Privacy Policy
This policy explains what personal data Verified Peptides collects, why we collect it, how we use and protect it, and what rights you have over your information. We’ve written it to be read, not archived.
Overview
Verified Peptides (verifiedpeptides.online) is committed to handling personal data responsibly, transparently, and in compliance with applicable privacy laws — including the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
This policy applies to all personal data collected through our website, ordering system, email communications, and customer support channels. It does not apply to data processed by third-party websites we may link to.
Short version: We collect only what we need to process your order and run our business. We do not sell your personal data. We do not use it for advertising profiling. We will always tell you what we have and delete it when you ask, subject to legal retention requirements.
Who we are
The data controller for all personal data processed through this website is:
- Trading name
- Verified Peptides
- Website
- verifiedpeptides.online
- Privacy contact
- privacy@verifiedpeptides.online
- Scope
- This policy covers all data collected via this website, checkout, email, and support communications.
Data we collect
We collect personal data in three ways: information you give us directly, information collected automatically when you use our site, and information received from third parties (such as payment processors). The table below covers each category.
| Category | Data points | Source | Required? |
|---|---|---|---|
| Account & identity | Name, email address, account password (hashed), account creation date |
You | Required |
| Order data | Billing address, shipping address, order contents, order value, order history, lot numbers ordered |
You | Required |
| Payment information | Payment confirmation & transaction reference only. We never see or store your full card number. All payment processing is handled by our PCI-DSS-compliant payment processor. |
Payment processor | Required |
| Communication data | Emails, support tickets, live chat transcripts, and any information you include when contacting us |
You | Situational |
| Technical & usage data | IP address, browser type, device type, operating system, pages visited, session duration, referral source, click path |
Automatic (cookies & server logs) | Optional |
| Marketing preferences | Email opt-in/out status, communication preferences, unsubscribe records |
You | Optional |
| Professional context | Institution name, department, or research context — only if you voluntarily provide it (e.g. during onboarding or support) |
You (voluntary) | Optional |
We do not collect or process any special category data as defined under GDPR (such as health, genetic, or biometric data). Our products are sold for research purposes and we do not ask for or process information about how customers use our compounds personally.
How we use your data
We use personal data only for the purposes listed below. We do not use your data for purposes incompatible with those stated here without first notifying you and, where required, obtaining your consent.
Order fulfilment
Processing payments, packaging and dispatching orders, sending dispatch notifications and tracking information, and handling returns, replacements, and refunds.
Customer communication
Responding to enquiries and support requests, sending order confirmations and account notifications, and communicating about issues affecting your order.
Legal & compliance
Meeting our obligations under consumer protection law, tax legislation, anti-money-laundering regulations, export control requirements, and responding to valid legal requests from authorities.
Service improvement
Analysing aggregate usage patterns to improve website performance and navigation. This analysis uses anonymised or aggregated data wherever possible and is never used for individual profiling.
Marketing (with consent)
Sending newsletters, product updates, and research-relevant communications — only to customers who have explicitly opted in. You can unsubscribe at any time from any email we send.
Fraud prevention & security
Detecting and preventing fraudulent transactions, unauthorised account access, and abuse of our platform. Technical data such as IP addresses may be used for this purpose.
We never sell your data. We do not sell, rent, or trade personal data to third parties for marketing, advertising, or any commercial purpose. We do not share data with data brokers.
Legal basis for processing
For customers in the UK and European Union, we are required to identify a legal basis for each processing activity under the UK GDPR and GDPR respectively. The following table maps our processing activities to their legal basis.
| Processing activity | Legal basis |
|---|---|
| Order processing, dispatch, payments | Contract Necessary to perform the contract with you |
| Customer support & communications | Contract Necessary to perform the contract with you |
| Tax records, legal compliance, export controls | Legal obligation Required by law |
| Fraud prevention & security | Legitimate interests Protecting our business and customers |
| Website analytics & service improvement | Legitimate interests Improving our service — anonymised where possible |
| Marketing emails & newsletters | Consent Explicit opt-in required; withdrawable at any time |
| Non-essential cookies & tracking | Consent Managed via our cookie consent tool |
Where we rely on legitimate interests as our legal basis, we have assessed that our interests are not overridden by your rights and freedoms. You may object to processing conducted on this basis — see Your Rights below.
Sharing & disclosure
We share personal data only with third parties who need it to help us deliver our service, and only to the extent required. We do not allow third-party service providers to use your data for their own purposes.
- Payment processors
- We use PCI-DSS-compliant processors (e.g. Stripe) to handle card payments. They receive billing name, amount, and card data — we never see your full card number.
- Shipping carriers
- Name, delivery address, and contact information are passed to our carrier partners (UPS, DHL, Royal Mail, DPD, etc.) solely to fulfil delivery. Carriers may also access this data for customs compliance.
- Email & support platforms
- We use third-party platforms to manage email delivery and customer support tickets. Data is processed under Data Processing Agreements that restrict use to service delivery only.
- Website & analytics
- Our website runs on WordPress. We use analytics tools to understand site usage. Where possible, we configure these to anonymise IP addresses and minimise personal data collection.
- Legal & regulatory authorities
- We may disclose personal data to law enforcement, tax authorities, or regulatory bodies where required by law or in response to a valid legal process. We will notify you where we are legally permitted to do so.
- Business transfers
- If Verified Peptides is acquired, merged, or undergoes a restructuring, personal data may be transferred as part of that transaction. We will notify affected customers and ensure continued compliance with this policy.
Cookies
We use cookies and similar tracking technologies on our website. Some are strictly necessary for the site to function; others are optional and activated only with your consent.
| Type | Purpose | Consent required? |
|---|---|---|
| Strictly necessary | Session management, shopping cart state, security tokens, cookie consent preferences. Without these the site cannot function. |
No — essential |
| Functional | Remembering your preferences (currency, language, saved addresses) to improve your experience across visits. |
Yes |
| Analytics | Measuring page views, session duration, and navigation patterns to understand how the site is used and improve it. We use anonymised data where possible. |
Yes |
| Marketing / targeting | We do not use advertising cookies or third-party retargeting pixels. No advertising networks have access to your browsing behaviour through this site. |
Not used |
You can manage your cookie preferences at any time through the cookie settings banner on our website, or via your browser settings. Withdrawing consent for optional cookies does not affect your ability to place orders.
Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. The periods below reflect our current retention schedule.
- Order & transaction records
- Retained for 7 years from the date of transaction to comply with tax and accounting obligations. This is a legal requirement in most jurisdictions where we operate.
- Account data
- Retained for the lifetime of your account, plus 2 years after account closure or your last order (whichever is later), unless a longer period is required by law.
- Support & communication records
- Retained for 3 years from the date of last correspondence, to enable us to reference prior interactions and resolve recurring issues.
- Marketing consent records
- Retained for the duration of your subscription, plus 3 years after unsubscribe to evidence consent and comply with marketing regulations.
- Analytics & technical data
- Aggregated or anonymised data may be retained indefinitely. Raw IP logs are retained for no more than 90 days before anonymisation or deletion.
- Deletion requests
- On receipt of a valid erasure request, we delete or anonymise personal data within 30 days, subject to any legal retention obligations that require us to keep specific records.
Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures are reviewed and updated regularly.
Encryption in transit & at rest
All data transmitted between your browser and our servers is encrypted via TLS 1.2+. Sensitive data stored in our systems is encrypted at rest using industry-standard methods.
Payment security
Card payments are processed by PCI-DSS Level 1 certified processors. We never store, transmit, or have access to full payment card numbers. Tokenisation is used for recurring payment processing.
Access controls
Access to personal data is restricted on a strict need-to-know basis. Staff with access to customer data receive privacy training, and access is logged and reviewed periodically.
Breach response
In the event of a data breach affecting your personal data, we will notify relevant supervisory authorities within 72 hours and inform affected individuals without undue delay where required by law.
No transmission of data over the internet can be guaranteed to be 100% secure. While we take extensive precautions, we cannot guarantee absolute security. If you have concerns about your account security, contact us immediately at privacy@verifiedpeptides.online.
Your rights
Depending on where you are located, you have a range of rights over your personal data. We honour these rights for all customers, regardless of jurisdiction, to the extent permitted by applicable law.
Right to access
Request a copy of all personal data we hold about you. We will provide this within 30 days of a verified request, at no charge.
Right to rectification
Ask us to correct inaccurate or incomplete personal data. Most account data can be updated directly in your account dashboard without needing to contact us.
Right to erasure
Request deletion of your personal data. We will erase it within 30 days, except where we are required to retain it by law (e.g. tax records).
Right to restrict processing
Ask us to suspend processing of your data in specific circumstances — for example, while you contest its accuracy or object to how we are using it.
Right to data portability
Receive your personal data in a structured, machine-readable format (CSV or JSON) to transfer to another controller where technically feasible.
Right to object
Object to processing based on our legitimate interests, or to direct marketing at any time. We will stop processing immediately upon a valid objection to marketing.
Right to withdraw consent
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right not to be sold (CCPA)
California residents have the right to opt out of the sale of personal information. We do not sell personal data — this right is satisfied by default.
Right to complain
If you believe we have mishandled your data, you have the right to complain to your local supervisory authority (e.g. the ICO in the UK, or your national DPA in the EU).
To exercise any of the rights above, email privacy@verifiedpeptides.online with your full name and the email address associated with your account. We will verify your identity before acting on any request and will respond within 30 days. We will never charge a fee for a reasonable first request.
International data transfers
We operate fulfilment and support infrastructure in both the United States and the European Union. This means your personal data may be transferred to and processed in countries outside your country of residence.
- US–EU transfers
- Data transferred from the EU to our US operations is protected by Standard Contractual Clauses (SCCs) approved by the European Commission, or by equivalent transfer mechanisms where applicable.
- UK transfers
- Data transferred from the UK is governed by UK-approved international data transfer agreements (IDTAs) or addenda to SCCs as approved by the UK ICO.
- Third-party processors
- Where third-party service providers process data in countries outside the UK or EU, we ensure appropriate safeguards are in place — typically SCCs or adequacy decisions — before engaging them.
- Adequacy decisions
- Where the European Commission or UK government has issued an adequacy decision for the destination country, we rely on that decision as the transfer mechanism.
Children’s privacy
Our products are research-grade peptides intended exclusively for professional laboratory use. This website and our services are directed solely at adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18.
If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@verifiedpeptides.online and we will delete it without delay.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by email (if you have an account with us) and by posting a prominent notice on our website prior to the change taking effect.
Your continued use of our website or services after any changes constitutes acceptance of the updated policy. If you disagree with the changes, you should stop using the site and may request deletion of your data.
Minor updates — such as clarifications that do not alter how your data is used — may be made without notice. We recommend reviewing this page periodically. The version of this policy that was in force at the time of your order governs data collected during that transaction.
Contact us
For all privacy-related enquiries, requests to exercise your rights, or concerns about how we handle your personal data, please contact us using the details below. We aim to respond to all privacy enquiries within 5 business days and to complete all data subject requests within 30 days.
- Privacy email
- privacy@verifiedpeptides.online
- General contact
- hello@verifiedpeptides.online
- Website
- verifiedpeptides.online
- Supervisory authority (UK)
- Information Commissioner’s Office (ICO) — ico.org.uk
- Supervisory authority (EU)
- Your national Data Protection Authority — Find your DPA
Questions about your data?
We respond to all privacy enquiries within 5 business days.