Privacy Policy

Last Updated: September 2025

Owner and Data Controller
COCO POSITIVO, S.L. (“GoCoCo”)
Tax ID: B67411926
Address: C/ Riera de Sant Miquel, 3, Entresuelo, 08006 Barcelona, Spain
Contact: contact@gococo.app

At a Glance
We collect identifiers (email, device ID), subscription details, and health/nutrition logs you provide.

We use this data to run the app (tracking, insights, reminders), manage subscriptions, and improve our services.

We do not sell personal data. Some analytics/ads may count as “sharing” under California law — you can opt out anytime.

You can access, delete, or export your data by contacting contact@gococo.app.

1. Information We Collect

We collect the following categories of data when you use the GoCoCo app or website:Identification data: name, email, phone, address.

Browsing data: IP address, device, operating system, browser, cookies.

Interaction data: forms, support requests, feedback.

Subscription and billing data: payment info for subscriptions or refunds.

Nutrition and health-related data (sensitive data): meal photos, logs, scans, goals, streaks, and other wellness insights voluntarily provided by the user.

2. Legal Basis for Processing

We process your data under:Consent: when you agree to tracking, notifications, or newsletters.

Contract: to provide paid subscriptions and premium services.

Legal obligations: tax, accounting, fraud prevention.

Legitimate interests: app analytics, security, fraud prevention, and service improvement.

For sensitive health data (nutrition and wellness information such as food photos, logs, or health insights), we only process this information based on your explicit consent, which you may withdraw at any time.

3. Purposes of Processing

We use your data to:Provide food scanner and meal tracker functions.

Generate nutrition and wellness insights (including daily analyses).

Manage subscriptions, payments, and billing.

Send notifications, reminders, and streak updates.

Provide customer support.

Comply with applicable laws.

4. Data Accuracy

Users must provide accurate, up-to-date information and notify GoCoCo of any changes to their personal data.

5. Data Retention

Data is retained while your account is active. After closure, retention periods vary by category:Billing and payment data: up to 5 years, as required by tax and accounting laws.

Nutrition and health-related data: deleted within 6 months of account closure, unless you ask us to keep it longer.

Security and technical logs: up to 12 months. After these periods, data is securely deleted or anonymized unless longer retention is required by law.

6. Users’ Rights

You may exercise the following rights at any time: access, rectification, erasure, restriction, objection, portability, withdraw consent, and not be subject to automated decisions.
Requests can be sent to contact@gococo.app or by mail to our Barcelona office.We respond to all valid requests within one month (or as required by law). If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority (e.g., the AEPD in Spain) or appeal under applicable US state laws.GoCoCo does not make automated decisions with legal or similarly significant effects. Insights, scores, and streaks are provided solely for educational and motivational purposes.

7. Security

We implement appropriate technical and organizational measures to protect personal data. However, no system is 100% secure.
In the event of a personal data breach, we will notify affected users and regulators without undue delay, in accordance with applicable laws.

8. Sharing of Data

We do not sell personal data. Data is only shared with:
Service providers (processors): e.g., hosting, payments, analytics, support tools, acting under our instructions and subject to contractual safeguards.

Legal authorities: where required by law.

9. International Transfers

Data may be transferred outside the EU (e.g., to the United States) when using third-party service providers. In such cases, safeguards such as Standard Contractual Clauses (SCCs) are applied.

10. Children’s Privacy

United States: The service is not directed to children under 13.

EU/Spain: The service is not directed to children under 14. We do not knowingly collect children’s data. Parents may contact us to request deletion.

11. Consumer Health Data (US States) — CHD

In certain US states (e.g., Washington, Oregon, Colorado), nutrition logs, scans, goals, streaks, and related wellness insights are classified as Consumer Health Data.We collect and use CHD solely to provide app functions (tracking, analysis, insights).

We share CHD only with service providers (processors) necessary to operate the app and subject to contractual safeguards.

We do not sell CHD.

Users have the right to access, delete, or withdraw consent regarding this data.

Geofencing: GoCoCo does not use geofencing near health facilities for targeted marketing or data collection.

12. US State Privacy (CPRA, CO, VA, CT, UT, TX)

Notice at Collection (California)
Categories collected:
identifiers (email, device ID), commercial data (subscriptions), internet/electronic activity (app usage, IP, device), and sensitive data (nutrition/health data).
Purposes: provide app functions, manage subscriptions, customer support, analytics, compliance.
Retention: while account is active; certain records up to 5 years for legal/tax obligations.Sensitive data limitation: used only to provide the service, not for advertising without your consent.
Sale/Sharing: GoCoCo does not sell personal data. Advertising/analytics SDKs used in the mobile app may be considered “sharing” under CPRA. Users can opt out via a “Do Not Sell or Share My Personal Information” link (where available) or by contacting contact@gococo.app.
Global Privacy Control (GPC): GoCoCo honors browser GPC signals.Exercising US privacy rights: To access, delete, correct, or opt out of sale/sharing (as applicable in your state), contact contact@gococo.app or write to our address above.

13. Marketing Compliance

Email marketing: complies with CAN-SPAM and always includes an unsubscribe link.

SMS/automated notifications: comply with TCPA, requiring prior consent.

14. HIPAA Disclaimer

GoCoCo is not a HIPAA-covered entity or business associate. The Application is intended for general wellness and educational purposes only.

15. Disclaimer: Educational and Wellness Purposes Only

GoCoCo is intended for lifestyle support and education. It is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease. Information provided (food scores, insights, reminders) is for self-education only. GoCoCo does not provide medical advice. Always consult a qualified healthcare professional.

16. Links to Third-Party Sites

Our Service may include links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to review their policies

17. Updates

GoCoCo may update this Privacy Policy from time to time. Users will be notified of material changes.