Privacy policy
What we collect, why we collect it, who sees it, and what you can ask us to do about it.
Last updated 4 September 2026. These terms are between you and BacLab.
1.Who we are
BacLab is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are accountable for it under the UK GDPR and the Data Protection Act 2018.
- How to reach us about data protection
- [email protected]
We have not appointed a Data Protection Officer; we are not required to. Data protection questions go to the contact above.
2.What we collect
We collect only what an order needs. Specifically:
- Identity and contact data
- Your name, email address and, where you give it, your phone number.
- Delivery data
- The postal address you supply so the order can be sent to you. For card orders this reaches us from Stripe after payment, because the address is collected on Stripe’s checkout page rather than ours.
- Order data
- What you bought, the quantity, the price, the currency, the order status, and the dates the order moved between statuses.
- Payment data
- A payment reference from the payment provider, the provider name, and the method used (for example “card”). We never receive, see or store your card number, expiry date or security code.
- Correspondence
- Messages you send us, and our replies.
- Email delivery records
- Which order emails were sent to which address and when, so we do not send the same message twice.
We do not ask for, and do not want, any special category data — including health data. Please do not send us any.
3.Why we use it, and our lawful basis
- To take and fulfil your order — performance of a contract
- Processing payment, packing, dispatching, and sending order confirmation, dispatch and delivery emails. Without this data we cannot sell to you.
- To keep accounting and tax records — legal obligation
- We must retain records of what we sold, to whom and for how much, to satisfy HMRC and company law.
- To answer your questions and handle returns — legitimate interests
- Our interest in running a business that responds to its customers. We have considered your rights and consider this processing unintrusive and expected.
- To prevent fraud and secure the site — legitimate interests
- Our interest, and yours, in not being defrauded. This includes rate-limiting and checking orders that look anomalous.
- To send repurchase reminders — the PECR soft opt-in
- See clause 5.
- To measure how the site is used — consent
- See clause 6.
4.Payments
Card, Apple Pay and Google Pay payments are processed by Stripe Payments Europe, Ltd. on Stripe’s own hosted checkout page. Your card details are entered there and never pass through this website. Stripe is a separate data controller for the payment data it collects, and processes it under its own privacy policy at stripe.com/gb/privacy. Stripe returns to us only what we need to fulfil the order: your name, email, delivery address and a payment reference.
Where cryptocurrency payment is offered, the payment gateway receives the order reference and the amount. It does not receive your name, email or address, and we do not receive your wallet address except where you give it to us for a refund.
5.Email we send you
Transactional email. Order confirmation, dispatch and delivery notifications are part of fulfilling your order. They are not marketing and you cannot opt out of them while an order is live — you would not know where your order was.
Repurchase reminders. We may email you once, some time after an order, to say that your supply is likely running low. This is marketing. We send it under the “soft opt-in” in regulation 22(3) of the Privacy and Electronic Communications Regulations 2003: you bought a similar product from us, it is about that product, and every such email carries a one-click unsubscribe link. Use it and we will record your address on a suppression list and never send you another. You may also opt out at any time by emailing [email protected].
Email is delivered by Resend, acting as our processor. We keep a record of which emails were sent to which address and when.
8.Transfers outside the UK
Some of our providers process data outside the UK, including in the United States. Where that happens we rely on the safeguards permitted by Article 46 of the UK GDPR — a UK adequacy decision where one covers the country, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for details of the safeguard used for any specific transfer.
9.How long we keep it
- Order and payment records
- 6 years from the end of the financial year the order falls in, because HMRC requires it. We cannot delete these earlier, even on request.
- Correspondence
- Up to 2 years after the matter is closed, so we can pick up a returning question.
- Email suppression list
- Indefinitely. Keeping your address on a do-not-email list is the only way to guarantee we do not email you again.
- Server and security logs
- Typically 30 to 90 days, depending on the provider.
When a retention period ends we delete the data or irreversibly anonymise it, so what remains can no longer identify you.
10.How we protect it
The site is served over HTTPS. Admin access requires a password and is protected by a signed, HTTP-only, secure session cookie, with credentials stored as bcrypt hashes. Access to order data is limited to the people who need it to pack and support orders. No system is perfectly secure, and we cannot guarantee the security of data in transit across the internet, but we will notify you and the ICO where a breach is likely to result in a risk to your rights, within 72 hours of becoming aware of it.
11.Your rights
Under the UK GDPR you have the right to:
- be informed about how we use your data — this notice;
- access a copy of the data we hold about you;
- rectify data that is inaccurate or incomplete;
- erasure of your data, where we have no overriding reason to keep it — note that tax records are such a reason;
- restrict our processing while a dispute about accuracy or legitimate interests is resolved;
- data portability — to receive the data you gave us in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests, and to object to direct marketing at any time, absolutely; and
- withdraw consent at any time where we rely on it, without affecting processing carried out before you withdrew it.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these, contact [email protected]. We respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity first, so that we do not disclose your data to someone else.
12.Complaining to the regulator
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at any time — ico.org.uk/make-a-complaint or 0303 123 1113. Complaining to us first is not a precondition of complaining to them.
13.Children
This site is not intended for anyone under 18 and we do not knowingly collect data about children. If you believe a child has given us personal data, contact [email protected] and we will delete it.
14.Changes to this notice
We update this notice when what we do with personal data changes. The date at the top of this page is the date of the current version. Where a change materially affects you — a new purpose, a new recipient, a new lawful basis — we will tell you directly rather than relying on you re-reading this page.
Questions about this page: [email protected] · Back to BacLab