Legal
Privacy Policy and Cookie Policy
One document, one URL, covering both. It states what is collected, who receives it, how long it is kept and how to exercise a right — and its processor list is checked against a real network capture before every deploy that adds a request.
- Privacy Policy version
- 1.0
- Cookie Policy version
- 1.0
- Effective date
- 2026-08-16
- Canonical URL
- /privacy
- Review status
- Draft — pending sign-off by qualified United States counsel
Who is responsible for your data
Elitist Peptides is operated by [PENDING - COUNSEL: LEGAL_ENTITY], [PENDING - COUNSEL: ENTITY_ADDRESS]. Orders are fulfilled from our facility in [PENDING - COUNSEL: FULFILLMENT_STATE], United States. These Terms and any dispute arising out of or relating to them are governed by the laws of the State of [PENDING - COUNSEL: GOVERNING_STATE], without regard to its conflict-of-laws rules, and the exclusive venue for any dispute is the state and federal courts located in [PENDING - COUNSEL: VENUE_COUNTY], [PENDING - COUNSEL: GOVERNING_STATE].
That entity is the controller of the personal data described in this policy. Written requests go to the support mailbox published on the Contact page, which is the single address for privacy correspondence.
What we collect
We collect only what an order or an account actually requires.
- Account data. Email address, password (stored only as a salted hash), name, and an optional organisation name.
- Order data. Items, quantities, prices, order number, shipping and billing address, the lot code shipped against each line, and carrier tracking data.
- Attestation data. Agreement version, ISO 8601 timestamp, network address and browser user agent for each research-use confirmation and each checkout attestation. Section 4 explains why.
- Correspondence. Messages you send us and our replies, including a written refusal where a request asks for information we do not supply.
- Technical data. Server request logs containing network address, timestamp, requested path, response status and user agent, produced by the hosting platform.
We do not collect a date of birth. The eligibility check is an attestation, and a birthdate would be personal data we would have to hold, protect and disclose for no verification value. We do not collect health data, we do not ask what you intend to do with a material, and we do not profile you.
Why we use it, and the lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Fulfilling an order | Account, order and address data | Performance of a contract |
| Serving the catalogue behind the entry confirmation | Gate cookie | Legitimate interests, and legal obligation |
| Recording eligibility and research-use attestations | Version, timestamp, network address, user agent | Legal obligation, and legitimate interests |
| Lot traceability and certificate records | Order line, lot code, certificate reference | Legal obligation |
| Fraud, chargeback and abuse handling | Order, payment reference, request logs | Legitimate interests |
| Answering correspondence | Email address and message content | Legitimate interests |
| Catalogue and documentation updates by email | Email address | Consent, withdrawable at any time |
Where the basis is legitimate interests, the interest is operating a restricted-sale catalogue lawfully and keeping records that let us answer for what we shipped. You may object to that processing under section 9.
Attestation records
Every acceptance of the Research Use Only Agreement and every checkout attestation is logged with the agreement version, the ISO 8601 date and time, the network address the acceptance came from, the browser user agent, and the account identifier or email address where one exists. This is stated plainly here because a consent log that is not disclosed is itself a problem.
These records are the evidence that a restriction was presented and accepted. They are retained for the period in section 7, are not used for marketing, and are not sold or shared.
Third-party processors
The list below is intended to match, exactly, the outbound requests this site actually makes. It is checked against a network capture of a production build before any deploy that adds a script or a request. The two entries marked pending are named before they are engaged: no data flows to either until the entry is completed and this list is re-verified.
Last verified against the site’s actual outbound requests on .
| Processor | Role | Data received |
|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery, database and file storage | All site data at rest, plus request logs containing network address and user agent |
| [PENDING - COUNSEL: PAYMENT_PROCESSOR] | Payment authorisation and capture | Name, email, billing address, card data entered directly into the processor’s own fields, and the order amount |
| [PENDING - COUNSEL: EMAIL_PROVIDER] | Transactional and opt-in email delivery | Email address, name and message content |
We disclose data to a public authority where we are legally required to, and to professional advisers under a duty of confidence. We do not sell personal data and we do not share it for cross-context behavioural advertising.
Payment handling
Card details are entered into fields hosted by the payment processor and are transmitted to it directly. We do not receive, process or store a full card number, and we could not produce one if asked. What we retain is the processor’s transaction reference, the amount, the currency, the result, and the last four digits and card brand where the processor returns them, so that a refund or a dispute can be matched to an order.
Retention
| Category | Retention | Reason |
|---|---|---|
| Order and transaction records | 7 years from the order date | Tax, accounting and limitation periods |
| Attestation and agreement acceptances | 7 years from the acceptance | Evidence that the restriction was presented and accepted |
| Lot and certificate traceability records | Retained indefinitely | A certificate must stay resolvable for the life of the material |
| Account data | Until deletion is requested, then 30 days | Operating the account |
| Support correspondence | 3 years from the last message | Handling repeat questions and disputes |
| Server request logs | 30 days | Security and abuse handling |
Deleting an account does not delete an order record, an attestation record or a lot traceability record. Those are kept for the periods above because we are required to be able to say what we shipped, to whom, against which certificate, and on what representation.
Security and breach notification
Data is encrypted in transit. Passwords are stored only as salted hashes. Access to production data is limited to the people who need it to operate the business. Certificate files are served through our own application rather than from a public bucket address, so the storage keys are never exposed.
If a breach affects your personal data and is likely to result in a risk to your rights, we notify you without undue delay and, where the law requires it, the relevant supervisory authority within 72 hours of becoming aware.
GDPR and UK GDPR rights
We ship only within the fifty United States and the District of Columbia, so most visitors will not be covered by the GDPR or the UK GDPR. Where you are, you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting processing already carried out.
Send a request to the support mailbox on the Contact page. We acknowledge within one business day and respond substantively within one month; where a request is complex we may extend by two further months and we will tell you why within the first month. We may ask for information to confirm the request comes from you, and we do not charge for a request unless it is manifestly unfounded or excessive.
Our hosting and processing take place in the United States. Where personal data is transferred from the European Economic Area or the United Kingdom, the transfer is made under the European Commission and UK standard contractual clauses in our processor agreements. You may complain to your supervisory authority; we would rather you raised it with us first.
CCPA and CPRA rights
If you are a California resident you have the right to know what personal information we collect, use and disclose; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising a right.
In the 12 months before the effective date of this policy we collected the categories in section 2, for the purposes in section 3, and disclosed them for a business purpose to the processors in section 5. We have not sold personal information and we have not shared it for cross-context behavioural advertising. We do not knowingly collect sensitive personal information, and we do not use or disclose any for a purpose that would require an opt-out.
Submit a request by email to the support mailbox on the Contact page. We confirm your identity by matching the request to an order number or the email address on the account, and we do not ask for additional identity documents. An authorised agent may act for you by supplying written permission signed by you; we may still contact you to confirm it.
Age of users
This site is restricted to people 21 years of age or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 21. If we learn that we hold data from a person under that age, we delete it and close the account.
The eligibility check is an attestation, not verification. See Age and eligibility in the Research Use Only Agreement for exactly what we do and do not claim to check.
Email and SMS
Transactional email — order confirmation, dispatch, tracking, and answers to your questions — is sent because you placed an order or wrote to us, and cannot be unsubscribed from while an order is open.
Optional email about new lots, published certificates and stock is sent only with your consent, is never a condition of purchase, and every message carries a one-click unsubscribe link that we honour immediately.
We do not operate an SMS programme. We do not send marketing or transactional text messages and we do not collect a mobile number for that purpose. If that changes, this section will be replaced with the message frequency, the autodialer disclosure, the STOP and HELP keywords, the carrier-charges line, and a statement that consent is not a condition of purchase — before the first message is sent.
Changes to this policy
This is version 1.0, effective 2026-08-16. Where a change is material we give notice by email to account holders and show a notice on the site. Superseded versions are retained and produced on request.
Contact
Written support is available at support@elitistpeptides.com. Hours: Monday to Friday, 9:00 a.m. to 5:00 p.m. Eastern Time, excluding public holidays. First-response target: One business day.
Use the Contact page for any privacy request, and put the request type in the subject line so it is routed correctly.