For Research Use Only. Not for Human Consumption.

Privacy Policy

Last updated: August 16, 2026

This document is published in English. The English version is the legally binding version; any translation is provided for convenience only.

This Policy explains what personal data we collect, why, who processes it on our behalf, and the rights available to you under the GDPR (EU/EEA), UK GDPR, the Swiss Federal Act on Data Protection (FADP), the Brazilian LGPD and the California CCPA/CPRA.

1. Controller

The controller (and, under the LGPD, the "controlador") is VENOMTOP GROUP LLC, a single-member limited liability company formed under the laws of the State of Wyoming, United States (formed May 4, 2026; Wyoming filing ID 2026-001968169), with registered agent and principal office at Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801, USA.

Privacy contact: privacy@venomtop.com.

2. Personal data we collect

We collect only what the store actually needs to operate. Specifically:

  • Account data (optional): email address, full name and account credentials. Credentials are created and verified by our authentication provider; we never see or store your password.
  • Order data: order number, the products and quantities ordered, prices, currency and totals, discount and coupon applied, chosen payment method, order status, and the research-use declaration you accepted.
  • Contact and delivery data: name, email address, telephone number and shipping address (and billing address where provided), plus any delivery notes you enter.
  • Coupon and referral data: which coupon code was used with which order and the email address it was used by, so per-customer usage limits can be enforced.
  • Messages you send us: the name, email address and message content submitted through the contact form.
  • Technical data: the country derived from your IP address (used only to select the display currency and available payment methods), plus standard server and security logs generated by our hosting and CDN providers.

We do NOT collect payment card data, bank credentials, government identification numbers or any health data. All payments are settled off-platform through the method you choose.

3. Purposes and legal bases

  • Creating, fulfilling and shipping your order, and providing customer support — performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7, II).
  • Operating optional customer accounts and order history — performance of a contract.
  • Fraud prevention, abuse prevention, enforcing coupon limits, and securing the site — legitimate interests (GDPR Art. 6(1)(f); LGPD Art. 7, IX).
  • Selecting display currency and available payment methods from IP-derived country — legitimate interests.
  • Improving the store and its content — legitimate interests.
  • Transactional email (order confirmation, payment instructions, shipping notifications) — performance of a contract.
  • Retaining commercial and accounting records — legal obligation (GDPR Art. 6(1)(c)).
  • Non-essential storage, where applicable — consent (which you may withdraw at any time).

4. Processors and sub-processors

  • Supabase — managed PostgreSQL database and authentication. Receives account, order, address, coupon and contact-message data. Hosted in the United States.
  • Lovable — application hosting and deployment of the website and its server functions. Processes request data in transit.
  • Cloudflare — CDN, edge delivery and image/asset storage; supplies the country header used for currency detection. Processes IP addresses and request metadata.
  • Resend — transactional email delivery. Receives recipient email address, name and the order details contained in the message.
  • ipapi.co — fallback IP geolocation when the CDN country header is unavailable. Receives the visitor IP address only.

We do not sell personal data and we do not share it for cross-context behavioural advertising. We may disclose data where required by law or to establish, exercise or defend legal claims.

5. International transfers

We are a United States company and all data is processed in the United States. For data originating in the EEA, the United Kingdom, Switzerland or Brazil, this is a transfer to a third country.

Honest disclosure: we rely on the transfer terms contained in our providers' standard data processing agreements, which incorporate the EU Standard Contractual Clauses. We have not yet executed a separate, bespoke set of Standard Contractual Clauses with each data exporter, and we have not completed a formal transfer impact assessment. We state this plainly rather than claim a level of formal compliance that is not yet in place. If this matters to your decision to purchase, please contact us before ordering.

6. Retention periods

We keep personal data for the periods set out below. Periods run from the date of the order, the last exchange, or the closure of the account, as applicable.

  • Order records and order items, including shipping and billing addresses, totals, payment method and transaction detail: 7 years from the order date, to meet tax and accounting record-keeping requirements.
  • Customer account and profile: retained while the account is active; deleted on request, or after 3 years of account inactivity.
  • Contact-form messages: 2 years from the last exchange.
  • Coupon redemption records: retained with the associated order, therefore 7 years.
  • Back-office security records (MFA enrolment and recovery codes for staff and administrator accounts): retained for as long as that back-office account exists.
  • Server, hosting and CDN logs held by our providers: retained according to those providers' standard periods, which are typically short-term.

Certain records may be retained beyond these periods where we need to comply with a legal obligation, resolve or defend a dispute, prevent fraud or abuse, or enforce our agreements.

Honest disclosure: this system does not currently run an automated deletion job. Deletion is carried out on request and during periodic manual review of stored records, not automatically at the moment a retention period expires. We state this plainly rather than describe automation that does not exist.

7. Do not send us health information

Please do not submit medical records, prescriptions, treatment plans, diagnoses, test or laboratory results relating to a person, dosage or administration questions, or any other health or medical information to us through the website, the contact form, your account, order notes, email, WhatsApp or any other support channel.

We do not provide medical advice, prescribing services, clinical guidance or patient care of any kind. Our products are supplied strictly for laboratory research use only, and we are not able to answer questions about human or veterinary use.

We do not ask for, and do not wish to receive, health data. We do not use any health information for any purpose. Where such information reaches us despite this notice, we will delete it rather than retain it, and we will not act on it beyond deleting it. Any reply we send will not address the health content.

This means we do not knowingly process special category data under Article 9 of the GDPR, sensitive personal data under the LGPD, or sensitive personal information under the CCPA/CPRA.

8. Your rights (GDPR, UK GDPR, FADP, LGPD)

  • Access — obtain confirmation of processing and a copy of your data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have data deleted where we have no overriding legal basis to keep it.
  • Restriction — limit how we process your data in certain circumstances.
  • Portability — receive data you provided in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdrawal of consent — at any time, without affecting prior lawful processing.
  • Information about automated decision-making — we do not carry out automated decision-making or profiling with legal or similarly significant effects.

9. Your rights (California CCPA/CPRA)

  • Right to know what personal information we collect, use and disclose, and the categories of recipients.
  • Right to delete personal information, subject to statutory exceptions such as completing a transaction or complying with a legal obligation.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information — we do not sell or share personal information for cross-context behavioural advertising, and we have not done so in the preceding 12 months, so there is nothing to opt out of.
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA.
  • Right to non-discrimination for exercising any of these rights.

10. Exercising your rights

Send your request to privacy@venomtop.com from the email address associated with your orders, or contact support@venomtop.com. We may need to ask for limited additional information to verify your identity. We aim to respond within 30 days (extendable by a further 60 days for complex requests, with notice), which meets the GDPR one-month, LGPD 15-day-where-applicable and CCPA 45-day frameworks; where a shorter statutory deadline applies to you, we will meet that deadline.

You also have the right to lodge a complaint with your supervisory authority — your national data protection authority in the EEA, the ICO in the United Kingdom, the FDPIC in Switzerland, or the ANPD in Brazil.

11. EU representative (GDPR Article 27)

We have no establishment in the European Union. As of the date of this Policy, no representative under Article 27 of the GDPR has been appointed. We disclose this rather than imply compliance we have not yet achieved; the position is under review and this Policy will be updated when a representative is appointed.

12. Children

This service is intended exclusively for adults aged 21 or over. We do not knowingly collect personal data from minors. If we learn that we have collected data from a minor, we will delete it.

13. Security

Measures actually in force:

  • All traffic is encrypted in transit (HTTPS/TLS).
  • Database row-level security policies isolate each customer's records, so one customer cannot read another's orders, profile or addresses.
  • Sensitive operations (order creation, pricing, discounts, stock) are recalculated and enforced on the server, not trusted from the browser.
  • Back-office access is role-based and restricted to authorised staff, with two-factor authentication available for those accounts.
  • Internal cost and margin data is not exposed to public endpoints.
  • No card data is ever collected or stored, because all payments are handled offline through your chosen method.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Changes to this Policy

We may update this Policy. The current version is always published at venomtop.com/legal/privacy with a “Last updated” date. Material changes will additionally be notified by email to account holders where we have a valid address.

VENOMTOP GROUP LLC · 30 N Gould St Ste R, Sheridan, WY 82801, USA · venomtop.com