Free UK shipping over £50Batch COA on requestSame-day dispatch, Mon–FriFree UK shipping over £50Batch COA on requestSame-day dispatch, Mon–Fri

Research use only — not for human or animal consumption

Legal

Privacy policy

What personal data we collect when you shop with us, why we hold it, who we share it with and what you can ask us to do about it.

Last updated 5 September 2026

Draft. This document is published so that our terms are visible rather than absent, but it is not final: the company details shown in brackets are not yet confirmed, and it has not been reviewed by a legal adviser. It will be finalised before we accept our first order.

1. Who is responsible for your data

Peptides2U is a trading name of WOW London Ltd, registered in England and Wales (company number [COMPANY NUMBER]), registered address 10 Harland Avenue, Croydon CR0 5QB, United Kingdom. We are the data controller for the personal data described here.

For anything in this policy, including any request about your data, message us on WhatsApp at +44 7957 615629 or write to us at 10 Harland Avenue, Croydon CR0 5QB, United Kingdom.

2. What we collect

We collect what we need to sell you something and get it to you, and no more. We do not buy personal data from anyone, and we do not sell yours.

  • Account details — your name, email address, phone number if you give one, and a securely hashed password. We never store your password itself.
  • Order details — the items you bought, the price you paid, your billing and delivery addresses, and your order history.
  • Payment data — handled by our payment processor. We receive confirmation that a payment succeeded and a reference for it. We do not receive or store your full card number.
  • Correspondence — the emails you send us and our replies, so we can deal with your query and keep a record of what was agreed.
  • Technical data — your IP address and basic request information kept in our server logs, used to keep the site running and to detect abuse.

3. Why we use it, and on what basis

Where UK or EU data protection law applies to you, these are the legal bases we rely on:

  • To perform our contract with you — creating your account, taking your order, taking payment, dispatching goods, handling returns and answering questions about an order.
  • To meet legal obligations — keeping accounting and transaction records for as long as the law requires.
  • For our legitimate interests — preventing fraud and abuse, securing the site, and understanding which products people buy so we can stock the catalogue sensibly.
  • With your consent — marketing email, if you ask for it. We do not send marketing without it, and every message carries an unsubscribe link.

4. Who we share it with

We share your data only with the suppliers who make the service work, and only with what they need:

Each of them acts on our instructions and is not permitted to use your data for their own purposes. We will also disclose data where we are legally required to.

  • Payment processing — [CARD ACQUIRER] and [CRYPTO PAYMENT PROCESSOR], who receive your payment details directly.
  • Delivery — the carrier handling your parcel receives your name, delivery address, phone number and email so they can deliver and notify you.
  • Hosting — our site and database run on DigitalOcean infrastructure in London, United Kingdom.
  • Email delivery — the provider that will send your account and order emails. Transactional email is not switched on yet and no provider has been appointed; this list will name one before any email is sent.

5. International transfers

We are established in the United Kingdom and our site and database are hosted in London, so your data is stored in the UK. Where we transfer data out of the UK we rely on appropriate safeguards for that transfer.

6. How long we keep it

We keep your account for as long as you have one. Ask us to close it and we will delete or anonymise your account data.

Order and payment records are kept for as long as accounting and tax law requires, even after an account is closed, because we are obliged to be able to evidence a transaction. Server logs are kept for a short period and then discarded.

7. Your rights

Depending on where you live you may have the right to ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent to marketing at any time.

Message us on WhatsApp at +44 7957 615629 or write to us, and we will respond within one month. We will not charge you for a reasonable request.

If you are in the United Kingdom and you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can put it right.

8. Cookies

This site sets only the cookies it needs to function. There is no advertising cookie, no tracking pixel and no third-party analytics on this site today. If that changes, this policy will change with it and we will ask for your consent before setting anything that is not strictly necessary.

The cookies we set are:

The cart, sign-in and sign-up cookies are set as HTTP-only, so page scripts cannot read them. The cache identifier does not carry that flag. Blocking these cookies will stop the cart and sign-in from working.

  • _medusa_cart_id — remembers your basket between visits, for 7 days.
  • _medusa_jwt — keeps you signed in, for 7 days.
  • _medusa_pending_customer — holds the details you typed at sign-up while you go to your inbox to verify your email address, for 24 hours.
  • _medusa_cache_id — a random identifier that keeps your cached pages separate from other visitors', for 24 hours. It is not linked to you and is not used to profile you.

9. Security

The site is served over HTTPS, passwords are stored hashed, and access to the database is restricted to the application. No system is perfect: if a breach ever affects your data and puts you at risk, we will tell you and the relevant regulator.

10. Children

This site is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.

11. Changes to this policy

If we change how we use your data we will update this page and change the date at the top. Where the change is significant we will tell account holders by email.