Home
Tools About Contact

Privacy Policy

Peptide.ST Last updated July 27, 2026 Netherlands
01

Introduction

Peptide.ST ("we," "us," or "our") is committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) and Dutch data protection law.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have regarding your data when you visit peptide.st or place an order with us.

By using our website, you acknowledge that you have read and understood this Privacy Policy. We may update this policy from time to time, the "Last updated" date at the top of this page always reflects the most current version.

02

Data We Collect

We collect personal data only when it is necessary to provide our services. The categories of data we may collect include:

  • Identity data: Full name, company or institution name
  • Contact data: Email address, phone number, billing and shipping address
  • Transaction data: Order history, payment method type (we do not store full card details), and invoices
  • Technical data: IP address, the approximate country derived from it, browser type, device information, and operating system. Section 7 explains in full where your IP address is used, why, and for how long it is kept
  • Usage data: Standard web server request logs (page requested, timestamp, referring URL) kept by our hosting provider
  • Communication data: Messages sent via our contact form or support email
  • Marketing preferences: Your opt-in or opt-out status for newsletters and promotional emails

We do not collect sensitive personal data (such as health, biometric, or financial account data) beyond what is strictly required to process your order.

03

How We Use Your Data

We use your personal data solely for the purposes for which it was collected. These purposes include:

  • Processing and fulfilling your orders, including shipping and invoicing
  • Communicating with you about your order status, refunds, or support inquiries
  • Sending newsletters and product updates (only with your explicit consent)
  • Showing you the correct currency, delivery country, and shipping rate at checkout
  • Keeping the website secure and preventing spam, fraud, and payment abuse
  • Complying with legal obligations, such as tax record-keeping and customs declarations
  • Verifying buyer eligibility for research peptide purchases

We do not build visitor profiles, we do not use behavioural advertising, and we do not run third-party analytics or advertising trackers on this website. We will never sell, rent, or trade your personal data to third parties for their own marketing purposes.

05

Data Sharing

We may share your personal data with trusted third-party service providers who assist us in running our business, always under strict data processing agreements. These include:

  • Payment processors: To handle transactions securely (e.g. Stripe, Mollie)
  • Shipping carriers: To dispatch and track your order
  • Email service providers: To deliver order confirmations and newsletters
  • IP geolocation provider: ip-api.com, which receives your IP address at checkout and returns only a two-letter country code (see Section 7)
  • Address lookup provider: photon.komoot.io, used only while you type an address in the checkout search field
  • Hosting provider: Which operates the servers and keeps standard web server logs
  • Legal or regulatory authorities: Where required by applicable law or court order

All third-party processors are contractually required to handle your data securely, only for the specified purposes, and in compliance with the GDPR.

06

Cookies & Tracking

We use a small number of first-party cookies. We do not use analytics cookies, advertising cookies, or third-party tracking pixels, and we do not share cookie data with advertising networks. The cookies we set are:

  • vfy_access: Strictly necessary. Grants access to the checkout after you arrive from our product pages. Session-based and signed
  • pst_ref: Functional. Stores a referral code when you arrive through a partner link, so the referral can be credited. Expires after 30 days
  • ship_country: Preference. Remembers the delivery country you selected, so your own choice takes priority over automatic detection
  • Session cookies: Strictly necessary. Keep your cart and your sign-in state on administrative pages working during a visit

Because we set no analytics or marketing cookies, there is no consent banner to accept or reject. You can delete or block cookies at any time through your browser settings. Note that blocking the strictly necessary cookies will prevent checkout from working.

07

IP Addresses & Location Detection

We do not block, ban, or refuse access to this website based on your IP address or your location. Every visitor from every country can reach every page. This section explains exactly where your IP address is used, why, on what legal basis, how long it is kept, and which external services are involved.

Country detection at checkout

When you open our checkout page, your IP address is sent to the lookup service ip-api.com, which returns a two-letter country code and nothing else. We use that country code only to:

  • Pre-select your country in the delivery form
  • Display prices in the matching currency (EUR, or USD for the United States)
  • Show the shipping rate that applies to that country

You can change the country yourself at any time with the country selector, and your own choice always overrides the detected one. The lookup happens once per page load, the result is not written to any database, it is not linked to your name, email, or order, and it is not used for profiling, advertising, or access control. Visitors on local or private network addresses are not looked up at all.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely presenting the correct currency and delivery options without asking every visitor to configure them manually. Retention: none, the country code exists only for the duration of the page request.

Delivery restrictions are based on the address, not on your IP

We cannot ship to a small number of countries, currently Norway, Sweden, and Finland, because shipments to those destinations are seized by customs and cannot be delivered or refunded. Those countries are therefore not offered in the delivery country list. This restriction applies to the delivery address you choose, not to your IP address or your location: residents and visitors of those countries can browse the entire website, read all content, and order to any address in a country we do ship to.

IP addresses we store

We record an IP address in the following situations, and nowhere else:

  • With a completed order: the IP address used to place the order is stored with the order record, as evidence in the event of payment fraud, a chargeback, or a disputed transaction. Legal basis: legitimate interest (fraud prevention and defence of legal claims). Retention: with the order record, which we must keep for 7 years under Dutch tax law
  • With a newsletter signup: the IP address is recorded together with the email address and timestamp, as proof that the subscription was requested from that device. Legal basis: our accountability obligation to demonstrate consent (Article 7(1) GDPR). Retention: for as long as you remain subscribed, and removed when you unsubscribe
  • With a contact or complaint form submission: the IP address is included in the notification email that reaches our support mailbox, so that abusive or automated submissions can be recognised. It is not written to any database. Legal basis: legitimate interest (spam and abuse prevention). Retention: with the support message, 3 years from last contact
  • In standard web server logs: our hosting provider records requests, including IP address, as every web server does. These logs are used only for security and troubleshooting. Legal basis: legitimate interest (security and availability). Retention: a limited period in line with our hosting provider's standard log retention

These records are stored outside the public web root and are accessible only to authorised personnel. They are never sold, never shared for marketing, and never used to build a profile of you.

External services that receive your IP address

As with any website, some parties necessarily see your IP address because your browser connects to them directly, or because we pass it on for a specific purpose:

  • ip-api.com: country lookup at checkout, as described above
  • Stripe: our payment processor, for payment processing and its own fraud checks
  • photon.komoot.io: address autocomplete, only while you are typing in the address search field
  • Our hosting provider and content delivery hosts: for serving the website, its fonts, images, and scripts

We use no analytics, advertising, or tracking service of any kind. If you would prefer that no country lookup takes place, you can reach the site through a VPN or privacy proxy, which changes nothing about your ability to use it, or contact us and we will tell you exactly what is recorded against your order.

08

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes it was collected for, or as required by applicable law. Our general retention periods are:

  • Order & transaction data: 7 years (Dutch tax law requirement)
  • Account & contact data: Duration of the customer relationship + 2 years
  • Marketing data: Until you withdraw consent or unsubscribe
  • IP address stored with an order: With the order record, 7 years (see Section 7)
  • IP address stored with a newsletter signup: Until you unsubscribe
  • IP address in server logs: A limited period, in line with our hosting provider's standard log retention
  • Support communications: 3 years from last contact

After the applicable retention period, your data is securely deleted or anonymized.

09

Your Rights

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention obligations
  • Right to restriction: Request that we limit the processing of your data in certain circumstances
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent: Withdraw consent for consent-based processing at any time

To exercise any of these rights, please contact us using the details in Section 13. We will respond to your request within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

10

Data Security

We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

These measures include SSL/TLS encryption for all data in transit, secure server infrastructure, access controls limited to authorized personnel only, and regular security reviews. Our payment processing is handled by PCI-DSS compliant third-party providers, we never store full payment card details on our systems.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in accordance with GDPR Article 33 and 34.

11

International Transfers

Peptide.ST is based in the Netherlands and primarily processes data within the European Economic Area (EEA). Where we use service providers located outside the EEA (such as our payment processor, email platform, or the IP country lookup described in Section 7), we ensure appropriate safeguards are in place, including:

  • European Commission Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules (BCRs) where applicable

You may request details of the safeguards in place for any specific international transfer by contacting us.

12

Minors

Our website and products are strictly intended for individuals aged 18 and over. We do not knowingly collect or process personal data from persons under the age of 18.

If we become aware that personal data from a minor has been submitted to us without verified parental consent, we will promptly delete that data. If you believe a minor has provided us with personal data, please contact us immediately.

13

Contact & DPO

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:

We are committed to resolving any privacy concerns promptly. If you are not satisfied with our response, you have the right to escalate your complaint to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).