Iluma Peptide Co.

Legal

Privacy Policy

What we collect, why we collect it, and how we keep it safe. We don't sell your data — ever.

Effective 2026-05-04

1. What we collect

  • Account data: name, email, and password hash when you register.
  • Order data: items purchased, prices, and shipping address.
  • Payment data: we never see your card numbers or wallet keys. Crypto payments are processed by NOWPayments; we receive only the on-chain transaction hash and confirmation status.
  • Site analytics: aggregated, anonymized page-view data. We do not use third-party advertising trackers.
  • Communications: emails you send to support and any messages exchanged via the contact form.

2. How we use it

  • To process and ship your orders.
  • To provide customer support and respond to inquiries.
  • To send transactional emails (order confirmation, shipment tracking) and — only if you opt in — newsletters about new products and restocks.
  • To improve site reliability and fix bugs.
  • To comply with legal obligations.

3. We do not sell your data

We do not, and will not, sell, rent, or trade your personal data to advertisers, data brokers, or any other third party.

4. Service providers

We share data only with the service providers strictly necessary to operate the Site:

  • Supabase — account, order, and content database (hosted in the US).
  • NOWPayments — cryptocurrency payment processing.
  • Resend — transactional email delivery.
  • Shipping carriers — receive only the address required to deliver your order.

Each provider is contractually bound to use your data only for the services we engage them for.

5. Data retention

  • Order records are retained for 7 years to satisfy tax and accounting obligations.
  • Account data is retained until you request deletion.
  • Marketing consent is retained until you unsubscribe.

6. Your rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data (some order records may be retained as required by law).
  • Export your data in a portable format.
  • Withdraw marketing consent at any time.

To exercise any of these rights, email research@ilumapeptide.co. We respond within 30 days.

7. Security

Account passwords are hashed using industry-standard algorithms and never stored in plaintext. All data is encrypted in transit (TLS 1.3) and at rest. Access to production systems is restricted to authorized personnel with two-factor authentication.

8. Cookies

We use a small number of strictly necessary cookies for site functionality (authentication, age gate acknowledgment). We do not use advertising or third-party tracking cookies.

9. Children

The Site is not directed to anyone under 21. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us so we can remove it.

10. Changes

We may update this policy. The "Effective" date above reflects the most recent revision. Material changes will be announced on the Site or via email.

11. Contact

Privacy questions or requests? Email research@ilumapeptide.co.