Skip to content
Vestrand Bioscience

DRAFT — requires review and approval by qualified legal counsel before launch. Not legal advice.

This page is a working template, not a final or authoritative legal document. Bracketed tokens such as {{LEGAL_ENTITY}} and {{GOVERNING_LAW_STATE}} are placeholders that must be completed, and every clause must be reviewed, edited, and approved by a licensed attorney in the operating jurisdiction before it is published or relied upon.

Policy · Draft template

Privacy Policy

How we collect, use, share, retain, and protect personal information, and the rights available to you. This draft includes sections flagged for specific privacy regimes that a privacy attorney must review before launch.

Effective date
{{EFFECTIVE_DATE}}
Last reviewed
{{LAST_REVIEWED}}
Version
Draft 0.1

Consumer health data notice — Washington My Health My Data Act

A record that an identifiable person purchased certain research compounds may, under Washington’s My Health My Data Act (MHMDA) and similar laws, constitute “consumer health data.” MHMDA has no revenue threshold and a private right of action. It requires a separate Consumer Health Data Privacy Policy with its own homepage link. See Section 11. This is flagged as our largest privacy exposure and must be reviewed by counsel. {{CONSUMER_HEALTH_DATA_POLICY_URL}}

1. Who we are

This Privacy Policy explains how {{LEGAL_ENTITY}} (trading as “Vestrand Bioscience,” “we,” “us”), the controller of your personal information, handles that information. You can contact us at {{PRIVACY_EMAIL}} or {{COMPANY_ADDRESS}}. Where the EU or UK GDPR applies, our representative is {{EU_UK_REPRESENTATIVE}} (see Section 10).

2. Personal information we collect

We collect only what we need to operate the site and fulfill orders:

  • Account data — name, email address, and a hashed password.
  • Order data — shipping and billing address, order contents, and an optional phone number for carrier delivery.
  • Payment data — processed by our payment processor ({{PAYMENT_PROCESSOR}}); we receive transaction identifiers and confirmation, not your full card number.
  • Compliance records — your age and research-use attestation, the policy versions you accepted, and a hashed IP address, retained as a record of the steps taken at purchase.
  • Support and inquiries — the content of messages you send us (for example, wholesale or contact requests).
  • Technical and security data — limited log and device information, and cookies strictly necessary to operate the site (see Section 8).

We decline to collect data we do not need, including full date of birth, government identifiers, health conditions or medical history, free-text “reason for purchase,” and precise geolocation. We do not knowingly collect information from children (see Section 13).

3. How and why we use your information

We use personal information to:

  • process, fulfill, and support your orders and manage your account;
  • take payment and prevent fraud and abuse, including risk scoring of transactions;
  • meet our legal, tax, and record-keeping obligations, including retaining research-use and age attestations;
  • operate, secure, and improve the site; and
  • send you service communications and, only with your separate consent, marketing communications.

Where the GDPR applies, our lawful bases are: performance of a contract (fulfilling your order and account); legal obligation (tax, records, and compliance); our legitimate interests in securing the site and preventing fraud, balanced against your rights; and consent for marketing. {{COUNSEL_LAWFUL_BASIS_REVIEW}}

4. When we share information

We share personal information only with service providers that help us operate, and only as needed:

  • Payment processing{{PAYMENT_PROCESSOR}}.
  • Shipping and carriers{{CARRIERS}}.
  • Email and communications{{EMAIL_PROVIDER}}.
  • Hosting and infrastructure{{HOSTING_PROVIDER}}.
  • First-party analytics{{ANALYTICS_PROVIDER}}, configured without cross-site advertising identifiers.

We may also disclose information to comply with law, enforce our terms, or protect rights and safety, and in connection with a merger or sale of assets. We do not sell your personal information for money, and we do not share purchase-level data with advertising platforms or use session-replay tools on product, cart, checkout, or account pages. See Section 9 for “sale” and “share” as those terms are defined by certain US laws.

5. International transfers

We operate from {{OPERATING_COUNTRY}}. If we ever transfer personal information across borders, we will use an appropriate safeguard (such as standard contractual clauses) and describe it here. {{COUNSEL_TRANSFER_MECHANISM}}

6. How long we keep information

We keep personal information only as long as needed for the purpose it was collected, then delete or de-identify it. Indicative periods ([COUNSEL] to confirm for the operating jurisdiction):

  • Order and transaction records — approximately {{ORDER_RETENTION_YEARS}} years (tax and records).
  • Research-use and age attestation — life of the account plus the order-records period; retained as a compliance artifact even after account deletion, with identity fields pseudonymized.
  • Security and audit logs — a limited investigation window, then aggregated or deleted.
  • Web and access logs — a short period, with IP addresses hashed.
  • Marketing consent records — for the life of the consent plus a limited period to evidence it.

If you ask us to delete your account, we pseudonymize your identity and retain only the records we are required to keep, under a surrogate key.

7. Your rights and how to exercise them

Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information; to opt out of certain processing; to withdraw consent; and to appeal a decision. Region- specific rights are described in Sections 9–11. To make a request, contact {{PRIVACY_EMAIL}} or use {{DSAR_INTAKE_URL}}. We will verify your identity using the minimum information necessary and respond within the timeframe the applicable law requires. You will not be discriminated against for exercising your rights.

8. Cookies and similar technologies

We aim to use only cookies and storage that are strictly necessary to operate the site — for your session, cart, security (CSRF), and to remember your cookie choices — plus privacy-preserving, cookieless first-party analytics. We do not use third-party advertising or marketing cookies or trackers by default. If that ever changes, we will provide a compliant consent mechanism and update this policy and any linked cookie notice: {{COOKIE_POLICY_URL}}.

9. United States — California (CCPA/CPRA) and other state laws

California residents (CCPA/CPRA). You have the right to know and access the personal information we collect, use, and disclose; to correct inaccurate information; to delete your information; and to opt out of the “sale” or “sharing” of personal information and of certain targeted advertising. We do not sell your personal information for money. To the extent any disclosure of cookie or device data counts as a “sale” or “share,” you may exercise the “Do Not Sell or Share My Personal Information” right via {{DO_NOT_SELL_URL}}, and we honor the Global Privacy Control (GPC) browser signal. You may use an authorized agent, and you may appeal a denied request. We will not discriminate against you for exercising these rights.

Other US states. Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others — may have comparable rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising and sales, and appeal. Texas and several other states apply without a numeric size threshold. Contact us as described in Section 7 to exercise these rights. {{COUNSEL_STATE_LAW_REVIEW}}

10. European Union and United Kingdom (GDPR / UK GDPR)

This section applies only if and when we offer goods or services to individuals in the EU or UK. Our current recommendation is {{EU_SHIPPING_DECISION}} (see our Shipping Policy); if we do not serve the EU/UK, this section is informational and the EU/UK-specific mechanisms below are not yet in force. Where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent at any time, and the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner’s Office). Our lawful bases are described in Section 3. We would appoint an Article 27 representative, identified in Section 1, and rely on an appropriate transfer safeguard per Section 5. [COUNSEL] to confirm scope, representative, transfer mechanism, and distance-selling obligations before any EU/UK sales.

11. Washington My Health My Data Act and consumer health data

This section requires review by a privacy attorney before launch

Whether, and how, MHMDA and comparable laws (for example, Nevada SB 370 and Connecticut’s consumer-health-data provisions) apply to this catalog, and the exact consent and authorization mechanics, are [COUNSEL] determinations. The text below is a starting draft.

Washington’s My Health My Data Act defines “consumer health data” very broadly, to include information that identifies a consumer’s past, present, or future physical or mental health status, including the purchase of certain products and information inferred from other data. A record that an identifiable person purchased certain research compounds could be treated as consumer health data from which health status might be inferred.

Because MHMDA applies without a revenue threshold and carries a private right of action, where it applies we intend to:

  • maintain a separate Consumer Health Data Privacy Policy, linked from our homepage, describing the categories of consumer health data, the purposes of collection, and the categories of recipients: {{CONSUMER_HEALTH_DATA_POLICY_URL}};
  • collect consumer health data only as necessary to provide a product or service you requested, and obtain affirmative, opt-in consent for any collection beyond that, with separate consent before any sharing;
  • not sell consumer health data absent valid written authorization that meets the Act’s requirements;
  • not share purchase-level data with advertising platforms, and not use session-replay tools on product, cart, checkout, or account pages; and
  • honor your rights to access, withdraw consent, and request deletion of consumer health data, and observe the Act’s geofencing prohibition around facilities providing health services.

12. Automated decision-making

We use automated risk scoring to help detect and prevent fraudulent or abusive orders. This may flag an order for manual review or decline. It does not profile you for advertising. Where you have a right to do so, you may request human review of a decision that significantly affects you by contacting {{PRIVACY_EMAIL}}.

13. Children

The site is intended for qualified researchers who are adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact {{PRIVACY_EMAIL}} and we will delete it.

14. How we protect information

We use administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, hashed passwords, access controls, and audit logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable law.

15. Changes to this policy

We may update this policy; the effective date and version above show when it last changed, and we archive prior versions. Material changes will be notified as required by law. Questions may be directed to {{PRIVACY_EMAIL}}.