Privacy Policy
Privacy Policy Effective: August 28, 2026
1. Scope. This policy explains how Protocol Bioscience LLC d/b/a Protocol Peptides ("we," "us") collects, uses, and shares personal information when you use our site or place an order.
2. Information we collect.
- You provide: name, shipping address, email address, order contents, and account credentials if you create an account.
- Research profile. Because we supply research-use-only materials, an account must carry a research profile before it can order. We collect: your organization or institution name and type, your lab, department, or group, your position or title, your stated research purpose and research focus, your organization's website, your country, a work or institutional email address, and — optionally — a tax identification number, a LinkedIn profile URL, and an ORCID iD. We confirm control of the work email address by sending it a one-time link, and we check any ORCID iD you give us against ORCID's public API. We record the outcome of that review, the reasons for it, and any internal notes our reviewers write.
- Marketing consent. If you choose to receive marketing email, we keep a record of that choice: your email address, the exact wording you agreed to and its version identifier, where you gave or withdrew consent, and the date and time. We keep every change, so the record shows if you opted in, opted out, and opted in again. We keep it because we have to be able to show that an address on our marketing list agreed to be there, and because a withdrawal we cannot evidence is a withdrawal we cannot prove we honoured. We do not record your IP address or browser against this choice.
- Research-use attestation. When you submit a research profile and again at each checkout, we retain the attestation you accept: the verbatim text, its version identifier and a cryptographic hash of it, the date and time of acceptance, the IP address and browser user-agent string of the request in which you accepted it, and the account and organization it was accepted under.
- Order compliance record. For each order we retain a record combining the above: the attestation version and timestamp, the IP address and user-agent of acceptance, your account and organization, the shipping address, and — where our payment processor provides one — an opaque payment-instrument fingerprint. We never receive or store full card numbers or security codes.
- Automatically: IP address, device and browser information, and general location (used to enforce shipping restrictions), plus the cookies and local storage described in §7.
- Aggregate usage analytics. We collect which pages are viewed, the referring site or campaign tag, approximate location (country or region level), and device and browser class. This is collected by analytics software we run on our own servers, it is not linked to your account or to you as an individual, and it sets no cookie and no persistent identifier — see §7.
Why we collect the IP address and user-agent with an attestation. These are kept as evidence of who accepted the research-use terms and when, so that we can demonstrate to our payment providers, banks, auditors, and regulators what controls applied to a given order. They are used for that purpose, for fraud and abuse prevention, and for nothing else — in particular, not for advertising or profiling.
- Payments: cryptocurrency payments are processed by our third-party payment processor. We receive and retain the payment status, the amount, the asset used, and transaction identifiers. We never receive or store your wallet private keys. Note that blockchain transactions are public by design; we do not control what third parties can infer from on-chain data.
3. How we use it. To process and ship orders, enforce age and geographic restrictions, verify that purchasers are qualified researchers and decide whether an account may purchase, retain the research-use attestation and the per-order compliance record, provide support, prevent fraud and abuse, demonstrate our compliance controls to payment providers, banks, auditors, and regulators, and comply with law. We do not use your information for third-party advertising or for automated profiling beyond the research-profile review described in §2.
If, and only if, you have asked us to, we also use your email address to send you marketing email about new products, restocks, and research-use offers. This is separate from the order and account emails you receive because you bought something, which we send regardless. You can stop marketing email at any time using the unsubscribe link in any such message or by emailing <support@protocolpeps.com>, and we act on it without asking why.
4. Sharing. We share personal information only with service providers needed to run the store — shipping carriers, our payment processors, hosting and infrastructure providers, and error-monitoring services — and with authorities where legally required. We do not sell or share personal information for advertising purposes. Our usage analytics adds no third party: that software runs on our own infrastructure, so the data described in §2 is not sent to an analytics vendor.
4a. Payment processing. Depending on how you choose to pay, your payment is handled by one of the following, and only the information that processor needs is shared with it:
- Card, Apple Pay and Google Pay — processed by Stripe. Your card details are sent from your browser directly to Stripe. We never receive or store your full card number. We receive only the last four digits, the card brand, and whether the payment succeeded.
- Cryptocurrency — processed by our cryptocurrency payment processor, which receives the order amount and a payment reference.
- Bank transfer, Venmo, wire, and purchase orders — settled directly with you. We record what you tell us you sent and who confirmed receipt.
4b. Fraud detection by Stripe. Stripe collects identifying information about the devices that connect to its services, and uses it to operate and improve those services, including fraud detection. On our site this happens on the checkout page, when payment details are entered — not while you browse the catalog. Stripe uses this information to decide whether a payment is likely to be fraudulent, and a payment may be declined on that basis. You can read Stripe's privacy policy at stripe.com/privacy.
5. Retention. We retain order records, research-use attestations, and the per-order compliance record described in §2 for 7 years to meet legal, tax, and audit obligations. This includes the IP address and user-agent captured with each attestation. Research profiles, their review history, and reviewer notes are retained for the same period, because they are the record of the controls that applied to your orders. Server and diagnostic logs are retained for approximately 90 days. Account data is retained until you ask us to delete it, subject to these retention periods.
Marketing consent records are retained for 7 years, the same period as order records, because they are the evidence that a message we sent was one you asked for. Withdrawing consent does not delete this record — it adds the withdrawal to it. Deleting the history would remove our proof that we stopped when you asked. A deletion request under §6 still reaches this record; once it is gone we have no consent on file, which means we do not email you.
6. Your rights. Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to opt out of sale or sharing (we do neither). To exercise any right, email support@protocolpeps.com from the address associated with your order. We will verify and respond as applicable law requires.
Where we rely on your consent — currently only for marketing email — you may withdraw it at any time, and withdrawing is as easy as giving it: use the unsubscribe link in any marketing message, or email us. Withdrawing consent does not affect anything we did while it was in force.
We do not discriminate against you for exercising your rights.
7. Cookies & local storage. Everything we store in your browser is listed below. All of it is first-party — set by this site, readable only by this site — and none of it is shared with an advertising network or any other third party.
| What | Where | Kept for | What it does | |---|---|---|---| | Cart identifier | Cookie | 7 days | Remembers your basket between pages. | | Sign-in token | Cookie | 7 days | Keeps you signed in, if you have an account. | | Language preference | Cookie | 1 year | Remembers the language you chose. | | Cache identifier | Cookie | 1 day | A random value that keeps your cached pages separate from other visitors'. It identifies a cache partition, not you. | | Referral identifier | Cookie | 60 days | If you arrived through a referral or affiliate link, records who referred you so their referral can be credited if you order. | | Age acknowledgment | Local storage | Until cleared | Remembers that you confirmed you are of age, so we do not ask again. | | Order-receipt marker | Session storage | Until the tab closes | Stops a single order being counted twice. | | Affiliate sign-in token | Cookie | 7 days | Only if you are one of our affiliates and sign in at affiliates.protocolpeps.com to fetch your own link and collateral. Keeps you signed in there. It is never set by the shop, and a customer will never receive it. |
The referral identifier is not strictly necessary and we are not claiming it is. It exists so that a person who introduced you to us can be paid, and it is the one item above that serves us rather than you. It records an identifier for the referrer — not for you. It is not used to build a profile, is not read by anyone else, and is not combined with your browsing to target you with anything.
The affiliate sign-in token is for a different audience, and it is listed anyway. It is set only on affiliates.protocolpeps.com, only after somebody follows a sign-in link we emailed them, and only for people who have an affiliate agreement with us. A shopper cannot obtain it and will never be sent one.
We could have argued it sits outside this policy on that basis. We are listing it instead, because the sentence above says everything we store in your browser is below, and a reader should not have to reason about which of our hostnames a promise covers. Unlike the referral identifier, this one is strictly necessary: it is what keeps an affiliate signed in to their own account, and there is no version of that feature without it.
What none of this does. No third-party or advertising cookies. No tracking of you across other websites. No profiling, and no automated decisions about you. No selling or sharing of this data — see §4 for the only parties who receive anything at all.
Our usage analytics is cookieless. It sets no cookie, writes nothing to your browser's storage, and assigns you no persistent identifier — so there is nothing to carry your activity between visits and nothing that could later be tied back to you. Visits are counted using a value derived on our server from your IP address and browser type, combined with a secret that rotates, and that value cannot be reversed to recover either. This is deliberate rather than incidental: analytics that needed your consent would mean putting a consent banner in front of the site, and we would rather collect less.
Our forward commitment, and an amendment to it. An earlier version of this section said we used strictly necessary cookies only, and promised that if that changed, "this policy and a consent mechanism will be updated first." The referral identifier changed it. We have updated this policy in the same release that introduced the cookie, so no visitor received it while this section still said otherwise — but we did not build a consent mechanism, and we are recording that plainly rather than quietly dropping the promise.
Going forward we are making a narrower commitment we can actually keep: we will not set anything in your browser for advertising, cross-site tracking or profiling, and we will not share what is listed above with a third party for those purposes. If we ever intend to, we will ask you first. You can also refuse or delete all of it in your browser settings; doing so will sign you out and empty your basket, and the age prompt will return.
8. Security. We use reasonable technical and organizational measures to protect your information, including encryption in transit. No method of storage or transmission is 100% secure.
9. Where data is stored. Our infrastructure is hosted in Iceland (within the EEA) and may be accessed from the United States for operations and support. This includes the usage analytics described in §2: it is stored on that same infrastructure, in Iceland, and is not transferred to an analytics provider.
10. EU/UK visitors. If you are in the EU, EEA, or UK, we process your personal data to perform our contract with you (orders), to comply with legal obligations (records, tax), for our legitimate interests (fraud prevention, security), and — for marketing email only — on the basis of your consent, which you may withdraw at any time (§6). You additionally have the rights to data portability, restriction of processing, objection, and to lodge a complaint with your supervisory authority. Contact support@protocolpeps.com to exercise these rights.
11. Children. The site is not directed to anyone under 21; we do not knowingly collect information from minors.
12. Changes. We may update this policy; the effective date reflects the current version. Material changes will be noted on this page.
13. Contact. support@protocolpeps.com — Protocol Bioscience LLC, 30 N Gould St, Sheridan, WY 82801, USA.