Research Use Only · Not For Human Or Animal Consumption · 21+ Only

Legal · Research Use Only

Privacy Policy

Last updated: November 21, 2026

Research Use Only Notice

That Peptide Store sells materials strictly for in-vitro laboratory research. Products are not drugs, cosmetics, dietary supplements, or food and are not intended for human or animal consumption, ingestion, therapeutic, diagnostic, or clinical use. Accounts are restricted to qualified researchers who are at least 21 years of age.

1. Who we are

This Privacy Policy describes how That Peptide Store ("we", "us", "our") collects, uses, and protects information from researchers who create an account or place an order for research materials on thatpeptidestore.com and through the That Peptide Store mobile app for iOS and Android (collectively, the "Service"). This page is maintained by That Peptide Store and is the authoritative source referenced by our Apple App Store and Google Play listings.

Data controller: That Peptide Store, Odessa, TX, United States. Contact: privacy@thatpeptidestore.com.

2. Information we collect

  • Account information: full legal name, email address, date of birth, and password (stored hashed).
  • Compliance confirmations: your 21+ age confirmation, research-use consent, and Privacy Policy acknowledgment, with timestamps.
  • Order information: shipping address, items ordered, subtotal, taxes, delivery method, and payment method (we do not store full card numbers).
  • Phone number (optional): collected only if you enable SMS order-status alerts, and verified via a one-time code.
  • Support & correspondence: messages you send us and support ticket history.
  • Technical data: device model, OS version, browser, IP address, approximate location derived from IP (country/region only), and basic analytics needed to operate and secure the Service.
  • Mobile push token (mobile app only): a Firebase Cloud Messaging token generated by your device when you grant notification permission. Used solely to deliver order and shipping notifications you have opted into. You can revoke notification permission at any time in your device settings.
  • Crash and diagnostics: anonymized crash reports and performance traces to keep the app stable. No message content, order content, or personal identifiers are attached.

We do not collect precise GPS location, contacts, photos, microphone data, health or fitness data, biometric identifiers, or browsing history outside our Service.

3. Why we collect it

  • To verify you meet the 21+ research-use eligibility requirement.
  • To process and ship research-material orders.
  • To provide receipts, tracking, subscriptions, and rewards.
  • To detect fraud, prevent abuse, and comply with legal obligations.
  • To send transactional email (order confirmations, shipping, receipts) and — only if you opt in — research updates.
  • To send push notifications you have opted into (order updates, shipping alerts, and — only if you opt in separately — restock notifications).

3a. Data collection summary (mobile app disclosures)

The following table maps to Apple's App Privacy and Google Play's Data Safety categories.

Data typePurposeLinked to youUsed for tracking
Name, emailAccount, supportYesNo
Phone numberOrder-status SMS (opt-in)YesNo
Shipping addressOrder fulfillmentYesNo
Payment infoPurchases (via processor)YesNo
Purchase historyApp functionality, reorderYesNo
Push notification tokenOrder/shipping notificationsYesNo
Device ID, IP addressSecurity, fraud preventionYesNo
Product interactionsFirst-party analyticsNoNo
Crash logs, diagnosticsApp stabilityNoNo

We do not use any collected data for cross-app or cross-site tracking, and we do not share data with data brokers or advertising networks.

4. Age & research-use eligibility

You must be at least 21 years old and acting in a research capacity to create an account. We store your date of birth and the timestamp of your 21+ and research-use confirmations as a compliance record. We do not knowingly collect information from anyone under 21.

Children's privacy (COPPA). The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 21. If we learn that we have collected information from a child, we will delete it. Parents or guardians who believe a child has submitted information should email privacy@thatpeptidestore.com.

5. How we share information

We do not sell your personal information. We share the minimum information needed with vetted service providers who help us operate: payment processors, shipping carriers, email/SMS providers, hosting and database providers, and fraud-prevention tools. Providers are contractually restricted to using data only to perform their services for us. We may disclose information if required by law or valid legal process.

Named subprocessors:

  • Supabase — database, authentication, and file storage (US)
  • Cloudflare — DNS, CDN, edge runtime (global)
  • Firebase Cloud Messaging (Google) — mobile push delivery only
  • Resend — transactional email delivery
  • Stripe, PayPal, Cash App — payment processing (they act as independent controllers of payment data)
  • Shipping carriers (USPS, UPS, FedEx) — order delivery

6. How we protect information

Traffic is encrypted in transit (HTTPS). Passwords are stored hashed. Account data is protected by row-level security so only you (and authorized admins for order fulfillment) can access it. Payment card details are handled by PCI-compliant processors and never stored on our servers.

7. Retention

We retain account and order records for as long as your account is active and for a reasonable period afterward to comply with tax, accounting, and legal-hold obligations. You may request deletion of your account at any time (see Section 9).

Typical retention windows: account data — for the life of the account plus 30 days after deletion request; order and tax records — 7 years (US tax law); support tickets — 3 years; push tokens — until you disable notifications or uninstall the app; crash logs — 90 days.

8. Cookies & analytics

We use strictly-necessary cookies to keep you signed in and to remember cart state. We use limited first-party analytics to understand how the site is used and to improve reliability. We do not use third-party advertising cookies.

9. Your choices & rights

  • Access, correct, or delete your account information from your account settings, or by emailing us.
  • Unsubscribe from marketing email at any time using the link in any marketing message.
  • Request a copy of your data or ask us to erase it, subject to legal record-keeping requirements.
  • Turn off push notifications at any time in your device settings (iOS: Settings → Notifications → That Peptide Store; Android: long-press the app icon → App info → Notifications).
  • Revoke SMS opt-in by replying STOP to any message from us or by removing your phone number in Account settings.
  • Delete your account and all associated data in-app from Account → Delete my account, or by emailing privacy@thatpeptidestore.com. When you submit the in-app request we immediately sign you out of every device and schedule your account for permanent deletion in 30 days. During this grace period you can sign back in and cancel the request to restore your account with no data loss. On the purge date we anonymize your profile (name, email, phone, shipping address, referral code) and strip the same fields from your past orders; order ids, dates, item lists, and totals are retained to comply with tax and accounting obligations. Auth login sessions are permanently revoked.

US state privacy rights (CA, CO, CT, UT, VA, TX, and others): Residents of these states have the right to know what personal information we collect, to request a copy, to correct inaccuracies, to request deletion, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as defined by these laws. To exercise any right, email privacy@thatpeptidestore.com. We will verify your request via your account email and respond within 45 days.

International users. The Service is operated from the United States. If you access it from outside the US, you consent to transfer and processing of your information in the United States, which may have different data-protection rules than your country.

9a. Mobile app permissions

  • Notifications — required for order and shipping alerts. Optional; you can decline or revoke.
  • Camera — used only if you scan a batch QR code to verify authenticity. Images are processed on-device and never uploaded.
  • Network access — required to reach our servers.

The app does not request contacts, precise location, microphone, health, calendar, or photo library access.

9b. Security incidents

If we discover a security incident that affects your personal information, we will notify affected users without undue delay and as required by applicable law. Report suspected vulnerabilities to security@thatpeptidestore.com.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of the site after changes take effect constitutes acceptance of the updated policy.

11. Contact

Questions about this policy or your data? Contact us or email privacy@thatpeptidestore.com. For a copy of the data-safety declarations we submit to Apple and Google, see the tables in Sections 2, 3a, and 5 above — they are the authoritative source referenced by our store listings.