Skip to content

Privacy Policy

Effective date: 10 September 2026

1. Controller and scope

ICTHendrikse, registered with the Dutch Chamber of Commerce under number 73774693, is the controller for personal data processed through calorietoken.net and the current CalorieApp, except where an identified third party acts as an independent controller. Privacy contact: info@calorietoken.net.

This notice covers the public website, WordPress accounts and Xaman/XUMM login, the CalorieApp identity bridge, the current nutrition application, contact communications, and active shop functionality.

2. Data we process

  • Technical and security data such as IP address, browser/device information, timestamps, requested pages, security events, and essential cookie identifiers.
  • WordPress account information and the public XRP Ledger address associated with a Xaman/XUMM-authenticated account.
  • Authentication state, single-use authorisation codes, opaque internal identifiers, session tokens, and login/logout timestamps.
  • Public-ledger-derived information displayed for an account, such as publicly observable token balances or rank information.
  • Food searches, nutrition information, quantities, and food logs in CalorieApp.
  • Contact details and message content when you contact us.
  • Order, billing, delivery, payment-status, and legally required accounting information when shop functions are used.

Never send private keys or seed phrases. We do not need them and current CalorieApp V2 does not provide custody.

XRP Ledger addresses and transactions are public blockchain information. ICTHendrikse can consider requests concerning its own off-chain links and application records but cannot alter or erase the XRP Ledger.

3. Purposes and lawful bases

We process data to provide requested website, authentication, nutrition, logging, contact, and shop functions; secure and diagnose the service; answer requests; and meet tax, accounting, consumer-protection, and other legal obligations. Depending on the activity, the legal basis is performance of a contract or requested pre-contract steps, legitimate interests in operating a secure service, compliance with a legal obligation, or consent.

Non-essential analytics, marketing, attribution, or third-party embedded content is loaded only after consent where legally required. We do not use CalorieApp nutrition data for automated decisions producing legal or similarly significant effects.

4. Authentication and CalorieApp

Xaman/XUMM and WordPress provide external identity context. The identity bridge uses a short-lived state and single-use server-to-server code. CalorieApp then creates an opaque HttpOnly session. Current CalorieApp V2 is non-financial and non-custodial. No wallet custody or financial transaction layer is claimed in V1.

Default expiry periods are five minutes for a login state, sixty seconds for an authorisation code, thirty minutes of session inactivity, and eight hours maximum session duration.

5. Recipients and third parties

Suppliers needed for selected functions may include the WordPress hosting environment and plugins, Xaman/XUMM, Render for temporary CalorieApp hosting, Open Food Facts for food searches, and providers supporting email, security, shop, payment-status, or infrastructure functions. Third parties may act as processors or independent controllers under their own notices.

LiveCoinWatch or other external widgets can receive technical data when loaded and are treated as non-essential content where consent is required. Open Food Facts searches should not contain names, wallet credentials, or unnecessary personal information.

Where personal data is transferred outside the European Economic Area, an applicable adequacy decision or appropriate safeguards such as European Commission standard contractual clauses are used where required.

6. Retention

  • Authentication states, codes, and sessions follow the short expiry periods stated above.
  • CalorieApp food logs remain until deleted by the user or the associated account is lawfully deleted, subject to backup and security-cycle delays.
  • WordPress account/profile links remain while active or until a valid deletion request is completed, unless retention is legally required.
  • Contact correspondence is normally retained for up to two years after closure, unless needed longer for a dispute or legal obligation.
  • Tax and accounting records are retained for the applicable statutory period, commonly seven years in the Netherlands.
  • Operational logs follow documented security and hosting schedules and are deleted or anonymised when no longer necessary.

7. Cookies

Essential technologies may be used for security, WordPress login, Xaman/XUMM authentication, CalorieApp sessions, load balancing, and requested shop functions. Non-essential statistics, attribution, advertising, social-media, and external-media technologies require prior consent where required. Visitors can reject non-essential technologies and later withdraw consent through Cookie Settings.

8. Your rights

Subject to the GDPR and applicable exceptions, you may request access, rectification, erasure, restriction, objection, and portability, and withdraw consent at any time. Contact info@calorietoken.net. Proportionate identity verification may be required. We normally respond within one month.

You may complain to the Dutch Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl.

9. Security, nutrition information, and children

We use proportionate safeguards, but no internet service is risk-free. Nutrition information may come from Open Food Facts, can be incomplete, and is not medical or professional dietary advice. The services are not directed at children and are intended for users aged 18 or older.

10. Changes

Material changes will be identified by a new effective date and communicated where required.

Website and CalorieApp features: September 2026

Language and the help guide

The website can remember your selected display language on your device and share that preference with the embedded CalorieApp. This preference is separate from signing in. The Calorie Help guide matches questions against bundled project information in your browser; this guide does not create a support ticket or email, or send your question to an external AI service. Avoid entering personal, medical or wallet information in it.

Food sources and optional test accounts

Open Food Facts supplies product-search results. CalorieApp also contains a small, attributed USDA FoodData Central reference-food selection; this is not a live USDA search service. Using that bundled selection does not itself send a search to USDA. Food-source records remain separate from your private food history.

The optional Testnet guide helps you obtain a test-only XRP Ledger account through the external Testnet tools it identifies. Those services receive the technical information associated with your visit under their own notices. Testnet is separate from Mainnet, can be reset and has no real monetary value. Never use a real wallet recovery phrase or send real funds to a test address. Creating a Testnet account does not automatically create a CalorieApp session or move your existing food history.

Account controls and retention

Where available, an authenticated private export downloads your own application records to your device; downloading does not delete the server copy or transmit the export to another service. Import and whole-account erasure remain separately controlled features and are not enabled by this website styling update. Erasing CalorieApp records cannot erase a separate WordPress or Xaman account, public ledger records or source-provider data.

The planned inactive-account policy is 24 months of inactivity with a 30-day advance warning. Automatic warning delivery and enforcement are not yet implemented. The engineering target for encrypted-backup retention after erasure is at most 30 days, subject to provider and restore verification; this is not a statement that the target has already been proved on the live host. Ask through the privacy contact above about an applicable request or retention requirement.

External media, markets and your choices

X, YouTube, XPMarket and AllChainBridge/SWFT are separate external services. An external link does not load the destination until you open it; an allowed embed can transmit technical data to that provider. Your cookie choices continue to apply where consent is required. We do not silently override a refusal. You can browse public information without creating an account; saving a personal food log needs an authenticated account and the information necessary to provide that function.