← Home

Privacy Policy

Last updated: 16 August 2026

We collect only what we need to take an order, deliver it and answer your questions. This shop runs no advertising or analytics tracking — the only cookie we set is the one that keeps you signed in.

Who is responsible for your data

Decode Peptides is the data controller for the personal data described on this page. If you have any question about how we handle it, or you want to exercise one of the rights listed below, email [email protected].

What we collect and why

Account details
Your name, email address and a securely hashed password, if you choose to create an account. We never store your password in readable form.
Order details
Billing and delivery address, email address, phone number and the contents of your order. We need these to accept payment, ship the parcel and handle any later query.
Payment data
Card payments are processed by our payment provider. Your card number never reaches our servers and we do not store it — we only receive confirmation that a payment succeeded or failed.
Messages you send us
Emails and contact-form messages, so we can reply and keep a record of the conversation.
Peptide assistant chats
Questions you type into the on-site assistant are sent to our AI provider to generate an answer. The conversation is kept in your own browser and you can clear it at any time from within the chat window.
Technical logs
Our servers record IP address, browser type and the pages requested. These logs keep the site secure and let us diagnose faults.

Legal bases for processing

Under Article 6 of the GDPR we rely on:

  • performance of a contract — creating your account, taking payment, shipping your order and dealing with returns;
  • legal obligation — keeping invoices and accounting records for the periods German and EU tax law require;
  • legitimate interests — securing the website, preventing fraudulent orders and answering support requests;
  • consent — only where you have actively opted in, for example to a marketing email. You can withdraw consent at any time.

Cookies and browser storage

This storefront sets no advertising, profiling or analytics cookies, so there is nothing here for you to consent to or opt out of. What we do use is limited to what makes the shop work:

Session cookie
A sealed, HTTP-only, secure cookie that keeps you signed in for up to 30 days. It holds a reference to your session, not your personal details.
Cart (local storage)
Your basket is saved in your own browser so it survives a page reload. It never leaves your device until you check out.
Assistant history (local storage)
Your chat with the peptide assistant is stored locally in your browser so the thread is still there when you return.

Clearing your browser data removes all three. Note that the separate WordPress area used for our affiliate programme may set its own cookies when you visit it.

Who else processes your data

We share data only with the providers we need to run the shop, and only to the extent they need it. Each acts as a processor under contract with us:

  • our card payment provider, to authorise and settle payments;
  • our AI provider, to generate answers in the on-site peptide assistant;
  • the carrier that delivers your parcel, which receives the delivery address and your contact details for the tracking notification;
  • our email delivery and hosting providers, which handle transactional mail and store the site's data.

We do not sell your personal data, and we do not share it for anyone else's marketing.

Transfers outside the EU

Some of the providers above operate outside the European Economic Area, in particular our AI provider. Where data leaves the EEA we rely on the European Commission's Standard Contractual Clauses or an adequacy decision to keep the protection equivalent to what the GDPR requires. Please avoid typing personal or sensitive information into the assistant — it is there to answer questions about compounds, not to handle your data.

How long we keep it

  • Order and invoice records: retained for the statutory accounting period under German law, which runs up to ten years.
  • Account data: kept while your account is open, and deleted on request unless we must retain part of it for the tax records above.
  • Support correspondence: normally up to two years after the matter is closed.
  • Server logs: rotated after a short period, typically within a few weeks.

Your rights

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or provide it in a portable format. You may object to processing we base on legitimate interests, and you may withdraw any consent you have given without affecting what we did before you withdrew it.

Write to [email protected] and we will respond within one month. If you are not satisfied with our answer you can complain to your national data protection authority; in Bavaria this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

Security

The site is served over TLS, passwords are stored hashed, and the session cookie is sealed and HTTP-only so it cannot be read by scripts in your browser. No system is perfectly secure, but we take appropriate technical and organisational measures to protect your data and we review them as the shop changes.

Children

This shop is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a minor has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this page as the shop or our providers change. The date at the top always shows the current version, and material changes will be highlighted here.

Contact

Questions about this policy? Email [email protected] or use the contact page. See also our disclaimers and shipping & returns pages.