Test mode — all payments in preview use Stripe test cards (e.g. 4242 4242 4242 4242).
⬤ All products are sold strictly as laboratory reagents for in-vitro research use only. Not for human or veterinary use.
The Pretty Little Peptides — sunset beach brand badgeKayethel Peptides

Trust & Security

Security, Privacy & Compliance

This page is maintained by Kayethel Peptides to answer common security and privacy questions about our catalog and ordering platform. It describes controls currently enabled in the app and is editable project content — not an independent certification or third-party audit attestation.

Access & Authentication

Customer accounts are protected by email-and-password authentication backed by our managed backend provider. Sessions use signed tokens stored in the browser and are rotated on sign-in. Administrative views are gated by a server-validated role assignment — role membership is never read from client-side storage.

Checkout requires an authenticated session and a completed researcher qualification record before a payment session can be created.

Data Protection

Traffic to the site and to backend APIs is encrypted in transit using industry-standard TLS. Row-level access rules restrict customer data (orders, subscriptions, qualifications, affiliate records) so that signed-in users can only read rows tied to their own account. Order and subscription rows are written only by trusted server-side webhook handlers, never directly by the browser.

Sensitive payment details are handled entirely by our payment processor (Stripe) and are never stored on our servers.

Data Collection & Use

We collect the information needed to process orders and operate your account: name, email address, shipping address, institutional affiliation (for researcher qualification), and order history. We do not sell or rent personal data. See the full Privacy Policy for details on collection, use, and retention.

Subprocessors & Integrations

Operating the site relies on a small set of trusted subprocessors:

  • Lovable Cloud (Supabase) — application database, authentication, edge functions, storage.
  • Stripe — payment processing and subscription billing.
  • Resend — transactional and alert email delivery.
  • Lovable AI Gateway — AI assistant and content generation features.

Each subprocessor is used only for the function listed above. Credentials are stored as server-side secrets and are not exposed to the browser.

Shared Responsibility

Platform-level capabilities (managed hosting, database, authentication, secret storage) are provided by Lovable Cloud. Configuration of access rules, data handling practices, content, and compliance disclosures on this site are the responsibility of Kayethel Peptides. Customers are responsible for maintaining the confidentiality of their account credentials and for using our products in accordance with the Research Use Only terms.

Research Use Only Compliance

All products sold are intended strictly for in-vitro laboratory research. Orders require an 18+ acknowledgement and a researcher qualification record (institution, role, and institutional email) before checkout. Users cannot self-assign a "verified" status — verification flags are administered server-side.

Vulnerability Reporting

If you believe you've found a security issue, please report it to security@kayethelpeptides.com. Please include reproduction steps and avoid testing that could affect other users or their data. We will acknowledge reports and work in good faith to investigate and remediate confirmed issues.

Privacy Requests & Contact

To request access to, correction of, or deletion of personal data we hold about you, contact privacy@kayethelpeptides.com. For general inquiries, see our FAQ.

This page describes controls enabled in our application at the time of writing. Nothing on this page should be interpreted as a regulatory certification (e.g. SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS) unless we publish a separate attestation referencing the relevant audit. Last updated June 2026.