Effective Date: March 28, 2026  |  Last Updated: August 24, 2026

Your privacy matters to us. This isn’t boilerplate — we actually mean it. This Privacy Policy explains what data we collect, why we collect it, who we share it with, and what control you have over it. We wrote it in plain language because privacy policies shouldn’t require a law degree to understand.

This policy applies to all information collected through elutide.com, our ordering process, customer support interactions, and any related communications from Elutide LLC, a Wyoming limited liability company (“Elutide,” “we,” “us,” or “our”).


1. What We Collect

Information You Give Us Directly

When you create an account, place an order, or contact us, you provide:

  • Account information: Name, email address, date of birth (for age verification), and a password (stored only in hashed form).
  • Order information: Shipping address, billing address, and payment details (credit/debit card). We do not store your full card number — that’s handled by our payment processor (see Section 3).
  • Communications: Anything you send us via email, chat, phone, or the contact form — including your name, email, and the content of your message.
  • Research Use Agreement: Your acknowledgment and acceptance of our research-use terms.

Information Collected Automatically

When you visit elutide.com, some data is collected automatically by our systems and third-party tools:

  • Device and browser info: IP address, browser type, operating system, device type, screen resolution.
  • Usage data: Pages visited, time spent on pages, referring URLs, click behavior, and search queries on our site.
  • Cookies and similar technologies: Small files stored on your device that help us remember your preferences, keep you logged in, and understand how people use our site. See Section 5 for the full breakdown.
  • Analytics data: We use Google Analytics to understand traffic patterns and site performance. Google may collect and process data according to its own privacy policy.
  • Real-time visitor analytics (first-party): We run our own first-party analytics that records, in real time, the pages you view and the path you take through the Site, your approximate location (city, region, and country) derived from your IP address, your device and browser, and the source that referred you. This is collected with a first-party script and stored on our own servers; it is not sent to any analytics vendor. (Like all traffic to elutide.com, these requests transit our security/CDN provider, Cloudflare — see Section 3.) If you are signed in to an Elutide account, this activity is associated with your account so our team can provide support and detect fraud or abuse. It is kept only briefly for operational monitoring and then automatically purged.

2. How We Use Your Information

We use your data for these specific purposes:

  • Processing and fulfilling your orders — verifying your identity and age, charging your payment method, shipping your products, and sending order confirmations and tracking info.
  • Customer support — responding to your questions, resolving issues, and following up on returns or refund requests.
  • Account management — maintaining your account, storing your order history, and providing access to your COA library.
  • Site improvement — analyzing how people use elutide.com so we can make it better. This includes understanding which products people view, where visitors drop off, and what content is most useful.
  • Security and fraud prevention — detecting unusual activity, preventing unauthorized access, and protecting against fraudulent orders.
  • Legal compliance — meeting our obligations under applicable laws, responding to legal requests, and enforcing our Terms of Service and Research Use Agreement.
  • Communications — sending transactional emails (order confirmations, shipping updates, account notifications). We will not send marketing emails unless you opt in, and you can unsubscribe at any time.

We do not use your data to make automated decisions that have legal or similarly significant effects on you.

3. Who We Share Your Information With

We do not sell your personal information for money, and we never will. As explained in Section 8, our use of advertising measurement tools may be considered “sharing” (and under some laws, a “sale”) of limited identifiers for cross-context behavioral advertising — and you can opt out of that at any time.

We share your data only with the following categories of service providers, and only to the extent necessary for them to do their job:

  • Card payment processing: Credit and debit card payments are processed by our third-party payment processor through a secure hosted checkout (you may be redirected to checkout.elutide.com to complete payment). The processor receives your name, billing address, email, and card details in order to authorize and settle the charge. We never see or store your full card number. The processor is PCI-DSS compliant and its handling of your data is governed by its own privacy policy.
  • Direct payment (Zelle): If you pay by Zelle, your payment is handled by your own bank under its privacy policy. (Venmo was previously accepted; the same handling applied to those payments.) We receive the payment confirmation (sender name, amount, and payment reference) needed to match your payment to your order. These confirmation emails arrive in our own business mailboxes (hosted by Microsoft) and are matched to orders by our automated software, which reads only our mailboxes — never yours.
  • Shipping carrier: UPS receives your name and shipping address to deliver your orders.
  • Shipping label generation: ShipStation receives your name, shipping address, and order contents to produce shipping labels and transmit shipment details to the carrier.
  • Delivery tracking: TrackShip monitors carrier tracking numbers on our behalf and sends delivery-status updates (in transit, out for delivery, delivered) back to elutide.com. It receives your order number, tracking number, carrier name, and destination city, state, and ZIP code.
  • Email delivery: Resend delivers our transactional and opt-in marketing email (order confirmations, shipping updates, account notifications, newsletters). Postmark processes certain inbound email to our support mailboxes. Each processes the relevant email addresses and message content solely to deliver or route mail for us.
  • Text messaging: Our business phone and SMS provider (OpenPhone) transmits the text messages we exchange with you (order updates, support replies, opt-in marketing). It processes your phone number and message content on our behalf.
  • Checkout address and phone verification: To catch typos and prevent failed deliveries and fraud, the shipping address you enter may be checked against Smarty’s US address verification service, and your phone number may be validated through Telnyx’s number lookup service. Each receives only the data point being verified.
  • Review invitations: When your order is delivered, we send an optional review invitation through Trustpilot’s Automated Feedback Service. Trustpilot receives your name, email address, and order reference solely to invite your review. You can decline or ignore the invitation at any time.
  • Live chat: Tidio powers our live chat widget. When you use chat, Tidio processes your messages, name, email (if provided), and basic device information. Tidio’s privacy practices are governed by their own privacy policy.
  • Analytics: Google Analytics collects usage data to help us understand site traffic and behavior. We use IP anonymization where available.
  • Advertising measurement — Google: Google Ads and Google Tag Manager receive event data (page views, add-to-cart, purchase, and contact events) so we can measure which campaigns lead to orders. On the order-confirmation page, we use Google’s Enhanced Conversions feature, which sends your name, email address, phone number, and billing address to Google in hashed or truncated form per Google’s Enhanced Conversions specification to improve conversion attribution. Google uses this data to optimize advertising delivery.
  • Advertising measurement — Meta: We use the Meta Pixel on elutide.com. When you browse our site, the pixel transmits event data (page views, product views, add-to-cart, checkout, and purchase events) to Meta (Facebook and Instagram). Meta receives your IP address, browser and device information, and pages you visit on our site. This helps us measure ad performance and optimize our campaigns. Meta may combine this with data it already holds about you if you have a Facebook or Instagram account. In addition to the browser pixel, we send certain events (such as purchases) to Meta server-to-server via the Conversions API; where identifiers like an email address are included, they are hashed before transmission.
  • Marketing attribution: ThoughtMetric receives order and site-event data (order id, amount, a pseudonymous visitor identifier, and the pages and marketing source associated with your visit) so we can understand which marketing channels work. It does not receive your card details.
  • Compliance verification: Our checkout compliance provider processes your age and research-use attestations (the checkboxes you confirm at checkout) and related order context to maintain verification records.
  • Security and delivery network: Cloudflare sits in front of elutide.com as our CDN and security proxy; all site traffic (including your IP address and request data) passes through it to block attacks and speed up the site. Wordfence provides on-server firewall and security monitoring and processes IP addresses and request data to detect and block threats. Pingdom collects sampled, aggregated page-performance timings.

We may also share information when required by law, subpoena, or court order, or when necessary to protect the rights, property, or safety of Elutide, our customers, or others.

4. How We Protect Your Information

We take data security seriously — it’s literally the day job of our founder. Here’s what we do:

  • Encryption: All data transmitted between your browser and elutide.com is encrypted via TLS/SSL. Your connection is always HTTPS.
  • Payment security: We never store your full credit card number. Card processing is handled entirely by our PCI-DSS compliant payment processor on its own hosted checkout; card data never touches our servers.
  • Access controls: Only authorized personnel have access to customer data, and only for the specific purposes described in this policy.
  • Server security: Our VPS is monitored, firewalled (Wordfence), and maintained with regular security updates.
  • Account security: Your account is password-protected. We recommend using a strong, unique password and not sharing your login credentials.

No system is 100% secure — anyone who tells you otherwise is selling something. But we invest real effort into protecting your data and we respond quickly if something goes wrong.

5. Cookies and Tracking Technologies

We use cookies and similar technologies on elutide.com. Here are the principal ones and why they run:

Essential Cookies (Required)

These keep the site working. Without them, you can’t log in, add items to your cart, or check out.

  • WordPress session cookies
  • WooCommerce cart and session cookies
  • Login and authentication cookies
  • Cloudflare security cookies (e.g. __cf_bm) used for bot protection

Analytics Cookies

These help us understand how people use the site so we can improve it. They don’t directly identify you by name.

  • Google Analytics 4 (_ga, _ga_*) — tracks page views, session duration, and traffic sources; linked to our Google Ads account. We use IP anonymization where available. Retention: 26 months.
  • ThoughtMetric — a pseudonymous attribution cookie tying your visit source to any eventual order.

Advertising Cookies

These measure whether our ads led you here and help ad platforms show more relevant ads. This is the category privacy laws call “sharing” for cross-context behavioral advertising — see Sections 7 and 8 for how to opt out.

  • Meta Pixel (_fbp, _fbc) — ties site events to Meta ad campaigns.
  • Google Ads / Tag Manager cookies — conversion measurement and campaign attribution.
  • Referral/ambassador cookie — if you arrive through an ambassador’s link, a first-party cookie remembers the referral so they get credit. It is not shared with ad platforms.

Functional Cookies

These support features like live chat and remember your preferences.

  • Tidio chat cookies — remembers your chat history and preferences so you don’t have to repeat yourself.

Managing Cookies

You can control cookies through your browser settings. Most browsers let you block or delete cookies. Keep in mind that blocking essential cookies will break the shopping and account features on our site.

6. How Long We Keep Your Data

We don’t keep your data forever. Here’s our retention schedule:

  • Account and order data: Retained for 3 years after your last purchase, then deleted or anonymized on our periodic purge cycle — except records we must keep longer under tax and other laws (transaction records are typically retained up to 7 years).
  • Age and research-use attestation records: Retained for as long as needed to document compliance, typically 5 years after your last order.
  • Communications: Support emails and chat transcripts are retained for 2 years to maintain service quality and resolve any follow-up issues.
  • Analytics data: Google Analytics data is retained for 26 months (Google’s default with our configuration).
  • Server logs: IP addresses and access logs are retained for approximately 90 days for security monitoring, then routinely deleted.

If you close your account, we delete your personal data from our active systems within 45 days, except where retention is required by law (such as tax records related to completed transactions). Deleted data may persist in encrypted backups for a limited period before being overwritten in the normal backup rotation; backups are not used to restore deleted personal data except for disaster recovery.

7. Your Rights

Regardless of where you live, we believe you should have control over your personal data. Here’s what you can do:

  • Access your data: Request a copy of the personal data we hold about you.
  • Correct your data: Update or fix inaccurate information. You can do most of this directly in your account settings.
  • Delete your data: Request that we delete your personal data. We’ll comply within 45 days (with notice if we need a permitted extension), except where we’re legally required to retain certain records.
  • Download your data: Request a portable copy of your data in a common format.
  • Opt out of marketing: Unsubscribe from any marketing emails using the link at the bottom of the email, reply STOP to any text, or contact us directly.
  • Opt out of advertising “sharing”: Ask us to exclude your data from advertising pixels and conversion measurement (see Section 8). You can also block advertising cookies in your browser. We treat the Global Privacy Control (GPC) browser signal as a valid opt-out of sale/sharing for that browser.
  • Withdraw consent: Where we rely on your consent for data processing, you can withdraw it at any time.

To exercise any of these rights, email us at [email protected] with the subject line “Privacy Request.” We’ll verify your identity and respond within 30 days. We will be adding a self-service data management tool to your account dashboard in the future.

We will never discriminate against you for exercising your privacy rights. No price changes, no service downgrades, no attitude.

8. California Residents (CCPA/CPRA)

If you’re a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: You can request the categories and specific pieces of personal information we’ve collected about you, the sources, the business purposes, and who we’ve shared it with.
  • Right to delete: You can request deletion of your personal information, subject to certain exceptions (like completing a transaction or complying with legal obligations).
  • Right to correct: You can request that we correct inaccurate personal information.
  • Right to opt out of sale/sharing: We do not sell your personal information for money. However, our use of advertising tools such as the Meta Pixel, Meta Conversions API, and Google Ads conversion measurement (including hashed identifiers sent through Enhanced Conversions) may constitute “sharing” for cross-context behavioral advertising under the CPRA. You can opt out at any time: email us with the subject line “Do Not Share My Info”, enable the Global Privacy Control (GPC) signal in your browser (which we treat as a valid opt-out), or block advertising cookies. Opt-out requests are honored within 15 business days, and opting out does not affect your ability to shop with us.
  • Sensitive personal information: The only CPRA-defined sensitive personal information we collect is your account login credentials (email plus password, stored only in hashed form). We use them solely to authenticate your account — a purpose permitted by the CPRA — so no “Limit the Use of My Sensitive Personal Information” link is required. Date of birth is collected only for age verification and is not sensitive personal information under the CPRA.
  • No retaliation: We will not discriminate against you for exercising any CCPA/CPRA rights.

Categories of personal information collected in the last 12 months:

  • Identifiers (name, email, shipping address, IP address)
  • Commercial information (purchase history, order details)
  • Internet activity (browsing behavior on elutide.com, search queries)
  • Geolocation data (approximate location from IP address)
  • Inferences and hashed identifiers disclosed to advertising platforms for measurement (see Section 3)

We have not sold personal information in the last 12 months. We have disclosed personal information to service providers for business purposes, and have “shared” limited identifiers and internet-activity data with advertising platforms for measurement, as described in Section 3. Use the opt-out above to stop that sharing.

To submit a CCPA/CPRA request, email [email protected] with the subject line “CCPA Request.” You may also designate an authorized agent to make a request on your behalf.

9. Other State Privacy Laws

Several other states have enacted comprehensive privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and others. While these laws vary in their specifics, the rights we provide in Section 7 generally meet or exceed the requirements of these frameworks.

If you’re a resident of a state with specific privacy legislation and believe your rights aren’t fully addressed here, contact us at [email protected] and we’ll work with you. Residents of states whose laws provide an appeal right may appeal any refusal of a privacy request by replying to our decision; we will respond within the statutory period.

10. Children’s Privacy

Elutide.com is not intended for anyone under 21 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us immediately at [email protected] and we will promptly delete that information.

11. Data Breach Notification

If we become aware of a data breach that compromises your personal information, we will:

  • Notify affected customers via email without unreasonable delay after we confirm the breach and its scope — and in all cases within the timeframes required by applicable state breach-notification laws. Our goal is that you hear it from us first, as fast as the investigation allows.
  • Notify applicable state attorneys general and regulatory bodies as required by law.
  • Provide a clear description of what happened, what data was affected, and what steps we’re taking to fix it and prevent it from happening again.

We don’t bury bad news. If something goes wrong, you’ll hear about it directly from us, not from a news article.

12. Third-Party Links

Elutide.com may contain links to other websites (for example, our payment processor or shipping carrier). We’re not responsible for the privacy practices of those sites. When you leave elutide.com, we encourage you to read the privacy policy of any site you visit.

13. Changes to This Policy

We may update this Privacy Policy as our business evolves or as laws change. When we make material changes, we’ll update the “Last Updated” date at the top and notify registered users by email. Your continued use of elutide.com after changes are posted means you accept the updated policy.

14. Contact Us

Questions, concerns, or requests about your privacy? We’re here.

Elutide LLC
3906 Baldwin, Auburn Hills, MI 48326
Email: [email protected]
Subject line: “Privacy Request”
Website: elutide.com
Phone: (586) 300-5006

We aim to respond to all privacy-related inquiries within 30 days.


For Research Use Only. Not Intended for Human Consumption.

© 2026 Elutide LLC. All rights reserved.

0
Have a question? Chat with us! ×