Privacy Policy.
Effective February 1, 2026
1. Information we collect
- Account data: name, business email, organization, buyer type, hashed password.
- Order data: items purchased, shipping address, phone number, order value, IP address at checkout, per-order attestations, and terms version.
- Payment data: we do not store card numbers. Card payments are processed by our PCI-DSS compliant hosted processor (VERIFIED Crypto Checkout). We receive only a transaction reference. Native crypto payments record the transaction hash and destination wallet.
- Compliance data: buyer-type declaration, RUO/21+ attestations, and IP address to support age-gate and jurisdictional restrictions.
- Technical data: cookies for authentication (httpOnly JWT), session, cart persistence, and referral capture (?ref=). We do not run third-party ad-tracking pixels.
2. How we use it
- Fulfill orders, provide COAs, and send transactional email (order confirmation, shipment notification, refund).
- Verify buyer eligibility, enforce RUO/21+ restrictions, and screen orders for compliance flags.
- Prevent fraud, chargeback abuse, and unauthorized access.
- Operate the affiliate/loyalty programs (attribution and payout).
- Comply with legal obligations including recordkeeping, tax, and law-enforcement requests.
3. Who we share it with
We share the minimum data necessary with the following service providers, each bound by a data-processing agreement:
- VERIFIED Crypto Checkout — card acceptance & settlement (payment processor).
- Resend — transactional email delivery.
- USPS / UPS / FedEx — carrier fulfillment (shipping address only).
- Koveralabs / third-party assay labs — batch-level COA data (no buyer PII).
- Cloud hosting — Emergent (US-based).
We do not sell your personal information. We do not share your data with advertisers. We may disclose your information when required by law, subpoena, or court order.
4. Cookies
We use strictly-necessary cookies for authentication (access_token, refresh_token, both httpOnly), cart persistence, and referral capture. We do not use marketing or advertising cookies. You may disable cookies in your browser, but the site will not function without the authentication cookies.
5. Data retention
Order records, buyer attestations, and audit logs are retained for seven (7) years to satisfy US recordkeeping requirements. Account data is retained until you request deletion. Marketing consents are retained for the duration of your account.
6. Your rights (US & adjacent)
Depending on your jurisdiction, you may have the right to (a) request access to your personal data, (b) request correction or deletion (subject to our recordkeeping obligations), (c) opt out of any sale of personal information — we do not sell, and (d) receive a portable copy of your data.
To exercise any of these rights, email support@nebulaaminos.com from the address on file. We respond within 30 days.
7. Security
Site-wide TLS 1.3 (HTTPS). Passwords are hashed with bcrypt. Tokens are httpOnly and same-site. Card data never touches our servers. Access to production data is restricted to authorized personnel and audit-logged.
8. Children
Nebula Aminos is not directed to individuals under 21. We do not knowingly collect personal data from anyone under 21. If you believe we have collected data from a minor, contact us immediately and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top of the page indicates when the current version took effect.
10. Contact
Nebula Aminos · 113 W Ryker Ln, Midvale UT 84047, USA · 305-877-7739 · support@nebulaaminos.com.