Privacy Policy — BioLongevity Labs
Research Use Only: All products are for scientific research only — not for human or animal use.
Legal Document

Privacy
Policy

This Privacy Policy explains how BioLongevity Labs collects, uses, stores, and protects your personal information when you access our website, create an account, or purchase research-grade compounds from our catalog.

Effective Date April 14, 2022
Last Revised March 22, 2024
Jurisdiction United States (CCPA / GDPR-aligned)
Version 2.1
This policy is effective as of January 1, 2026 and was last revised on June 1, 2026. By accessing our website or placing an order, you agree to the practices described herein.
§ 01

Overview & Scope

Who we are and what this policy covers

BioLongevity Labs ("we," "us," or "our") operates the website at biolongevitylabs.online and associated subdomains (the "Site"). We are a chemical supplier of research-grade peptides and bioregulators sold exclusively for Research Use Only (RUO) purposes.

This Privacy Policy applies to all information collected through our Site, including account registration, research catalog browsing, order placement, and communications with our team. It does not apply to third-party websites or services we link to, which are governed by their own privacy policies.

We are committed to handling your personal information responsibly, transparently, and in accordance with applicable data protection laws, including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR) where applicable to EU/EEA residents, and other relevant US state privacy laws.

Research Use Only Context

Account registration requires acknowledgment of our Research Use Only terms. The personal and institutional information you provide during registration is used in part to verify eligibility to purchase research-grade compounds. We do not sell, rent, or lease this information to third parties for marketing purposes.

§ 02

Data We Collect

Categories of personal information and how it is gathered

We collect personal information in three ways: information you provide directly, information collected automatically, and information received from third parties.

Data Category Examples Purpose Basis
Account Information Name, email, password (hashed), institution, title Account creation, RUO verification, order access Required
Contact Information Email address, phone number, mailing address Order confirmation, shipping, support Required
Order & Transaction Data Items purchased, quantities, order history, invoice records Order fulfillment, COA delivery, compliance records Required
Payment Information Billing address, last 4 digits of card (full card data handled by PCI-compliant processor) Payment processing Required
Institutional Data Institution name, department, research context provided during registration RUO eligibility verification Required
Technical & Usage Data IP address, browser type, device identifiers, pages visited, session duration Site security, analytics, fraud prevention Automatic
Cookie Data Session cookies, preference cookies, analytics identifiers Site functionality, performance analytics Automatic
Communications Data Emails, support tickets, chat transcripts sent to or from our team Support resolution, compliance Voluntary

We do not collect sensitive personal information such as health records, government identification numbers, or financial account credentials. Payment card data is processed exclusively through our PCI DSS-compliant payment processor and is never stored on our servers.

§ 03

How We Use Your Data

Purposes and legal bases for processing

We use the personal information we collect for the following purposes, each supported by a lawful basis under applicable law:

Order Fulfillment & Account Management
  • Processing and confirming research orders and payments
  • Generating and delivering Certificates of Analysis (COA) and MSDS documents
  • Coordinating shipping and providing tracking information
  • Maintaining your account and order history in your dashboard
Research Use Only Verification & Compliance
  • Verifying institutional affiliation and RUO acknowledgment status
  • Maintaining order records for regulatory compliance and audit purposes
  • Screening orders against OFAC sanctions lists and restricted-party databases
Site Operations & Security
  • Detecting and preventing fraudulent orders, account takeovers, and unauthorized access
  • Monitoring site performance and resolving technical issues
  • Sending transactional emails (order confirmations, shipping alerts, COA delivery)
Communications & Support
  • Responding to customer support requests, technical questions, and COA inquiries
  • Sending account and order status notifications
  • Sending optional research catalog updates and new compound announcements (opt-in only; unsubscribe available in every email)
No Sale of Personal Information

BioLongevity Labs does not sell, rent, or lease your personal information to third parties for their own marketing or commercial purposes. We do not engage in interest-based advertising using your personal data.

§ 04

Data Sharing

When and with whom we share your information

We share personal information only in the limited circumstances described below. We do not share personal data for third-party advertising purposes.

Service Providers (Data Processors)

We engage trusted third-party service providers who process personal data on our behalf, under contractual data processing agreements that restrict their use of your data to the services they provide us:

  • Payment processors — PCI DSS-compliant providers (e.g., Stripe) for secure payment authorization. They receive billing address and payment details; we do not store full card numbers.
  • Shipping carriers — name, shipping address, and order details are shared with carriers (UPS, FedEx, USPS, DHL) solely for delivery of your order.
  • Email service providers — transactional email platforms receive email addresses and order data to send order confirmations, shipping notifications, and COA delivery emails.
  • Analytics providers — aggregated, pseudonymized usage data may be processed by analytics platforms to help us understand site performance. We do not share identifiable personal data with analytics providers.
  • Fraud prevention services — IP addresses and device fingerprints may be shared with fraud prevention vendors to detect and block unauthorized orders.
Legal & Regulatory Disclosure

We may disclose personal information when required to do so by law, subpoena, court order, or in response to a lawful request from a government authority. We may also disclose information to comply with applicable regulations (including OFAC sanctions screening), to protect our legal rights, or to prevent fraud or illegal activity.

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will provide notice before any such transfer and before your data becomes subject to a materially different privacy policy.

§ 05

Data Retention

How long we keep your information

We retain personal information for as long as necessary to fulfill the purposes described in this policy, to comply with legal and regulatory obligations, and to resolve disputes.

Data Category Retention Period Reason
Account Information Active + 3 years Account management, support, compliance
Order & Transaction Records 7 years Financial compliance, tax obligations, audit trail
RUO Acknowledgment Records 7 years Regulatory compliance, legal defense
Shipping & Delivery Records 5 years Order dispute resolution, carrier claims
Payment Records (partial) 7 years Financial regulation, chargeback dispute window
Support Communications 3 years from last contact Support history, quality assurance
Technical / Usage Logs 90 days Security monitoring, fraud detection
Cookie / Analytics Data Up to 26 months Analytics reporting cycles

When data is no longer needed and no legal obligation requires its retention, we securely delete or anonymize it. Anonymized or aggregated data that cannot identify any individual may be retained indefinitely for business analytics purposes.

§ 06

Cookies & Tracking

How we use cookies and similar technologies

Our Site uses cookies and similar tracking technologies to maintain session state, remember preferences, and understand how visitors interact with our catalog. We do not use third-party advertising cookies.

You can manage cookie preferences through your browser settings or by using the cookie preferences link in the footer of our site. Disabling essential cookies will impair account login and checkout functionality. Our Site does not respond to Do Not Track (DNT) browser signals at this time, as there is no uniform standard for DNT interpretation.

§ 07

Data Security

How we protect your information

We implement commercially reasonable administrative, technical, and physical safeguards to protect your personal information against unauthorized access, disclosure, alteration, and destruction.

  • TLS/SSL encryption — all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. HTTPS is enforced site-wide.
  • Password hashing — account passwords are stored as salted cryptographic hashes. We cannot recover your password in plain text, only reset it.
  • Payment security — full payment card data is processed by our PCI DSS-compliant payment processor and is never stored on our infrastructure.
  • Access controls — internal access to personal data is restricted to personnel with a need-to-know basis. Access is logged and reviewed.
  • Regular backups — data is backed up regularly with encrypted backups stored in geographically separated locations.
No Absolute Security Guarantee

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. If you suspect unauthorized access to your account, change your password immediately and contact our support team.

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law, within the timeframes prescribed (e.g., 72 hours under GDPR).

§ 08

Your Privacy Rights

Rights available under CCPA, GDPR, and applicable US state law

Depending on your location, you may have the following rights with respect to your personal information. We will respond to all valid requests within the timeframes required by applicable law (typically 30–45 days).

Right to Know / Access

Request a copy of the personal information we hold about you, including the categories of data, sources, purposes, and third parties we have shared it with.

Right to Deletion

Request that we delete your personal information, subject to exceptions required by law (e.g., order records required for tax compliance or regulatory obligations).

Right to Correction

Request correction of inaccurate personal information we hold about you. You can update most account information directly through your dashboard.

Right to Portability

Request a machine-readable copy of the personal data you have provided to us, where technically feasible. Available for account and order data.

Right to Opt Out

Opt out of optional marketing emails at any time via the unsubscribe link in any email or through your account notification preferences. We do not sell personal data.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights — including by denying services, charging different prices, or providing a different quality of service.

How to Exercise Your Rights

Submit a privacy request by emailing privacy@biolongevitylabs.online or by using the contact form at our contact page. Include your full name, registered email address, and a description of your request. We may need to verify your identity before processing your request. We will respond within 30 days (or 45 days if extended notice is provided).

§ 09

Children's Privacy

Our Site is not intended for minors

BioLongevity Labs is a supplier of research-grade chemical compounds for institutional scientific research. Our Site and services are intended exclusively for adults aged 18 and older who are affiliated with research institutions or qualified laboratories.

We do not knowingly collect personal information from individuals under the age of 18. If you believe that a minor has provided us with personal information, please contact us immediately at privacy@biolongevitylabs.online and we will take steps to delete that information promptly.

§ 10

International Data Transfers

Cross-border processing of personal information

BioLongevity Labs is based in the United States. If you are accessing our Site from outside the United States — including from the European Union or European Economic Area — your personal information may be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your country.

For transfers of personal data from the EU/EEA to the United States, we rely on appropriate transfer mechanisms as required by applicable law, which may include Standard Contractual Clauses (SCCs) as approved by the European Commission, or other legally recognized transfer mechanisms. By using our Site, you acknowledge and consent to this transfer.

EU/EEA residents have the right to lodge a complaint with their local supervisory authority if they believe their data has been processed in violation of the GDPR. Contact details for EU data protection authorities are available at edpb.europa.eu.

§ 11

Policy Changes

How we notify you of updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will:

  • Update the "Last Revised" date at the top of this policy
  • Send an email notification to all registered account holders
  • Display a prominent notice on our Site for a period of at least 30 days
  • Archive prior versions of this policy which remain accessible on request

Your continued use of the Site following the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree to the revised policy, please discontinue use of our Site and contact us to close your account.

§ 12

Contact Us

Privacy questions, rights requests, and data concerns

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a concern about how your personal information is handled, please contact us using the details below. We aim to respond to all privacy-related inquiries within 5 business days.

Privacy Inquiries

For data subject requests, privacy questions, or to report a concern about your personal information:

privacy@biolongevitylabs.online
Contact Form

Mailing address: BioLongevity Labs — Privacy Office, [Address], United States. For GDPR-specific inquiries, EU residents may also contact us at the email above referencing "GDPR Request" in the subject line.

Research Use Only

Chemical Supplier Statement: BioLongevity Labs is a chemical supplier — not a compounding pharmacy (503A) or outsourcing facility (503B) under the FD&C Act. All products are Research Use Only (RUO), not for human or animal use.

© 2026 BioLongevity Labs. All rights reserved. This Privacy Policy is governed by the laws of the United States. Subject to change; check this page for the current version.