Privacy Policy
What personal information the site collects, how it is used and shared, how long it is kept, and the privacy rights available to residents of California and other states.
Contents
1. Scope and Who We Are
This Privacy Policy explains how Theorys Labs LLC, which operates the Theorys Labs brand and the website at theoryslabs.com, handles personal information about visitors to the Site, account holders and customers. For privacy law that distinguishes between a “controller” or “business” and a “processor” or “service provider,” we are the controller and business for the information described here.
This policy covers the Site and the orders placed through it. It does not cover third-party websites we link to, or the independent practices of the service providers named in section 8, each of which has its own privacy policy.
Using the Site is subject to the Terms of Service. Cookies and similar technologies are described in more detail in the Cookie Policy.
Contact details for privacy questions and requests are in sections 20 and 22.
2. Definitions
- Personal information means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. It does not include information that has been deidentified or aggregated so that it can no longer reasonably be linked to you.
- Sensitive personal information has the meaning given by applicable state privacy law, and includes categories such as government identifiers, precise geolocation, account log-in credentials in combination with a password, and information about health, race, religion, sexual orientation or union membership.
- Process means any operation performed on personal information, including collecting, storing, using, disclosing, transferring and deleting it.
- Sell and share have the meanings given by California law: to sell is to disclose personal information to a third party for monetary or other valuable consideration; to share is to disclose it to a third party for cross-context behavioural advertising.
- Service provider or processor means a company that processes personal information on our behalf and under our instructions, and is contractually limited to that purpose.
3. Personal Information We Collect
We collect only what the Site needs in order to work, to take and fulfil orders, to keep the research-use records our Research Use Only Disclaimer requires, and to meet our legal obligations. The categories below reflect the Site as implemented at the last updated date of this policy.
Information you give us
- Account information. Your name, email address and password. Passwords are stored only as a cryptographic hash — we cannot read your password.
- Order and delivery information. Billing name and address, shipping name and address, email address, telephone number where you provide one, and any delivery note or order comment you add.
- Research-use attestations. The confirmations you give at registration and at checkout — that you are at least 21, that you are a qualified researcher, and that you are purchasing for in-vitro laboratory research only — recorded together with the version of the wording you acknowledged, the date and time, and the IP address the confirmation came from.
- Verification information. Where we ask for further information about you, your organisation or your intended research before accepting an order, whatever you choose to send us in response.
- Support correspondence. The content of emails and messages you send us, and our replies.
- Content you submit. Reviews, comments or other submissions, if and where the Site invites them.
Information generated by your use of the Site
- Order history and cart activity. The products you have ordered, order totals, order status, and the contents of your cart before checkout.
- Server log data. Our web server records the requests it receives: your IP address, the date and time, the URL requested (which, on a product page, indicates the product you viewed), the HTTP status and size of the response, the referring URL where the browser sends one, and your browser’s user-agent string.
- Device and browser information. Information your browser sends with each request, such as user agent, language and the capabilities implied by it.
- Cookies and local storage. The identifiers and state described in the Cookie Policy, including your log-in session, your cart session, and your recorded acknowledgement of the research-use notice.
- Approximate location. We do not collect precise geolocation and do not ask your browser for it. Your IP address is inherently indicative of approximate location (typically the region or city level), and the address you enter tells us where an order is going.
Information we receive from others
- Payment result information from our payment processor, as described in section 4.
- Delivery information from carriers, such as tracking status and delivery confirmation for your shipment.
What we do not collect
We do not knowingly collect sensitive personal information as that term is defined by state privacy law, beyond your account credentials. We do not collect government identifiers, precise geolocation, biometric identifiers, genetic information, health records, or information about your race, ethnicity, religion, political opinions, sexual orientation or union membership, and we ask that you not send such information to us. We do not buy personal information from data brokers, and we do not build advertising profiles.
4. Payment Information
Card payments on the Site are processed by Clover, through the Clover payment integration installed on our store platform. When you pay, your card details are entered into payment fields served by the processor and are transmitted to the processor to authorise the transaction.
Because of that design, the Site is not intended to receive or store your full payment card number, and we do not use full card numbers for any purpose. What we hold is the information needed to identify and reconcile a payment — for example a transaction or authorisation reference, the result of the authorisation, and the amount — together with the billing name and address you entered. An order record may also include the card brand and the last four digits of the card where our payment processor returns them to the store; neither is ever accompanied by a full card number.
The processor handles your card details as an independent controller of that data for its own compliance and fraud-prevention purposes, under its own privacy policy and under the payment card industry rules that apply to it. Please read the processor’s privacy policy before paying: Clover’s privacy notice is published at clover.com/privacy-policy.
Refunds are issued to the original payment method through the same processor; we cannot refund to a different card or by another means.
5. Where the Information Comes From
- Directly from you — when you register, sign in, fill in the cart or checkout, acknowledge the research-use notice, contact support, or reply to a verification request.
- Automatically from your device — through ordinary web requests, our server logs, and the cookies and local storage described in the Cookie Policy.
- From our payment processor — the payment result information described in section 4.
- From carriers — tracking and delivery status for your shipment.
- From our own systems — records we create about your account and orders, such as order status, internal notes about a support case, and the attestation records described in section 3.
6. How We Use Personal Information
We use personal information for the following purposes:
- To operate the Site — serving pages, maintaining your session, keeping your cart, and remembering that you have acknowledged the research-use notice.
- To create and maintain your account — authentication, password reset, and showing you your order history and, where you are signed in, pricing.
- To take, process and fulfil orders — accepting payment, preparing and dispatching shipments, providing tracking, and handling cancellations, replacements and refunds.
- To communicate with you about orders and your account — order confirmations, dispatch and delivery notices, payment problems, service messages, and responses to your enquiries.
- To satisfy our research-use requirements — recording and, where necessary, evidencing the age, qualification and research-use attestations described in the Research Use Only Disclaimer; carrying out proportionate verification where we suspect a prohibited use; and declining or cancelling orders where appropriate.
- To prevent fraud, abuse and misuse — detecting fraudulent orders and payment abuse, enforcing the Terms of Service and the Acceptable Use Policy, and protecting the Site, our customers and our business.
- To maintain security and diagnose problems — server logging, error investigation and integrity monitoring.
- To improve our products and the Site — understanding, in aggregate, what is ordered and what is not working.
- To comply with law — tax, accounting and record-keeping obligations, responding to lawful requests, and establishing, exercising or defending legal claims.
- For any other purpose we describe to you at the point of collection, or to which you consent.
We do not use personal information to build advertising profiles, to make automated decisions that have legal or similarly significant effects on you without human involvement, or for cross-context behavioural advertising.
7. Legal Bases for Processing
This section applies where a legal basis is required by law — in particular for individuals in the European Economic Area, the United Kingdom and Switzerland (see section 15). Our bases are:
- Performance of a contract — to create your account, take and fulfil your order, take payment, and deal with cancellations, replacements and refunds.
- Compliance with a legal obligation — tax, accounting and other statutory record-keeping, and responding to lawful requests.
- Legitimate interests — securing the Site, preventing fraud and misuse, keeping records of research-use attestations and verification, enforcing our terms, understanding in aggregate how the Site is used, and establishing or defending legal claims. Where we rely on legitimate interests, we consider your rights and expectations, and you may object as described in section 15.
- Consent — for anything we ask your permission for, such as optional marketing messages if we introduce them, or non-essential cookies if we ever set any. You may withdraw consent at any time; withdrawal does not affect processing already carried out.
- Protection of vital interests or public interest — in the unlikely event that safety or a comparable interest requires it.
8. When We Disclose Personal Information
We do not sell your personal information. We disclose it only as described here. As implemented at the last updated date of this policy, the recipients are:
- Our payment processor — Clover, to authorise, capture, refund and reconcile payments, and for its own fraud-prevention and compliance purposes (see section 4).
- Our hosting provider — DigitalOcean, LLC, which hosts the virtual private server the Site runs on and therefore stores the site database, files and server logs on our behalf. Those server logs are written by our own nginx web server on that machine; no third-party analytics, logging or monitoring service receives them.
- Carriers — the delivery companies that carry your order receive the name, address, telephone number where provided, and package details needed to deliver it.
- Our store platform vendor — the Site runs on WordPress with WooCommerce (Automattic Inc.), self-hosted by us. The platform’s usage-statistics option is currently enabled, which sends non-personal store configuration and usage data to Automattic; it is not a route by which customer records leave the Site.
- Google LLC — as the provider of the web-font service the Site loads typefaces from, Google receives the network request for those files, which includes your IP address and user-agent string. No account or order information is sent.
- Professional advisers — accountants, auditors, insurers and lawyers, where they need the information to advise us, under duties of confidentiality.
- Authorities and other parties, where the law requires or permits — to comply with a subpoena, court order, or other lawful request; to establish, exercise or defend legal claims; to investigate suspected fraud or a breach of the Terms of Service; or to protect the rights, property or safety of Theorys Labs, our customers or the public.
- A successor in a business transaction — if we are involved in a merger, acquisition, financing, reorganisation, insolvency or sale of assets, personal information may be transferred as part of that transaction, subject to this policy or a successor policy that is materially no less protective.
- Anyone else you direct or consent to.
Service providers are permitted to use personal information only to provide their service to us, except where a provider acts as an independent controller for its own regulatory, fraud-prevention or compliance purposes — most notably the payment processor.
As implemented at the last updated date, the Site does not include any third-party web analytics, advertising or social-media pixel, tag manager, session-recording tool, chat widget, customer-data platform, or email or SMS marketing platform. Nothing on the Site sends your browsing or purchase activity to an advertising network.
9. Sale, Sharing and Targeted Advertising
We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising or use it for targeted advertising, as those terms are defined by California and other state privacy laws. We do not sell or share the personal information of minors, and we do not knowingly collect it (see section 16).
This is supported by how the Site is built: it contains no advertising pixels, no analytics trackers and no tag manager, so there is no mechanism by which your activity here is passed to an advertising or data business. We also confirm that we do not disclose personal information for monetary or other valuable consideration through any arrangement outside the Site, and that we do not sell, rent or share it with third parties for their own marketing purposes.
Because there is currently no sale or sharing, there is nothing for a “Do Not Sell or Share My Personal Information” link to opt you out of. If we ever introduce advertising technology or any disclosure that constitutes a sale or share, we will update this policy and the Cookie Policy before doing so, provide an opt-out mechanism, and honour opt-out preference signals as described in section 17.
10. Cookies and Similar Technologies
The Site uses a small number of cookies and browser-storage entries, all of which are strictly necessary for it to function: keeping you signed in, keeping your cart, protecting forms against cross-site request forgery, and remembering that you have acknowledged the research-use notice. At the last updated date of this policy the Site sets no analytics, advertising, profiling or social-media cookies.
The Cookie Policy lists each technology, the purpose it serves, who sets it and how long it lasts, and explains the controls available to you, including browser controls and the Global Privacy Control signal.
11. How Long We Keep Information
We keep personal information for as long as we need it for the purposes described in this policy, and then delete it or deidentify it. How long that is depends on the record:
- Order and transaction records — kept for as long as required to meet tax, accounting, warranty, dispute-resolution and other legal obligations that apply to us.
- Research-use attestation records — kept with the account or order they relate to, because they evidence the basis on which a sale was made.
- Account records — kept while your account is open; after closure, we keep what we must for the obligations above and delete the rest.
- Support correspondence — kept while needed to handle the matter and for a reasonable period afterwards.
- Server logs — kept for the operational and security period configured on our server, then rotated out.
Our retention periods are: order and transaction records — seven years from the date of the order, to meet tax and accounting requirements; account records — for as long as the account remains open, and deleted on request as described above; and server logs — fourteen days, after which they are rotated out and deleted. Where we are required to keep information for a statutory period, that period governs regardless of any shorter period we might otherwise apply. We may keep deidentified or aggregated information, which is no longer personal information, indefinitely.
12. Security
We take reasonable technical and organisational measures to protect personal information. Those measures include: encryption in transit using HTTPS/TLS across the Site; storing passwords only as cryptographic hashes; keeping payment card entry with our payment processor rather than on our servers; restricting administrative access to the site and the server it runs on to a small number of accounts; running the public website under a dedicated, restricted operating-system account separate from other services; and applying platform and security updates.
No system is completely secure, and we cannot guarantee the security of information transmitted to or from the Site. You also have a part in this: use a strong, unique password, do not share your credentials, and tell us promptly at support@theoryslabs.com if you think your account has been compromised.
If a breach of security affecting your personal information occurs, we will notify you and any regulator as, and where, applicable law requires.
13. Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights set out below. We do not discriminate against anyone for exercising them: we will not deny you goods or services, charge you a different price, or give you a different level of quality because you made a request.
- Right to know. To ask what categories and specific pieces of personal information we have collected about you, the categories of sources, our purposes, and the categories of third parties to whom we disclose it. Sections 3, 5, 6 and 8 describe our practices for the preceding 12 months.
- Right to delete. To ask us to delete personal information we collected from you, subject to the exceptions the statute allows — for example, records we must keep to complete a transaction, comply with a legal obligation, or detect and prevent fraud.
- Right to correct. To ask us to correct inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share personal information (see section 9), so there is currently nothing to opt out of. If that changes, we will provide the required mechanism.
- Right to limit the use of sensitive personal information. We do not collect or use sensitive personal information beyond account credentials, and we do not use it to infer characteristics about you, so there is nothing to limit.
- Right of portability. To receive the personal information you gave us in a readily usable format, where technically feasible.
- Right to non-retaliation for exercising any of these rights.
Categories collected. In the preceding 12 months we have collected the following statutory categories: identifiers (such as name, email address, postal address, telephone number, IP address and account identifiers); commercial information (products viewed and ordered, and order records); internet or other electronic network activity information (server log and request data); inferences drawn from that information only to the limited extent needed to operate the store and prevent fraud; and, as account credentials, information that may be treated as sensitive personal information. We do not collect the statutory categories of biometric information, precise geolocation, professional or employment information beyond what a customer volunteers, education information, or protected-classification characteristics.
Authorised agents. You may use an authorised agent to make a request. We will ask the agent for proof of your written permission and may ask you to verify your own identity directly.
How to make a request, and how we verify it, is described in section 20.
14. Other U.S. State Privacy Rights
Several other U.S. states have comprehensive privacy laws that give their residents similar rights — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, with further states’ laws taking effect over time. Where such a law applies to you, and subject to its own conditions and exceptions, you may:
- confirm whether we process your personal data, and access it;
- obtain a portable copy of the data you provided;
- correct inaccuracies;
- ask us to delete it;
- opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects — none of which we do (see section 9); and
- appeal a decision we make on your request.
Appeals. If we decline your request, you may appeal by replying to our decision or writing to support@theoryslabs.com with “Privacy appeal” in the subject line. We will review the appeal and tell you the outcome, with reasons, within the period the applicable law allows. Where your state provides it, you may also contact your state attorney general if you are dissatisfied with the outcome.
We apply the substance of these rights to residents of any U.S. state that provides them, whether or not the state is listed above. We are also happy, as a matter of practice, to consider requests from residents of states that do not yet grant them.
15. European Economic Area, United Kingdom and Switzerland
Theorys Labs is a United States business, the Site is hosted in the United States, and orders are accepted only for delivery within the territories described in our Shipping Policy. We do not target the Site at individuals in the European Economic Area, the United Kingdom or Switzerland. The Site is nonetheless reachable from those places, so where the EU or UK General Data Protection Regulation or Swiss data protection law applies to our processing of your personal data, you have the rights to: access your data; have inaccurate data rectified; have data erased; restrict processing; object to processing based on legitimate interests, and to direct marketing at any time; receive your data in a portable format; withdraw consent where we rely on it; and not be subject to a decision based solely on automated processing that has legal or similarly significant effects (we do not make such decisions).
Our legal bases are in section 7. To exercise a right, contact us as described in section 20. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office.
International transfers. If you use the Site from outside the United States, your information is transferred to and processed in the United States, where privacy laws differ from those in your country. All of our processing takes place in the United States: we do not transfer personal information out of the United States, and no processor we use processes it elsewhere on our behalf. We therefore do not rely on a cross-border transfer mechanism.
16. Children’s Privacy
The Site is not directed to children, and we do not knowingly collect personal information from them. Nobody under 21 may create an account, place an order, or use the Site to buy anything: our eligibility requirement is 21 years of age or older, which is higher than the thresholds in the Children’s Online Privacy Protection Act and in state privacy laws.
If you believe a child has given us personal information, contact us at support@theoryslabs.com and we will delete it and close any associated account. We do not sell or share the personal information of anyone we know to be under 16.
17. Do Not Track and Global Privacy Control
Do Not Track. Browsers can send a “Do Not Track” header, but there is no common standard for what a website must do in response, so we do not respond to it. The practical answer is in section 9: we do not track you across other websites in the first place.
Global Privacy Control. The Global Privacy Control is a browser or extension signal that communicates a request to opt out of the sale and sharing of personal information. We treat it as a valid opt-out request under the laws that recognise it. At present it has nothing to act on, because we do not sell or share personal information and set no advertising or analytics cookies, so a visitor sending the signal is already in the position it asks for. If we ever introduce technology that constitutes a sale or share, we will process the signal as an opt-out for the browser that sends it before doing so, and will say so here.
You can also control cookies directly, as described in the Cookie Policy.
18. Order, Account and Marketing Communications
Transactional messages. We send emails you cannot opt out of while you have an open order or an account, because they are part of the service: order confirmations, dispatch and delivery notices, payment problems, password resets, security notices, and replies to your support messages. These are sent from our own server infrastructure.
Marketing. At the last updated date of this policy we operate no email or SMS marketing platform and send no marketing campaigns. If we introduce marketing messages, they will be sent only where the law allows — on your consent where consent is required — every message will include a way to unsubscribe, and we will honour opt-outs promptly. Unsubscribing from marketing does not stop transactional messages.
We do not sell or rent your email address or telephone number to anyone for their own marketing.
19. Third-Party Links
The Site may link to websites we do not operate. This policy does not apply to them. We do not control their content or their privacy practices, and a link is not an endorsement. Read the privacy policy of any site you visit from here before giving it personal information.
20. How to Make a Privacy Request
To exercise any right described in sections 13, 14 or 15 — access, portability, correction, deletion, opt-out where applicable, or an appeal — contact us:
- Email: support@theoryslabs.com — put “Privacy request” in the subject line.
- Post: Theorys Labs LLC, 8023 Vantage Dr., Ste. 535, San Antonio, TX 78230, marked “Privacy request”.
Tell us what you are asking for and enough information for us to find your records — typically the email address on your account and, for an order-specific request, the order number. If you have an account, you can also see and change much of your information by signing in.
Verification. We will verify your identity before acting on a request, in a way proportionate to its sensitivity — usually by confirming control of the email address on the account, and for a request about a specific order by matching details of that order. We will not ask for more information than we need, and we use anything you send for verification only for that purpose. If we cannot verify you, we will tell you and, where possible, explain what would let us proceed.
Timing. We acknowledge requests promptly and respond within the period the applicable law allows — generally 45 days, extendable once where the law permits and we tell you why. There is no charge for a reasonable request; where the law allows us to charge for an excessive or repetitive one, we will tell you before doing any work.
Limits. We may decline all or part of a request where the law permits or requires it — for example, where we must keep a record for tax or legal-defence purposes, where deleting data would prevent us from completing a transaction you asked for, or where a request would disproportionately affect someone else’s rights. We will tell you which exception we are relying on.
21. Changes to This Policy
We may update this policy as our practices, our technology or the law changes. When we do, we change the “last updated” date at the top of this page, and the updated policy takes effect when posted. For material changes we will take additional reasonable steps to notify you, which may include a notice on the Site or an email to account holders, and where the law requires consent we will ask for it before applying the change to information already collected.
Because the disclosures in this policy are tied to what the Site actually deploys, adding a new analytics, advertising, marketing or fraud-prevention service is a change that requires this policy and the Cookie Policy to be updated at the same time.
22. Contact Us
For privacy questions or requests:
- Privacy contact: support@theoryslabs.com
- General support: support@theoryslabs.com
- Post: Theorys Labs LLC, 8023 Vantage Dr., Ste. 535, San Antonio, TX 78230
- Website: theoryslabs.com
If you are dissatisfied with how we have handled a privacy matter, tell us and we will try to put it right. Depending on where you live, you may also complain to your state attorney general or to your data protection supervisory authority.
Privacy Policy · last updated August 17, 2026. Earlier text is replaced on publication; the text on this page is the text in force.