Every lot independently tested — see its certificate of analysis before you buy.Batch-linked purity, price and stock — the exact vial on our shelf, never an aggregate.
Legal

Privacy policy

How Peptaion collects, uses, and protects personal data when you use this website or place an order, in accordance with the EU General Data Protection Regulation.

Last updated 25 July 2026

1. Who we are

Peptaion OÜ ("Peptaion", "we", "us") is the data controller for personal data processed through peptaion.com. For any question about this policy or your data, email [email protected].

2. Data we collect

When you place an order: your name, email address, shipping address, and phone number if you provide one.

When you create an account: the email you register with and your order history.

When you subscribe to research updates: your email address, the date consent was given, and any research areas you choose to follow so we can tailor what we send.

When you ask to be notified that a product size is back in stock: your email address, the size requested, and the request and confirmation dates.

When you use the support chat: the messages you type in the conversation, and the optional reply email you may attach to feedback.

Automatically, when you browse the site: your IP address, browser type, and the pages you visit, for security and to keep the site working correctly.

We do not collect payment card details — cryptocurrency and bank-transfer payments are handled directly by the relevant payment processor or your bank, not stored by us.

3. Why we process your data

To fulfil and ship an order, and to provide customer support (performance of a contract).

To keep accounting and tax records (legal obligation).

To secure the website and prevent fraud (legitimate interest).

To send research updates, only where consent has been given (withdrawable at any time).

4. Who we share it with

We share only what is necessary to fulfil an order: shipping details with our courier, and payment details with the payment processor chosen at checkout. Third-party providers host the website, manage its content, and monitor it for errors; each processes data only on our instructions and under a data processing agreement.

We do not sell, rent, or trade personal data to third parties for marketing purposes.

5. International transfers

Our infrastructure is hosted within the European Economic Area. Where a service provider processes data outside the EEA, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

6. Support chat and feedback

The on-site support chat is automated. To generate a reply, the text of your conversation is processed by our AI provider (Anthropic) under a data processing agreement — only what you type in the chat is sent; your account, order, and payment records are never attached automatically. Support conversations are not used for analytics, profiling, or marketing.

Continuing a conversation on WhatsApp is optional and happens only when you choose to open the link yourself; the emailed conversation transcript goes to our own support mailbox. Feedback submitted through the widget is kept as the intake for the public commitments board, and a reply email you attach is used only to respond to you.

Support conversations are deleted automatically 90 days after they start.

7. Site measurement

To understand how the site is used, we count page and catalog activity ourselves, on our own infrastructure — no third-party analytics service, script, or tracker is involved.

This measurement is identifier-free by construction. No cookie is set and nothing is stored on or read from your device for it; no session identifier, visitor identifier, IP address, or browser fingerprint is recorded. Each measurement is a simple daily total — for example, how many times a product page was viewed on a given day — so what we keep is aggregate statistics that cannot describe or identify any individual visitor.

What we count: product page views and add-to-cart clicks, checkout starts, research-area and library-article page views, and the search terms and filter options used in the catalog. Orders and revenue are taken from our own order records, not from browsing measurement.

Because these totals contain no personal data, there is nothing to consent to and nothing to delete; they are kept as long-term site statistics. Browsers that send a Do Not Track or Global Privacy Control signal are additionally excluded from this counting altogether.

8. Back-in-stock requests

You can ask to be emailed once when a specific product size is back in stock. We store only your email address, the size requested, and the request and confirmation dates — nothing else. The request is activated by a confirmation link sent to your address (double opt-in), and it is separate from the research-updates list: neither signs you up for the other.

The request is used for exactly one message: when that size is available again, we send a single email and the request is complete. Unconfirmed requests are deleted after 7 days; confirmed requests are held for up to 6 months and then deleted if the size has not returned; once the notification is sent, the request record is deleted within 30 days.

Every email about a request carries a cancellation link that removes all requests held for your address immediately.

9. How long we keep data

Order and invoice records: 7 years, to meet accounting and tax obligations.

Account data: for as long as the account is active, or until deletion is requested.

Research-updates consent: until you unsubscribe.

Back-in-stock requests: per the windows above — at most 6 months.

Support-chat conversations: deleted automatically after 90 days.

10. Cookies

This website uses only strictly necessary cookies — a session cookie that keeps a signed-in visitor logged in, and nothing else. We do not use marketing, advertising, or third-party analytics cookies, so there is no cookie-consent banner to show.

11. Your rights

Under the GDPR you may ask to access, correct, or delete your personal data, restrict or object to its processing, or receive a copy of it in a portable format. Where processing is based on consent, it may be withdrawn at any time. Send a request to [email protected]; we respond within 30 days.

If you have an account, you can act on most of these rights yourself from your account page: download a copy of your own data at any time, manage or turn off your research-updates subscription and any back-in-stock requests, and delete your account.

Deleting your account removes your sign-in, your saved email addresses, your reviews, your research-updates subscription, and any back-in-stock requests, and signs you out. Your past order and invoice records are the one thing we cannot erase on request: Estonian accounting law requires us to keep source documents for seven years from the end of the financial year in which the transaction was recorded, and the GDPR expressly preserves this obligation. We keep those records only as accounting documents, reachable by us and our accountant and no longer through any login, and we delete them once that period ends.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority in your own EU member state.

12. Security

Data is encrypted in transit, and access to personal data is restricted to those who need it to run the business.

13. Changes to this policy

We may update this policy from time to time; the current version applies. Material changes are reflected in the "last updated" date on this page.