Privacy Policy
Last updated: May 26, 2026
Fiber First respects your privacy. This policy explains what data we collect, why we collect it, and how we keep it safe. We've written it in plain language because legal jargon helps no one.
Who we are
Fiber First is a product of Holistic Health Collective, based in the Netherlands. You can reach us anytime through our contact form.
What we collect
- Your name and email address — when you create an account or join our list
- Payment information — processed securely by Mollie. We never see or store your card details
- Account preferences — your fiber target, units, settings
- Tracking data — foods you log, fiber intake, plant count, gut score
- Basic technical info — browser, device type, IP address (used for currency detection, security, and analytics)
How we use it
- To provide the service (tracking, calculations, syncing your data)
- To send you emails — product updates, news, and occasional tips. You can unsubscribe anytime
- To process payments for Premium subscriptions
- To improve Fiber First using aggregated, anonymized usage patterns
- To respond to your support questions
Legal basis for processing
Under GDPR, we need a legal basis to process your personal data. Here's how it breaks down:
- Contract performance — to create your account, run your subscription, and provide the service
- Consent — for marketing emails, optional analytics, and Meta Pixel cookies
- Legitimate interest — for security, fraud prevention, and improving the product
- Legal obligation — for tax records and regulatory compliance
You can withdraw consent anytime — every marketing email has an unsubscribe link, and you can change your cookie choices whenever you like.
Who we share it with
We don't sell your data. We work with a small number of trusted providers to run the service:
- Mollie — payment processing
- Acumulus — invoicing and tax records
- Amazon SES — marketing email delivery
- Zoho ZeptoMail — transactional emails
- Cloudflare — hosting and app infrastructure
- Supabase — secure data storage for your account and tracking history
- Google — optional sign-in, if you choose to log in with Google
- Meta (Pixel, Conversions API & Custom Audiences) — the pixel and Conversions API are only set if you accept cookies, and measure how our ads perform; we also share a hashed version of your email to build advertising "custom audiences" (see the note just below)
Each of these providers has its own privacy policy and processes data on our instructions.
A note on custom audiences. To keep our advertising relevant and cost-effective, we may share an irreversibly hashed (scrambled) version of your email address with Meta to create "custom audiences." We use these mostly to exclude people who already have Fiber First or have already taken our quiz — so we don't show you ads you don't need — and, to a lesser extent, to reach new people with similar interests. Meta cannot read the hashed email, and we never share your name, your quiz answers, or any other personal details for this. The legal basis is our legitimate interest in efficient advertising; you can object at any time by contacting us, and you can limit interest-based ads directly in your Meta account settings.
International data transfers
Some of our service providers are based outside the European Economic Area — for example, Supabase, Amazon SES, and Meta. When your data is transferred outside the EEA, we rely on:
- EU Standard Contractual Clauses (SCCs) — approved by the European Commission
- EU-US Data Privacy Framework — for providers that participate
These mechanisms ensure your data has equivalent protection wherever it's processed.
How long we keep it
We keep your data as long as you have an account with us. Cancelling a subscription doesn't delete your account — your data stays in case you want to resubscribe later. To permanently delete your account and data, contact us through our form, and we'll process the request as soon as we can.
Your rights
Under GDPR, you have the right to:
- Access the data we hold about you
- Correct anything inaccurate
- Delete your data
- Export your data in a portable format
- Object to certain types of processing
Contact us through our form to exercise any of these rights. We respond within 30 days.
Data breach notification
In the unlikely event of a data breach that affects your personal information, we'll notify you and the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of discovery, as required under GDPR. The notification will explain what happened, what data was affected, and what we're doing about it.
Cookies
We use a small number of cookies. Some are essential — they keep you logged in, remember your settings, and allow the site to function. Others, like Meta Pixel, help us measure how our ads perform. You can manage cookies through your browser settings.
Children
Fiber First is intended for users 16 and older. We don't knowingly collect data from anyone younger.
Changes to this policy
We may update this policy from time to time. We'll provide notice of significant changes. The "last updated" date at the top reflects the current version.
Contact
Questions about your privacy? Get in touch through our contact form and we'll respond as quickly as we can.