Shop by goal

  • Metabolic Signalling
  • GH-Axis Research
  • Muscle & IGF Research
  • Tissue and Cellular Models
  • Regenerative Research
  • Cellular Senescence Research
  • Cognitive Research
  • Multi-Compound Blends
  • Accessories
  • All compounds →
  • Popular compounds

  • BPC-157
  • TB-500
  • GHK-Cu
  • Retatrutide
  • Semaglutide
  • Ipamorelin
  • All bestsellers →
  • Research resources

  • Research Areas
  • Certificates of Analysis
  • Research Glossary
  • Compare Compounds
  • Peptide Guides
  • Delivery Guide
  • Track Order
  • Recently viewed

  • All peptide guides
  • Crypto Blog
  • How to Reconstitute
  • Reconstitution Calculator
  • How to Store
  • Research
  • Certificates of Analysis
  • Sign In
  • Create Account
  • My Account
  • My Orders
  • My Referrals
  • Log Out
  • Track Order
  • Refer a Friend
  • Follow us on Twitter/X
  • How-to guides

    Privacy Policy.

    Published: May 2026 · GDPR-aligned

    Version 1.01 · Updated 18 June 2026

    1. Overview

    New-U Research Compounds ("we," "us," or "our") is a brand operated by Hilxera Distribution Services LLC. We operate the website new-u.io.

    This Privacy Policy explains how we collect, use, disclose and safeguard your personal information. It covers visits to our website, orders and other interactions with our services. By using our website you consent to the practices described here.

    This policy is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). It also covers the UK GDPR and Data Protection Act 2018. It addresses equivalent consumer data-protection laws in the United States, including the California Consumer Privacy Act / CPRA.

    2. Data Controller & Legal Basis

    Hilxera Distribution Services LLC, registered in Wyoming (ID: 2026-001928701), is the data controller for personal data processed through new-u.io. You can reach our privacy contact at newu.io.peptides@gmail.com.

    Under GDPR Article 6, we process your personal data only where one of the following legal bases applies:

  • Performance of a contract (Art. 6(1)(b)) - processing orders, shipping, and customer support.
  • Legal obligation (Art. 6(1)(c)) - tax, accounting, anti-fraud, and regulatory record-keeping.
  • Consent (Art. 6(1)(a)) - marketing emails, SMS updates, non-essential cookies, and research-verification data. Consent is freely given, specific, informed, and can be withdrawn at any time.
  • Legitimate interests (Art. 6(1)(f)) - fraud prevention, network security, and aggregate analytics. We balance these interests against your rights and only rely on this basis where it does not override your freedoms.
  • We do not knowingly process special-category data under GDPR Article 9.

    3. Information We Collect

    Information You Provide Directly

    We collect personal information that you voluntarily provide when you:

  • Place an order for research-grade peptide compounds
  • Create an account or register for order tracking
  • Subscribe to our newsletter or email communications
  • Contact us via email, contact form, or other channels
  • Apply for or participate in our affiliate programme
  • Submit a referral through our refer-a-friend programme
  • Post in our community forum, including a chosen handle, your posts and replies, and any avatar or banner image you upload
  • Use our optional dosage tracker, including the protocols, doses, and weight entries you choose to log
  • Enable browser or SMS reminders (we store the push-subscription endpoint or, with consent, your mobile number)
  • Leave a product review or rating
  • This information may include your name, email address, shipping and billing address, and telephone number. It may also include payment details. It can include research-related enquiries, forum content, tracker entries or reviews you submit.

    Information Collected Automatically

    When you visit our website, we automatically collect certain technical data, including:

  • Browser type, version, and device information
  • IP address and approximate geographic location
  • Pages visited, time spent on each page, and navigation paths
  • Referral source and search terms used to reach our site
  • Operating system and screen resolution
  • Information from Third Parties

    We may receive limited information from third-party services we integrate with. That can include payment processors confirming transaction status. It can also include affiliate networks providing referral data.

    4. How We Use Your Information

    We use the information we collect for the following purposes:

  • Order fulfilment: Processing, packaging, dispatching, and tracking your peptide orders
  • Communications: Sending order confirmations, shipping updates, live carrier-tracking notifications, delivery notifications, and payment receipts
  • Customer support: Responding to enquiries, resolving issues, and providing post-sale assistance (including via an AI support assistant that can look up your order by reference or email)
  • Community & optional tools: Operating our community forum, displaying product reviews, and delivering the email, SMS, and browser-push reminders you opt into for the dosage tracker
  • Referrals: Attributing refer-a-friend and affiliate referrals and calculating any associated commission
  • Marketing: Sending promotional emails, product announcements, and newsletters (only with your explicit consent; you may opt out at any time)
  • Compliance: Verifying that purchases are made for legitimate research purposes in accordance with applicable regulations
  • Fraud prevention: Detecting and preventing fraudulent transactions, chargebacks, and unauthorised account access
  • Site improvement: Analysing usage patterns to improve website performance, user experience, and product offerings
  • Legal obligations: Complying with applicable laws, regulations, and lawful requests from authorities
  • 5. Payment Processing & Financial Data

    We accept payments via card and digital-wallet rails. Those rails are processed through independent PCI DSS-compliant providers, including Quiklie , Peptide-Pay , Conflux , Lexicons , TagadaPay , NexaPay , MoneyEU , Etomin , Payriox and CLKK Wallet .

    Cryptocurrency is processed through licensed gateways, including NOWPayments , StableDrop , PassimPay , Paymento , PayRam and Cashu .

    The line-up shown at checkout may change without notice as we onboard new providers or retire existing ones. All payment transactions are handled by these third-party processors. We are not the merchant of record for raw card data. We do not use Stripe.

    What each processor sees (data minimisation)

    Each processor receives only the fields it needs to settle a single transaction. No single processor sees all your payments. We never share marketing, browsing or unrelated order history with them.

  • Card & digital-wallet processors receive your billing address, the order amount, an order reference and the card or wallet credentials you enter on their hosted form. The card number, CVV and expiry are submitted directly into the processor's secure frame. Those values are never seen by our servers . We only receive a tokenised reference, the last four digits of the card, the card brand and the auth / settlement status.
  • Cryptocurrency gateways receive the order amount, an order reference and (where applicable) a contact email for invoice notifications. They return a deposit address, an invoice ID and the on-chain transaction status. We never receive, request or store your wallet private keys, seed phrase or wallet balance.
  • On-chain transparency for crypto payments

    Cryptocurrency networks are public ledgers by design . Once you broadcast a payment, the sending address, deposit address, amount and transaction hash become permanent public records on the relevant blockchain.

    We do not add to that record beyond the deposit address generated for your invoice. We cannot remove or redact entries that already exist on a public chain. If on-chain privacy matters to you, consider funding payments from a wallet that has no link to your real-world identity.

    What we retain on our servers

  • We do not store complete credit or debit card numbers, CVVs, or expiry dates.
  • For card transactions we retain only the tokenised processor reference, the last four digits of the card, the card brand (Visa / Mastercard / Amex), the auth status, and the settlement timestamp.
  • For crypto transactions we retain only the deposit address generated for your invoice, the settlement asset and network, the transaction hash, the confirmed amount, and the payment status, never wallet private keys.
  • Payment data is transmitted over encrypted connections (TLS 1.2+) at all times and is subject to the same row-level security, AWS KMS envelope encryption, and access controls described in § 6.
  • Retention periods for these records are set out in § 11.
  • 6. Data Security & Our Locally-Accessed Secure Database

    Article 32 GDPR requires us to implement "appropriate technical and organisational measures" to protect your data. We take this obligation seriously.

    Our architecture follows one core principle: your personal data lives in a single secured database that is never exposed to the public internet and can only be accessed from our private backend .

    Where your data is stored

  • Managed PostgreSQL database (Supabase-hosted Postgres) is the system of record for customer records, orders and account data. There is at most one encrypted, access-controlled backup mirror. There are no unsecured copies on laptops, spreadsheets or third-party CRMs.
  • No public database endpoint. The database is not reachable from the public web. It is only accessible from inside our private server network. Queries originate from our own application code. They never come directly from your browser.
  • Row-level security (RLS) is enabled so that, even inside the network, each row can only be read by the authorised service role. A compromised key for one surface cannot read another surface's data.
  • Parameterised queries only. Every SQL statement uses placeholders and bound parameters, eliminating SQL-injection as an attack path.
  • Encryption

  • In transit: All traffic between your browser, our servers, and the database is encrypted with TLS 1.2+ (HSTS enforced).
  • At rest: Database storage volumes are encrypted with AES-256. Sensitive PII fields (name, address, phone, date of birth, tax ID) are additionally encrypted at the application layer using AWS KMS envelope encryption before they are written to a row. Even a raw database dump does not reveal those fields in cleartext.
  • Key management: Encryption keys live in AWS KMS with strict IAM policies. No key material is ever committed to source control or sent to the browser.
  • Payment data: We never see or store full card numbers. Card data is tokenised by our PCI DSS-compliant card processors before it reaches our servers. Crypto transactions are settled through licensed gateways. We retain only the transaction reference, settlement asset and payment status.
  • Access control & monitoring

  • Need-to-know access for any human operator; production DB credentials are rotated and stored in a secrets manager, never in chat, email, or code.
  • Admin endpoints gated by a server-side admin key and rate-limited (60 requests/minute by default on API routes).
  • Audit trail on order and payment mutations. That helps us investigate issues. Where required under GDPR Art. 33/34, we notify the relevant supervisory authority within 72 hours of discovering a personal-data breach.
  • Web application firewall & DDoS protection in front of the public site; age-gate and content-protection on sensitive pages.
  • Principle of data minimisation: we only collect fields we genuinely need for your order or legal compliance, and we do not sell data to brokers.
  • No system is 100% secure. If a personal-data breach ever occurs that is likely to result in a risk to your rights and freedoms, we will notify you. We will also notify the competent supervisory authority within the timeframes required by GDPR.

    7. Cookies & Tracking Technologies

    Our website uses cookies and similar technologies for the following purposes:

  • Essential cookies: Required for core site functionality including shopping cart persistence, session management, and checkout processing. These cannot be disabled without breaking site functionality.
  • Preference cookies: Store your preferences such as selected currency and display settings.
  • Analytics cookies: Help us understand how visitors interact with our website so we can improve the user experience.
  • Affiliate tracking: Used to attribute referrals to our affiliate partners for commission purposes.
  • You can manage or disable cookies through your browser settings. Disabling essential cookies may prevent you from completing purchases or using certain site features.

    8. Third-Party Services & Processors

    We share limited data with the following categories of third-party service providers. Each provider is contractually obligated to handle your information securely. Each may use it only for the purposes we specify:

  • Email & SMS delivery: MailerSend - for sending transactional emails (order confirmations, shipping updates), opt-in SMS reminders, and marketing communications
  • Payment processing: The independent card, digital-wallet, and cryptocurrency processors named in § 5. Each receives only the fields required to settle your transaction, and no single processor sees all payments
  • Shipping labels: FedEx - receives the delivery name and address needed to generate a shipping label
  • Live shipment tracking: 17TRACK - receives your order reference and tracking number to provide carrier status updates. We deliberately do not share your email address with 17TRACK; all tracking notifications come from us
  • Address validation: Google - validates the shipping address you enter at checkout
  • Customer-support AI: Anthropic - powers an assistant that can look up your order by reference or email to answer support questions
  • Cloud infrastructure: Vercel (multi-region application hosting, including EEA and US regions), Supabase (managed PostgreSQL database and image storage for forum uploads), DigitalOcean (supporting infrastructure), and Amazon Web Services KMS (encryption-key management)
  • Shipping & fulfilment: Postal and courier services - for order delivery (we share only the information necessary for shipping)
  • We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

    9. Research Verification

    As a supplier of research-grade peptide compounds, we may collect and retain information to verify legitimate scientific research purchases. By placing an order you confirm that:

  • You are at least 21 years of age
  • You are a qualified researcher or purchasing on behalf of a research institution
  • Products will be used solely for lawful in-vitro research and laboratory purposes
  • You are in compliance with all applicable local, national, and international regulations
  • Verification data may be retained as part of our compliance records.

    9A. Community Forum, Reviews & Optional Tools

    Some features are optional and only process data when you choose to use them:

  • Community forum: Your chosen handle, posts, replies and any avatar or banner image you upload are publicly visible on the site. Uploaded images are stored in our managed cloud storage (Supabase). All forum content is moderated and may be flagged, hidden or removed. Do not post other people's personal data. Do not claim that products are safe for human use.
  • Product reviews: Reviews are shown publicly. We attribute them to "Verified buyer" unless you explicitly consent to display your name.
  • Dosage tracker: The tracker stores only the protocols, doses and weights you log. That data powers your reminders and an educational visualization. This data is never sold or used for marketing. The tracker does not provide medical advice. These compounds remain research-use-only.
  • Reminders: If you enable browser-push or SMS reminders, we store only the push-subscription endpoint or (with consent) your mobile number. We use that data solely to deliver those reminders. You can revoke them at any time in your browser or by replying STOP.
  • 10. International Data Transfers

    Where processing can occur

    We ship to customers in the EU, USA and UK. Your data may be processed and stored in any of these regions.

    Our application is hosted across multiple regions on Vercel, including the EEA and the United States. Our database is a Supabase-managed PostgreSQL instance. Encryption keys are held in AWS KMS. Certain supporting infrastructure runs on DigitalOcean.

    Safeguards for EEA and UK transfers

    For customers in the European Economic Area (EEA) or United Kingdom, transfers outside the EEA / UK use safeguards required by GDPR Chapter V. Those safeguards most commonly include the European Commission's Standard Contractual Clauses (SCCs) , the UK International Data Transfer Addendum, an adequacy decision or the processor's binding corporate rules.

    Several of our payment processors (named in § 5) are established outside the EEA. You can request the specific transfer mechanism for your order from newu.io.peptides@gmail.com. By using our services you acknowledge that your information may be processed in countries whose data-protection laws differ from your own.

    11. Data Retention

    We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy:

  • Order records: Retained for a minimum of 7 years for legal, tax, and compliance purposes
  • Customer accounts: Retained for the duration of your account plus 2 years after the last activity
  • Email subscribers: Retained until you unsubscribe or request deletion
  • Affiliate data: Retained for the duration of the affiliate relationship plus 3 years
  • Analytics data: Aggregated and anonymised data may be retained indefinitely for statistical purposes
  • You may request deletion of your personal data at any time, subject to our legal retention obligations.

    12. Your Rights Under GDPR & UK GDPR

    All Customers

    Regardless of your location, you have the right to:

  • Request access to the personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion of your personal data (subject to legal retention requirements)
  • Opt out of marketing communications at any time
  • Withdraw consent for data processing where consent is the legal basis
  • EU & UK Customers (GDPR / UK GDPR)

    In addition to the rights above, if you are located in the EEA or UK, you also have the right to:

  • Request restriction of processing of your personal data
  • Request data portability - receive your data in a structured, commonly used, machine-readable format
  • Object to processing based on legitimate interests
  • Lodge a complaint with your local data protection supervisory authority
  • To exercise any of these rights, contact us at newu.io.peptides@gmail.com. We will respond to all requests within 30 days.

    13. Children's Privacy

    Our website and services are not intended for individuals under the age of 18. Purchases of research compounds require purchasers to be at least 21 years of age. We do not knowingly collect personal information from minors.

    If we become aware that we have collected data from a person under 18, we will take immediate steps to delete that information.

    14. Contact Us & Complaints

    For privacy concerns, data access requests, or questions about this policy, contact us at:

    New-U Research Compounds (operated by Hilxera Distribution Services LLC) Email: newu.io.peptides@gmail.com Website: new-u.io

    EU and UK residents also have the right to lodge a complaint with their national data-protection supervisory authority. Examples include the UK Information Commissioner's Office at ico.org.uk, and the relevant EU member-state authority listed on edpb.europa.eu.

    We would appreciate the chance to address your concerns directly first.

    15. Changes to This Policy

    We may update this Privacy Policy from time to time. Updates can reflect changes in our practices, technology or legal requirements.

    When we make material changes, we will update the version number and "Updated" date at the top of this page. Where appropriate, we will also notify you by email or a prominent notice on our website. We encourage you to review this policy periodically.

    PRECISION. PURITY. PERFORMANCE.

    Research peptides at >99% HPLC-verified purity, third-party tested by Janoshik Analytical & Freedom Diagnostics, with Certificates of Analysis published per released batch. Supplied strictly for laboratory research use.

    Shop

  • All research compounds
  • Price list
  • Where to buy peptides
  • Compare compounds
  • Compare vial sizes
  • Affiliate programme
  • Research

  • Peptide 101
  • Published COAs
  • Research areas
  • Research blog
  • How-to guides
  • Peptide guides
  • Research glossary
  • Support

  • Track your order
  • Contact us
  • Shipping & delivery
  • FAQ
  • Community forum
  • Customer reviews
  • Refund policy
  • Ways to Pay

  • Google Pay
  • Apple Pay
  • Venmo
  • PayPal
  • Cryptocurrency
  • Cash App
  • Card payments
  • Bank transfer (SEPA)
  • Paying with crypto
  • Live crypto prices
  • Shop by goal

  • Metabolic Signalling
  • GH-Axis Research
  • Muscle & IGF Research
  • Tissue and Cellular Models
  • Regenerative Research
  • Cellular Senescence Research
  • Cognitive Research
  • Multi-Compound Blends
  • Accessories
  • Shop by compound

  • BPC-157
  • TB-500
  • GHK-Cu
  • Tesamorelin
  • Semaglutide
  • CJC-1295 (without DAC)
  • Ipamorelin
  • MOTS-C
  • All compounds →
  • Shop by region

  • United Kingdom
  • Australia
  • Canada
  • Canada (FR)
  • Ireland
  • Malta
  • Germany
  • France
  • Spain
  • Italy
  • Netherlands
  • Portugal
  • Greece
  • Austria
  • Poland
  • Sweden
  • Finland
  • Denmark
  • Norway
  • Croatia
  • Slovakia
  • Slovenia
  • Estonia
  • Latvia
  • Lithuania
  • Czechia
  • Hungary
  • Romania
  • Bulgaria
  • Belgium
  • Belgium (FR)
  • Luxembourg
  • United States
  • Northern Ireland
  • Research use only (RUO). All products are sold strictly for laboratory and research purposes — not for human or veterinary consumption. Purchasers must be 21 or older.

    All rights reserved. Copyright of New-U held with Hilxera Distribution Services LLC 2026.

    Website & business operated by Hilxera Distribution Services LLC. Registered in Wyoming, ID: 2026-001928701.

    © 2026 New-U Research Compounds · new-u.io

    Research use only — not for human consumption. All products are supplied strictly for laboratory research purposes.

    © 2026 New-U Research Compounds · new-u.io — Copyright held with Hilxera Distribution Services LLC. All rights reserved.