RUO labs only · Qualified accounts

Crescent BioLabs

Crescent BioLabs legal

Privacy Policy

How we collect, use, disclose, retain, and protect personal information—and the choices available to you.

Last updated
April 9, 2026
Version
PRIVACY-V0.1-20260409

For laboratory research use only

Products sold on this site are intended exclusively for in-vitro laboratory research by qualified professionals. They are not drugs, dietary supplements, foods, cosmetics, or medical devices; they are not FDA-approved for any purpose; and they are not for human or animal consumption under any circumstances.

01

Scope and who we are

This Privacy Policy applies to crescentbiolabs.com, related pages and services, account registration, purchases, support communications, and other interactions with Crescent BioLabs. It does not govern independent third-party sites or services.

Crescent BioLabs is the controller or business responsible for personal information described here, except where a service provider acts independently under its own policy.

02

Definitions

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. “Process” means collecting, using, storing, disclosing, analyzing, or deleting Personal Information. “Service Provider” means an organization that processes information for a business purpose under contract or applicable law.

03

Information we collect

Information you provide

  • identity and account details, including name, email, authentication identifiers, age confirmation, and researcher-profile information;
  • transaction and fulfillment details, including order history, billing contact, shipping address, selected payment method, and carrier records;
  • research eligibility information, including organization, role, field, intended research application, and certifications;
  • communications, support requests, reviews, survey responses, and marketing preferences.

Information collected automatically

  • device, browser, IP address, operating system, language, approximate region, and identifiers;
  • pages viewed, referral data, clicks, cart activity, checkout events, session timing, and error diagnostics;
  • cookie, local-storage, consent, fraud-prevention, and authentication data.

Payment providers process payment credentials directly. We do not intend to store full payment-card numbers in the storefront.

04

Sources of information

We collect information directly from you, automatically from your browser or device, and from providers that support authentication, payments, fraud prevention, shipping, communications, analytics, advertising, and account security. We may also review public institutional or professional sources when verifying researcher affiliation.

05

How we use information

  • create, authenticate, secure, and administer accounts;
  • evaluate research eligibility and enforce research-use restrictions;
  • process, fulfill, track, support, refund, or investigate orders;
  • prevent fraud, chargeback abuse, security incidents, and illegal activity;
  • operate, debug, personalize, measure, and improve the site;
  • send transactional notices and, with appropriate permission, marketing;
  • comply with law, enforce agreements, preserve records, and protect rights and safety.
06

Legal bases for processing

Where the GDPR, UK GDPR, or similar law applies, we process information as necessary to perform a contract, comply with legal obligations, pursue legitimate interests such as fraud prevention and site security, protect vital interests where applicable, or act on consent. You may withdraw consent prospectively where consent is the basis.

07

How we disclose information

We may disclose Personal Information to providers that perform services on our behalf, including:

  • Clerk for identity, authentication, and account security;
  • Vercel and infrastructure providers for hosting, databases, delivery, security, performance, and operational analytics;
  • payment, fraud-prevention, banking, shipping, fulfillment, and communications providers used for a transaction;
  • Google, Meta, PostHog, TikTok, Reddit, or similar analytics and advertising providers only when configured and permitted by your consent choices;
  • professional advisers, insurers, auditors, regulators, courts, and law enforcement where legally appropriate;
  • a successor or transaction counterparty in a merger, financing, restructuring, or sale.

Providers receive only information reasonably necessary for their function and are subject to their own contractual and legal duties.

08

Sale, sharing, and targeted advertising

We do not sell Personal Information for money. Some advertising or analytics disclosures may be considered “sharing,” targeted advertising, or a “sale” under broad state-law definitions. Non-essential advertising and analytics are controlled through consent choices and our Cookie Preferences control.

You may opt out by rejecting non-essential cookies or reopening Cookie Preferences in the footer. We honor a browser Global Privacy Control signal as an opt-out where detected.

09

Cookies and similar technologies

We use cookies, pixels, local storage, and similar technologies for authentication, cart and preference continuity, consent storage, security, analytics, and advertising. Details and controls are in our Cookie Policy.

10

Data retention

We retain information only as long as reasonably necessary for the purposes described here, including account service, order fulfillment, laboratory-use records, tax and accounting, fraud prevention, disputes, legal compliance, and security. Retention varies by record type and may be extended by a legal hold or statutory requirement.

When information is no longer required, we delete, de-identify, or securely isolate it, subject to backup and technical limitations.

11

Security

We use administrative, technical, and physical measures designed to protect Personal Information, including encrypted transport, access controls, account authentication, monitoring, and provider safeguards. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

Protect your credentials, use a unique password, enable available security methods, and notify us at support@crescentbiolabs.com if you suspect unauthorized access.

12

California privacy rights

Subject to applicability thresholds, verification, exceptions, and applicable law, California residents may request access to categories or specific pieces of Personal Information, correction, deletion, and information about sources, purposes, and disclosures. They may opt out of sale or sharing and may not be discriminated against for exercising a right.

Email support@crescentbiolabs.com with the subject “CCPA Request.” We may verify identity by matching information already on file and may require proof of authority from an agent. A detected Global Privacy Control signal is treated as an opt-out of sale or sharing.

13

Other U.S. state rights

Residents of states with comprehensive privacy laws may have rights to access, correct, delete, or obtain a portable copy of Personal Information and to opt out of targeted advertising, sale, or certain profiling. Email support@crescentbiolabs.com with the subject “State Privacy Request,” your state, and the right requested. Where law provides an appeal, you may appeal by replying to our decision.

14

EEA, UK, and Switzerland

Where applicable, individuals may request access, rectification, erasure, restriction, portability, or objection; withdraw consent; and complain to a supervisory authority. Information may be transferred to the United States or other provider locations using lawful transfer mechanisms where required.

To exercise a right, contact support@crescentbiolabs.com. Some rights are limited by legal exceptions, contract necessity, or overriding lawful grounds.

15

Children’s privacy

The site and products are not directed to children. Accounts and purchases require users to be at least 21. We do not knowingly collect Personal Information from children under 13 or knowingly sell, share, or use for targeted advertising the Personal Information of minors where prohibited. A parent or guardian who believes a child provided information should contact support@crescentbiolabs.com.

16

Do Not Track and Global Privacy Control

Because there is no universal technical standard for Do Not Track, the site may not respond to every DNT signal. We configure PostHog to respect DNT and honor Global Privacy Control as an opt-out of non-essential sale or sharing when the browser exposes the signal.

17

Marketing communications

With permission, we may send product, promotional, or research-news communications. You may unsubscribe from email through its link, reply STOP to eligible marketing texts, or contact support@crescentbiolabs.com. Transactional and legal notices may continue.

Any SMS marketing requires a separate opt-in and is subject to applicable communications law; message and data rates may apply.

18

Third-party links

The site may link to independent resources. Their privacy practices are governed by their own policies. Review those policies before submitting Personal Information.

19

Updates to this policy

We may update this Policy and will post the revised version with a new effective date. Where required, material changes receive additional notice. Previous versions may be retained for business or legal records.

20

Contact us

For privacy questions or requests, email support@crescentbiolabs.com. Include enough detail for us to understand the request, but do not send passwords, full payment credentials, or unnecessary sensitive information.