Privacy Policy
Last updated: August 24, 2026
Health Stacker ("we", "us", "our") operates the healthstacker.com website and digital guide
store (the "Service"). This policy explains what personal information we collect, why we
collect it, who we share it with, how long we keep it, and the rights and choices you have.
It applies to visitors, account holders, and purchasers. If you do not agree with this
policy, please do not use the Service.
1. Information We Collect
1.1 Information you provide directly
- Account data: name, email address, and a password (stored only as a cryptographic hash) when you create an account.
- Purchase data: the products you buy, order totals, order references, and payment status. Your card or PayPal details go directly to our payment processors (Stripe, PayPal) over their own secure connections and are never stored on our servers.
- Communications: messages you send to support, refund requests, survey responses, and your email preferences.
1.2 Information collected automatically
- Usage data: pages viewed, referring pages, clicks and interaction events, approximate (city-level) location derived from IP address, device and browser type, and screen size.
- Analytics and experimentation data: product analytics events and A/B experiment assignments used to understand how the Service is used and to improve it.
- Advertising data: where advertising pixels are enabled for a campaign (for example Meta, Google, or TikTok pixels), those providers collect events such as page views and purchases to measure ad performance and build audiences.
- Cookies and similar technologies: see the separate Cookie Policy.
1.3 Categories under US state privacy laws
For readers in states with comprehensive privacy laws (such as California), the information
above falls into these statutory categories: identifiers (name, email, IP address);
commercial information (purchase history); internet or electronic network activity (usage
and analytics data); approximate geolocation (from IP address); and inferences (experiment
assignments and content preferences). We do not collect biometric data, precise
geolocation, or sensitive personal information as defined by those laws.
2. How We Use Information
We use personal information to:
- deliver purchased guides and operate your account and dashboard;
- process payments, refunds, and chargebacks through our payment processors;
- send transactional email (receipts, delivery, account and security notices);
- send marketing email only with your consent, which you can withdraw at any time via the unsubscribe link in any marketing message;
- improve our content, pages, and checkout flows, including A/B experiments;
- measure advertising performance where pixels are enabled;
- detect and prevent fraud and abuse, enforce our Terms of Service, and comply with legal obligations such as tax and accounting rules.
We do not use personal information for automated decisions that produce legal or similarly
significant effects about you.
3. Legal Bases (EEA/UK Readers)
Where the GDPR or UK GDPR applies, we process personal information on these bases:
contract (delivering what you bought and operating your account), consent
(marketing email and non-essential cookies), legitimate interests (service analytics,
fraud prevention, and improving the Service, balanced against your rights), and **legal
obligation** (tax, accounting, and responding to lawful requests).
4. Sharing and Disclosure
We share personal information only as described here, and we **do not sell personal
information for money**:
- Payment processors: Stripe and PayPal receive the data needed to process your payment and handle disputes, under their own privacy policies.
- Service providers: hosting and infrastructure, database and authentication, email delivery, analytics, and customer-support tooling — in each case limited to what the service requires and bound by contract to use it only for us.
- Advertising partners: where ad pixels are enabled, providers such as Meta, Google, or TikTok receive event data. Under some state laws this counts as "sharing" for cross-context behavioral advertising; Section 8 explains how to opt out.
- Legal and safety: we may disclose information to comply with law, enforce our terms, or protect the rights, safety, and property of our users, the public, or the Service.
- Business transfers: if we are involved in a merger, acquisition, or asset sale, personal information may transfer as part of that transaction, subject to this policy.
5. Data Retention
- Account data: kept while your account is active, deleted or anonymized within 90 days of a verified deletion request except where law requires longer retention.
- Order and payment records: retained for as long as required for tax, accounting, and dispute-handling purposes (typically 7 years).
- Analytics data: retained in identifiable form for no longer than 24 months, after which it is deleted or aggregated.
- Support communications: retained for up to 24 months after the ticket closes.
6. Security
Accounts are protected by hashed credentials; connections to the Service are encrypted in
transit (HTTPS); payment details never touch our servers; and access to production data is
restricted to personnel who need it. No internet service can guarantee absolute security —
if we learn of a breach affecting your personal information, we will notify you as required
by applicable law.
7. International Transfers
We operate from the United States, and our service providers may process data in the US
and other countries. Where EEA/UK data is transferred internationally, we rely on
recognized safeguards such as standard contractual clauses implemented by our providers.
8. Your Rights and Choices
Depending on your region, you may have the right to:
- know/access the personal information we hold about you and receive a portable copy;
- correct inaccurate personal information;
- delete your personal information;
- opt out of "sharing" for cross-context behavioral advertising — we honor the Global Privacy Control (GPC) browser signal as a valid opt-out, and you can also decline advertising cookies via the controls described in the Cookie Policy;
- non-discrimination: we will not deny you the Service, charge different prices, or degrade quality because you exercised a privacy right;
- withdraw consent to marketing at any time via the unsubscribe link or by emailing us.
To exercise any right, email support@healthstacker.com from the address associated with your account (or
provide enough information for us to verify you). We respond within the timeframe your
local law requires (45 days in most US states, extendable once; one month under GDPR). If
we decline a request, we will explain why, and you may appeal by replying to our decision;
you also have the right to complain to your local data-protection or consumer-protection
authority.
9. Do Not Track and GPC
We honor the Global Privacy Control signal as an opt-out of sharing, as described above.
Legacy "Do Not Track" browser signals have no settled meaning and are not acted on beyond
the controls already described.
10. Children
The Service is for adults 18 and older. We do not knowingly collect personal
information from children; if you believe a child has provided us personal information,
contact us and we will delete it.
11. Changes to This Policy
We will post updates here and revise the "Last updated" date. For material changes we will
provide more prominent notice, such as email to account holders, where required.
12. Contact
Health Stacker, a publication of Barker Publishing Network. Email: support@healthstacker.com. Please include "Privacy Request" in the subject line for
rights requests so we can route them quickly.