDF-rendering copies: to create and technically verify the file, the solved plan request and a temporary PDF copy are held in a private internal rendering queue. These temporary data are automatically deleted on a schedule, normally within 24 hours after the render finishes. The customer PDF we provide and the order record follow the other retention periods in this section.
- Plan availability: your private plan link is enabled for up to 30 days. During that period, we process the personalization details to provide the plan, support you, and perform an offered one-time adjustment. The 30-day period is an access period; it is not a blanket promise that every field in the order record is automatically deleted on day 30.
- Personalization data: some profile details currently remain stored with the order record. Their continued retention is determined by whether they remain necessary for support, abuse/payment evidence, or the establishment, exercise, or defence of legal claims. Statutory retention duties for invoices and accounting records do not automatically apply to all body and preference details.
- Invoice and payment records: where a record is an accounting voucher or invoice, the statutory retention period is generally eight years under German law (§ 147 AO, § 14b UStG). Depending on its classification, commercial correspondence has a six-year statutory retention period (§ 257 HGB). Periods generally begin at the end of the relevant calendar year and may be extended for open tax proceedings or legal claims.
- Technical access and referral logs: these are kept while necessary for security, abuse and fraud prevention, payment disputes, or legal claims. These logs are not currently subject to one uniform automatic 30-day deletion period.
- Contract and acceptance evidence: evidence of the terms accepted at purchase is retained while necessary for contract administration, payment disputes, legal claims, or statutory obligations. The 30-day plan-access period does not apply to this evidence.
6. Your Rights (GDPR)
You have the right to:
- Access the personal data we hold about you (Art. 15 GDPR)
- Correction of inaccurate data (Art. 16 GDPR)
- Deletion of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence.
7. Cookies and Analytics
We use neither Google Analytics nor the TikTok pixel. After you consent, however, we use Microsoft Advertising UET for the advertising and conversion measurement described below.
-
Language preference: the
__Host-hm_langcookie stores your language selection for up to one year. -
Privacy preference: the
hm_consentcookie stores your optional analytics choice for up to 180 days. It is needed so we can respect that choice and apply a later withdrawal. -
Referral link: if you use a valid
referral link, the
__Host-hm_refcookie may store its code for up to 30 days so the offered benefit and partner attribution remain available. -
Optional audience measurement: only
after you consent,
hm_sidstores a randomly generated pseudonymous identifier andhm_srcstores a campaign source for up to 30 days. The identifier contains no name, email address, or body data. - Data-minimised first-party analytics — on our own server only, we record which page was viewed and which button was clicked, together with the country and — where available — the region (e.g. state) provided to us by Cloudflare and only a bot flag derived from the User-Agent. Private plan IDs are removed from page paths before storage. After you consent, we additionally measure active visible time, maximum scroll depth, the stage reached in the plan-building journey, and campaign parameters. In these audience events, we store neither your IP address nor the raw User-Agent. This is separate from the server, plan-access, and referral-link logs described above, which may contain an IP address and User-Agent for security and evidentiary purposes.
- Optional Microsoft Advertising measurement (UET): the UET tag loads only after you consent. Microsoft Advertising then receives page activity, a page path scrubbed of private identifiers, referrer, browser and device information, the IP address, and Microsoft cookie identifiers. For a completed purchase, we also send a pseudonymous transaction ID, the amount actually paid, and the currency. We send no name, email address, body data, plan contents, or Stripe session ID. The purpose is to measure and improve our advertising. Microsoft Advertising states that it retains UET data for 390 days; related Microsoft and UET cookies may remain for up to 13 months. Microsoft is the recipient; learn more in the Microsoft Privacy Statement.
These pseudonymous session, attribution, and engagement records are retained for no longer than 12 months. If a purchase is attributed, the random identifier can be linked to the corresponding order during that period and is therefore not anonymous.
Optional audience and Microsoft Advertising measurement,
and storage of hm_sid and hm_src,
occur only with
your consent under Art. 6(1)(a) GDPR and
§ 25(1) TDDDG. You may withdraw that consent at any
time with effect for the future. Basic audience and security
measurement without a persistent identifier relies on
Art. 6(1)(f) GDPR (legitimate interest in a secure,
functional service, abuse prevention, and data-minimised
audience measurement).
8. Contact
For any privacy-related questions, please contact us at:
[email protected]