Data collected
Peptide Local has no public accounts, newsletter capture, advertising identifier, or analytics identifier cookie. It offers an optional vendor-review contribution form, a private contact form, and default-on, identifier-free aggregate analytics. A first-party preference cookie is stored only when analytics is turned off. Peptide Local does not ask for health information and should never be used to submit it.
Contact messages
The contact form stores the selected topic, optional name and organization, reply email, subject, message, optional referenced page URL, message status, timestamps, and a one-way content hash used to reject exact duplicates. When a correction starts from a price listing, the private record also stores that listing's stable record ID and a snapshot of the product, vendor, labelled size, published price, availability, checked date, dataset version, public record path, and original seller source. This preserves what the reader saw so the editorial desk can reproduce the claim before changing public data.
These records are private and used to review or respond to the message. The contact record does not store an IP address, user agent, referrer, advertising identifier, password, payment data, or health information. Do not submit medical records, health details, order numbers, passwords, payment information, or other sensitive data. Messages may be retained while the editorial, commercial, privacy, or legal request remains relevant and may be archived or deleted when no longer needed.
Review contributions
The optional review form stores the selected vendor, 1–5 business-experience rating, interaction topic, relationship category, material-relationship disclosure, interaction month, headline, report text, moderation status, timestamps, and a one-way content hash used to reject exact duplicate submissions. The application review record does not store a name, account, email address, order number, IP address, user agent, referrer, identity document, or health information.
Submissions remain private while pending. An editor may approve the report unchanged or reject it under the published content policy. Approved reports appear publicly on the relevant vendor profile and are labeled “anonymous · unverified.” Because the form intentionally collects no identity or contact channel, Peptide Local cannot prove a submitter purchased from the vendor or contact the submitter about a decision.
Do not include personal data, confidential information, medical details, dosage, product-use claims, adverse events, names, contact details, order numbers, or links. To report an approved contribution that should be reviewed for privacy, accuracy, or legal reasons, email admin@peptidelocal.com with the vendor, headline, and interaction month.
Analytics
Identifier-free analytics starts by default without an opt-in prompt. Peptide Local records aggregate page, qualified-view, action, coarse location, source, and real-user performance events, but does not create or store a visitor or session identifier. Events therefore cannot be joined into a person’s session or journey. A route records at most one qualified view per page load after 15 visible seconds or meaningful pointer, keyboard, touch, or scroll input after three seconds. The signal separates likely reading from a raw load, but it is not a unique-visitor estimate.
The stored location is the coarse country and region supplied by the hosting network. Traffic source stores only a source category and referring hostname, not the referring page or query. Event fields may also include the public product-and-vendor record ID and placement for an outbound commercial click, the source path, destination path, and placement for a prominent internal research link, outcome and currency for a calculator comparison, the public dataset identifier, format, and version for a download, the public peptide and destination-country slugs selected in the global status checker, or a Core Web Vitals name, value, rating, navigation type, and route template. Comparison-tool events contain only a bounded action name and result category, such as a finder match, filter choice, vendor-control use, jump, or reset. They do not contain the entered search text, selected vendor names, matched peptide, result count, or prices. A route template groups pages such as product profiles without storing page content or query text.
The server derives the canonical vendor and affiliate readiness from the public record ID and accepts only tightly formatted public paths, slugs, and performance fields. WebDriver-controlled browsers do not start client analytics, and requests carrying known crawler, command-line, headless-browser, or hosting-network automation signals are rejected before event storage. Signed-in allowlisted owner requests are rejected before event storage as well. On the production domain, an event must also carry browser-generated same-origin Fetch Metadata and a same-origin page referrer whose path matches the reported page. These request checks are used only to accept or reject the event and are not stored. The event record does not store an IP address, user agent, full referrer URL, query string, visitor ID, session ID, partner ID, search-field text, outbound URL, exact calculator inputs, exact calculated prices, name, email, or health details.
Cloudflare Web Analytics runs on eligible public site pages as an anonymous traffic and performance baseline. Its lightweight beacon measures page loads, paths, referring sources, country, device and browser categories, navigation timing, and Core Web Vitals. Cloudflare states that Web Analytics does not use cookies or localStorage, does not log query strings, and does not fingerprint individuals through IP addresses, user-agent strings, or other data. Like any network service, Cloudflare receives ordinary request metadata needed to deliver and process the beacon. A random page-load identifier distinguishes one measurement payload and is not reused as a visitor or session identifier.
Optional Google Analytics forwarding runs with analytics and advertising storage denied, advertising data redaction enabled, Google signals and ad personalization disabled, and query-free page URLs. Google may receive ordinary request metadata needed to deliver the service, but Google Analytics is not permitted to read or write analytics cookies; it receives cookieless pings rather than identified sessions. Google Analytics and Cloudflare Web Analytics load only after the first browser interaction or a six-second delay, so neither blocks the initial page render. Peptide Local’s first-party page and action totals remain immediate.
“Analytics settings” in the footer can turn Peptide Local’s first-party action totals, Google Analytics forwarding, and Cloudflare Web Analytics off or back on for that browser at any time. An opt-out flag is stored in browser storage and a first-party cookie so the server can reject stray first-party events from that browser. Opening the protected owner report automatically saves the opt-out state in that browser, and the server separately rejects authenticated allowlisted owner events. Analytics does not start on preview or local-development hosts or on private /internal pages. A previous “Not now” choice is preserved as an opt-out; the former random daily visitor identifier is removed and no new daily visitor identifiers are created.
Before the July 20, 2026 update, analytics was consent-controlled and accepted a random identifier that changed daily. New first-party events do not contain that field, and the owner report no longer presents unique-visitor estimates.
Outbound links
Commercial links pass through a no-store Peptide Local redirect tied to the exact public comparison record. The server preserves the reviewed product URL and appends a validated partner query only when that vendor is configured. When anonymous analytics is on, a fresh random click token may also be attached when the vendor has a confirmed click-ID parameter; the same token is stored with the aggregate click event for future commission matching and is never reused as a visitor or session identifier. The redirect works when analytics is off or without a click token and does not store an event by itself. External sites and affiliate networks have their own privacy practices and may attribute a click; review the destination policy before interacting with it.
Changes
This policy will be updated before adding review identity verification, email capture, public accounts, personalization, advertising pixels, visitor-level analytics, or other collection beyond the behavior described above.