Privacy policy

Effective from April 12, 2026 · compliant with GDPR (EU) 2016/679

1. Data controller

The data controller is the operator of Histamin.io. Contact: info@histamin.io.

2. What data we process

  • Email address – provided at registration, used for sign-in and communication.
  • Hashed password – we store only a one-way hash (bcrypt), never the password itself.
  • Scan history – product compositions and analysis results that the user chooses to save.
  • Consent records – date, IP address, and type of consent (terms, marketing) under Art. 7 GDPR.
  • Analytics data – anonymized traffic statistics via Google Analytics (only with consent).

3. Purpose and legal basis of processing

  • Performance of contract (Art. 6(1)(b) GDPR) – operating the user account and storing scan history.
  • Legitimate interest (Art. 6(1)(f) GDPR) – securing the Service and protecting against misuse.
  • Consent (Art. 6(1)(a) GDPR) – sending email updates and analytics cookies.

4. Retention period

  • Account data is retained for the lifetime of the account.
  • After account deletion, all personal data is removed within 30 days.
  • Consent records are kept for 3 years in case of a legal dispute.

5. Data recipients

We do not sell your personal data or provide it to third parties for marketing. Data may be shared solely with:

  • The hosting provider (processor, bound by a data processing agreement).
  • Google LLC – within reCAPTCHA and Google Analytics (only with consent), transfer to the USA under standard contractual clauses.
  • Brevo SAS (formerly Sendinblue) – an email marketing platform; your email address is passed only if you consented to receive updates. Registered office: 7 rue de Madrid, 75008 Paris, France. Processing takes place within the EU.
  • Stripe Inc. – payment gateway for processing payments; transfer to the USA under standard contractual clauses (SCC). More info: stripe.com/privacy.

6. Your rights

You have the right to:

  • access your personal data (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (“right to be forgotten”, Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • portability of data (Art. 20 GDPR),
  • withdrawal of consent at any time without giving a reason,
  • lodging a complaint with the Office for Personal Data Protection (uoou.cz).

Send requests to info@histamin.io. We will respond within 30 days.

7. Cookies

We use only analytics cookies (Google Analytics) and technical cookies necessary for the Service to function (session, cookie consent). Analytics cookies are activated only with your consent via the bar on the website.

8. Security

Passwords are stored as a bcrypt hash. Communication takes place encrypted over HTTPS. Database access is restricted to the necessary minimum.

9. Changes to the policy

We will inform you of any material changes by email. The current version is always available on this page.