Privacy Policy
Last updated: 23 July 2026
1. Who we are
Peptides Éire is the data controller for personal data collected through eirepeptide.shop. Contact: support@eirepeptide.shop.
2. What we collect
- Account data: email address, name, hashed password (via our authentication provider).
- Order data: billing and shipping address, phone number, items ordered, order total.
- Payment metadata: transaction ID, status, last-4 of card — we never receive full card numbers.
- Communications: emails and support requests you send us.
- Technical data: IP address, browser, device information, and cookies (see our Cookies Policy).
3. Why we use it
- To process and dispatch your orders (contract).
- To send order confirmation, shipping, cancellation and refund emails (contract).
- To meet our legal, tax and accounting obligations (legal obligation).
- To detect fraud and secure the site (legitimate interest).
- To send marketing only where you have opted in (consent).
4. Who we share it with
We share the minimum necessary data with trusted processors: our hosting and database provider (Supabase / Lovable Cloud), our payment provider (PeptidePay), our transactional email provider (Lovable Emails), and shipping carriers. All processors are bound by contractual GDPR-compliant terms.
5. How long we keep it
Order and invoice data is retained for 6 years to meet Irish tax law. Account data is retained while your account is active and for up to 12 months after deletion. Marketing consent records are retained until you unsubscribe plus 12 months.
6. Your rights
Under GDPR you have the right to access, correct, delete, restrict or port your personal data, and to object to processing. To exercise these rights, email support@eirepeptide.shop. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).
7. International transfers
Some processors may host data outside the EEA. Where they do, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism.
8. Security
We use TLS/SSL for all traffic, encrypted databases with row-level security, hashed passwords, and access controls limiting personal data to authorised staff only.
9. Changes
We may update this policy from time to time. Material changes will be highlighted on this page and, where relevant, by email.
This document is a template intended to be reviewed and finalised by a qualified Irish solicitor before commercial launch.
Back to shop