Privacy Policy
Last updated: March 12, 2025
Ethical Peptides ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform for research-grade peptides.
1. Information We Collect
1.1 Information You Provide Directly
We collect information that you provide directly to us when you:
- Create an account: Name, email address, password (stored in encrypted form), and any profile information you choose to add
- Place orders: Shipping address, billing address, payment information, order details, and any special instructions related to your peptide research
- Contact us: Messages, support requests, inquiries, and any attachments you send
- Participate in research: Survey responses, feedback, and voluntary information you submit
1.2 Information Collected Automatically
When you access our platform, we automatically collect certain technical information, including:
- Device information: Browser type, operating system, device identifiers
- Usage data: Pages visited, time spent, links clicked, and navigation paths
- IP address and general location: For security, fraud prevention, and compliance purposes
- Cookies and similar technologies: We use essential cookies for authentication and session management; see Section 6 for details
1.3 Information from Third Parties
We may receive information from:
- Payment processors: Confirmation of transactions and limited payment status information
- Authentication providers: If you sign in via Google or other social providers, we receive your name, email, and profile image as permitted by those services
- Analytics providers: Aggregated, anonymized usage statistics to help us improve our platform
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide our services: Process and fulfill your peptide orders, manage your account, and deliver the platform functionality you request
- To communicate with you: Send order confirmations, shipping updates, account notifications, and respond to your inquiries
- To improve our platform: Analyze usage patterns, fix issues, and develop new features
- To ensure security: Detect and prevent fraud, unauthorized access, and abuse of our platform
- To comply with legal obligations: Meet regulatory requirements, respond to lawful requests from authorities, and enforce our Terms and Conditions
- To send marketing communications: With your consent, send updates about new products, research, and promotions (you may opt out at any time)
3. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA) or UK, we process your personal data based on:
- Contract performance: To fulfill our agreement with you (e.g., processing orders)
- Legitimate interests: To improve our services, prevent fraud, and ensure security
- Consent: Where you have given explicit consent (e.g., marketing emails)
- Legal obligation: Where required by applicable law
4. How We Share Your Information
We do not sell your personal information. We may share your information only in the following circumstances:
- Service providers: With trusted third parties who assist us (hosting, payment processing, email delivery, analytics) under strict data processing agreements
- Legal requirements: When required by law, court order, or government request, or to protect our rights, property, or safety
- Business transfers: In connection with a merger, acquisition, or sale of assets, subject to the same privacy commitments
- With your consent: In any other case where you have given explicit permission
5. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. After account closure, we may retain certain information for:
- Legal and regulatory compliance: Typically 7 years for financial and tax records
- Dispute resolution: Until any disputes are resolved
- Security and fraud prevention: As long as necessary to protect our platform and users
Anonymized or aggregated data may be retained indefinitely for analytics and improvement purposes.
6. Cookies and Tracking
We use the following types of cookies:
- Essential cookies: Required for authentication, session management, and core platform functionality; these cannot be disabled
- Functional cookies: Remember your preferences (e.g., language) to improve your experience
- Analytics cookies: Help us understand how visitors use our platform (we use these only with your consent where required)
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest where applicable
- Access controls and authentication requirements for our systems
- Regular security assessments and monitoring
- Training for staff on data protection and security practices
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Restriction: Request that we limit how we use your data in certain circumstances
- Portability: Receive your data in a structured, commonly used format
- Object: Object to processing based on legitimate interests or for direct marketing
- Withdraw consent: Where processing is based on consent, withdraw it at any time
- Complaint: Lodge a complaint with your local data protection authority
To exercise any of these rights, please contact us using the details in Section 10.
9. International Transfers
If you are located outside the country where our servers are hosted, your information may be transferred to and processed in that country or other jurisdictions. We ensure appropriate safeguards (such as Standard Contractual Clauses approved by the European Commission) are in place for such transfers where required by law.
10. Children’s Privacy
Our platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately so we can delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email or display a prominent notice on the platform. We encourage you to review this policy periodically.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or have concerns about our data practices, please contact us at hello@ethicalpeptides.com.
We will respond to your request within the timeframe required by applicable law (typically 30 days for GDPR requests).