Privacy Policy
Last updated: July 12, 2026
Overview
Everyday Peptides, LLC respects the privacy of visitors, researchers, and customers. This Privacy Policy explains the personal information we collect, why we use it, how we disclose it, how long we keep it, and the choices available to you.
Notice at collection
Depending on how you use the website, we may collect:
- Identifiers and contact information, such as name, email address, telephone or mobile number, billing address, shipping address, IP-derived information, and device identifiers.
- Research-access information, including age confirmation, researcher type, accepted statement and version, timestamps, signed access-cookie data, token hashes, and cryptographic hashes derived from IP address or browser information.
- Commercial information, including items viewed, cart contents, orders, payment status, returns, claims, coupons, and shipping records.
- Account information, if customer accounts are enabled.
- Communications sent to support or submitted with a return or shipping claim.
- Internet or device activity, such as browser type, device type, referral page, interactions, error logs, and security events.
- Marketing and analytics information, if optional analytics, advertising, email, or SMS tools are later enabled.
We use this information to operate and secure the storefront, document access and checkout attestations, process and deliver orders, communicate with customers, provide support, prevent fraud, maintain records, comply with law, improve operations, and send optional marketing only where permitted.
Information you provide
We collect information you submit through the access gate, checkout, account features, support messages, return or shipping claims, and optional marketing forms. Do not send Social Security numbers, medical records, patient information, clinical information, or unnecessary sensitive information.
Payments
Payment providers collect and process payment information under their own privacy and security practices. Complete payment-card numbers and card security codes are not stored in the WordPress database. We may receive limited transaction information such as payment status, transaction identifier, payment method, card brand or last digits where supplied, billing details, and fraud-screening results.
Research-access records and essential cookie
The access gate places a signed, host-specific, HttpOnly, SameSite=Lax browser cookie that normally expires after 30 days. It allows that browser to re-enter without completing the same attestation on every visit and does not contain a name or email address.
We also keep a server-side audit record that may include researcher type, exact confirmation version and text hashes, date and time, a token hash, and keyed cryptographic hashes derived from the IP address and browser user-agent. These records help document access, prevent abuse, and support compliance. The cookie and record are an access acknowledgment, not identity or credential verification.
Other cookies and similar technology
Essential cookies may support research-access status, shopping-cart and checkout functions, security, fraud prevention, account sessions, and preferences. Blocking essential cookies may prevent the gate, cart, checkout, or account from working.
Analytics or advertising cookies must not be enabled until the actual tools are identified and any required notice, consent, opt-out, and Global Privacy Control handling are in place.
How we use information
- Operate, maintain, and secure the website.
- Record research-access and checkout attestations.
- Review, accept, process, ship, and support orders.
- Detect fraud, abuse, unauthorized access, and payment risk.
- Handle returns, delivery inquiries, and Shipping Protection claims.
- Send order, security, legal, and service communications.
- Maintain financial, tax, operational, and compliance records.
- Analyze and improve website performance.
- Send optional marketing only after the required consent or other lawful authorization.
- Respond to lawful requests and protect legal rights.
Service providers and disclosures
We may disclose only the information reasonably necessary to website hosting, security, e-commerce, payment, fraud-prevention, email, text-support, customer-service, shipping, carrier, label, claim, accounting, legal, and other professional providers. Depending on the live configuration, providers may include Bluehost; WordPress and WooCommerce; FunnelKit; Titan; each enabled payment provider; Pirate Ship or ShipStation and selected carriers; SliceWP if it is enabled; and analytics or advertising providers only if those tools are later activated and disclosed.
We may also disclose information when required by law, to prevent fraud or protect safety and rights, or to a successor in a merger, acquisition, financing, reorganization, or sale of business assets, subject to applicable law.
No sale of personal information
As of the effective date, Everyday Peptides does not sell personal information for money. As of the effective date, we do not share personal information for cross-context behavioral advertising.
Before enabling Meta Pixel, Google advertising, retargeting, or another technology that may constitute a sale or sharing under applicable privacy law, we will update this Policy and deploy any required opt-out and preference-signal controls. Adding a pixel can change this statement even when no customer list is sold for money.
Email and text communications
Transactional messages may administer access, payments, orders, shipping, policy changes, security, claims, and support. Promotional email will include a working unsubscribe method, and valid opt-outs will be honored as required by law.
The number 267-283-1660 is for support texts only and is not answered by voice. Sending a support text does not constitute consent to marketing SMS. Before marketing SMS is introduced, it requires a separate voluntary opt-in, dedicated SMS terms, consent records, and STOP/HELP handling.
Retention
We retain each category only as long as reasonably necessary for the purpose collected, including legal, tax, accounting, fraud-prevention, dispute, safety, and compliance needs. Our general schedule is:
- Completed, refunded, and paid-cancelled orders; tax records; payment-transaction metadata; order-specific checkout attestations; and applicable legal-policy snapshots: seven years after the order or record closes.
- Standalone research-access audit events, including privacy-minimized request hashes: 12 months. The access cookie itself normally expires after 30 days.
- Support, return, Shipping Protection, carrier-claim, and chargeback files: four years after the matter closes.
- Routine security and access logs: generally 90 days. Logs associated with an actual security incident may be retained for up to four years after the incident closes.
- Unpaid pending or failed checkouts and abandoned-cart records: generally 30 days after the last activity or applicable status.
- Customer accounts: while active. An account may be treated as inactive and deleted after 24 months without a login or order, while transaction records that must be retained are preserved or anonymized separately.
- Marketing-consent evidence: while subscribed and for four years after withdrawal or the last marketing message. Minimal suppression information may remain while that marketing program operates so an opt-out can continue to be honored.
Backup copies follow the applicable hosting provider’s rolling overwrite schedule and are not used for ordinary operations. If a backup is restored, applicable deletions are reapplied. We may retain a limited record longer when reasonably necessary for an active transaction, legal hold, tax requirement, dispute, claim, chargeback, fraud review, security investigation, or other legal obligation. Providers may apply their own documented retention schedules to information they process.
Security
We use reasonable administrative, technical, and organizational measures appropriate to the information and our operations. No website, transmission, or storage system can be guaranteed completely secure.
Your choices and privacy rights
You may update checkout or account information, unsubscribe from promotional email, decline optional marketing, adjust browser cookie settings, and contact us to request access, correction, deletion, or a copy of personal information where applicable law provides that right. We may verify identity before fulfilling a request and may retain information where a lawful exception applies.
U.S. state privacy rights
Residents of states with applicable privacy laws may have rights to access, correct, delete, or obtain a copy of personal information and to opt out of certain sale, sharing, targeted advertising, or profiling. If the California Consumer Privacy Act applies to Everyday Peptides, California residents may exercise the rights provided by that law, including applicable rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive information, and receive equal service without unlawful discrimination.
We do not currently sell personal information or share it for cross-context behavioral advertising. Where legally required, we will recognize applicable opt-out preference signals, including Global Privacy Control. We do not presently respond to the older, non-standardized browser “Do Not Track” signal.
Submit a request to info@everydaypeptides.ltd with “Privacy Request” in the subject line. You may also write to the address below or use the text-support number.
People under 21
The storefront is not intended for anyone under 21. We do not knowingly authorize access or purchases by anyone under 21. Contact us if you believe a person under 21 submitted information.
Changes to this Policy
We may update this Policy as services, plugins, providers, laws, or business practices change. The current version and updated date will remain publicly available.
Contact
Everyday Peptides, LLC
502 W 7th St, Ste 100
Erie, PA 16502
Email: info@everydaypeptides.ltd
Text support only: 267-283-1660
Voice calls are not answered.
This public address is for company and legal correspondence. It is not the merchandise return address.