Privacy Policy
1. What this policy covers
This Privacy Policy explains what information Titrate Testing ("Titrate," "we," "us") collects through titratetesting.com, why we collect it, how it's stored, and who we share it with.
2. Information we collect
Information you provide directly:
- Name (required at checkout)
- Email address (for order confirmation, shipping instructions, and delivering your results)
- Phone number (optional, collected at checkout)
- Vendor/product information you submit with your test request (e.g., compound, vendor name, lot/batch details)
- Payment information — processed entirely by Stripe; Titrate does not receive or store your full card number.
Information we intentionally do not collect on the public site: your shipping/ship-to address for the laboratory is never displayed publicly — it is sent to you privately via email only.
Information collected automatically: Cloudflare's standard server/request logs, generated as part of running the site. We do not use any separate analytics or advertising cookies beyond this default logging.
3. How we use your information
We use the information we collect to:
- Process and fulfill your test order;
- Generate and deliver your shipping instructions and lot/batch number;
- Communicate with you about your order status, including transactional emails sent via Resend;
- Generate your Certificate of Analysis (COA) and, where applicable, publish test results to the public COA lookup tool and vendor directory;
- Detect and prevent fraud or abuse;
- Comply with legal obligations.
We do not sell your personal information, and we do not use it for advertising or marketing without your consent.
4. What we publish publicly
Titrate's vendor-blind model publishes test results (pass/fail and relevant COA detail) tied to a vendor and batch/lot identifier, so that a public track record can build over time. We do not publish your name, email, phone number, or any other personal/customer identifying information as part of this public record — only the vendor and product/batch-level test data.
5. Who we share information with
- Stripe — processes your payment. Stripe's own privacy policy governs how they handle your payment data.
- Resend — sends transactional emails (order confirmations, shipping instructions, result delivery) on our behalf.
- The testing laboratory — receives only what's needed to run and report the test (compound/test type and the lot/batch number used to match your physical sample). Consistent with Titrate's vendor-blind model, the laboratory is not given the vendor's identifying business information as a matter of course.
- Cloudflare — hosts the site and database (D1) and file storage (R2) that the Service runs on.
We do not share your information with any other third party except as required by law, or with your explicit consent. We do not sell your personal information, as that term is defined under the California Consumer Privacy Act or similar state privacy laws.
6. Data storage and retention
Your order and submission data is stored in Titrate's Cloudflare D1 database and associated file storage (R2 for COA documents). We retain this data for as long as needed to maintain the public verification track record and to comply with legal, tax, and accounting obligations — we do not delete it on a fixed schedule.
7. Your rights
You may request access to, correction of, or deletion of your personal information by contacting us at [email protected]. Depending on your state of residence, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA). Note that published, anonymized test/track-record data (vendor- and batch-level, not tied to your personal identity) may be retained as part of Titrate's public verification record even after a deletion request, since it does not identify you personally.
8. Children's privacy
The Service is not directed to, and is not intended for use by, anyone under 18. We do not knowingly collect information from minors.
9. Security
We take reasonable measures to protect your information, including restricting access to the admin dashboard and storing credentials and API keys outside of chat history or version control. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
11. Contact
Questions about this Privacy Policy can be directed to [email protected].
