Legal · Privacy policy
Privacy policy. Less data, longer trust.
The shop is the data controller for every researcher account and every order on file. This Policy explains exactly what personal data we collect, why we collect it, who processes it on our behalf, and how long we keep it. It is written against the EU GDPR, and we honour CCPA / CPRA and LGPD in parallel where they apply.
Who we are and how to reach the data team
The shop is the data controller for personal data collected through this site, the account system, the cart and checkout flows, and the inboxes published on the contact page. Where an EU representative is required under Article 27 GDPR, correspondence is accepted through the same contact page.
Privacy correspondence (access requests, rectification, deletion, portability, objection, complaints) is acknowledged within five business days and substantively answered within thirty days, extendable by sixty days for complex requests.
What we collect, and why
We follow data-minimisation: we only collect the personal data we need to verify research eligibility, fulfil orders, ship parcels through DHL Express or FedEx, comply with HMRC and customs paperwork, and run email support.
- Identity: full name, date of birth (only where local law requires age verification of 21 or older), institutional affiliation, role title.
- Contact: email address, telephone number, shipping and billing addresses.
- Order: cart contents, lot trace, order ID, order status, courier tracking number, ETA, customs paperwork status.
- Attestations: research-use-only checkbox state at signup and at checkout, with timestamp, IP address and user-agent.
- Payment: enough payment metadata to reconcile the order with the processor reference. Full card numbers are never stored on shop infrastructure.
- Support history: email message threads, ticket timestamps, attachments you choose to send.
- Site usage: page views, search terms, cart actions, error logs.
- Cookies: cart and session cookies, plus advertising and analytics identifiers.
Legal basis for processing
Under Article 6 of the EU GDPR, every act of processing is grounded in contract, legal obligation, or legitimate interest. We do not rely on consent for processing that is essential to deliver an order.
Processors and sub-processors
The shop operates with a small, deliberately curated set of processors. Each processor is bound by a written Data Processing Agreement under Article 28 GDPR, with appropriate Standard Contractual Clauses where data leaves the EEA.
- Supabase (Frankfurt, EU region): authentication, primary database, attestation log storage.
- Medusa.js on Railway (EU region): order, cart, fulfilment-ticket data.
- Resend (eu-west-1): transactional email.
- Vercel (multi-region edge with EU origin): site hosting.
- DHL Express + FedEx: name and shipping address only.
- Independent third-party lab: receives anonymised lot identifiers only; no researcher PII is shared with the lab.
- Payment processor of record: receives the minimum data required to charge and reconcile the order.
- Google Analytics 4: pseudonymous traffic and on-site behaviour events. IP addresses are not stored by default.
International transfers
Most processing happens inside the European Economic Area. Where personal data is transferred to a third country, for example to a courier hub or a payment processor with a US legal entity, the transfer is supported by an adequacy decision or Standard Contractual Clauses.
We do not transfer personal data to jurisdictions on the EU restricted list and we do not transfer data to any country under EU or United Nations sanctions.
Retention periods
We retain personal data only for as long as we have a lawful purpose to do so. After the listed period the records are deleted or pseudonymised; aggregate, non-identifiable analytics may be kept.
Your rights as a data subject
- Right of access (Article 15).
- Right to rectification (Article 16).
- Right to erasure (Article 17).
- Right to restriction (Article 18).
- Right to portability (Article 20).
- Right to object (Article 21).
- Right not to be subject to solely-automated decisions (Article 22). We do not run automated decision-making with legal effect.
- Right to withdraw consent at any time.
- Right to lodge a complaint with your local supervisory authority.
Cookies and similar technologies
The shop uses cookies and equivalent storage to make the cart, language switch and account session work, and to measure how visitors and advertising campaigns reach the site.
Security and breach response
We follow a layered security approach: encryption in transit (TLS 1.3 only), encryption at rest on the database, role-based access on the admin console, audit logs on every privileged action, and time-limited support-staff access tokens.
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within seventy-two hours of becoming aware, and we notify affected researchers without undue delay.
Children and minors
The Site and the Service are not directed to anyone under the age of 21. The minimum age to create an account or to place an order is 21 years, regardless of the local age of majority. We do not knowingly collect personal data from minors.
Changes to this Privacy Policy
We update this Privacy Policy when our processing meaningfully changes, for example when we add or remove a processor, change a retention period, or expand to a new jurisdiction. Material changes are notified by email to all account holders.
Google API Services and Gmail user data
Where you connect a Google account, use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The shop does not transfer Google user data to third parties except as necessary to provide or improve the user-facing feature you authorised, to comply with applicable law, or as part of a merger, acquisition or sale of assets.