Privacy & data security
The short version: your cart lives in your own browser, there are no accounts, no trackers and no analytics on this site, and nothing you type leaves the page.
1. What this site stores
This storefront keeps everything on your device. Two browser localStorage keys are used: peptidekontor_cart_v1 (the items and quantities in your cart) and peptidekontor_promo_v1 (your promo code, if any). Both store only product identifiers and numbers — no names, no addresses, no payment details.
2. What this site does not do
- No accounts. There is no registration, no user database and no server-side profile.
- No trackers or analytics. The page loads no third-party tags, pixels, fingerprinting or session-recording scripts.
- No advertising networks. Nothing about your visit is shared with ad platforms.
- No sale of data. We do not sell, rent or broker personal data — there is none held to sell.
3. What you type
Forms — checkout, newsletter signup, the contact form — validate in your browser. The newsletter and contact forms are local to the page and never transmitted. Checkout is different by necessity: an order cannot ship without a delivery address, so the contact details, shipping address, delivery instructions and order contents you enter are sent to our order service so the parcel can be labelled and dispatched. That is the only place your address goes.
We do not accept card payments at all. This storefront takes cryptocurrency only, settled either to our own deposit addresses or through our ChangeHero gateway. We never see, receive or store a full card number, expiry or CVC, because no card form exists on this site.
Your order receipt is kept in sessionStorage for the duration of the browser tab only, so the confirmation page can show you what you ordered and where it is going. It is discarded when you close the tab.
4. Cookies
No cookies are set for tracking. Cart state uses localStorage specifically because it stays on your device and is not sent with requests. You can clear both keys at any time via your browser's site-data settings — the cart simply resets to empty.
5. Security
The site is served over HTTPS with a Content-Security-Policy, Referrer-Policy and X-Content-Type-Options headers. Because no personal data is stored server-side, there is no account database to breach.
6. Retention & deletion
Data in your browser persists until you clear it or it expires with site data. Deleting the two keys above removes everything this site holds about your session.
7. Your rights
If you contact us about data you believe we hold (for example, in a production order record), you may request access, correction or deletion. Because this demo stores nothing server-side, the fastest path is clearing your own site data.
8. Changes to this policy
Any material change will be published on this page with an updated date. Questions about the policy go through the contact page.
Last updated: October 2026 · PeptideKontor