Certificate issued with every lot · For laboratory research use only
Policies

Privacy policy.

What Derby City Labs collects, why, who else sees it, and your choices.

Who we are and what this policy covers

This Privacy Policy explains how Falls City Ventures LLC, trading as Derby City Labs ("we", "us"), collects, uses, discloses and protects personal information when you visit derbycitylabs.com (the "Site"), order from us, or contact us. We are responsible for the personal information described here.

The Site is intended only for people in the United States who are 21 or older. This policy does not cover third-party sites or services, which have their own policies.

Personal information we collect

We collect only what we need to supply research materials and run the Site.

  • Identifiers and contact details you give us: name, email address, postal address, and telephone number if you choose to give one.
  • Professional information: the institution or company you order for, if you give it, and any further evidence of eligibility we ask for.
  • Researcher and age confirmation: the fact that you confirmed you are 21 or older and buying for research use, with the date and time, and the version of our Terms you agreed to.
  • Order and commercial information: the materials you buy, order references, amounts, shipping details, delivery status and your returns or dispute history.
  • Account information, if you open an account: your name, email address and a password, which our order system stores only in hashed form, and your reward points balance and history.
  • Payment information: handled directly by our payment processor. We receive only limited information from it, such as the card type, last four digits, authorization result and fraud-screening signals. We never receive or store full card numbers or security codes.
  • Communications: messages you send us by email, through the contact form or by opening a ticket in the help center, and our replies. A ticket also records the page it was opened from.
  • Wholesale applications: your organization's name, type and website, your name, role, work email, telephone number if you give one, city and state, a description of the research, expected volume, the materials you are interested in, and the statements you confirmed.
  • Newsletter sign-ups: your email address, where you signed up, when, and the exact consent wording you agreed to.
  • Marketing preferences: whether you agreed to receive email or text messages, when, and the exact wording you agreed to.
  • Technical information collected automatically: IP address, browser and device type, the pages requested, referring page and the date and time, recorded in server and security logs. An approximate location may be inferred from an IP address. We do not collect precise geolocation.

We do not seek, and ask you not to send us, sensitive personal information such as health information, Social Security numbers, government identification numbers (unless we ask for them to verify eligibility for a wholesale account), or financial account credentials.

Where it comes from

  • Directly from you, when you confirm the researcher statements, order, open an account, subscribe or contact us.
  • Automatically from your browser or device when you use the Site.
  • From service providers, such as our payment processor (payment result and fraud signals) and delivery carriers (tracking and delivery status).

How we use it

  • To take, verify, fulfill and deliver your orders, and handle returns and refunds.
  • To verify that you are eligible to buy, keep the record of your researcher confirmation, and enforce our Terms and Research Use Policy.
  • To run your account and reward points, and apply wholesale pricing to an approved account.
  • To communicate with you about your orders and answer your questions.
  • To send email or text messages about new materials, restocks and offers, only if you opted in.
  • To detect, prevent and investigate fraud, chargebacks, misuse of the Site, security incidents and prohibited uses of materials.
  • To operate, maintain, secure and improve the Site.
  • To keep the records the law requires, including tax and accounting records, and to comply with legal obligations, lawful requests and court orders.
  • To establish, exercise or defend legal claims.

We do not use personal information for automated decisions that have legal or similarly significant effects on you, except that our payment processor may screen payments for fraud automatically. You may contact us to have a declined order reviewed by a person.

Who we share it with

We share personal information only as follows:

  • Fulfillment partner: a US-based fulfillment provider that packs and ships orders receives your name, delivery address, order contents and, where needed for delivery, your telephone number.
  • Payment processor: receives the details needed to take payment and screen for fraud, under its own privacy policy.
  • Delivery carriers: receive your name, address and parcel details.
  • Hosting and security: the Site is hosted by Cloudflare, Inc., which processes technical information, including IP addresses, to serve the Site and protect it from attacks. Cloudflare also stores what you send through the Site's forms (contact messages, help-center tickets, wholesale applications and newsletter sign-ups) in a database located in North America. To limit abuse of those forms we keep a one-way, salted fingerprint of your IP address, never the address itself.
  • Order system: orders, accounts and reward points are held in our order system (WordPress and WooCommerce), which runs on servers in the United States operated for us by our hosting provider.
  • Fonts: the Site loads its typefaces from Google Fonts, so Google LLC receives your IP address and browser information when a page loads.
  • Email and text messaging: order and account emails, and marketing messages if you opt in, are sent through email and SMS delivery providers acting on our behalf.
  • Professional advisers, such as lawyers, accountants and auditors, under duties of confidentiality.
  • Authorities: regulators, law enforcement, courts and others where the law requires it, to respond to lawful process, or where we reasonably believe disclosure is needed to prevent fraud, to protect people or property, or to address a suspected use of a material in breach of our Terms.
  • Business transfers: a buyer or successor in a merger, acquisition, financing or sale of assets, under obligations consistent with this policy.

Our service providers may use personal information only to provide their services to us. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Email and text messages

Email. If you opt in, at checkout or with the newsletter form at the foot of every page, we send messages about new materials, restocks and offers. Every marketing email carries an unsubscribe link, and we honor unsubscribes within 10 business days. Each identifies us and includes our postal address.

Text messages. If you tick the text-message box at checkout, you agree to receive recurring automated marketing text messages from Derby City Labs at the number you provide. Consent is not a condition of purchase. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. Carriers are not liable for delayed or undelivered messages. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging opt-in data and consent are never shared with any third party except the providers that send our messages.

Transactional messages. We send order confirmations, dispatch notices, password resets and service messages whether or not you opt in to marketing, because they relate to your order or account.

Cookies and similar technologies

We use as little as possible, and nothing for advertising or analytics:

  • dcr_researcher_ok cookie: records that you completed the researcher confirmation, so you are not asked again. Strictly necessary. Expires after 30 days.
  • dcr_session cookie: set only if you sign in to an account, keeps you signed in for up to 30 days, and cannot be read by the page's scripts. Strictly necessary for the account.
  • Cart: stored in your own browser's local storage (key site_demo_cart_v1:dcr) so your cart survives a page reload. It never leaves your device until you check out.
  • Order confirmation: your last order reference is held in your browser's session storage to show the confirmation page, and is deleted when you close the tab.
  • Security cookies: Cloudflare may set short-lived, strictly necessary cookies to distinguish people from automated traffic and protect the Site.

The Site runs no analytics, advertising pixels or tracking tags. If we ever add one, we will update this policy first, with its purpose and retention, and offer any choice the law requires. Because we do not track you across sites, we do not respond differently to Do Not Track signals; we treat a Global Privacy Control signal as an opt-out of any sale or sharing, which we do not do in any case.

How long we keep it

  • Order records, invoices and researcher confirmations: seven years after the order, for tax, accounting and legal purposes, and to evidence the terms on which each material was supplied.
  • Accounts and reward points: while the account is open, then as order records for any orders it placed.
  • Wholesale account records and eligibility evidence: seven years after the account closes.
  • Correspondence, contact messages and help-center tickets: three years after the last message, or longer if it relates to an order or dispute.
  • Wholesale applications: seven years after the account closes if approved; two years after the decision if declined.
  • Form abuse-prevention records (the salted IP fingerprint and a counter): about two hours.
  • Marketing contact details: until you unsubscribe, then a suppression record (your email or number only) so we do not contact you again.
  • Text-message consent records: five years after consent is withdrawn, to evidence consent.
  • Server and security logs: 90 days, unless needed to investigate a security incident.

We may keep information longer where the law requires it or to establish, exercise or defend a legal claim, and then only for as long as needed.

How we protect it

The Site is served only over encrypted HTTPS connections. Access to order records is restricted to people who need it, and protected by strong authentication. We do not store card numbers. Our service providers are chosen for their security practices and bound to protect the information they handle.

No system is perfectly secure. If a breach affects your personal information, we will notify you and any authority as the law requires.

Your choices and rights

Whatever state you live in, you may ask us to:

  • tell you what personal information we hold about you, and give you a copy in a portable format;
  • correct personal information that is inaccurate;
  • delete personal information, except where we must keep it (for example order and researcher-confirmation records, and tax records), in which case we will tell you what we kept and why;
  • stop sending you marketing messages, at any time, which you can also do with the unsubscribe link or by replying STOP.

We grant these rights voluntarily to every customer. To use them, email [email protected] from the address you ordered with. We will verify your identity by matching information we already hold, and may ask for more if the request concerns sensitive records. An authorized agent may act for you with your signed permission, and we may verify your identity with you directly. We respond within 45 days, and will tell you if we need up to 45 more. If we decline a request, you may appeal by replying with "Appeal" in the subject line, and we will answer within 60 days.

We will not discriminate against you for exercising these rights.

State privacy laws

As of the date above, we do not meet the thresholds that make the comprehensive consumer privacy laws of Kentucky, California or any other state apply to us, and this policy does not claim that they do. We nonetheless follow their main principles and offer the rights above to everyone. We will update this policy if a law comes to apply.

California. We do not sell personal information or share it for cross-context behavioral advertising, and we do not disclose personal information to third parties for their own direct-marketing purposes (California Civil Code section 1798.83).

Nevada. We do not sell covered information as defined by Nevada law. You may still email us to register a request.

Children

The Site is not directed to anyone under 21, and no one under 21 may order. We do not knowingly collect personal information from children under 13, or from anyone under 18. If you believe a minor has given us personal information, email [email protected] and we will delete it.

Where your information is processed

We operate in the United States and the Site is intended only for US residents. Our website host runs a global network, so technical information such as IP addresses may be processed by its servers outside the United States. Order records are stored in the United States.

Changes to this policy

We may update this policy. The date above shows when it last changed. If we make a material change, we will post it here before it takes effect and, where we have your email and the change affects you, tell you by email.

Contact

Privacy questions and requests: [email protected]
Mail: Falls City Ventures LLC, 30 N Gould St Ste R, Sheridan, WY 82801

We do not have a telephone line; please use email.

Every lot

Documented before
it is listed.

Independently assayed, traceable to the batch, and dispatched from the United States.

View the catalog →
Named laboratory

The laboratory that assayed your lot is named on the certificate issued with the order.

Lot-level traceability

Every vial carries its lot number, so a result traces back to that exact batch.