Privacy Policy
Data Controller: OptimalPep is the data controller responsible for the processing of personal data collected through this Site.
This Policy describes the information we collect, how it is used, and the choices available to you when accessing our website and services. By using the Site, you acknowledge and agree to this Policy.
This Policy applies to Site visitors, registered account holders, and customers. It does not apply to third-party websites or services that may be accessed through links on our Site.
1) Information we collect
Data You Provide
Account credentials and identifying information (e.g., name, email address, password).
Transactional information, including billing and shipping details and contact information.
Communications submitted through support channels, forms, reviews, or surveys.
Marketing subscriptions and communication preferences.
Automatically Collected Information
Technical information related to your device and browser, including IP address, user agent, and language preferences.
Website usage data, such as page visits, interactions, referring URLs, and session length.
General location data inferred from IP address at the city or regional level.
Information collected via cookies, local storage, and similar tracking technologies (see Cookies).
Sensitive Data:
We do not collect or retain protected health information, government identification numbers, or complete payment card details. All payment processing is handled securely by authorized third-party processors
2) How we use your information
Provide the Service: create/manage accounts, process orders, deliver products, and provide customer support.
Improve & secure: monitor performance, fix bugs, prevent fraud/abuse, maintain the Site.
Communicate: transactional emails (orders, shipping, account), and—if you opt in—newsletters and promotions. You can unsubscribe anytime.
Compliance: tax/accounting, legal obligations, and enforcing our terms.
3) Cookies and Related Technologies
What we use cookies For
Essential: Required for core site functionality, including navigation, cart, checkout, and account login.
Analytics: Used to measure site traffic, usage patterns, and overall performance.
Preferences: Used to remember your settings and choices to enhance your experience.
Marketing: Used only with your consent, such as for email tracking pixels or advertising tags.
Your control
You may control or disable cookies through your browser settings.
Where required, we obtain consent prior to deploying non-essential cookies.
We recognize and honor Global Privacy Control (GPC) signals as an opt-out of the sale or sharing of personal data, where applicable.
4) Data security
We employ industry-standard safeguards to protect personal information, including TLS/SSL encryption during transmission, secure hosting environments, access controls, and regular system updates. While no method of transmission or storage is completely secure, we will notify affected individuals and relevant regulators of any data incident as required by applicable law.
5) When we share information
We do not sell your personal information. We may share limited information with trusted service providers that assist us in operating the Site and delivering our services. These providers are permitted to use such information solely to perform services on our behalf and are required to protect it.
Common processors
Payment Processors: Third-party payment providers (e.g., Stripe, PayPal); full card details are not stored by us.
Email and Communications: Service providers supporting transactional and consent-based marketing communications (e.g., Klaviyo).
Shipping and Fulfillment Partners: Carriers and logistics platforms used for order fulfillment.
Analytics and Infrastructure Providers: Hosting providers, CDNs, monitoring tools, and analytics services.
We may disclose personal information as required by law, in response to lawful requests, to protect rights, property, or safety, or in connection with a merger, acquisition, restructuring, or similar corporate transaction.
6) Data retention
Account and order records: Retained while your account remains active and thereafter as required for tax, accounting, fraud prevention, and legal compliance (typically 5–7 years for orders and invoices).
Support communications: Retained as needed to resolve inquiries, maintain records, and improve customer service.
Marketing data: Retained until you unsubscribe, request deletion, or after a reasonable period of inactivity.
When information is no longer required, we securely delete or de-identify it.
7) Your rights & choices
Global Privacy Rights
Depending on your location and applicable law, you may have the right to:
-
Request access to a copy of your personal information.
-
Request correction of inaccurate or incomplete data.
-
Request deletion of your personal information, subject to applicable legal and regulatory obligations.
-
Request data portability, where applicable, to receive your information in a commonly used, machine-readable format.
-
Withdraw consent at any time, including for marketing communications.
-
Object to or request restriction of certain processing activities based on our legitimate interests.
U.S. State Privacy Rights (e.g., CA/CPRA, CO, CT, UT, VA)
Depending on your state of residence, you may have the right to know, access, correct, delete, and obtain a portable copy of your personal information. You may also have the right to opt out of targeted advertising, the sale of personal information, or certain profiling activities.
OptimalPep does not sell personal information and does not share personal information for cross-context behavioral advertising purposes. For California residents, we honor browser-based opt-out signals, including the Global Privacy Control (GPC), and we do not discriminate against individuals for exercising their privacy rights.
How to Exercise Your Rights
To submit a privacy-related request, please email [email protected] with “Privacy Request” in the subject line. We may require verification of your identity before processing your request. Authorized agents may submit requests on your behalf where permitted by applicable law.
For individuals located in the European Union or United Kingdom, you also have the right to lodge a complaint with your local data protection or supervisory authority.
8) International data transfers
OptimalPep is based in the United States and may process personal information in the U.S. and other countries. Where personal data is transferred from the EU, UK, or EEA to jurisdictions that do not provide an adequacy decision, we implement appropriate safeguards, such as the EU Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.
9) Children's privacy
Our Site is intended for individuals eighteen (18) years of age or older. We do not knowingly collect personal information from minors. If you believe that a minor has provided personal information through our Site, please contact us and we will promptly take appropriate steps to delete such information.
11) Contact
Questions or requests? Email us at [email protected].