← Back to BactoCore

Privacy Policy

Draft — last edited September 2026
Note on this document: this describes what the site actually collects and does with data, as built. It is not legal advice. Whether this satisfies a specific regulation (GDPR, CCPA, or others) depends on where your business and customers are located — have a lawyer confirm that before relying on this as final, particularly the retention and rights sections below, which are flagged as open decisions.

1. What we collect

DataWhenWhy
Name, email, password (hashed)Account registrationTo create and secure your account
Shipping name and addressPlacing an orderTo fulfil and ship your order
Order contents and historyPlacing an orderOrder fulfilment, your order history, accounting
Payment detailsCheckoutProcessed directly by our payment provider (Stripe) — we do not receive or store your full card number
Name, email, optional phone, messageContacting supportTo respond to your enquiry
Page path, referring site, browser type, country (derived from IP, not the IP itself)Browsing the siteBasic traffic analytics — see Section 3

2. What we do not collect

We do not store your raw IP address in our analytics. When you visit the site, your IP is used momentarily, on our own server, to determine your country (via an offline lookup — it is never sent to a third-party geolocation service) and to compute a one-way hash used only to approximate "same visitor, same day" for traffic counts. That hash is generated using a value that changes daily, so it cannot be used to identify or track you across different days, and it cannot be reversed back into an IP address.

3. Cookies

We use one essential cookie: a session cookie that keeps you signed in. It is required for the site to function (shopping cart, account, checkout) and is not used for advertising or cross-site tracking. We also load fonts from Google Fonts, which involves your browser making a request to Google's servers — see Google's own privacy policy for how they handle that request.

4. Who we share data with

We do not sell personal data to third parties, and we do not share it for advertising purposes.

5. Data retention

Decision needed: the current build does not automatically delete old data on a schedule — account, order, and support-message data persists until manually removed. Decide on concrete retention periods (e.g., "order records kept for 7 years for accounting purposes," "support messages deleted after 2 years") appropriate to your legal and accounting obligations, and have this section updated to match, ideally with the deletion actually automated to match what this page promises.

6. Your rights

You can request a copy of the personal data we hold about you, ask us to correct inaccurate data, or ask us to delete your account and associated data, by contacting us through the site's support form. Some information (such as completed order records) may need to be retained for accounting or legal reasons even after an account deletion request.

Decision needed: account and data deletion is currently a manual process handled on request, not a self-service feature in the account area. If your customer base or applicable law expects a self-service deletion option, that would need to be built separately.

7. Security

Passwords are stored using industry-standard one-way hashing (bcrypt) — we cannot see your actual password, and neither can anyone who might gain access to our database. Sessions are managed server-side. Payment card details never reach our servers. See our engineering documentation for further technical detail if relevant to your due diligence.

8. Children

This site is not directed at, and does not knowingly collect data from, anyone under 18.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page.

10. Contact

Questions about this policy, or requests relating to your data, can be sent through the site's support form.