Skip to content
ETHEREALPEPTIDES
ETHEREALPEPTIDES

Legal

Privacy policy

What we collect, why we collect it, who else sees it, how long we keep it, and what you can require us to do about it.

Last updated Governing entity Ethereal Labs LLCSections 15

This policy explains how Ethereal Peptides handles personal information collected through this website, through orders placed on it, and through correspondence with us. It applies to visitors and buyers alike.

We collect what an order and a compliance obligation genuinely require, and not more. We do not sell personal information.

1.Who is responsible

Ethereal Peptides is the controller of the personal information described in this policy — meaning we decide what is collected and why.

The controller is:

Ethereal Labs LLC, incorporated in Wyoming, United States
30 N Gould St
Sheridan, WY 82801

Privacy enquiries, including requests to exercise the rights in section 10, should be sent to support@etherealpeptides.co or through our contact page.

2.Information we collect

Information you give us. Name, email address, billing and delivery addresses, telephone number where provided, organisation and role where provided, order contents, the research-use acknowledgement recorded against an order, and the content of any message you send us. There are no customer accounts, so we hold no passwords or account credentials.

An email address you give us without ordering. If you enter your address to receive a discount code, we hold that address, the code issued to you, and the date. You can remove yourself at any time from the link in any offer email — see section 11.

Information collected automatically. IP address, approximate location derived from it, browser and device characteristics, pages viewed, referring page, and timestamps, collected through server logs and our hosting provider's standard request logging.

Information from third parties. Delivery status from carriers, and where applicable the results of sanctions or restricted-party screening.

What we do not collect. We never see or store payment card numbers, bank details or any financial credential — every payment method we accept is settled outside this website, so no payment data is entered here at all. What we record against an order is that payment was received and by which method. We do not knowingly collect special category or sensitive personal data, and you should not send it to us. We do not ask about health, and health information is not a relevant category for a research-use supply relationship.

3.Categories of personal information (California)

California law requires these to be set out by statutory category rather than described in prose. This is everything we hold, why, and who else sees it.

CategoryWhat this coversWhy we hold itDisclosed to
IdentifiersName, email address, telephone number, delivery and billing address, IP addressTo take, fulfil and support an orderCarriers; hosting and email providers
Commercial informationProducts ordered, order history, the payment method chosen, and the research-use declaration recorded against the orderTo fulfil the order and to keep the compliance and tax records the law requiresNot disclosed beyond our service providers
Internet or network activityPages viewed, referring page, timestamps, browser and device characteristicsSecurity and diagnosticsHosting provider
Geolocation dataApproximate location derived from IP address onlySecurity and fraud preventionHosting provider
Professional informationOrganisation and role, where you choose to give themOrder context and supportNot disclosed
Sensitive personal informationNone. We hold no financial account details, government identifiers, health data, precise geolocation or biometric data
Marketing recordsAn email address given to receive a discount code, the single-use code issued against it, and any unsubscribe and its dateTo send the offer asked for, and to honour an opt-outEmail delivery provider
InferencesNone. We do not profile you or build a behavioural picture from your activity

Retention for each category is set out in section 8.

We have not sold or shared personal information, as those terms are defined by the CCPA and CPRA, in the preceding twelve months, and we do not do so now. We run no advertising and no cross-context behavioural advertising, so there is nothing to opt out of. We collect no sensitive personal information, so there is no right to limit its use to exercise.

We do not knowingly collect or sell the personal information of anyone under 16. This site is restricted to buyers aged 21 or over.

4.Cookies and similar technologies

We use only strictly necessary technologies. There is no analytics, no advertising and no cross-site tracking on this site, which is why you are not asked to accept cookies.

  • Cart. A cookie holding an identifier for your cart, so it survives navigation. It is set as httpOnly, meaning page scripts cannot read it.
  • Research-use acknowledgement. Held for the duration of your visit only, so it is not re-asked while you move between pages. It is cleared when you close the browser and the declaration is made again on your next visit.
  • Date of your first acknowledgement. A single date, kept so we can show how long this browser has been on record. It is the only part of the acknowledgement that outlives the visit.
  • Offer preference. Whether you have dismissed or accepted the discount offer, and when, so it is not shown to you repeatedly. No email address is stored in your browser.
  • Security and delivery. Set by our hosting provider to route requests and mitigate abuse.

Some state is held in your browser's local storage rather than in cookies; clearing site data clears it.

5.How we use information, and on what basis

  • To perform the contract — processing and dispatching orders, taking payment, providing tracking, handling returns and answering support enquiries.
  • To comply with legal obligations — tax and accounting records, sanctions screening, and retention of the research-use acknowledgement as a compliance record.
  • For our legitimate interests — preventing fraud and abuse, securing the site, and enforcing our Terms of Service and compliance policies. We balance these against your interests and rights.
  • With your consent — the welcome offer and any subsequent offer email, where you gave us your address for that purpose. Consent can be withdrawn at any time, without affecting processing already carried out.
  • For our legitimate interests, where you left a purchase unfinished — reminding you about a basket you did not complete, at the address you entered while checking out. We do this because you had already begun a purchase and the reminder concerns your own order. We send at most four, we stop as soon as you order or unsubscribe, and you can opt out from any of them.

We do not use personal information for automated decision-making that produces legal or similarly significant effects. Every order is reviewed by a person before it is dispatched, because payment is confirmed manually.

6.Who we share it with

We share personal information only where it is necessary, and only with:

  • Carriers — the delivery address and contact details needed to deliver the parcel;
  • Service providers — hosting, content delivery and email delivery, each acting on our instructions under a written agreement. We do not share personal information with a payment processor, because there isn't one;
  • Address validation — when you enter a shipping address at checkout, that address alone is sent to Google's Address Validation service to confirm it is deliverable by USPS. Nothing else about you or your order is sent with it, and we do it to stop parcels going astray. Your address is still saved and used by us whether or not the check succeeds;
  • Professional advisers — legal and accounting, where necessary;
  • Authorities — regulators, customs and law enforcement where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims;
  • A successor — in connection with a merger, acquisition or transfer of the business, subject to this policy continuing to apply.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

7.International transfers

We and our service providers operate in more than one country, so personal information may be transferred to and processed in a jurisdiction other than your own, including the United States. Where information is transferred out of the United Kingdom or the European Economic Area, we rely on an adequacy decision where one applies, or on Standard Contractual Clauses together with any additional measures the transfer requires.

8.How long we keep it

  • Order and transaction records, including the research-use acknowledgement — retained for the period required by tax, customs and regulatory law, and thereafter for as long as needed to defend legal claims.
  • Contact details supplied at checkout — kept with the order they belong to. Where checkout was started but not completed, the address stays with that unfinished basket and is deleted with it 15 days after you last touched it. Ask us and we will remove it sooner.
  • An email address given to receive a discount code — held, with the code issued to you, until you unsubscribe or ask us to delete it. Unsubscribing leaves only the record that you did so, which is what stops us contacting you again.
  • Support correspondence — generally two years from the last message in the thread.
  • Server logs — a short rolling window, kept for security and diagnostics.
  • Marketing consent records — until consent is withdrawn, plus a record of the withdrawal itself.

When information is no longer needed it is deleted or irreversibly anonymised. Note that the compliance record attached to an order cannot be deleted on request while a legal retention obligation applies to it.

9.Security

We apply technical and organisational measures appropriate to the information we hold: encryption in transit, access limited to personnel who need it, and logging of administrative access. Because every payment method settles outside this website, no financial credential is ever transmitted to or stored by us — which removes the most sensitive category of data from our systems entirely. No system is perfectly secure, and we do not claim otherwise. Where a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.

10.Your rights

Depending on where you are, you may have some or all of the following rights:

  • Access — to obtain a copy of the personal information we hold about you;
  • Rectification — to have inaccurate information corrected;
  • Erasure — to have information deleted where we have no continuing basis to keep it;
  • Restriction and objection — to limit or object to processing carried out on the basis of legitimate interests;
  • Portability — to receive information you provided in a structured, machine-readable format;
  • Withdrawal of consent — at any time, where processing relies on consent;
  • Non-discrimination — we will not degrade service or pricing because you exercised a privacy right.

Requests are answered within the period the applicable law allows — one month under UK and EU data protection law, forty-five days under California law, extendable where a request is complex. We may need to verify your identity first. If you are dissatisfied with our response you may complain to your local supervisory authority.

11.Marketing

We send offer emails only where you gave us your address to receive them. Separately, if you begin checkout and do not finish, we may remind you about that basket at the address you entered — at most four times, stopping as soon as you order or unsubscribe.

Every message of either kind carries a working unsubscribe link that takes effect immediately, and the same control appears beside our name in most email clients. Transactional messages — order confirmations, dispatch and tracking notices, and replies to your own enquiries — are not marketing and continue regardless of marketing preferences.

12.Age of users

This site is intended for qualified researchers aged 21 or over. It is not directed at children, and we do not knowingly collect personal information from anyone under 21. If we learn that we have, we will delete it and close any associated account.

14.Changes to this policy

We may update this policy as our practices, our providers or the law change. The date at the head of this document reflects the current version. Where a change materially affects how we handle information already collected, we will take reasonable steps to tell you directly.

15.Contact

To exercise a right, ask a question, or raise a concern about how we handle personal information, use the compliance route on our contact page. We would rather resolve a complaint ourselves than have you take it elsewhere first, but you are entitled to do either.