Legal
Privacy Policy
Research Use Only Product Sales
Ovrform, LLC
Last updated August 4, 2026
1
Introduction and Scope
1.1 This Privacy Policy for Ovrform, LLC, a Nevada limited liability company (“Ovrform”, “we,” “us,” or “our”), is applicable to our websites, applications, and platforms, and to all of the products and services provided and distributed by us via such websites, applications, and platforms (collectively, our “Services”). This Policy describes how and why we collect, store, use, share, and protect (“Process”) your personally identifiable information (“PII” or “Personal Data”) via our websites, applications, and platforms (collectively, “Websites”), during our provision of Services, and when you may use our Services. This Policy also provides information about the rights and choices you have with respect to the Personal Data we maintain.
1.2 By using our Services, you agree to let us collect and use your Personal Data as described in this Policy. Therefore, before you provide us with any Personal Data, you should review this Policy carefully, and in its entirety, to ensure you understand its terms.
1.3 This Policy covers our Websites along with all of our Services offerings. So, when you read “Websites” and “Services” in this Policy, please understand that we are referencing any combination of one or more of them as the context of use provides and requires. Also, if we refer to our “Terms”, then we mean the “Terms and Conditions” that you agree to when you purchase, use, and/or receive our Services.
1.4 Our Services include selling research-use-only peptides and related products online, directly to purchasers throughout the United States (“Purchasers”). Our products are labeled for laboratory research use only. They are not sold for human or veterinary use, and we do not provide medical advice, diagnosis, or treatment.
1.5 What Personal Data do we Process? Depending upon how you chose to visit, use, and interact with our Websites and/or Services, the Personal Data we Process may include information relating to (i) Purchasers of our Services, (ii) our various third-party service providers and suppliers (“Partners”), and (iii) general users of our Websites (“Users”). In this respect, we act as a Data Controller.
1.6 How and Why do we Process your Personal Data? We Process your Personal Data to provide, improve, and administer our Services, communicate with you for safety and security purposes, and to comply with Applicable Law. We may also Process your information for other purposes with your express consent. We Process your information fairly, securely, and only when we have a valid legal reason to do so. In this respect, we act as a Data Processor.
1.7 We are not a health care provider. We are not a covered entity nor a business associate under the Health Insurance Portability and Accountability Act (“HIPAA”). Nothing in this Policy should be read as a claim that we provide health care services.
1.8 Even though we are not a health care provider, several state laws define “consumer health data” by how data is used, not by who holds it. Some of the Personal Data we collect could fall inside those definitions. Section 13 of this Policy explains this directly and tells you what we do and do not do with that information.
1.9 We have operations throughout the United States (US). Accordingly, our data protection obligations necessarily include compliance with applicable US legislation such as the California Consumer Privacy Act (CCPA; Cal. Civ. Code § 1798.100 et seq.), the California Privacy Rights Act (CPRA; Cal. Civ. Code § 1798.100 et seq.), the Electronic Signatures in Global and National Commerce Act (ESIGN Act; 15 U.S.C. § 7001 et seq), the Uniform Electronic Transactions Act (UETA), CAN-SPAM Act, 15 U.S.C. § 7701 et seq. (2003), the Telemarketing and Consumer Fraud and Abuse Prevention Act (TCFAPA; 15 U.S.C. §§ 6101-6108), the Telephone Consumer Protection Act (TCPA; 47 U.S.C. § 227 et seq), and any other regulations that may govern our conduct and Services performance (collectively, “Applicable Law”). For additional terms which may apply to you based on your residency status or location, please refer to Sections 11 and 12 of this Policy which outline certain residency-specific terms. To be clear, all information in this Policy is applicable to you unless otherwise indicated based on your residency status.
1.10 This Policy does not create compliance by itself. Our business practices, our website code, and our contracts, must match how this Policy states we Process your Personal Data. Where this Policy describes a control, we maintain that control.
1.11 Questions or Concerns? Reading this Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices as stated herein, then discontinue use of our Websites, and please do not use our Services. Regardless, if you have any questions or concerns about this Policy, then you may contact us via email at support@ovrformpeptides.com, privacy@ovrformpeptides.com, or by any other means provided at https://www.ovrformpeptides.com/contact-us.
Note that to the extent that any provisions of this Policy are inconsistent with Applicable Law, or to the extent you provide your express consent for uses not specifically described herein, then such Applicable Law and/or your express consent, will govern our use of your Personal Data.
2
Personal Data We Collect
2.1 Information you provide to us.
2.1.1 Account and order information. Name, email address, postal and billing address, phone number, password, and order history.
2.1.2 Payment information. Payment card or bank information, which is collected and processed by our payment processor.
2.1.3 Purchaser eligibility and use representations. Statements you make confirming that you are purchasing for laboratory research use, that you are of legal age, and any institution, laboratory, or business affiliation you give us.
2.1.4 Communications. The content of emails, chat messages, support tickets, product questions, reviews, and survey responses you send us.
2.1.5 Marketing preferences. Your subscription choices and the categories of content you ask to receive.
2.2 Information we collect automatically.
2.2.1 Device and connection data. IP address, device identifiers, browser type and version, operating system, language settings, and general location inferred from IP address.
2.2.2 Usage data. Pages and product listings you view, search terms you enter on our site, links you click, referring and exit pages, time on page, and the dates and times of your visits.
2.2.3 Interaction data captured by tracking technologies. Cookies, pixels, tags, software development kits, local storage, and similar technologies place and read identifiers on your browser or device. Section 4 describes these in detail, including session recording.
2.2.4 Transaction telemetry. Cart contents, abandoned carts, and the sequence of steps you take through checkout.
2.3 Information we receive from third parties.
2.3.1 Payment processors and fraud prevention providers. Transaction approval or decline results, chargeback and dispute records, and fraud risk indicators.
2.3.2 Shipping and fulfillment providers. Delivery status, address verification results, and delivery exceptions.
2.3.3 Advertising and analytics platforms. Aggregate campaign performance, and, where we run advertising, information about which of our ads you saw or clicked.
2.3.4 Service providers that host, secure, or operate our website. Security and availability logs.
3
How We Use Personal Data
3.1 We use personal information to:
3.1.1 create and maintain your account and process, fulfill, ship, and confirm your orders;
3.1.2 take payment, issue refunds, and handle chargebacks and disputes;
3.1.3 verify eligibility to purchase and record your research-use representations;
3.1.4 respond to your questions and provide customer support;
3.1.5 detect, investigate, and prevent fraud, abuse, and security incidents;
3.1.6 operate, secure, debug, and improve our website and services;
3.1.7 send transactional messages about your orders and account;
3.1.8 send marketing messages where you have not opted out, and measure whether those messages work;
3.1.9 comply with Applicable Law, respond to lawful requests, and establish or defend legal claims; and
3.1.10 maintain business records, including tax, accounting, and product traceability records.
3.2 Data minimization. We limit the collection of personal information to what is reasonably necessary and proportionate to provide or maintain the specific product or service you request from us.
3.3 Purpose limitation. We use personal information only for the purposes described in this Policy, for purposes compatible with those purposes, or for another purpose we disclose to you before we use the information that way.
3.4 We do not collect, use, or sell personal data for the purpose of training large language models.
3.5 What we do not do. We do not use your purchase history or your browsing behavior on our site to infer, predict, score, or label your physical or mental health status, and we do not build or buy audience segments based on inferred health status.
4
Tracking Technologies, Analytics, and Session Recording
4.1 What we use. We use the following categories of technology on our website:
4.1.1 Strictly necessary technologies, which keep you logged in, hold your cart, route traffic, and protect against fraud and attack. These cannot be turned off through our preference tool because the site will not work without them.
4.1.2 Analytics technologies, which tell us how the site is used so we can fix and improve it.
4.1.3 Session recording and replay technologies, which record your interactions with our pages. Section 4.4 explains this separately.
4.1.4 Advertising and measurement technologies, including pixels and tags placed by advertising platforms, which allow us and those platforms to measure campaign performance and to show you our ads on other sites and apps.
4.2 No consent wall. We do not block access to our website until you agree to tracking. You can browse and buy without accepting analytics or advertising technologies.
4.3 Our own opt-out mechanism. We provide a first-party opt-out. A “Do Not Sell or Share My Personal Information” link and a tracking preferences control appear on every page of our website. We do not send you to an industry association website in place of our own mechanism. Industry tools may exist, but they are not a substitute for the control we provide.
4.4 Session recording. Some pages on our website use session recording technology operated by a service provider on our behalf. This technology can capture your clicks, scrolling, mouse movement, keystrokes in form fields, and page navigation. We configure it to mask payment card fields and password fields. The provider acts as our service provider and is contractually prohibited from using what it records for its own purposes. We disclose this before you interact with the pages where it runs, and the Terms and Conditions include your consent to it.
4.5 Chat. Where we offer a chat feature, we display a notice before your first message telling you that the conversation is recorded, stored, and processed, and that a service provider operates the feature on our behalf.
4.6 Named recipients. The advertising and measurement platforms that receive information from technologies on our site are: Meta Ads Pixel; Google Tag for Google Analytics and Google Ads Script; Microsoft Clarity; Microsoft Ads Pixel for Bing Ads.
4.7 Tracking audit. We periodically audit the tracking technologies actually running on our website against the disclosures in this Policy.
5
How We Disclose Personal Data
5.1 Service providers and contractors. In the preceding 12 months, we disclosed the following categories of personal information to service providers and contractors for a business purpose: identifiers, customer records, commercial information, internet and network activity information, geolocation data inferred from IP address, and inferences drawn from that information.
5.2 Service providers and contractors are bound by written contracts that limit them to processing personal information for the purposes we specify, prohibit selling or sharing it, and prohibit using it for their own purposes.
5.3 Advertising and measurement platforms. Where our advertising technologies are active and you have not opted out, information is transmitted to the platforms named in section 4.6. Under California law and several other state laws, that transmission may count as a “sale” or a “share.” Section 6 explains your opt-out rights.
5.4 Payment, shipping, and fraud prevention partners, as needed to take payment, ship your order, and prevent fraud.
5.5 Professional advisors, including lawyers, accountants, and auditors, under duties of confidentiality.
5.6 Legal and safety disclosures. We disclose personal information where we are legally required to do so, to respond to lawful requests from government authorities, to enforce our terms, and to protect the rights, property, or safety of any person.
5.7 Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction.
5.8 We do not disclose personal information to any third party seeking to use it for civil immigration enforcement, and we do not knowingly sell personal information to a governmental unit that engaged in or supported civil immigration enforcement in the preceding six months.
5.9 Chargeback and payment disputes. If you dispute a charge with your bank or card issuer, we provide that institution with the records needed to respond, which may include your order history, shipping and delivery records, your checkout attestation, and our internal fulfillment verification records. Our Terms and Conditions and our Return and Refund Policy describe this practice.
5.10 Third-party websites. Our website may link to websites we do not control. We are not responsible for the privacy practices, security, or content of those websites. Read the privacy policy of any website you visit.
6
Sale and Sharing of Personal Data; Opt-Out Rights
6.1 What “sale” and “share” mean here. Under California law, “sale” is broad and does not require money to change hands. “Share” covers disclosing personal information for cross-context behavioral advertising. Other states use terms such as “targeted advertising” and “sale of personal data” that reach similar conduct.
6.2 Our disclosure. We share personal information for cross-context behavioral advertising and targeted advertising through the technologies described in section 4. The categories involved are identifiers, internet and network activity information, commercial information, and inferences.
6.3 How to opt out. You can opt out in any of these ways:
6.3.1 Click the “Do Not Sell or Share My Personal Information” link, which appears on every page of our website.
6.3.2 Send a browser-level or device-level opt-out preference signal, including the Global Privacy Control. Section 6.4 explains how we treat those signals.
6.4 Opt-out preference signals. We process a conforming opt-out preference signal as a valid request to opt out of the sale and sharing of personal information. We apply it to the browser or device that sent it, to any consumer profile associated with that browser or device, including a pseudonymous profile, and to you as an individual if we know who you are. We honor the signal even if it conflicts with a setting you previously chose on our site. If you previously sent a signal and later stop sending one, we do not treat the absence of a signal as your consent to opt back in.
6.5 Signal status display. When we process an opt-out preference signal from your browser, we display that we have done so. Our website shows an indicator reading “Opt-Out Request Preference Signal Honored,” and shows through a toggle or radio button that you have opted out.
6.6 No account, login, or identity verification is required to opt out. We do not ask you to create an account, confirm an email address, or verify your identity before we process an opt-out. We do not ask for information beyond what is necessary to send the signal. The opt-out is available in every medium in which we interact with you.
6.7 Consumers under 16. We do not sell or share the personal information of any consumer we have actual knowledge is less than 16 years of age. California law permits a business to do so with affirmative authorization from the consumer if the consumer is at least 13 and under 16, or from a parent or guardian if the consumer is under 13. We do not rely on that permission, and we have built no mechanism to collect that authorization. See Section 16.
6.8 We do not sell personal data of consumers under 16 in any state, and we do not sell precise geolocation data.
7
Sensitive Personal Data
7.1 What we collect. The categories of sensitive personal information we collect are: account log-in credentials in combination with a password or credential allowing access to the account, and payment card number in combination with a security or access code, where applicable.
7.2 Statement required by California regulation. We do not use or disclose sensitive personal information for purposes other than those specified in 11 CCR section 7027, subsection (m).
7.3 We do not sell sensitive personal information or sensitive data, in any state, for any consideration.
7.4 Where a state requires it, we collect, process, or share sensitive data only where doing so is strictly necessary to provide or maintain the specific product or service you requested, and we do not rely on your consent to go beyond that limit.
7.5 Where a state requires consent for sensitive data, we obtain consent before processing, and the processing must also be reasonably necessary in relation to the purposes we disclose. Consent alone is not enough. You may withdraw consent at any time through a mechanism at least as easy to use as the one you used to give it, and we stop the processing within fifteen days.
7.6 Consent is not obtained through terms of use. We do not treat your acceptance of our Terms and Conditions, your hovering over content, muting, pausing, or closing content, or any deceptive design as consent to collect or share sensitive data or consumer health data.
8
Automated Decisionmaking Technology
8.1 We do not use automated decisionmaking technology to make a significant decision about you. Under California regulation, a “significant decision” means a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Advertising to a consumer is expressly excluded from that definition.
8.2 We do use automated systems for ordinary commercial functions such as product recommendations, advertising delivery and measurement, and fraud scoring at checkout. None of these produces a significant decision as that term is defined.
8.3 Because we do not use automated decisionmaking technology for a significant decision, we do not provide a pre-use notice, an opt-out of automated decisionmaking technology, or a right to access automated decisionmaking technology. If that changes, we will update this Policy and provide those rights.
8.4 Separately, we conduct and document a risk assessment before we begin any processing activity that requires one under California regulation, including selling or sharing personal information and processing sensitive personal information.
9
Personal Data Retention
9.1 We keep personal information only as long as we need it for the purposes described in this Policy, and then we delete or deidentify it. We do not keep personal information that is no longer reasonably needed.
9.2 Retention schedule. We apply the following retention periods:
9.2.1 Account records: three (3) years after the account is closed.
9.2.2 Order, invoice, and shipping records, including checkout attestations and fulfillment verification records: seven (7) years, to meet tax, accounting, regulatory compliance, and product traceability requirements.
9.2.3 Payment authorization records held by us (not by our processor): three (3) years.
9.2.4 Customer support and chat records: one (1) year after the matter closes.
9.2.5 Marketing contact records: one (1) year after your last interaction with us, or until you unsubscribe, whichever comes first.
9.2.6 Website analytics and advertising identifiers: one (1) year from collection.
9.2.7 Session recording data: one (1) year from collection.
9.2.8 Security and access logs: one (1) year from collection.
9.2.9 Fraud investigation records: three (3) years after the investigation closes.
9.2.10 Records we must keep for a legal claim, an audit, or a legal hold: until the claim, audit, or hold ends.
9.3 Retention criteria. Where a fixed period is not workable, we set retention by the purpose the data serves, the length of our relationship with you, our legal and tax obligations, and whether we need the data to establish or defend a legal claim.
10
Data Security
10.1 We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, and destruction. Our safeguards include encryption in transit and at rest, access controls and least-privilege permissions, logging and monitoring, vendor security review, and employee training.
10.2 We require our service providers and contractors to maintain reasonable security appropriate to the personal information they handle, by written contract.
10.3 No system is perfectly secure. We cannot guarantee that personal information will never be accessed or disclosed in a way this Policy does not describe.
10.4 Where California regulation requires a business of our size and data volume to complete an annual cybersecurity audit, we complete that audit and certify its completion as required.
11
Your California Privacy Rights
11.1 If you are a California resident, you have the following rights.
11.1.1 Right to know. You can ask us for the categories of personal information we collected about you, the categories of sources, our business or commercial purposes, the categories of third parties to whom we disclosed it, and the specific pieces of personal information we hold about you.
11.1.2 Right to delete. You can ask us to delete personal information we collected from you, subject to exceptions the law allows.
11.1.3 Right to correct. You can ask us to correct inaccurate personal information we hold about you.
11.1.4 Right to opt out of sale and sharing. You can direct us to stop selling or sharing your personal information. Section 6 explains how.
11.1.5 Right to limit use of sensitive personal information. This right applies where a business uses or discloses sensitive personal information for purposes beyond those permitted by regulation. See section 7.2 for our statement on that point.
11.1.6 Right not to be retaliated against. You have the right not to be retaliated against for exercising privacy rights conferred by the CCPA, including when a consumer is an applicant to an educational program, a job applicant, a student, an employee, or an independent contractor.
11.1.7 Rights relating to automated decisionmaking technology. See section 8.
11.2 Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for proof that you gave it permission to act for you, except for opt-out requests, where we require nothing beyond what is needed to send the request.
11.3 Categories of information we collected in the preceding 12 months, the sources, the purposes, and the third parties involved are described in sections 2, 3, 4, and 5.
11.4 Business purpose disclosures. Section 5.1 lists the categories of personal information we disclosed to a service provider or contractor for a business purpose in the preceding 12 months.
12
Your Rights Under Other State Privacy Laws
12.1 General rights. Depending on where you live, you may have the right to confirm whether we process your personal data and to access it, to correct inaccuracies, to delete it, to obtain a portable copy, to opt out of targeted advertising, the sale of personal data, and certain profiling, and to appeal a decision we make on your request. Where consent is required for a processing activity, you may withdraw it.
12.2 Universal opt-out mechanisms. We honor browser-level and device-level opt-out preference signals, including the Global Privacy Control, everywhere we operate. We do this regardless of whether the state you live in requires it, because it is simpler and more reliable than a state-by-state approach.
12.3 State-specific notes.
12.3.1 Connecticut. The Connecticut Data Privacy Act applies to us if we control or process the personal data of 35,000 or more Connecticut consumers (excluding data processed solely to complete a payment transaction), if we control or process Connecticut consumers’ sensitive data, or if we offer Connecticut consumers’ personal data for sale in trade or commerce. Amendments to those applicability provisions took effect July 1, 2026. Connecticut’s consumer health data provisions apply to us with no revenue or processing threshold at all. See section 13.
12.3.2 Maryland. The Maryland Online Data Privacy Act, Md. Code Com. Law section 14-4701 et seq., took effect October 1, 2025. Amendments effective July 1, 2026 treat data we infer, and any other personal data we process for the purpose of identifying a sensitive attribute, as sensitive data. We do not sell sensitive data, and we limit collection to what is reasonably necessary and proportionate to provide or maintain the specific product or service you requested. We do not use the personal data of any consumer under the age of 18 for targeted advertising.
12.3.3 Rhode Island. Rhode Island law requires a commercial website conducting business in Rhode Island or with Rhode Island customers that collects, stores, and sells customers’ personally identifiable information to identify all third parties to whom it has sold or may sell that information. The third parties are identified in section 4.6 and section 5.
12.3.4 Indiana and Kentucky. Both laws took effect January 1, 2026. Each applies to a business that controls or processes the personal data of at least 100,000 consumers in the state, or of at least 25,000 consumers in the state while deriving more than 50 percent of gross revenue from the sale of personal data. Neither has a dollar revenue threshold or a small-business carve-out.
12.3.5 Montana. Montana law applies to a business that controls or processes the personal data of not less than 25,000 consumers, or of not less than 15,000 consumers while deriving more than 25 percent of gross revenue from the sale of personal data.
12.3.6 Colorado. Colorado’s duties concerning minors’ data took effect October 1, 2025 and apply regardless of data volume or revenue. Colorado treats biological and neural data as sensitive data.
12.3.7 Oregon. We do not sell the personal data of consumers under 16, and we do not sell precise geolocation data.
12.3.8 Laws taking effect later. Louisiana and Oklahoma take effect January 1, 2027. Alabama takes effect May 1, 2027. Vermont takes effect January 1, 2028, including its consumer health data provisions, which have no numeric threshold. We will update this Policy as those laws take effect.
13
Consumer Health Data
13.1 Why this section exists. We are not a health care provider and we are not regulated under HIPAA. Our products are labeled for laboratory research use only and are not sold for human use. Several state laws nonetheless define “consumer health data” by how information is used rather than by who holds it. Because of what we sell, some information we collect could fall inside those definitions. We address that directly rather than assume it away.
13.2 What could qualify. The categories most likely to be treated as consumer health data are: the specific products you view, search for, add to a cart, or buy; any inference that could be drawn from those actions about a physical or mental health condition; and any health-related statement you volunteer to our customer service team.
13.3 What we do with it. We use this information to process and fulfill your order, to answer your questions, to maintain the records our regulators and our payment partners require, and to operate and secure our website.
13.4 What we do not do with it. We do not sell consumer health data. We do not use your purchase history or browsing behavior to infer, predict, score, or label your health status. We do not build, buy, or use audience segments based on inferred health status. We do not use product-category signals to target advertising in a way that reveals or implies a health condition. We do not share consumer health data with an advertising platform.
13.5 Employee access. Access to information described in this section is limited to personnel who need it to do their jobs, and that access is logged.
13.6 Your rights. Where a state consumer health data law applies to us, you may ask us to confirm whether we collect, share, or sell your consumer health data, to identify who receives it, and to delete it. Section 14 explains how to ask. We will tell you if an exception prevents us from honoring a deletion request and we will explain which exception applies.
13.7 Authorization before any sale. We will not sell consumer health data. If that ever changes, we will first obtain your separate, written, signed authorization that is distinct from any consent to collect or share, and we will not condition the sale of any product on that authorization.
13.8 Geofencing. We do not use a geofence around any health care facility, pharmacy, medical office, or similar location to identify, track, collect data from, or send notifications or advertisements to consumers.
14
Your Rights
You have the following rights regarding your Personal Data in our possession. You have the right to:
- Request access to your Personal Data at any time subject to legal requirements. This allows you to obtain a copy of the Personal Data and verify that we are Processing it lawfully.
- To request the rectification of any Personal Data held by us which is incorrect, incomplete or inaccurate.
- Request the deletion of your Personal Data from our files and systems where we have no valid reason to continue to hold it.
- Object to our use of your Personal Data to meet our (or a third party’s) legitimate interests or where we use it for direct marketing purposes.
- Request that we limit the Processing of your Personal Data.
- Ask us to transfer your Personal Data to another person or organization (right to portability).
- Withdraw your previously provided consent and/or opt-out of continuing to receive communications from us related to our Services or third parties other than those that you have inquired about or are receiving.
How to Exercise Your Rights
14.1 How to submit a request. Submit a request in any of these ways:
14.1.2 Use the web form at ovrformpeptides.com/privacy-request.
14.2 Opt-out requests. To opt out of the sale or sharing of personal information, use the “Do Not Sell or Share My Personal Information” link in the footer of every page, or enable an opt-out preference signal such as the Global Privacy Control in your browser. We honor the signal automatically. We do not require you to create an account, verify your identity, or provide anything beyond what is needed to send the request.
14.3 Verification. For requests to know, delete, or correct, we verify your identity before we act. We match the information you give us against information already in our records. We ask only for what we need. We do not ask for a government identification document unless we cannot verify you any other way.
14.4 Timing. We acknowledge a request within 10 business days and respond within 45 calendar days. If we need more time, we tell you why before the first 45 days run and we take no more than an additional 45 days.
14.5 Cost. Requests are free. We may charge a reasonable fee, or decline, if a request is manifestly unfounded or excessive, and if we do we tell you why.
14.7 Authorized agents. You may use an authorized agent. We may ask the agent to show that you gave it permission to act for you, except for opt-out requests.
14.8 Authenticity. For the purposes of confidentiality and Personal Data protection, we may need to confirm your identity in order to respond to your request. In case of reasonable doubts concerning your identity, you may be asked to include a copy of an official piece of identification, such as an ID card, passport, or driver’s license along with your request. A black and white copy of the relevant page of your identity document is sufficient. Upon receipt, all requests will be appropriately and promptly responded to.
15
Non-Discrimination and Financial Incentives
15.1 Non-discrimination. We will not deny you products, charge you a different price, provide a different level or quality of service, or suggest that we will do any of those things because you exercised a privacy right.
15.2 Financial incentives. We do not offer any financial incentive, loyalty program, discount, or other benefit in exchange for the collection, sale, or retention of personal information.
16
Minors
16.1 Our website and our products are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. Our checkout requires you to certify that you are at least 18.
16.2 If we learn that we have collected personal information from a person under 18, we delete it promptly.
16.3 We do not sell or share the personal information of any consumer we know to be under 16, and we do not use the personal data of any consumer under 18 for targeted advertising. We have built no mechanism to collect the affirmative authorization that would permit such a sale, and we do not intend to.
17
Changes to This Policy
17.1 We may, at our sole discretion, revise this Policy at any time in a manner consistent with Applicable Law. When we revise this Policy, we will incorporate the revisions into this Policy and will revise the “last updated” date at the top of this Policy. Please check this Policy periodically for the most current version and to confirm your continued agreement with its terms, which will be inferred by your continued association with us following any such modifications. If you do not agree with our policies and practices as stated herein, then discontinue use of our Websites, and please do not use our Services.
17.2 If we make a material change, we give notice before the change takes effect through a notice on our website and, where we have your email address and the law requires it, by email.
17.3 We do not apply a material change retroactively to information already collected without your consent where consent is required.
18
Contact Us
18.3 Effective date of this Policy: August 4, 2026. Last updated: August 4, 2026.