Privacy Policy

Last updated: August 2026

1. Introduction

Raven Peptides is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website and services, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

Raven Peptides is the data controller responsible for your personal data.

3. Information We Collect

We may collect the following types of personal data:

  • Identity data: name, email address
  • Contact data: delivery address, billing address, email address, phone number
  • Transaction data: details of orders, payments, and delivery records
  • Account data: username, password (encrypted), order history
  • Technical data: IP address, browser type, device information, cookies
  • Usage data: information about how you use our website

4. How We Use Your Data

We use your personal data for the following purposes:

  • Processing and fulfilling your orders (contractual necessity)
  • Sending order confirmations, dispatch notifications, and delivery updates
  • Managing your account and providing customer support
  • Processing payments securely through our payment providers
  • Complying with legal and regulatory obligations
  • Improving our website and services (legitimate interest)

5. Legal Basis for Processing

We process your personal data on the following legal bases under UK GDPR:

  • Contract: Processing necessary to fulfil your order
  • Legal obligation: Processing required for tax, accounting, or regulatory compliance
  • Legitimate interest: Improving our services, fraud prevention, website analytics
  • Consent: Where applicable, for marketing communications (you may withdraw at any time)

6. Data Sharing

We may share your personal data with the following third parties:

  • Payment processors: Stripe, for secure payment processing
  • Delivery partners: Royal Mail, DPD, Evri, or other carriers for order fulfilment
  • Hosting providers: For website hosting and data storage

We do not sell your personal data to third parties. Data shared with third-party processors is governed by their respective privacy policies and our data processing agreements.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Order records are retained for a minimum of 6 years to comply with HMRC requirements. Account data is retained until you request its deletion.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate personal data
  • Right to erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Right to restrict processing: Request that we limit how we use your data
  • Right to data portability: Request your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interest
  • Right to withdraw consent: Where processing is based on consent, withdraw at any time

To exercise any of these rights, please contact us. We will respond to your request within one month.

9. Cookies

Our website uses essential cookies to maintain your session and shopping cart. These are strictly necessary for the website to function and cannot be disabled. We do not use third-party tracking or advertising cookies.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Payment information is processed securely by our PCI DSS-compliant payment processor and is never stored on our servers.

11. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.