1. Scope

This Privacy Policy explains how Peptide Exchange ("the Platform", "we") collects, uses, and protects personal data of buyers, sellers, and visitors. It applies to all uses of the Platform and supplements our Terms of Service.

2. Data we collect

Account data. Name, email address, role, organization or institution, and account credentials (stored as salted hashes).

Verification data. For buyers: proof of licensure or institutional affiliation. For sellers: identity documents and business details submitted for KYC review. These are reviewed by Platform administrators and retained as described in Section 6.

Order and listing data. Orders, invoices, payment references, shipping addresses, listing details, Certificates of Analysis, and product photos. Per-order attestation records, including the attestation version and locale, are retained as compliance records.

Technical data. IP address, approximate geolocation (used for the geo-blocking control), browser and device characteristics, and audit-log entries recording authentication, attestation, checkout, and administrative actions.

Communications. On-platform dispute and conversation messages between buyers, sellers, and administrators.

3. How we use data

We use personal data to: (a) operate and secure the Platform; (b) verify eligibility, licensure, and institutional status; (c) process orders, payments, and refunds; (d) enforce the research-use-only restriction and detect non-research use, fraud, or abuse; (e) comply with legal, tax, and record-keeping obligations; (f) provide support and resolve disputes; and (g) improve the Platform. We do not sell personal data, and we do not use it for advertising profiling.

4. Legal bases

Where the GDPR applies, we process personal data on the bases of contract performance (Section 2), legal obligation (verification and compliance records), legitimate interest (security, fraud prevention, and Platform improvement), and consent where we ask for it. Where the CCPA/CPRA applies, you have the right to know, delete, and correct your personal data and to opt out of any sale or sharing of personal data — we do not sell or share personal data.

5. Sharing

We share personal data only with: (a) payment processors, to the extent required to execute payments and refunds; (b) hosting and infrastructure providers; (c) professional advisers, where necessary for legal or compliance purposes; and (d) authorities, where required by law or where necessary to prevent serious harm. Third-party sellers receive only the data needed to fulfil an order (shipping details, order references, and, where applicable, NET-terms billing details). [Counsel: confirm processor list and DPA requirements for target jurisdictions.]

6. Retention

Account data is retained while the account is active. Verification, attestation, order, and audit records are retained for the periods required by applicable law and for the limitation periods relevant to the Platform's compliance obligations — at minimum [MINIMUM RETENTION PERIOD, e.g., 3 years] from the related transaction. [Counsel: confirm retention schedule for KYC, attestation, and financial records in the operator's jurisdiction.]

7. Security

We protect personal data with encryption in transit, hashing of credentials and API keys, rate limiting on sensitive endpoints, role-based access for administrators, and a full audit trail of administrative actions. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

8. Your rights

Subject to applicable law, you may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing. At launch, these requests are handled manually: contact us using the details in Section 13, and we will verify your identity and respond within the timeframe required by applicable law. Where deletion conflicts with our compliance record-keeping obligations, we will restrict rather than delete. [Self-service export/deletion tooling is planned for a later phase (PLAN §12.1, M13); until it ships, all rights requests are fulfilled manually as described above.]

9. Cookies

The Platform uses only strictly necessary cookies and session storage: authentication and security (CSRF protection), and preference cookies that remember a choice you made yourself (display currency, interface theme). We do not use advertising or cross-site tracking cookies.

10. International transfers

Data is stored and processed on infrastructure in [REGION]. Transfers of personal data across borders are made on appropriate legal grounds, including adequacy decisions, standard contractual clauses, or the operator's lawful bases. [Counsel: confirm transfer mechanism for the operator's hosting region and target jurisdictions.]

11. Minors

The Platform is not directed to, and does not knowingly collect data from, anyone under 18. Accounts are restricted to individuals aged 21 or older (see Terms Section 3).

12. Changes to this Policy

We may update this Policy. Material changes will be announced on the Platform and take effect 30 days after notice, except where law requires a shorter period.

13. Contact

Privacy questions or requests: [OPERATOR EMAIL / DATA-PROTECTION CONTACT].