For laboratory research use only, not for human or veterinary use
Same-day dispatch before 2pm (Mon–Fri)
pepts.

Privacy policy

What we collect, why, who else sees it, and how to get it back or get rid of it. The short version: we take what an order needs, we do not sell it, we do not send marketing, and analytics stay off until you say yes.

Last updated: 5 October 2026

1. Who is responsible for your data

Demirius Ltd, trading as Pepts, is the data controller for the personal data described here. That means we decide why and how it is used, and we are the ones you can hold to this policy.

  • Registered name: Demirius Ltd, trading as Pepts
  • Registered in: England and Wales, company number 16820023
  • Registered office: 47 Cranwell Crescent, Eaton Leys, Milton Keynes, MK17 9GS, England
  • VAT registration number: GB 505 3821 14
  • Email: support@pepts.co.uk, or the contact form

For anything about your data, including a request to see it or delete it, email support@pepts.co.uk. We reply within one business day.

We are a small business and we have not appointed a Data Protection Officer, because we are not required to. Requests go to the address above and are handled by us directly.

2. What we collect

We collect what a shop needs to take an order and get a parcel to you, and very little else. We do not buy personal data from anyone, we do not build advertising profiles, and we never sell it.

  • Account data: your name, email address, whether the address has been verified, and a salted hash of your password. We never store or see your password itself.
  • Order data: the items you ordered, the price you paid, the delivery address, any note you added at checkout, the order status, the moment you accepted our terms, and, where we photograph your parcel as it is packed or handed over, those photos, which show the label.
  • Saved addresses: if you keep an address in your account, the name, street address, town, county, postcode and phone number on it.
  • Basket: what is in your basket, held against your account or against an anonymous basket identifier in a cookie if you are not signed in.
  • Payment data: if you pay by bank, the payment is initiated by Pepts's open-banking provider inside your own banking app. We receive a payment reference and a status. We never receive your card number, account number, sort code or banking login. If you pay by manual bank transfer we see what your bank shows on the transfer.
  • Sign-in records: for each active session, the time it was created and expires, your IP address and your browser's user agent string. This is what lets you stay signed in and lets us spot an account being attacked.
  • Postcode lookups: when you use the postcode finder at checkout we send the postcode (not your name or address) to our address-lookup provider, and we count lookups against your IP address so that the service cannot be drained by a script.
  • Reviews: the display name you choose, your rating, title and review text, and whether we could match it to a real order. If you are not signed in we also ask for your email address, which is never published: it lets us match the review to your order and write to you about it.
  • Restock alerts: the email address you gave and which product size you asked about.
  • Email records: a log of the transactional emails we sent you, including the emails as we sent them, and what our email provider reported back about each one: that it was delivered, that it bounced, or that it was opened. An open is reported by a small tracking image in the email, which your mail app may fetch whether or not you read the message, and it tells us nothing but the time. We use these reports to see whether an email reached you when you ask, and to stop writing to an address that bounces. They build no profile and are kept with the log. There is also a suppression list of addresses that bounced, complained, or asked not to be emailed, so that we never write to them again.
  • Messages: what you send us through the contact form, from your account, or by replying to one of our emails, and what we reply. Kept with your order history so a later question about the same order has its context.
  • Usage data: if you consent to analytics cookies, aggregated statistics about which pages are visited, from roughly where, on what kind of device. See the cookie policy.

We do not ask for and do not want any special category data: nothing about health, biometrics, ethnicity, beliefs or sexuality. Please do not put any of it in an order note, a review or a message to us.

3. Why we use it, and our lawful basis

UK GDPR requires us to have a specific lawful basis for each use. Here they all are.

What we doData usedLawful basis
Take and fulfil your orderAccount, order, address, payment referencePerformance of a contract with you
Run your accountAccount data, saved addresses, sign-in recordsPerformance of a contract with you
Send order confirmations, dispatch notices and account emailsEmail address, order dataPerformance of a contract with you
Send a restock alert you asked forEmail address, product sizeConsent, which you can withdraw at any time
Publish your reviewDisplay name, rating, review text, verified-purchase flag; the email address a guest gives, which is never publishedConsent, given when you submit it
Answer your messageName, email, order number, messageLegitimate interests: answering the people who write to us
Keep the site secure and stop abuse of the postcode lookupIP address, user agent, lookup countersLegitimate interests: protecting the service and its costs
Record that you accepted the terms and the research-use declarationTimestamp against your orderLegitimate interests: proving what was agreed, and complying with our own supply conditions
Keep accounting and VAT recordsOrder and payment recordsLegal obligation, under tax and company law
Suppress addresses that bounced or opted outEmail address, reasonLegitimate interests, and your right to object: the only way to honour an opt-out is to remember it
Understand what people want to buyWhat was added to, removed from and ordered out of baskets, against the basket identifierLegitimate interests: knowing which sizes to stock and how to price them
Measure how the site is usedAnalytics cookies and the usage data they generateConsent, given through the cookie banner

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and concluded it is not: each of those uses is narrow, expected, and hard to run a shop without. You can object to any of them, and we will stop unless we have compelling grounds not to. See your rights.

Marketing. We do not send marketing email. If we ever start, it will be opt-in, it will be separate from the transactional email above, and every message will carry a one-click unsubscribe.

4. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to remember your basket. These do not need your consent, because the shop cannot work without them.

We also use Google Analytics, which sets analytics cookies, and a Google Ads tag, which sets a cookie that tells us when one of our own adverts led to an order. Both are off until you accept them: no Google script loads and none of those cookies is set unless you choose Accept in the cookie banner, and you can change your mind at any time. Neither is used to build an advertising profile of you or to follow you to other sites. Declining costs you nothing; every part of the shop works either way.

The full list, with names, purposes and lifetimes, is in the cookie policy.

5. Who else sees it

We share personal data only with the providers that make the shop run, and only with what each one needs. They act on our instructions under a data-processing agreement, except where they are named below as a controller in their own right.

WhoWhat they seeWhy
VercelAnything sent to the site, in transit; request logsHosting and delivery of this website
NeonEverything stored in the shop databaseThe managed Postgres database behind the shop
ResendYour email address, the content of emails we send you, and whether each was delivered or openedDelivering transactional email and reporting what became of it
FenaYour name, email, order amount and reference, and delivery addressOpen-banking payment, only if you choose to pay by bank. Fena is a controller of the payment data it holds and is regulated by the FCA.
Ideal Postcodes, or postcodes.ioThe postcode you typed, and our IP addressTurning a postcode into a list of addresses at checkout. Your name and chosen address are never sent.
Royal MailThe delivery name, address and order reference on the labelDelivering your parcel. Royal Mail is a controller of that data for its own delivery purposes.
Google (Analytics, Ads, Search Console)Usage data from analytics cookies, only with your consent. For an order that followed a Google advert: the click identifier Google put on the link, the order number, the amount and the time, whether or not you accepted cookies; no name, address or e-mail. Search Console sees nothing from your visit.Understanding how the site is used, which adverts lead to orders, and how the site appears in search. Google is a controller in its own right for its advertising service.

We will also disclose data where the law requires it, to a regulator or a court, to establish or defend a legal claim, or to prevent fraud. If the business is ever sold or transferred, customer records would pass to the buyer under this policy, and we would tell you.

What is not shared. We run a data exchange with our sister site Pepmarket, and we use an AI service to help draft product descriptions in our admin tools. Neither one receives customer data: the exchange carries compound names, prices and catalogue information, and the drafting tool is given product facts. No order, account, address, review or message is sent to either.

6. Where your data goes

Our shop database is hosted by Neon on Amazon Web Services in Ohio, United States. Our hosting, transactional email and analytics providers (Vercel, Resend and Google) are US companies and also process data outside the UK. We would rather tell you that plainly than describe the stack as if it were all local.

When personal data leaves the UK we rely on one of the safeguards UK data protection law allows: an adequacy decision (which covers the EEA), the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it, or the International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, together with a transfer risk assessment. You can ask us for a copy of the safeguard that applies to a particular provider.

7. How long we keep it

We keep personal data only as long as we have a reason to, then delete it. The shorter windows below are enforced by a job that runs every night, not by somebody remembering.

WhatHow longWhy that long
Order and payment records6 years from the end of the financial year the order falls inHMRC requires VAT records to be kept for 6 years
Account, saved addresses, basketUntil you delete your account, or ask us toIt is your account; it exists while you want it
Guest basketDeleted once it has gone 90 days without a changeThe cookie that finds it lasts that long, so nobody can come back to an older one
How you arrived and which pages you viewed24 months; 90 days if it never led to a basket or an orderThe same window as the basket history it explains
Sign-in sessions (IP, user agent)Until the session expires or you sign outIt exists to keep you signed in
Postcode-lookup counters (IP)Cleared once an address has been quiet for 30 daysLong enough to stop a script coming back, no longer
Published reviewsUntil you ask us to remove themThey are useful to other researchers while they stand
Restock alertsDeleted as soon as the alert has been sentThe request is finished when the email goes out
Transactional email log24 monthsLong enough to answer "did that email ever reach me"
Email suppression listIndefinitely, unless you ask to be emailed againDeleting it would mean emailing someone who asked us not to
Marketing listUntil you unsubscribe; the record that you unsubscribed is then kept indefinitelyThe only way to honour an opt-out is to remember it
Messages, and any files attached to them24 monthsContext for a later question about the same order
Basket and checkout history (what was added, removed or ordered, and how far checkout got)24 monthsLong enough to compare one year with the next, no longer

Deleting your account. You can delete it yourself from your profile. That removes your name, email address, password, saved addresses and every sign-in session, and detaches your basket. Two things survive it, and we would rather say so than let you find out later. Orders you have already placed are kept, because we are legally required to keep the record of a sale, but they are detached from the deleted account, and your reviews keep only the display name you chose. And the log of emails we already sent you, and the suppression list if your address is on it, age out on the schedule above rather than going immediately, because the only way to honour "do not email me" is to remember the address. Ask us and we will delete whatever is not legally required.

8. How we protect it

  • The whole site is served over HTTPS.
  • Passwords are stored only as a salted hash. Nobody here can read yours, which is why a forgotten password is reset rather than recovered.
  • Card and banking credentials never touch our servers; the bank authorises the payment, not us.
  • Admin tools are restricted to accounts with an admin role, and every price and stock change is written to an audit ledger with the person who made it.
  • Database access is limited to the application and to the people who run it.

No system is perfectly secure. If a breach ever puts your rights at risk we will tell the Information Commissioner's Office within 72 hours, and we will tell you without undue delay where the risk to you is high.

9. Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you, and tell you what we do with it.
  • Correct anything inaccurate or incomplete. Most of it you can edit yourself in your account.
  • Delete it, where we no longer need it. We cannot delete the record of a completed sale before the tax retention period is up, and we will say so rather than pretend otherwise.
  • Restrict how we use it while a dispute about it is resolved.
  • Object to any use we base on legitimate interests.
  • Port your account and order data to another service, in a machine-readable format.
  • Withdraw consent at any time, for analytics cookies, restock alerts, or a published review. Withdrawing does not undo what was lawful before you did.

Email support@pepts.co.uk or use the contact form. We answer within one business day and complete the request within one month, which the law allows us to extend by two further months for a complicated one. There is no charge. We may ask you to confirm your identity, and we will only ask for what we need to be sure.

10. Complaining

Tell us first if you can: it is usually quicker, and we would rather fix it. You also have the right to complain to the UK's data protection regulator at any time, and doing so does not require you to come to us first.

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113, ico.org.uk/make-a-complaint.

11. Children, automated decisions, and changes

Children. This shop is not for under-18s and we do not knowingly collect data from them. If you believe a child has given us personal data, tell us and we will delete it.

Automated decisions. We do not make decisions that have a legal or similarly significant effect on you by automated means, and we do not profile you. Orders are reviewed by a person.

Changes to this policy. We update this page when what we do changes, and the date at the top is the date it last changed. If a change is significant, we will tell account holders by email rather than relying on you to check.

See also the cookie policy for what each cookie does, and the terms of sale for the contract itself.