PRIVACY POLICY
Last updated: May 2026
1. Data Controller
The party responsible for data processing on this website is:
Nord System s.r.o.
operating under the brand Glow Up Peptides
Milíčova 471/25, Žižkov
130 00 Praha 3, Czech Republic
E-Mail: support@glowup-peptides.com
1a. Data Protection Officer
We have assessed under Article 37 GDPR whether a data protection officer must be appointed. Based on the current nature and scale of processing, no statutory appointment obligation applies. Please send privacy requests to support@glowup-peptides.com.
2. Overview of Data Processing
The protection of your personal data is of great importance to us. We process your data exclusively on the basis of legal provisions — in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This privacy policy informs you about which data we collect, why we collect it, and what rights you have.
3. Hosting
Our website is hosted via Cloudflare Pages. When you visit our website, information is automatically stored in server log files, which your browser transmits automatically. This includes:
- IP address (anonymized)
- Date and time of the request
- Browser type and version
- Operating system used
- Referrer URL
Processing is carried out pursuant to Art. 6(1)(f) GDPR based on our legitimate interest in the security and optimization of our services. This data is not merged with other data sources.
Processor: Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare processes IP addresses + request metadata for DDoS mitigation and CDN delivery. A data processing agreement (DPA) per Art. 28 GDPR is in place. Cloudflare uses EU Standard Contractual Clauses for third-country transfers (USA).
3a. Protection Against Automated Attacks
To protect our forms (order, customer account, newsletter, support, stock notifications) against automated attacks (DDoS, spam bots, brute-force), we store the following data on each request in a separate protection table:
- IP address (full, for re-identification)
- Endpoint identifier (which form)
- On orders / newsletter / stock-notifications: the submitted email (to identify the same user)
- Browser identifier (User-Agent)
This data is stored for a maximum of 24 hours and then automatically deleted (hourly cleanup cron job). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system resilience per Art. 32(1)(b) GDPR). This data is not merged with other data sources and not shared with third parties.
Notice per Art. 22 GDPR: If you are erroneously blocked by our automated bot protection (e.g. due to unusual browser fingerprint), you have the right to manual review. Please email support@glowup-peptides.com with subject "Bot-Block — manual review" — we review the case manually within 24 hours and restore access if appropriate.
4. Order Data
When you place an order, we collect the following data:
- First and last name
- Email address
- Shipping address
- Phone number (optional)
- Payment information
- Order history
Processing is carried out for the performance of a contract pursuant to Article 6(1)(b) GDPR. We retain order and billing data for as long as necessary to perform the contract, handle claims, and comply with applicable Czech tax and commercial retention obligations.
4a. Retention Period per Data Category
We delete or anonymize personal data according to the following table:
| Data category | Retention | Legal basis |
|---|---|---|
| Orders, invoices, payment transactions | As required by applicable Czech tax and accounting rules; deleted or anonymized afterwards | Article 6(1)(b) and (c) GDPR |
| Customer account (email, name, address) | Until account deletion by user | Art. 6(1)(b) DSGVO |
| Newsletter subscription (email) | Until unsubscribe; confirmation IP+timestamp 36 months (Art. 7 proof) | Art. 6(1)(a) DSGVO |
| Support requests (email_threads, support_tickets) | 3 years after closure | Art. 6(1)(f) DSGVO |
| Reviews | Until deletion by author; anonymized on account deletion | Art. 6(1)(a) DSGVO |
| rate_limit_log (IP, endpoint, email identifier) | 24 hours (automatic cleanup cron hourly) | Art. 6(1)(f) DSGVO |
| admin_audit_log (GDPR accountability trail) | 90 days | Art. 5(2) DSGVO |
| Spam block list (blocked email addresses with spam behavior) | 365 days for repeat-spam mitigation; on request manually deletable immediately via support@glowup-peptides.com (subject "GDPR Art. 17 — delete spam-block entry") | Art. 6(1)(f) DSGVO |
| Server log files (Cloudflare) | Cloudflare standard 7 days | Art. 6(1)(f) DSGVO |
Account deletion and statutory retention: “My Account” → “Delete Account” deletes the customer profile and voluntary account data that is no longer needed. Where order, invoice, or payment data must continue to be retained under applicable law, it is separated from the active customer account, limited to the necessary minimum, and deleted or anonymized once the retention period expires.
5. Customer Account
You may voluntarily create a customer account. Our authentication service Supabase processes, in particular, your email address, authentication identifiers, and a cryptographic password hash; we do not have access to your plaintext password. Processing provides the account functions you request and is based on Article 6(1)(b) GDPR. You can delete the account at any time under “My Account” → “Delete Account”, or request help from support@glowup-peptides.com.
6. Payment Processing
For SEPA bank transfers, your banking details are used solely for payment allocation and are not shared with third parties.
For credit-card payments, we use TagadaPay for payment processing and Basis Theory to securely tokenize card data. During checkout, card details are transmitted directly to Basis Theory for tokenization; our database does not store the full card number or card verification code. We transmit the token and the order, contact, billing, and delivery data required for payment processing to TagadaPay. 3-D Secure is used where required by the payment flow or card issuer. The legal basis is Article 6(1)(b) GDPR; necessary fraud prevention is based on Article 6(1)(f) GDPR.
Crypto payment is currently not offered. Should it be offered again, the following applies: For crypto payments (Bitcoin/USDT), we use paygate.to as an external payment processor with a hosted payment page. For this payment, you are redirected to paygate.to's secure page. Your payment data is processed directly there — we never have access to complete account details. Transferred data: order reference, amount, currency. For more information, please refer to the paygate.to privacy policy.
7. Database & Storage
We use Supabase (Supabase, Inc.) as our database infrastructure. Your data is stored in a data center in Frankfurt am Main (eu-central-1) and does not leave the European Economic Area. All database tables are protected by Row Level Security (RLS), ensuring users can only access their own data.
8. Web Analytics
We use Umami Analytics only after consent to the “Analytics” category. The service is used for aggregated usage statistics. Without analytics consent, the Umami script is not loaded.
9. Error Monitoring & Analytics Services (with consent)
The following services are loaded only after your consent via the cookie banner. When you click "Necessary only", they are not loaded. Since these providers are based in the USA, third-country transfer occurs on the basis of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
- Sentry (Functional Software, Inc., USA) — for detecting and resolving technical errors. Transmitted: browser, OS, error details. IP addresses are not stored. Privacy policy.
- PostHog (PostHog Inc., EU region Frankfurt) — product analytics for improving user experience. Transmitted: aggregated click and usage events without personal data. EU hosting in Frankfurt. Privacy policy.
- Microsoft Clarity (Microsoft Corporation, USA) — session heatmaps for UX analysis. Transmitted: anonymized mouse and scroll movements, no input contents (form fields are masked). Privacy policy.
- Cloudflare Web Analytics (Cloudflare, Inc., USA) — privacy-friendly performance metrics (Web Vitals) without cookies and without personal data. Data processing is GDPR-compliant and cookie-free. Privacy policy.
- Meta Pixel & Conversions API (Meta Platforms Ireland Ltd., Ireland / Meta Platforms Inc., USA) — loaded only after active marketing consent. The service processes events such as page views, carts and purchase values as well as `_fbp`/`_fbc`, IP address and, where supplied during checkout, contact details. For the Conversions API, contact details are first transmitted to our own server function, normalized and SHA-256 hashed there; only the hash values are sent to Meta. You may withdraw consent at any time through “Cookie Preferences”. Legal basis: Article 6(1)(a) GDPR. Privacy policy.
10. Cookies & Local Storage
Our website uses no optional tracking technologies by default. Analytics services load only after consent to the “Analytics” category; Meta Pixel/Conversions API and Microsoft Clarity only after consent to the “Marketing” category. If you choose “Reject All”, only technically necessary functions remain active. You can change your selection at any time through “Cookie Preferences”. For necessary functions, we use your browser's local storage (localStorage), among other technologies:
- Entry confirmation: Your declaration of adulthood (18+) and research intent, with its confirmation timestamp, is stored locally on this device. It is valid for 30 days; an expired entry is removed on the next shop visit. No ID copy or date of birth; the declaration is not sent to the server. You can remove it at any time by clearing browser storage.
- Shopping cart: Storage of your selected products
- Language preference: Your selected language (DE/EN)
- Cookie consent: Whether you have accepted the cookie banner
- Account data: Encrypted login session
These entries are initially stored locally in the browser. Cart, account, and checkout data is transmitted to our systems or the providers named above when required for a function you request, such as sign-in, ordering, or payment. Local entries can be deleted at any time through your browser settings.
11. Returns & Refunds
When you request a return, cancellation or refund, we process the order number, your contact details, information about the request and any photos or evidence you provide voluntarily. This is necessary to handle your request and perform the contract (Article 6(1)(b) GDPR). Where data is required to establish, exercise or defend legal claims, processing is based on Article 6(1)(f) GDPR. Details of deadlines, refunds and statutory rights are set out in our cancellation & returns policy.
12. Email Communication
For transactional emails (order, payment and shipping information), we use Resend, a service of Plus Five Five, Inc. These emails are sent to process your order and are not newsletter advertising. The legal basis is Article 6(1)(b) GDPR.
12a. Newsletter (with explicit consent)
If you subscribe to our newsletter, we process your email address to send editorial and promotional content (e. g. new products, lab reports, seasonal offers). The legal basis is your consent under Art. 6(1)(a) GDPR.
Subscription process: After the form is submitted, the address provided is stored as active immediately and receives a welcome email with the advertised newsletter code. To document the subscription, we store its time, source and language together with technical security data. Please use only an email address that you control.
Retention: Active subscribers remain stored until they unsubscribe. Afterwards, we retain only the information required to document the withdrawal and prevent further messages for as long as necessary to comply with legal obligations or defend claims.
Right to withdraw at any time: Every newsletter email contains an unsubscribe link at the bottom. One click is enough — no justification needed, no further emails. You can also unsubscribe directly at /unsubscribe.html or send a message to support@glowup-peptides.com.
Delivery tracking: Resend logs technical delivery events such as delivery, bounces and spam complaints for message delivery and sender reputation. Addresses are disabled following hard bounces or spam complaints. We do not use open or click tracking for profiling.
Review invitations (Trustpilot): After your order is delivered, we transmit your email address and order reference to Trustpilot A/S (Copenhagen, Denmark, EU) so that Trustpilot can send you an invitation to review our service. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in customer feedback) in conjunction with §7(3) UWG (existing-customer exception). You may object to this processing at any time — informally by email to support@glowup-peptides.com. A data processing agreement per Art. 28 GDPR is in place with Trustpilot; processing takes place within the EU.
Right to object to profiling (Art. 21 GDPR): You can object to further processing of your data for marketing purposes at any time — via the unsubscribe link or by email to support@glowup-peptides.com.
13. SSL/TLS Encryption
Our website uses SSL/TLS encryption for security purposes. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://" and by the lock symbol in your browser bar. When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
14. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You can request information about your data stored with us at any time.
- Right to rectification (Art. 16): You can request correction of inaccurate data.
- Right to erasure (Art. 17): You can request deletion of your data, provided there are no statutory retention obligations.
- Right to restriction (Art. 18): You can request restriction of the processing of your data.
- Right to data portability (Art. 20): You can receive your data in a structured, commonly used format.
- Right to object (Art. 21): You can object to the processing of your data.
To exercise your rights, please contact us at support@glowup-peptides.com.
15. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. As our company is registered in the Czech Republic, the lead supervisory authority is:
Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27
170 00 Praha 7
Tschechische Republik / Czech Republic
www.uoou.cz
You may also contact the data protection authority for your habitual residence, place of work or the place of the alleged infringement. The European Data Protection Board (EDPB) provides a directory of EU/EEA supervisory authorities.
16. Disclosure of Data to Third Parties
We disclose personal data only where required for a requested service, performance of the contract, our legal obligations, or on the basis of your consent or a legitimate interest. Depending on the function used, this includes:
- Shipping (Sendcloud and the parcel carrier selected for the destination): name, delivery address, contact details and shipment data for label creation, delivery and tracking
- Card payments (TagadaPay and Basis Theory): payment token and the required order, contact, billing and delivery data; full card details are tokenised directly by Basis Theory
- Payment provider (paygate.to, not currently offered): order reference, amount and currency if this payment method is enabled again in the future
- Email service (Resend / Plus Five Five, Inc.): email address, message content and technical delivery information for transactional emails and, with consent, newsletters; processing in the United States may occur
- Review service (Trustpilot A/S, EU): Email address and order reference to send a review invitation after delivery (legitimate interest, objection possible at any time)
- Hosting/CDN (Cloudflare): IP address + request metadata for DDoS mitigation and fast delivery
- Database hosting (Supabase, EU Frankfurt): all order data + customer account data
- Captcha (Cloudflare Turnstile): IP + browser fingerprint for bot protection on forms
- Address validation (Google Address Validation and Geoapify): address components entered by you and technical request data to validate and complete the delivery address
- Password security check (Have I Been Pwned): only a non-reversible partial password hash to check whether it appears in known data breaches; the complete password is not transmitted
- Telegram Messenger (optional, only if you contact us voluntarily): If you contact us via @glowuppeptides, Telegram processes the exchanged messages under its own privacy terms. You may instead contact us by email at support@glowup-peptides.com. Telegram privacy policy.
Where a provider processes data on our behalf, an agreement under Article 28 GDPR is required. Other recipients act as independent controllers for their respective service. Transfers outside the EEA take place only on the basis of an applicable adequacy decision, appropriate safeguards such as EU Standard Contractual Clauses, or another statutory derogation.
We do not sell personal data. Disclosure for advertising purposes occurs only as described in Section 9 and only with the consent stated there; any other disclosure is limited to what is described in this policy or required by law.
17. Changes to This Privacy Policy
We reserve the right to update this privacy policy to comply with current legal requirements or changes to our services. The most current version will always be available on this page.
Questions about data protection?
Contact us at any time — we are happy to help.
