Privacy & data security
The short version: your cart lives in your own browser, there are no trackers and no analytics on this site. If you create an account we store your email and a one-way hash of your password; orders store the delivery address so a parcel can be shipped. Nothing else you type is kept.
1. What this site stores
This storefront keeps everything on your device. Two browser localStorage keys are used: peptidekontor_cart_v1 (the items and quantities in your cart) and peptidekontor_promo_v1 (your promo code, if any). Both store only product identifiers and numbers — no names, no addresses, no payment details.
2. Accounts
Accounts are optional. You can check out as a guest without creating one. If you choose to register, we store your email address and a salted scrypt hash of your password — never the password itself, and nothing that can be reversed back into it. A session cookie lets you stay signed in; it is HttpOnly, SameSite=Strict and sent over HTTPS, and only its SHA-256 hash is kept on our side, so our database cannot be used to impersonate a signed-in session.
We cannot recover a forgotten password for you, because we cannot read it. If you lose it, contact us and we will delete the account so you can register again. We never send marketing email, and there is no password-reset email system.
3. What this site does not do
- No advertising networks. Nothing about your visit is shared with ad platforms.
- No trackers or analytics. The page loads no third-party tags, pixels, fingerprinting or session-recording scripts.
- No sale of data. We do not sell, rent or broker personal data.
4. What you type
Forms — checkout, newsletter signup, the contact form — validate in your browser. The newsletter and contact forms are local to the page and never transmitted. Checkout is different by necessity: an order cannot ship without a delivery address, so the contact details, shipping address, delivery instructions and order contents you enter are sent to our order service so the parcel can be labelled and dispatched. That is the only place your address goes.
We do not accept card payments at all. This storefront takes cryptocurrency only, paid to our own wallet. If you choose to buy that cryptocurrency with a card, you do so directly on ChangeHero's own website — we are not involved in that transaction and hold no credential for it. We never see, receive or store a full card number, expiry or CVC, because no card form exists on this site.
Your order receipt is kept in sessionStorage for the duration of the browser tab only, so the confirmation page can show you what you ordered and where it is going. It is discarded when you close the tab.
5. Cookies
No cookies are set for tracking. Cart state uses localStorage specifically because it stays on your device and is not sent with requests. You can clear both keys at any time via your browser's site-data settings — the cart simply resets to empty.
6. Security
The site is served over HTTPS with a Content-Security-Policy, Referrer-Policy and X-Content-Type-Options headers. Passwords are stored only as salted scrypt hashes, which cannot be reversed; the fulfilment feed that exposes delivery addresses is behind a bearer token and refuses to serve anything if that token is unset.
7. Retention & deletion
Your browser data persists until you clear it or it expires. An account and its orders stay on our server until you ask us to delete them — email the address you registered with and we will remove the account and its session records.
8. Your rights
For data we hold about you — an account, a session record, or an order — you may request access, correction or deletion under GDPR and equivalent law. Contact us through the contact page; we have 30 days to respond. A password cannot be disclosed to anyone, including to you, because we hold only a one-way hash of it.
9. Changes to this policy
Any material change will be published on this page with an updated date. Questions about the policy go through the contact page.
Last updated: October 2026 · PeptideKontor