LEGAL
Privacy Policy
Last updated: July 2026
What we collect
When you create an account or place an order, we collect the information you provide to us: name, shipping address, email, phone number, order history, and payment sender details (e.g., Zelle sender name). We also store a hashed version of your password — never the plaintext. When you use the site, our infrastructure providers (Vercel, Supabase, Resend) may log request metadata such as IP address, user agent, and referrer.
How we use it
We use your information to fulfill orders, communicate about those orders, send account and security notifications, prevent fraud and abuse, and improve the site. We do not sell your personal information to third parties. Marketing emails, if any, will only go to accounts that have opted in and will contain an unsubscribe link.
Cookies & tracking
We use a small number of first-party cookies to keep you logged in and remember your cart. We do not use third-party advertising cookies. If you use the browser’s “Do Not Track” setting we will treat you as not opted in to any optional analytics.
Sub-processors
We rely on the following service providers to operate the site:
- Vercel (hosting, edge compute, logs)
- Supabase (Postgres database, storage)
- Resend (transactional email — verification, receipts, password reset)
Each processes your data on our behalf under their published terms.
Data retention
We keep account and order records for as long as your account is open, and for a period after closure as required by law or reasonably necessary for tax and dispute resolution. You may request deletion of your account at any time by contacting us; we will comply subject to legal retention requirements.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, port, or delete your personal information, and to object to certain processing. To exercise any of these rights, reach us at
@JFTpeptide or the contact channel on file. We will verify your identity before acting on a request.
Security
Passwords are stored using bcrypt hashing. Sessions are signed cookies over HTTPS. We limit administrative access to authorized operators. No system is perfectly secure — if we ever learn of a breach affecting your data we will notify you as required by law.
Changes
If this policy materially changes we will update the “Last updated” date and, for significant changes, notify account holders by email.
Note: This document is a template provided in good faith and does not constitute legal advice. The operator should have counsel licensed in their jurisdiction review and adapt this policy — particularly for CCPA/CPRA, GDPR/UK GDPR, or state-specific requirements — before relying on it.