Legal
Privacy policy
Last updated: PLACEHOLDER DATE
Template — needs review. This describes what the software actually does, which makes it a solid starting point, but it has not been reviewed by a lawyer and does not yet name your jurisdiction, your regulator, or your data-protection contact. Have counsel review it before launch.
What we collect
When you place an order: your name, email address, optional phone number and company, the return address you supply, and the details of the samples you're sending — including any vendor and batch information you choose to declare.
When you use the verifier: the certificate key you looked up, a salted hash of your IP address, and your browser's user-agent string. We keep a hash rather than the address itself so the log is useful for spotting abuse without identifying you.
When you use the file checker: only the SHA-256 fingerprint your browser computes. The file itself never leaves your device.
When you contact us: whatever you put in the message.
What we do with it
We use your contact details to run your order and send your results. We use sample details to produce the certificate. We use verification logs to detect abuse of the endpoint and nothing else.
We do not sell personal information, and we do not use it to build advertising profiles.
Who we share it with
Nobody, with three narrow exceptions: our hosting and database providers, who process data on our behalf under contract; payment processing, where applicable, handled by the processor rather than by us; and any disclosure legally required of us, which we will tell you about unless we are prohibited from doing so.
In particular, we never disclose to a vendor that their product was tested, who tested it, or what the result was.
Publication
We do not publish results. There is no public directory of certificates and no way to browse or search what we have tested.
A certificate is readable only by someone who has the unique key printed on it. Distributing that key — to a vendor, a forum, a buyer, or nobody at all — is entirely your decision.
How long we keep it
Certificate records are retained indefinitely, because verification has to keep working years after issue — that is the point of the service. Order contact details are retained for as long as we need them for tax and record-keeping obligations. Verification logs are retained for a limited period for abuse detection. Contact messages are retained until they are resolved and for a reasonable period afterwards.
Your rights
You can ask us what we hold about you, ask us to correct it, and in most cases ask us to delete it. Certificate records themselves cannot be deleted without breaking verification for anyone relying on them, but they can be revoked and unpublished.
Send requests to info@peptidetests.ca.
Security
Data is held in a managed database with row-level access controls. Unpublished certificates are not readable from the public web at all — they are only reachable through the verification endpoint, and only by someone holding the key printed on the report.