Comply RUO
CompliancePaymentsWhy StripeHow it worksMonitoringAffiliates
Login Get started
Compliance Payments Why Stripe How it works Monitoring FAQ Affiliates
Login Get started
Home / Legal / Privacy Policy
Privacy

Privacy Policy

Effective date: June 20, 2026 · Last updated: June 25, 2026

This Privacy Policy explains how Cevgate LLC, doing business as ComplyRUO, collects, uses, shares, and protects personal data across the ComplyRUO marketing site (complyruo.com), the merchant portal (app.complyruo.com), the affiliate portal (affiliates.complyruo.com), and the ComplyRUO WordPress plugin. It describes the categories of information we handle, why we handle them, who we share them with, the legal bases on which we rely, how long we keep the information, and the rights available to you under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the CCPA as amended by the CPRA, and other applicable privacy laws. In this Policy, “ComplyRUO,” the “Service,” the “Company,” “we,” “us,” or “our” means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO. “Merchant,” “you,” or “your” means the business that uses ComplyRUO; “Buyer” or “Customer” means the Merchant’s end customer (a research counterparty); and “Affiliate” means a participant in the ComplyRUO affiliate program.

Controller and processor roles. For buyer attestation data that ComplyRUO handles on behalf of a Merchant, ComplyRUO acts as a processor (a service provider) and the Merchant is the controller (the business). That relationship, including our processing obligations, security commitments, subprocessors, and international transfer safeguards, is governed by our Data Processing Addendum. For Merchant and Affiliate account data and for visitors to our sites, ComplyRUO is the controller. This Policy is not legal advice. ComplyRUO is not a law firm and does not provide legal, regulatory, tax, accounting, or medical advice.

Contents

  1. Who we are and scope
  2. Information we collect
  3. CCPA/CPRA categories, sources, purposes, and recipients
  4. How we use information
  5. Legal bases for processing (GDPR)
  6. How we share information
  7. Selling and sharing of personal information, and your opt-out
  8. Sensitive personal information
  9. No solely-automated decision-making
  10. Cookies, Global Privacy Control, and Do Not Track
  11. International data transfers
  12. Data retention
  13. Security and incident response
  14. Your privacy rights
  15. How to exercise your rights and verification
  16. Appeals and complaints
  17. Shine the Light and no financial incentives
  18. Children
  19. Changes and how to contact us

1.Who we are and scope

ComplyRUO is software and compliance infrastructure for the lawful, business-to-business sale of Research-Use-Only (RUO) peptides to qualified research counterparties. “ComplyRUO,” the “Service,” the “Company,” “we,” “us,” or “our” means Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO. ComplyRUO is not a bank, payment processor, acquirer, money services business, money transmitter, merchant of record, fiduciary, escrow agent, insurer, broker, financial or investment advisor, law firm or lawyer, accountant or tax advisor, and it is not a medical, scientific, or regulatory authority. It provides no legal, regulatory, compliance, tax, accounting, financial, scientific, or medical advice.

This Policy applies to personal data we handle through our marketing site at complyruo.com, the merchant portal at app.complyruo.com, the affiliate portal at affiliates.complyruo.com, and the ComplyRUO WordPress plugin installed on a Merchant’s site (together, the “Service”). It does not apply to a Merchant’s own website, store, or products, or to any third-party site that links to or from the Service; those are governed by the operator’s own privacy policy.

Controller and processor roles

Privacy law distinguishes the party that decides why and how personal data is processed (the “controller” or, under the CCPA/CPRA, the “business”) from the party that processes data on the controller’s instructions (the “processor” or “service provider”). Our role depends on the data:

  • We are the controller for Merchant and Affiliate account data and for personal data of visitors to our sites and prospective customers. This Policy is our notice for that processing.
  • We are a processor (service provider) for buyer attestation data that we handle on behalf of a Merchant. In that role the Merchant is the controller, the Merchant decides why and how that data is used, and our processing of it is governed by our Data Processing Addendum. Buyers with questions about that data should contact the Merchant first.

Related documents are cross-referenced throughout, including our Terms of Service, Acceptable Use Policy, Data Processing Addendum, Compliance & Attestation Policy, Affiliate Program Agreement, Cookie Policy, and Subprocessors list.

2.Information we collect

We collect the categories of information described below. We collect it directly from you, automatically through your use of the Service, and from the Merchant whose plugin generates buyer attestation records that we process. Section 3 maps these categories to the statutory CCPA/CPRA categories, the sources from which they are obtained, the purposes for which they are used, and the categories of recipients to whom they may be disclosed.

(a) Merchant and Affiliate account data

When you create or administer a Merchant account or an Affiliate account, or when you contact us, we collect the information you provide, which may include:

  • name and the name of your company or organization;
  • email address and, where provided, phone number;
  • business website or store URL;
  • your stated monthly processing volume and other onboarding details;
  • a hashed password (we store a one-way hash, not your plaintext password) and account, role, and authentication settings;
  • for Affiliates, the payout details you provide, including your Zelle handle, and your referral attribution and earnings records;
  • support, billing, and communications history, including messages you send us and notices we send you.

(b) Buyer attestation data processed on a Merchant’s behalf

When a Buyer completes a Merchant’s ComplyRUO compliance gate or checkout, the plugin generates a tamper-evident attestation record that ComplyRUO processes as a processor on the Merchant’s behalf. Depending on the Merchant’s configuration, this may include:

  • the counterparty type the Buyer selects (for example, the category of research entity);
  • the Buyer’s intended-use attestation, including the Research-Use-Only acknowledgment that the products are “For research use only. Not for human or animal consumption”;
  • masked identity information (we mask the Buyer’s identity in views available to anyone other than the owning Merchant);
  • a signature on file (for example, a drawn or typed signature) and the related attestation text;
  • the date and time (timestamp) of the attestation, the IP address from which it was made, and cryptographic hashes used to make the record tamper-evident.

The Merchant determines what is collected at its gate and why. Our handling of this category is governed by the Data Processing Addendum and the Compliance & Attestation Policy.

(c) Usage and technical data

When you use the Service, we and our infrastructure providers automatically collect technical information, which may include:

  • IP address, approximate (coarse) location derived from it, and network information;
  • device, browser, and operating-system details, and user-agent strings;
  • server logs, request and event metadata, error reports, and security and rate-limiting signals;
  • cookies, local storage, and similar technologies as described in Section 10 and in our Cookie Policy.

(d) Payment-related metadata

Payments are processed by Stripe, Inc. and its affiliates (“Stripe”). We do not receive or store full payment card numbers. Card data is submitted directly to Stripe and is handled under Stripe’s agreements and privacy policy. We receive payment-related metadata from Stripe such as transaction identifiers and amounts, fee and platform application-fee data, connected-account status, payout and settlement information, and chargeback, refund, dispute, reserve, and risk signals, which we use to operate the Service, calculate fees, and meet our compliance obligations.

3.CCPA/CPRA categories, sources, purposes, and recipients

This Section is our California notice at collection. It maps the information described in Section 2 to the categories of personal information enumerated under the CCPA as amended by the CPRA, identifies the sources from which we collect each category, the business and commercial purposes for which we use it, and the categories of recipients to whom we may disclose it for a business purpose. The following table covers the personal information we have collected in the preceding twelve months.

Statutory category (CCPA/CPRA) Examples we collect Sources Business or commercial purpose Categories of recipients
Identifiers Name, company name, email address, phone number, account identifiers, IP address, business or store URL. Directly from you; automatically from your use of the Service; from the Merchant for buyer records. Create and administer accounts, authenticate users, communicate, provide and secure the Service, prevent fraud, comply with law. Subprocessors and service providers; the owning Merchant; Stripe; banks, acquirers, and Card Networks; authorities where required.
Customer records and personal information categories (Cal. Civ. Code §1798.80) Name and contact details combined with account and onboarding information; Affiliate payout details (for example, a Zelle handle). Directly from you. Administer accounts and the affiliate program, calculate and pay commissions, billing, support, recordkeeping. Subprocessors and service providers; authorities where required.
Commercial information Stated processing volume, transaction identifiers and amounts, fee and application-fee data, payout and settlement information, dispute, chargeback, refund, reserve, and risk signals, referral and earnings records. Directly from you; from Stripe; automatically through the Service. Operate the Service, calculate and reconcile fees and commissions, compliance monitoring, fraud prevention, recordkeeping. Stripe; subprocessors and service providers; the owning Merchant; banks, acquirers, and Card Networks; authorities where required.
Internet or other electronic network activity Server logs, request and event metadata, device, browser, and operating-system details, user-agent strings, error reports, security and rate-limiting signals, essential cookie and session data. Automatically from your use of the Service; from infrastructure providers. Operate, maintain, secure, and improve the Service, authenticate sessions, detect and prevent abuse and security incidents. Subprocessors and service providers (for example, hosting and email); authorities where required.
Geolocation data Approximate (coarse, city or region level) location derived from IP address. We do not collect precise geolocation. Automatically from your use of the Service. Security, fraud prevention, rate limiting, and operating the Service. Subprocessors and service providers; authorities where required.
Professional or employment-related information Company role, the type of research counterparty selected at a Merchant gate, business affiliation. Directly from you; from the Merchant for buyer records. Administer accounts, perform the compliance gate and attestation Service for the Merchant, recordkeeping. The owning Merchant; subprocessors and service providers; authorities where required.
Audio, electronic, or similar information (records) Drawn or typed signature on file and related attestation text, support communications. From the Merchant’s gate for buyer records; directly from you for support. Generate, store, and verify tamper-evident attestation records as Stripe’s required preventive measures; respond to support requests. The owning Merchant; subprocessors and service providers; Stripe, banks, or authorities where needed or required.
Inferences Compliance scan classifications and risk indicators generated about a Merchant site by automated and AI-assisted review. Generated by us from information described above and from publicly accessible Merchant pages. Compliance monitoring (including the weekly automated scan), fraud prevention, and operating the Service. Results are advisory and best-effort (see Section 9). The Merchant; the AI classification subprocessor; authorities where required.

We do not collect the categories of biometric information, precise geolocation, or sensitive personal information for the purpose of inferring characteristics, beyond what is described in Section 8. We have not sold or shared any category of personal information in the preceding twelve months. We disclose the categories above to the listed categories of recipients for a business purpose only, as further described in Section 6 and Section 7.

4.How we use information

We use the information described above to:

  • provide, operate, maintain, secure, and improve the Service;
  • create and administer Merchant and Affiliate accounts and authenticate users and sessions;
  • run compliance scans (including our weekly automated scan) and generate, store, and verify the tamper-evident attestation records that function as Stripe’s required preventive measures;
  • calculate, collect, and reconcile fees, and calculate and pay Affiliate commissions;
  • communicate with you, including service, security, transactional, and administrative messages, and respond to your requests;
  • detect, investigate, prevent, and address fraud, abuse, security incidents, and prohibited or restricted activity;
  • comply with applicable law and Card Network rules (Visa, Mastercard, American Express, Discover, and other payment card networks), and enforce our agreements; and
  • cooperate with Stripe, the Card Networks, banks, processors, and governmental, regulatory, or law-enforcement authorities where needed or required.

For buyer attestation data, we use the data only to perform the Service for the Merchant and on the Merchant’s documented instructions, as set out in the Data Processing Addendum.

5.Legal bases for processing (GDPR)

Where the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, or comparable laws apply to our processing as a controller, we rely on the following legal bases:

  • Performance of a contract. To create and operate your account and to provide the Service you have requested under our Terms of Service or Affiliate Program Agreement.
  • Legitimate interests. To secure the Service, prevent fraud and abuse, conduct compliance monitoring and recordkeeping, maintain and improve the Service, and protect ComplyRUO’s rights and standing, where those interests are not overridden by your data-protection interests.
  • Legal obligation. To meet our obligations under applicable law, including tax, accounting, AML, and recordkeeping requirements, and to respond to lawful requests.
  • Consent. Where consent is required, for example for certain cookies or optional communications. You may withdraw consent at any time without affecting processing already carried out.

For buyer attestation data, the Merchant, as controller, is responsible for establishing the legal basis for the processing it instructs.

6.How we share information

We share personal data only as described in this Policy:

  • Subprocessors and service providers. We use a limited set of vetted providers to deliver the Service: Stripe for payment processing; Cloudflare for hosting, content delivery, and data storage; Resend for transactional and account email; and Anthropic for the AI classification used in our compliance scans. Each is bound by contract to protect the data and process it only for the purposes we specify. The AI classification subprocessor processes the content of a Merchant page only to return the classification for that scan; under the applicable enterprise terms it does not retain Buyer or Merchant data after the scan is complete and does not use that data to train or improve its models. A current list is maintained at Subprocessors.
  • With the Merchant. Buyer attestation data is made available to the owning Merchant, which is the controller of that data.
  • Stripe, Card Networks, banks, and authorities. We may share information with Stripe, the Card Networks, acquirers, banks, and processors, and with regulators, courts, and law-enforcement or governmental authorities, where needed to operate the Service, to comply with law, Card Network rules, or the Stripe Agreements, to respond to lawful requests, or to protect ComplyRUO, our users, or others.
  • Corporate transactions. In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, or in due diligence for one, information may be transferred subject to appropriate confidentiality protections.
  • With your direction or consent. Where you ask us to share information, or otherwise consent.

We disclose personal information to the categories of recipients above only for the business purposes identified in Section 3 and Section 4. We require service providers and subprocessors to handle personal information only as a service provider or processor under the applicable law, and not to retain, use, or disclose it for any purpose other than performing the services or as otherwise permitted by law.

7.Selling and sharing of personal information, and your opt-out

WE DO NOT SELL PERSONAL INFORMATION FOR MONEY. ON OUR PUBLIC MARKETING SITE WE USE GOOGLE ADVERTISING TAGS THAT, UNDER THE CCPA AS AMENDED BY THE CPRA, CAN CONSTITUTE “SHARING” PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING. YOU CAN OPT OUT AT ANY TIME, AND WE HONOR GLOBAL PRIVACY CONTROL SIGNALS AUTOMATICALLY. EXCEPT A SINGLE ACCOUNT-CREATED CONVERSION RECORDED WHEN YOU COMPLETE SIGN-UP, WE DO NOT USE THESE TAGS ELSEWHERE IN THE PORTALS OR AT CHECKOUT, AND WE DO NOT SHARE SENSITIVE PERSONAL INFORMATION OR THE PERSONAL INFORMATION OF KNOWN MINORS FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING.

On the public marketing site (complyruo.com) only, we use Google Analytics and the Google Ads tag to measure advertising performance and to show our ads to people who have visited us (remarketing). This can involve disclosing online identifiers (such as a cookie ID, device and browser information, and the pages you view) to Google for cross-context behavioral advertising, which the CCPA treats as “sharing.” We do not disclose personal information to data brokers, and we do not sell personal information for money. Separately, at the single moment you finish creating an account, we record one Google Ads “account created” conversion so we can tell which ads led to a sign-up. Apart from that, we do not use these advertising tags, and do not share personal information for advertising, in the merchant portal, the affiliate portal, the operator console, or on checkout pages.

Do Not Sell or Share My Personal Information. You can opt this browser out of the advertising tags using the control on our Cookie Policy, and we honor an enabled Global Privacy Control (GPC) browser signal automatically as an opt-out. You may also contact us using the details in Section 19. Opting out does not affect the essential, functional, and security storage the Service needs to run, and it does not change the business-purpose disclosures described in the categories table in Section 3.

AI subprocessor does not retain or train on your data

The AI classification subprocessor we use for compliance scans (Anthropic) is not an advertising, data-broker, or analytics partner, and its processing is not a sale or a share. It receives only the Merchant-page content needed to return a single scan classification, it does not retain Buyer or Merchant data after the scan is complete, and it does not use that data to train or otherwise improve its models. This commitment is provided under the applicable enterprise terms and is reflected in our Subprocessors list and our Data Processing Addendum.

8.Sensitive personal information

The CCPA as amended by the CPRA, and certain other laws, treat some categories of personal information as “sensitive.” In the ordinary course of providing the Service, ComplyRUO does not seek to collect sensitive personal information about Merchants, Affiliates, or Buyers. To the extent any information we handle could be characterized as sensitive (for example, account log-in credentials such as a username in combination with a password, or precise location, which we do not collect), we use and disclose it only for the purposes permitted under Section 1798.121(a) of the California Civil Code: to perform the Service, to secure accounts and prevent fraud and security incidents, to verify and maintain the quality of the Service, and as otherwise permitted by law.

BECAUSE WE DO NOT USE OR DISCLOSE SENSITIVE PERSONAL INFORMATION FOR PURPOSES BEYOND THOSE PERMITTED UNDER CALIFORNIA CIVIL CODE SECTION 1798.121(A), THE RIGHT TO LIMIT THE USE AND DISCLOSURE OF SENSITIVE PERSONAL INFORMATION DOES NOT ARISE. WE DO NOT USE SENSITIVE PERSONAL INFORMATION TO INFER CHARACTERISTICS ABOUT YOU.

We collect a one-way hash of your password rather than the plaintext password, and we hash and mask authentication and attestation tokens, so that credentials are not retained in a directly usable form. If a Merchant configures its gate to collect data that could be considered sensitive under the Merchant’s applicable law, the Merchant is the controller of that data and is responsible for its handling under the Data Processing Addendum.

9.No solely-automated decision-making

ComplyRUO operates an automated weekly compliance scan and uses AI-assisted classification (provided by Anthropic) to flag potential compliance issues on Merchant pages. These tools generate advisory, best-effort indicators only.

COMPLYRUO DOES NOT MAKE DECISIONS THAT PRODUCE LEGAL EFFECTS CONCERNING YOU, OR THAT SIMILARLY SIGNIFICANTLY AFFECT YOU, BASED SOLELY ON AUTOMATED PROCESSING, WITHIN THE MEANING OF ARTICLE 22 OF THE GDPR. SCAN AND CLASSIFICATION RESULTS ARE ADVISORY AND BEST-EFFORT, ARE NOT EXHAUSTIVE, MAY PRODUCE FALSE POSITIVES OR FALSE NEGATIVES, AND ARE NOT A LEGAL DETERMINATION, AN UNDERWRITING DECISION, OR A GUARANTEE OF ANY OUTCOME.

Approval, holds, reserves, suspension, and termination of a payment account are decided by Stripe, the Card Networks, and banks, not by ComplyRUO. The Merchant remains responsible for the lawfulness of its business, its products, its content, and its claims. We do not engage in profiling that produces legal or similarly significant effects through solely automated means. For more detail on the limitations of automated scanning, see our Compliance & Attestation Policy.

10.Cookies, Global Privacy Control, and Do Not Track

Our portals and apps use a small number of strictly necessary cookies and local-storage items to function: essential session and authentication tokens that keep you logged in and protect your account, security and anti-abuse signals, and the affiliate referral identifier used to attribute a referral correctly. Our public marketing site additionally uses Google Analytics and the Google Ads tag, which you can opt out of as described in Section 7. In the portals, the only advertising tag is a single account-created Google Ads conversion fired when you complete sign-up; we use no advertising tags at checkout. For details on each cookie, the advertising opt-out, and how to control cookies through your browser, see our Cookie Policy.

Global Privacy Control (GPC)

Some browsers and extensions can send a Global Privacy Control signal that communicates a request to opt out of the sale or sharing of personal information. As described in Section 7, the Google advertising tags on our marketing site can amount to “sharing” personal information for cross-context behavioral advertising. We honor an enabled GPC signal as a valid opt-out: when it is present, we automatically turn the advertising signals off for that browser. We do not sell personal information for money, so there is nothing further for a GPC signal to stop on that front.

Do Not Track (DNT)

Because there is no commonly accepted industry standard for how online services should respond to “Do Not Track” browser signals, the Service does not respond to DNT signals at this time. We will update this Section if a standard is adopted.

11.International data transfers

ComplyRUO operates from the United States, and our providers, including Cloudflare and Stripe, process and store data in the United States and other countries. If you are located in the European Economic Area, the United Kingdom, Switzerland, or another region with cross-border transfer rules, your information may be transferred to, and processed in, countries that may not provide the same level of data protection as your home country.

Where required, we rely on appropriate safeguards for such transfers, including the European Commission’s Standard Contractual Clauses for transfers out of the EEA, the UK International Data Transfer Addendum (or the UK Addendum to the Standard Contractual Clauses) for transfers out of the United Kingdom, and, for transfers out of Switzerland, the Standard Contractual Clauses as adapted for Switzerland and recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC), in each case together with supplementary measures as appropriate.

Where required by applicable law, ComplyRUO may appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR. The full international transfer framework for buyer attestation data that we process on a Merchant’s behalf is set out in our Data Processing Addendum. You may request more information about these safeguards using the contact details in Section 19.

12.Data retention

We keep personal data only as long as we need it for the purposes described in this Policy, after which we delete it or de-identify it. We do not retain personal data indefinitely. The table below states, by data type, a defined retention period (or, where a fixed period is not possible, the specific criteria we use to determine it) and the basis tied to that period, so that each retention is anchored to a purpose rather than left open-ended. When the applicable retention period expires, we erase the personal data or irreversibly anonymize (de-identify) it so that it can no longer be associated with you. This approach is designed to give effect to the storage-limitation principle in Article 5(1)(e) of the GDPR and to the comparable data-minimization and retention requirements of the CCPA as amended by the CPRA, which prohibit keeping personal information for longer than is reasonably necessary for the disclosed purpose. Where the law requires us to keep certain records, or where information is relevant to an actual or anticipated dispute, investigation, audit, or legal obligation, we may retain it only for the additional period necessary to satisfy that requirement, after which it is erased or anonymized.

Data type Retention period or criteria
Merchant and Affiliate account data (name, contact, account settings, hashed password) Basis: contract performance and account administration. Retained while the account is active and for up to twenty-four (24) months after the account is closed to handle reactivation, support, disputes, and security, then erased or anonymized, except where a longer financial or legal-hold period below applies to specific records.
Affiliate payout and earnings records Basis: legal obligation (tax, accounting, anti-fraud recordkeeping). Retained for seven (7) years after the relevant tax year in which the payout or earning arose, to satisfy tax, accounting, and audit obligations, then erased or anonymized.
Buyer attestation records (processed for a Merchant) Retained in accordance with the instructions of the Merchant (as controller) and ComplyRUO’s compliance, fraud-prevention, and recordkeeping needs, including the need to make records available to Stripe, the Card Networks, banks, or authorities. Governed by the Data Processing Addendum.
Payment-related metadata (transaction, fee, payout, dispute, and risk signals) Basis: legal obligation and dispute-defense (financial recordkeeping, Card Network rules, chargeback and reserve windows). Retained for seven (7) years after the transaction to which it relates, to reconcile and report fees, resolve disputes and chargebacks, and meet financial recordkeeping and compliance obligations, then erased or anonymized.
Server logs, security, and rate-limiting signals Basis: legitimate interest in security and abuse prevention. Retained on a rolling window of up to ninety (90) days, then erased or irreversibly aggregated so they are no longer personal data, except where a specific, identified security incident, dispute, or legal hold requires retaining particular entries for the additional period necessary to address it.
Support and communications history Basis: contract performance and legitimate interest in service quality. Retained for up to twenty-four (24) months after the matter is resolved for quality, dispute-resolution, and recordkeeping purposes, then erased or anonymized.
Cookies and local-storage items Session items expire when the session ends; persistent strictly necessary items are retained for the period described in our Cookie Policy.

13.Security and incident response

We use technical and organizational measures designed to protect personal data, including encryption of data in transit, one-way hashing of passwords and of authentication and attestation tokens, role-based access controls and least-privilege practices, monitoring and rate limiting, and the masking of Buyer identity information in any view available to anyone other than the owning Merchant.

We maintain an incident-response process. If we become aware of a security incident affecting personal data for which we are the controller, we will assess it and, where required by applicable law, notify affected individuals and the relevant authorities. Where we process buyer attestation data as a processor on a Merchant’s behalf, we will notify the affected Merchant (as controller) in accordance with the Data Processing Addendum so that the Merchant can meet its own notification obligations.

Notification posture and timing

Where we are the processor and a personal-data breach involves data we process on a Merchant’s behalf, our standing posture is to notify the affected Merchant (as controller) without undue delay and, in any event, within seventy-two (72) hours after we become aware of the breach, consistent with Article 33 of the GDPR and with the timing commitments in the Data Processing Addendum, so that the Merchant can meet its own deadlines. Where we are the controller and the GDPR or UK GDPR applies, we will likewise notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a breach that is required to be reported, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

For individuals whose personal information is subject to Arizona law, ComplyRUO follows Arizona’s data-breach notification statute, A.R.S. § 18-552. Where that statute applies and notice is required, we will notify affected Arizona individuals within forty-five (45) days after the determination that a breach of the security system has occurred, and we will provide any notice to the Arizona Attorney General and the consumer reporting agencies that the statute requires when the applicable thresholds are met. These periods run alongside, and do not displace, any shorter or longer timeline required by another applicable law, by Card Network rules, by the Stripe Agreements, or by the Data Processing Addendum; where multiple timelines apply, we follow the earliest one that governs the notice in question.

NO METHOD OF TRANSMISSION OR STORAGE IS PERFECTLY SECURE, AND WE CANNOT GUARANTEE ABSOLUTE SECURITY. WE DO NOT WARRANT THAT THE SERVICE IS UNINTERRUPTED, SECURE, OR ERROR-FREE. EXCEPT FOR ANY NOTIFICATION TIMELINE REQUIRED BY APPLICABLE LAW (INCLUDING THE SEVENTY-TWO (72) HOUR AND FORTY-FIVE (45) DAY POSTURES DESCRIBED ABOVE), BY CARD NETWORK RULES, OR BY THE DATA PROCESSING ADDENDUM, WE MAKE NO COMMITMENT TO A FIXED NOTIFICATION TIMELINE, AND ANY DESCRIPTION OF OUR PRACTICES IS NOT AN ADMISSION THAT A GIVEN TIMELINE APPLIES TO A PARTICULAR EVENT. YOU ARE RESPONSIBLE FOR KEEPING YOUR ACCOUNT CREDENTIALS CONFIDENTIAL AND FOR THE SECURITY OF THE SYSTEMS YOU USE TO ACCESS THE SERVICE.

14.Your privacy rights

GDPR, UK GDPR, and Swiss rights

If you are in the EEA, the United Kingdom, or Switzerland, you have the right, subject to legal limits, to: request access to your personal data; request rectification of inaccurate data; request erasure; request restriction of processing; receive your data in a portable format and have it transmitted to another controller; object to processing based on legitimate interests or carried out for direct marketing; withdraw consent where processing is based on consent; and lodge a complaint with your local supervisory authority. We will not discriminate against you for exercising these rights.

CCPA/CPRA rights

If you are a California resident, you have the right, subject to legal limits, to:

  • Right to know and access. Request the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it.
  • Right to delete. Request deletion of personal information we have collected from you, subject to legal exceptions.
  • Right to correct. Request correction of inaccurate personal information we maintain about you.
  • Right to data portability. Receive a copy of your personal information in a portable, and to the extent technically feasible, readily usable format.
  • Right to opt out of sale or sharing. Direct us not to sell or share your personal information. As stated in Section 7, we do not sell or share personal information, so there is nothing to opt out of.
  • Right to limit the use and disclosure of sensitive personal information. As stated in Section 8, we do not use or disclose sensitive personal information beyond the purposes permitted by law, so this right does not arise.
  • Right to non-discrimination. We will not discriminate against you, deny services, charge a different price, or provide a different level or quality of service, for exercising any of these rights.

Comparable rights may be available to residents of other US states with applicable privacy laws. You may use an authorized agent to submit a request on your behalf, subject to the verification standards in Section 15.

15.How to exercise your rights and verification

To exercise any of these rights, contact us at support@complyruo.com. We will respond within the time the applicable law allows. Buyers who wish to exercise rights in attestation data should contact the relevant Merchant first, because the Merchant is the controller of that data; we will support the Merchant in responding as set out in our Data Processing Addendum.

How we verify requests

To protect your information and to prevent fraudulent or unauthorized requests, we must verify your identity before we act on a request. Our verification process includes:

  • matching the identifying information you provide (such as the email address or account identifier associated with your account) to the information we hold on file;
  • confirmation through the email address on file or, where appropriate, a signed-in session in the merchant or affiliate portal;
  • requesting additional information reasonably necessary to verify your identity to a higher degree of certainty for sensitive requests, such as requests to delete data or requests for specific pieces of personal information; and
  • for an authorized agent, requiring proof that the agent is authorized to act on your behalf (for example, written permission you have signed) and, where permitted, separate verification of your own identity.

We will use the information you provide for a request only to verify the request and respond to it. If we cannot verify your identity or the agent’s authority to the standard the law requires, we may decline to act on the request and will explain why. We may also decline or limit a response where an exception under applicable law applies.

16.Appeals and complaints

If we deny your privacy request in whole or in part, you may appeal that decision. To appeal, reply to our response or contact us at support@complyruo.com with the word “Appeal” and a brief explanation of why you believe the decision was incorrect. We will review the appeal and inform you in writing of our decision and the reasons for it within the period required by applicable law.

Regardless of any appeal, California residents may file a complaint with the California Privacy Protection Agency or the California Attorney General, and residents of other jurisdictions may contact their state attorney general or applicable regulator. If you are in the EEA, the United Kingdom, or Switzerland, you may lodge a complaint with your local supervisory authority. We encourage you to contact us first at support@complyruo.com so that we have the opportunity to address your concern.

17.Shine the Light and no financial incentives

California Shine the Light

California Civil Code Section 1798.83 (the “Shine the Light” law) permits California residents to request information about a business’s disclosure of personal information to third parties for those third parties’ own direct-marketing purposes. ComplyRUO does not disclose personal information to third parties for their own direct-marketing purposes, so no Shine the Light disclosure is required. A California resident may nonetheless request confirmation of this practice by contacting us at support@complyruo.com.

No financial incentives

ComplyRUO does not offer financial incentives, and does not charge different prices or rates, or provide a different level or quality of service, in exchange for the collection, retention, sale, or sharing of personal information. Accordingly, no notice of financial incentive under Section 1798.125 of the California Civil Code is required.

18.Children

The Service is intended for businesses and the professionals who operate them. It is not directed to, and we do not knowingly collect personal data from, anyone under 18 years of age. The Service supports business-to-business sales only, and Buyers must be at least 21 years old. We do not sell or share the personal information of minors. If you believe a minor has provided us personal data, contact us at support@complyruo.com and we will take appropriate steps to delete it.

19.Changes and how to contact us

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect means you accept the updated Policy.

For privacy and data-protection questions or requests, contact us at support@complyruo.com. The data controller for the processing described in this Policy is Cevgate LLC, an Arizona limited liability company, doing business as ComplyRUO. Buyers should contact the relevant Merchant (the controller of attestation data) first. For our processing of buyer attestation data on a Merchant’s behalf, see the Data Processing Addendum; for cookies, see the Cookie Policy; and for our service providers, see the Subprocessors list.

ComplyRUO

Compliance and payments infrastructure for the lawful, B2B sale of research-use-only peptides.

ComplyRUO is software and compliance infrastructure; it is not a bank, payment processor, money services business, law firm, or medical or regulatory authority.

Product

How it works Compliance Payments Monitoring

Legal

Terms of Service Acceptable Use Privacy Compliance Policy Legal Center

Get started

Get started Why Stripe works Guides FAQ Affiliates Login

ComplyRUO is compliance and payments infrastructure for the lawful, business-to-business sale of Research-Use-Only peptides to qualified research counterparties under 21 CFR §201.128. It does not decide approval; your payment processor underwrites every account.

© 2026 ComplyRUO, a service of Cevgate LLC · complyruo.com