Privacy Policy
How we collect, use, protect, and share your personal information.
Effective Date: March 28, 2026 · Last Revised: March 28, 2026
At PeptidePure™, your privacy is extremely important to us. This Privacy Policy explains how we collect, use, protect, and share your personal information when you visit our website, create a clinician account, submit clinical forms, make a purchase, or otherwise interact with us. Please read this policy carefully. By using this site, you agree to its terms.
1. Information We Collect
We may collect the following types of information:
- Identity & Contact: Full name, email address, shipping and billing addresses, phone number, NPI number, professional credentials, and clinic name.
- Account Information: Login credentials, order history, and submitted clinical forms.
- Payment Data: Credit card details processed via Authorize.Net (we do not store raw card numbers on our servers).
- Clinical Data: SOAP notes, baseline assessments, treatment logs, adverse event reports, and patient outcomes submitted through our IRB-compliant forms. This data may constitute Protected Health Information (PHI) under HIPAA.
- Device & Usage Data: IP address, browser type, device identifiers, pages visited, and referral source.
- Cookies & Tracking: Session cookies, preference cookies, and analytics identifiers.
2. How We Use Your Information
We use your information to:
- Process and fulfill orders and provide customer support
- Verify clinician credentials and maintain account security
- Store and manage clinical form submissions in our secure IRB research database
- Communicate order updates, account notices, and (with consent) promotional messages
- Improve site performance, conduct analytics, and prevent fraud
- Comply with applicable federal and state laws and regulations
3. HIPAA Notice — Protected Health Information
PeptidePure™ operates as a Business Associate under HIPAA where clinical data is submitted through our platform on behalf of covered healthcare providers. For such data:
- We maintain administrative, physical, and technical safeguards consistent with the HIPAA Security Rule (45 C.F.R. Parts 160 and 164).
- Clinical form submissions (SOAP notes, patient outcomes, adverse event reports) are encrypted in transit (TLS 1.2+) and at rest (AES-256).
- PHI is accessible only to authorized personnel and is not sold, rented, or disclosed to third parties except as required by law or as permitted by your Business Associate Agreement (BAA).
- Clinicians who submit patient data through this platform are responsible for obtaining appropriate patient authorization under HIPAA and applicable state laws.
- To request a BAA, contact us at info@peptidepure.com.
- In the event of a breach involving PHI, we will notify affected parties as required under the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414).
4. California Privacy Rights — CCPA / CPRA
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, complying with a legal obligation).
- Right to Correct: You may request correction of inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. If this practice changes, we will provide a 'Do Not Sell or Share My Personal Information' link.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information (including health data) for purposes beyond those necessary to provide our services.
- Right to Non-Discrimination: Exercising your privacy rights will not result in discriminatory treatment.
- To submit a verifiable consumer request, contact us at info@peptidepure.com or via our Contact page. We will respond within 45 days as required by law.
5. How We Share Your Information
We never sell your personal data. We may share information only in the following circumstances:
- Service Providers: Payment processors (Authorize.Net), email delivery (Resend), cloud hosting (Vercel/Supabase), and analytics providers — bound by data processing agreements.
- Legal Compliance: Law enforcement or regulatory authorities when legally required.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, under confidentiality obligations.
- With Your Consent: Any other sharing will be with your explicit prior consent.
6. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain your authenticated session and remember preferences
- Track aggregate website performance and page analytics
- Prevent fraud and ensure platform security
We do not use third-party advertising cookies. You can disable cookies through your browser settings; however, some site features (including login) require session cookies to function.
7. Data Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, and periodic security reviews. All clinical data is stored in isolated, access-controlled database environments. However, no method of transmission or storage is 100% secure. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
8. Data Retention
We retain personal account data for as long as your account is active or as needed to provide services. Clinical form data submitted for IRB research purposes is retained per the applicable research protocol and applicable regulatory requirements. You may request deletion of non-research data at any time (see Section 4 for California residents; Section 9 for all others).
9. Your Rights (All Users)
Regardless of your location, you may:
- Access or update your personal information via your account settings
- Request deletion of your account and associated non-clinical data
- Opt out of marketing emails at any time via the unsubscribe link in any email
- Request a copy of data we hold about you
To exercise these rights, contact us at info@peptidepure.com or via our Contact page. We will respond within 30 days.
10. Third-Party Links
Our site may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies before sharing personal data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the Effective Date above and, where appropriate, by direct notice to registered users. Continued use of the site after any update constitutes acceptance of the revised policy.
12. Contact Us
For privacy questions, data requests, or to request a HIPAA Business Associate Agreement, contact us at:
PeptidePure™ · info@peptidepure.com · (858) 480-1017 · Mon–Fri, 9AM–4PM PST