Privacy and Cookie Policy
Last updated: October 4, 2026.
This policy explains how information is handled when you visit ChampsDiet.com, read recipes, leave a comment, or contact us.
Who is responsible for the website?
The website operator and data controller is ROAS, MB, company code 306014878, Lithuania.
For privacy questions or requests, email [email protected].
Information processed and why
Website delivery and security
When your browser requests a page, technical connection information, including your IP address and details of the request, is processed to deliver that page. The website runs on WordPress and is hosted by Hostinger. We use Wordfence to help protect it against spam, abusive requests, and unauthorized access. WordPress and security features can use cookies for authenticated sessions and security checks.
Comments
If you use a comment form, we receive the information you enter, such as your name, email address, optional website address, and comment. WordPress also records the commenter’s IP address and browser information for comment administration and spam detection. An approved comment and the name used with it can be publicly visible. Avoid putting private information in the comment itself.
Email correspondence
When you email us, we receive your email address, message, and any information or attachments you choose to send. We use these to handle your question or request and any related follow-up.
Analytics
We use Google Analytics 4 to understand how visitors use the website and which recipes and features are useful. Depending on the configuration and privacy choices that apply, measurement can include pages viewed, interactions, referral information, device and browser information, approximate location, and cookie or other identifiers. Google Tag Manager helps manage the website’s tags.
Advertising
Advertising helps fund ChampsDiet.com. We use Google AdSense and Setupad advertising technology. Advertising services can process information such as the page being viewed, IP address, device and browser information, identifiers, consent choices, and ad interactions to deliver ads, measure performance, and detect fraud. Personalized advertising can use information about interests and activity. The consent message identifies the purposes and partners included in that message.
How Google uses information: read Google’s explanation of how it processes personal information and how Google uses information from sites that use its services.
Setupad provides advertising and header-bidding technology. See Setupad’s privacy policy for its information about data use and privacy choices. Some pages use an Onnetwork video player; see Onnetwork’s player privacy information.
Purposes and legal grounds
For processing covered by the GDPR, the grounds for the uses described above are:
- Website delivery, security, and abuse prevention: our legitimate interests in providing a functioning website, protecting it and its visitors, and preventing misuse.
- Comment administration and responding to messages: our legitimate interests in maintaining the website’s discussion, moderating spam or abuse, and responding to inquiries and privacy requests.
- Optional analytics, advertising storage, and personalized advertising: consent where required and requested through the consent message, for the purposes described there. Partners can identify additional purposes and grounds in their disclosures and the message’s settings.
- Recording and honoring privacy choices and handling statutory requests: compliance with applicable data-protection obligations, including the obligation to be able to demonstrate consent where processing relies on it.
Legitimate interests can be relied on only where they are not overridden by your interests or fundamental rights and freedoms. You can object for reasons relating to your particular situation. See the rights and contact information below. Where processing relies on consent, you can withdraw that consent. The European Commission explains these legal grounds for processing.
Reading a recipe does not require you to send a comment or email. If you choose to submit one, information needed to administer the comment or reply to your request is necessary for that function. Do not include information unrelated to what you want us to handle.
Cookies and privacy choices
Cookies are small pieces of information stored in your browser. The website and its services can also use browser storage and similar technologies. These support functions such as remembering privacy choices, login and comment-form preferences, analytics, and advertising.
Use the privacy settings in the consent message to review purposes and advertising partners and to make or change your choices. If a Setupad message is displayed, Manage Settings opens those choices and Consent to all accepts the choices presented. If you previously consented through that message, Withdraw Consent provides the withdrawal option. You can reopen the website’s privacy settings control to review or change a choice.
Withdrawal affects future processing that relies on the withdrawn consent. It does not make earlier consent-based processing unlawful or itself erase information already collected. To ask about deletion of information, use the contact route below.
Declining personalized advertising does not necessarily remove all advertising. Technical requests can still be needed to deliver and protect the website. With an advanced Google Consent Mode configuration, Google tags can send consent-state and limited measurement signals without analytics or advertising storage cookies when that storage consent is declined. Cookie choices should therefore not be interpreted as a promise that all requests to a provider stop.
You can also delete or block cookies in your browser. Deleting cookies can remove saved privacy choices and cause the consent message to appear again.
For additional Google controls, visit Google My Ad Center. Google offers a Google Analytics opt-out browser add-on for supported browsers. These tools have their own scope and do not replace the site’s choices for other partners.
Who receives information
Website administrators can access information needed to operate the website, moderate comments, handle correspondence, and respond to requests. Approved comments are publicly accessible.
Hostinger provides hosting; Wordfence provides website security technology; Google provides analytics and advertising services; Setupad provides advertising technology; and Onnetwork provides video-player technology. Advertising partners identified in the consent message can also receive information for the purposes disclosed there. A browser can contact these services directly when their features or tags load.
Provider information is available in Hostinger’s privacy policy, Wordfence’s privacy policy, and the Google and Setupad policies linked above.
How long information is kept
- Comments: a published comment does not have a fixed publication period. It and its associated moderation information can remain in WordPress until removed, for example following a moderation decision or a privacy request. Removing a public comment and removing associated administrative records are separate operations.
- Correspondence: retention is assessed according to whether the inquiry or privacy request is still open, whether a related follow-up remains to be handled, and whether information is needed for an unresolved complaint or dispute. You can use the privacy contact below to request removal of correspondence relating to you.
- Connection and security records: Wordfence Live Traffic records security-related traffic, with a configured maximum of 30 days and 2,000 rows. Incident records can be retained while an attack, abuse report, or related complaint is being investigated and resolved. Hostinger handles connection records according to its hosting service and published privacy information.
- Analytics: the current Google Analytics settings retain event data for 2 months and user data for 14 months. The user-data retention period resets after new user activity. Most standard aggregated reports are not affected by these settings. See Google’s retention information.
- Privacy preferences and provider records: the configured SharedID identifier cookie has a 365-day expiry; configured ID5 browser storage has a 90-day expiry. Whether these identifiers are stored depends on the applicable consent and service behavior. Cookies and saved preferences otherwise remain according to the applicable browser-storage or provider lifecycle, or until you clear them. Providers describe retention for their own information in the linked policies; withdrawing consent does not automatically delete their earlier records.
You can contact us about the information relating to a particular comment or request. If information is required for a specific legal obligation or an unresolved claim, deletion can be limited to that extent rather than being promised automatically.
International processing
The named providers operate internationally. Information handled through their services can be processed outside Lithuania and the European Economic Area, including in the United States. The applicable provider’s privacy information describes its processing locations and transfer practices.
Google’s data-transfer frameworks page explains the adequacy mechanisms, Data Privacy Framework certification, and standard contractual clauses that Google describes for its transfers. Setupad’s policy describes the use of standard contractual clauses or other mechanisms when information is transferred outside the EEA. These are the providers’ published descriptions of their practices.
Contact us if you need information about the transfer arrangements applicable to information handled through ChampsDiet.com or how to obtain relevant safeguards. Provider links above also provide their privacy contact routes.
Your privacy rights and complaints
Under the GDPR, subject to the conditions and exceptions that apply, you can request access to your information, correction, deletion, or restriction of processing. You can object to processing based on legitimate interests. Data portability applies to qualifying automated processing based on consent or a contract. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal. See the European Commission’s information about individual privacy rights.
To make a request, email [email protected]. Give enough information to locate the relevant comment or correspondence, such as the page address and the email address used. We may need proportionate information to verify that the request concerns you. Please do not send passwords or unrelated sensitive information.
You can also lodge a complaint with a data-protection supervisory authority, particularly in the EEA country where you live or work or where the alleged infringement occurred. Lithuania’s supervisory authority is the State Data Protection Inspectorate; its services page provides complaint information. You do not have to contact us before using your right to complain.
Policy updates
We will update this page when the website’s practices change.
