Privacy Policy
Last updated: 6 August 2026
This Privacy Policy explains how MetabolizeLean (“we”, “us”, “our”) collects, uses and discloses personal information when you visit this Site. It is intended to comply with the UK GDPR and the Data Protection Act 2018, where applicable.
1. Information we may collect
- Technical data: IP address, browser type, device type, operating system, referring URL, pages viewed, time stamps.
- Cookie & tracking data: as described in our Cookie Policy (including advertising and analytics identifiers).
- Contact data: name, email address and message content if you contact us via the Contact page.
- Click & conversion data: whether you clicked advertiser links; limited conversion signals may be shared with advertising partners (e.g. Taboola-style networks) for campaign measurement.
2. How we use information
- To operate, secure and improve the Site
- To measure traffic, engagement and advertising performance
- To respond to enquiries
- To comply with legal obligations
- To attribute referrals and commissions to advertising partners
3. Disclosure of information
We may share limited information with:
- Hosting and analytics providers
- Advertising and affiliate networks (for attribution and fraud prevention)
- The Advertiser (Hume Health) where necessary for order support or dispute resolution
- Professional advisers or authorities when required by law
We do not sell your personal health data. We do not sell personal information in the ordinary sense of trading customer lists; however, advertising technologies may involve sharing identifiers for interest-based advertising as disclosed in our Cookie Policy.
4. Hume Health product data
According to the Advertiser’s public materials, Hume Health states that users own their data, that data is encrypted, may be exported, and is not sold to third parties. For authoritative details, always review the privacy policy on the official Hume Health website at checkout or in the app.
5. International transfers
Service providers and advertising partners may process data outside the United Kingdom (including the United States, the EEA and other jurisdictions). Where we transfer personal information internationally, we take reasonable steps to ensure it is handled consistently with this Policy and applicable UK data protection requirements, including appropriate safeguards where required.
6. Security
We use reasonable technical and organisational measures to protect personal information. No method of transmission or storage is completely secure.
7. Retention
We retain information only as long as needed for the purposes described above, or as required by law, then delete or de-identify it where practicable.
8. Your rights
Under the UK GDPR, you may request access to, correction or erasure of personal information we hold about you, object to or restrict certain processing, and request data portability where applicable. You may also lodge a complaint with the Information Commissioner’s Office (ICO) if you are not satisfied with our response.
9. Children
This Site is intended for adults. We do not knowingly collect personal information from children under 16.
10. Changes
We may update this Policy periodically. The “Last updated” date reflects the current version.
11. Contact
Privacy enquiries: see our Contact page.