Meridian Legal
Privacy Policy
Last updated: August 25, 2026
Company registration details are being finalized
This document has been reviewed and is the operative version. A few registration details are still being entered and appear below as bracketed ALL-CAPS terms; those specific items are not yet statements of fact. Everything else on this page applies as written.
The controller name and registered address are still being entered. Everything this policy states about what the site collects has been checked against the code that collects it.
Research Use Notice
Meridian Research sells research chemicals and peptides strictly for in vitro laboratory and experimental use. Products are not for human or animal consumption. This policy governs how we handle data collected through the purchase and use of research-grade compounds on this platform.
1. Who We Are
This policy is issued by [ENTITY NAME], trading as Meridian Research (“we”, “us”). We are the controller of the personal information described in this policy.
Registered address: [REGISTERED ADDRESS]. Privacy contact: support@meridianresearchllc.net.
2. Notice at Collection (California)
This section is our Notice at Collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. At or before the point we collect anything, this is what you should know:
- What we collect: identifiers (name, email address, IP address), customer records (shipping address), commercial information (what you ordered), limited internet activity, and account log-in credentials. The full list is in Sections 3 and 6.
- Why: to create and secure your account, to take and ship your order, to keep the research-use attestation and order records our compliance posture requires, to prevent fraud and abuse, and — only with your consent — to count page views, to measure whether advertising we paid for produced accounts and orders, and to send you email you asked for.
- Sold or shared: We do not sell personal information for money, and we never have. We do share a limited amount of it for cross-context behavioral advertising: three advertising pixels run on this site — Snapchat's, TikTok's, and Meta's — and Snap Inc., TikTok Inc., and Meta Platforms, Inc. each receive your IP address, your browser's user-agent string, and cookies their own scripts set, alongside the bare fact that a page was viewed, a product page was viewed, an account was created, an item was added to a cart, a checkout was begun, or an order was completed. None of the three ever receives the identity of the product — no product name, compound, or lot — and none of them receives your email address or phone number. Two of the three wait for your consent, which is given by entering the site: the research-use confirmation shown before the site opens says so above the button, and there is no separate cookie banner for a new visitor. Meta's does not wait — it loads with the page and reports that landing, before you answer that confirmation. All three stop for the same two controls: use the “Do Not Sell or Share My Personal Information” link in the site footer or send a Global Privacy Control signal, and none of the three loads at all. See Sections 4 and 7.
- Sensitive personal information: the only sensitive category we collect is your account log-in credentials, used solely to sign you in and secure the account. See Section 8.
- How long we keep it: account information while your account is open; order records for at least seven years; see Section 16 for the rest.
3. Information We Collect
We collect the following categories of information:
- Account information: Name and email address when you create an account. If you set a password we store only a one-way hash of it — we never store or have access to the password itself. If you sign in with Google or Apple, we receive your email address and name from that provider.
- Order information: Research compounds purchased, quantities, order amounts, and order history.
- Shipping information: Delivery address provided at checkout for fulfillment of research orders.
- Payment information: Payments are handled by PayPal, including the funding options PayPal presents at checkout. We receive a payment identifier and the amount; we do not receive, store, or have access to your card numbers or bank details.
- Age and eligibility attestation: The attestation statements you accepted at signup and at checkout, stored verbatim, with a timestamp and the IP address the acceptance came from. No government ID and no date of birth is collected or stored.
- IP address: Recorded with account creation and with each order as part of that compliance record, and used transiently to enforce rate limits and to block abusive addresses. It is not attached to the page-view records described below.
- Affiliate referral clicks: If you arrive through an affiliate referral link, we log the referral code, the page you landed on, your browser's user-agent string, and a truncated one-way hash of your IP address — not the address itself. This is how a referral is credited and how referral fraud is detected.
- Consented page views: Only if you accept non-essential cookies, we record the path of the page, the host of an external referring site, an opaque per-tab marker, and the hour of the visit. See Section 10.
- Consented campaign attribution: Only if you accept non-essential cookies, and only if you arrive on a link that carries campaign parameters or an advertising click identifier, we store those values in a cookie on your device for 60 days along with the page you landed on and the host of an external referring site. If you then place an order, that record is copied onto the order so we can tell which campaign it came from. We keep the first one only — a later click does not overwrite it. Nothing in it is sent to the advertising platform. See Sections 10 and 13.
- Advertising measurement: Three advertising pixels run here, and each reports the same six things — Snapchat's to Snap Inc., TikTok's to TikTok Inc., and Meta's to Meta Platforms, Inc.: that a page was viewed, that a product page was viewed, that an account was created, that an item was added to a cart, that checkout was begun, and that an order was completed. Snapchat's and TikTok's load only if you accept non-essential cookies, which you do by entering the site, as Section 4 explains. Meta's loads when the page loads, before you answer that confirmation, so that a visit which ends at the confirmation is still counted; Section 10 explains why and Section 5 records the open question that raises. Because all three are third-party scripts running in your browser, each of the three companies also receives your IP address and user-agent string and sets its own cookies on your device. None of the three receives a product name, compound, lot, category, or description, and none receives an email address or phone number. See Sections 7, 10, and 13.
- Email subscription: If you subscribe to research updates, your email address and the domain part of that address.
- Support messages: Messages you send through the contact form are emailed to our support inbox with your name, email address, and message. They are not written to our customer database.
- Provider logs: Our hosting, database, email, and security providers keep their own operational and security logs, which can include IP addresses and request metadata. Their retention is governed by their terms, not ours.
4. How We Use Your Information
- To process and fulfill research compound orders and send order confirmations.
- To manage your account and authenticate your identity.
- To maintain records of research chemical sales, and of the research-use attestation, as our compliance posture and applicable law require.
- To respond to support inquiries and communications.
- To comply with legal obligations, including responding to lawful requests from regulatory or law enforcement authorities.
- To detect and prevent fraud, unauthorized use, or misuse of research compounds, including rate limiting and blocking abusive network addresses.
- To count page views, with your consent, so we can see which pages are useful.
- To tell, with your consent, which advertising campaign or referring link brought you to the site before an order, so we can judge whether that spending was worthwhile.
- To report to Snapchat and to TikTok, with your consent, and to Meta whether or not you have given it, that an advertisement of ours led to a page view, an account, a cart, a started checkout, or an order, so that advertising can be measured and optimized. All three stop entirely if you opt out of sale or sharing, or if your browser sends a Global Privacy Control signal.
Most of the measurement on this site is first-party, and all of it except one advertising pixel waits until you have accepted non-essential cookies. How that acceptance is collected changed on August 23, 2026, and this paragraph describes what actually happens rather than what a cookie banner would usually do. Before the site opens you are shown a research-use confirmation. It carries the two statements you are confirming, and directly beneath the button it states that by entering you accept cookies used to measure our advertising. Pressing that button records both at once, and the pixels that were waiting load immediately afterwards on that same visit. So entering the site IS the acceptance: there is no separate cookie banner for a new visitor, and there is no per-purpose or per-vendor opt-in — it is one decision, and it covers the page-view beacon, the campaign attribution, and Snapchat's and TikTok's advertising pixels described in Section 10 together. If you accepted the research-use confirmation before that date, you are instead shown a short banner once, with Allow and Decline, and your answer to it governs exactly the same things. Either way, the decision is recorded in your browser and can be withdrawn — see the end of this section and Section 7. Our own analytics are page-level, except for the campaign attribution described in Section 10, which is order-level and records where a visit came from rather than what you did on the site. Three third-party advertising tags are active: the Snapchat pixel, operated by Snap Inc., the TikTok pixel, operated by TikTok Inc., and the Meta pixel, operated by Meta Platforms, Inc. All three are described in full in Section 10. No Google pixel is present, there is no tag manager, no other vendor SDK is loaded, and there is no server-side conversions interface. Under the CCPA/CPRA each of these pixels is treated as a "share" of personal information for cross-context behavioral advertising, and under some other U.S. state privacy laws as targeted advertising — Section 7 says so plainly rather than denying it. The three do not all wait for the same thing, and rather than give you one tidy sentence that is true of none of them, here is the difference. Snapchat's and TikTok's are fetched only when all three of these are true: you have accepted non-essential cookies, you have not recorded the "Do Not Sell or Share My Personal Information" opt-out, and your browser is not sending a Global Privacy Control signal. Meta's is fetched when only the last two are true: it does not wait for you to accept anything. It loads with the page and reports that you arrived, before the research-use confirmation is answered — because that confirmation stands in front of every visit, and without this a visit that ends there could not be counted at all. So on a first visit that you abandon at the confirmation, Snapchat and TikTok are told nothing and Meta is told that a page was viewed. If you have not accepted, neither Snapchat's script nor TikTok's is requested at all — they are not loaded-and-suppressed. If you have recorded the opt-out, or your browser sends Global Privacy Control, then none of the three is requested, Meta included; those two controls are absolute and they are the only controls that bind all three. The three are independent of each other, so switching one off does not switch the others on or off. Because acceptance is bundled into entering the site, the way to withdraw it is the standing opt-out: use the "Do Not Sell or Share My Personal Information" link in the site footer, which stops all three pixels and the first-party measurement, or send a Global Privacy Control signal from your browser, which we honor automatically with nothing for you to click. That link and that signal are the only way to stop the Meta pixel, because it never asked. Clearing your browser storage for this site also clears the recorded consent. If we introduce further advertising or measurement partners, we will disclose them here and say which of these conditions each one waits for.
5. Legal Basis for Each Purpose (EEA and UK)
If you are in the European Economic Area or the United Kingdom, the GDPR requires us to identify a legal basis for every purpose. Ours are:
| Purpose | Information used | Legal basis |
|---|---|---|
| Creating and operating your account; signing you in | Name, email address, password hash, sign-in provider identifier | Performance of a contract (Art. 6(1)(b)) |
| Taking, fulfilling, and shipping an order; order confirmations and shipment notices | Name, email, shipping address, order contents | Performance of a contract (Art. 6(1)(b)) |
| Taking payment | Payment identifier and amount exchanged with PayPal | Performance of a contract (Art. 6(1)(b)) |
| Recording the 21+ and research-use attestation, and retaining order and compliance records | Attestation text, timestamp, IP address, order record | Legitimate interests (Art. 6(1)(f)) — evidencing that research materials were supplied lawfully and only to attesting purchasers. Where a legal obligation applies, Art. 6(1)(c). |
| Fraud prevention, rate limiting, blocking abusive addresses, and site security | IP address, request metadata | Legitimate interests (Art. 6(1)(f)) — keeping the site available and free of abuse |
| Crediting affiliate referrals and detecting referral fraud | Referral code, landing path, user-agent string, hashed IP address | Legitimate interests (Art. 6(1)(f)) — paying commission accurately |
| Counting page views | Path, referring host, opaque per-tab marker, hour of visit | Consent (Art. 6(1)(a)) — withdrawable at any time, with no effect on the site |
| Telling which advertising campaign or referring link produced an order | Campaign parameters and advertising click identifier from the link you arrived on, the page you landed on, referring host | Consent (Art. 6(1)(a)) — withdrawable at any time, with no effect on the site |
| Measuring advertising through the Snapchat pixel | IP address, user-agent string, cookies set by Snapchat's own script, and the fact that a page view, product view, sign-up, cart addition, checkout start, or order occurred | Consent (Art. 6(1)(a)) — withdrawable at any time, with no effect on the site |
| Measuring advertising through the TikTok pixel | IP address, user-agent string, cookies set by TikTok's own script, and the fact that a page view, product view, sign-up, cart addition, checkout start, or order occurred | Consent (Art. 6(1)(a)) — withdrawable at any time, with no effect on the site |
| Measuring advertising through the Meta pixel | IP address, user-agent string, cookies set by Meta's own script, and the fact that a page view, product view, sign-up, cart addition, checkout start, or order occurred | NOT consent, and we will not claim it. This pixel runs before the research-use confirmation is answered (Sections 4 and 10), so consent under Art. 6(1)(a) is not the basis it operates on. We record it as legitimate interests (Art. 6(1)(f)) — measuring advertising we have paid for — and we flag it as unresolved rather than settled: see the note directly below this table |
| Sending research updates by email | Email address | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Answering your support message | Your name, email address, and the contents of the message | Legitimate interests (Art. 6(1)(f)), or performance of a contract where the message concerns your order |
| Responding to lawful requests from courts, regulators, or law enforcement | Whatever the request lawfully reaches | Legal obligation (Art. 6(1)(c)) |
An open question, stated rather than smoothed over. The Meta pixel is the one mechanism on this site that runs before the entry confirmation is answered, so it cannot rest on consent, and an advertising pixel resting on legitimate interests is a contested position: the ePrivacy rules on storing and reading information on your device are generally read to require consent for advertising cookies irrespective of which Article 6 basis applies. Two facts bear on it and neither is a defence we are asserting here. This service is offered in the United States only — checkout accepts United States shipping addresses only, and that is enforced in code, not merely stated — so we do not offer goods into the European Economic Area or the United Kingdom. And the two absolute controls still apply to this pixel: a recorded sale/share opt-out or a Global Privacy Control signal stops it outright, before anything is fetched. This basis is under legal review and this paragraph will be replaced by its outcome. If you are in the EEA or the UK and you want this pixel not to run, send Global Privacy Control or use the footer link before browsing; Section 15 says the same.
Where we rely on legitimate interests, we have weighed those interests against your rights, and you can object at any time using the contact address in Section 20. Where we rely on consent, withdrawing it is as easy as giving it and does not affect processing that already happened.
6. Categories of Personal Information We Collect (California)
The categories below are the statutory categories in Cal. Civ. Code section 1798.140(v). This is what we have collected in the preceding twelve months.
| Category | Collected | Examples | Disclosed to |
|---|---|---|---|
| A. Identifiers | Yes | Name, email address, postal address, IP address, account identifier | Hosting, database, and email providers; payment processor; shipping carriers; Snap Inc., TikTok Inc., and Meta Platforms, Inc. — but only your IP address, which each of their advertising pixels receives inherently as a third-party script (Section 10). Neither Snap Inc. nor TikTok Inc. nor Meta Platforms, Inc. receives a name, email address, postal address, or account identifier |
| B. Customer records (Cal. Civ. Code 1798.80) | Yes | Name and shipping address given at checkout | Hosting and database providers; shipping carriers |
| C. Protected classifications | No | — | — |
| D. Commercial information | Yes | Products purchased, quantities, order history | Hosting and database providers; email provider (order confirmations) |
| E. Biometric information | No | — | — |
| F. Internet or network activity | Yes, limited | Pages viewed (only with consent), campaign parameters and advertising click identifier from a link you arrived on (only with consent), external referring host, user-agent string on an affiliate referral click, the occurrence of a page view, product view, sign-up, cart addition, checkout start, or order reported to the Snapchat and TikTok pixels (only with consent), and the same occurrences reported to the Meta pixel, which does not wait for consent and instead stops on the sale/share opt-out or a Global Privacy Control signal (Sections 4 and 10) | Hosting and database providers; Snap Inc., TikTok Inc., and Meta Platforms, Inc. (the pixel events only, never which product, and each counts as a share — see Section 7) |
| G. Geolocation data | No | We do not collect precise geolocation and do not derive location from your IP address | — |
| H. Sensory data (audio, video) | No | — | — |
| I. Professional or employment information | No | — | — |
| J. Education information | No | — | — |
| K. Inferences drawn to create a profile | No | We do not profile you, score you, or infer characteristics, preferences, or behavior. Snapchat, TikTok, and Meta may each draw their own inferences from the pixel events in Section 10; those are their inferences, made under their own policies, and we neither receive nor store them | — |
| L. Sensitive personal information | Yes, limited | Account log-in credentials (email address with password). See Section 8 | Database and authentication provider |
We collect this information directly from you, from your device when you use the site, and from PayPal when a payment completes. We do not buy personal information from data brokers.
7. Sale and Sharing of Personal Information
We do not sell personal information, and we have never received money or other valuable consideration in exchange for it. We do share personal information for cross-context behavioral advertising, as the CCPA/CPRA defines that term: the three pixels described in Section 10 disclose a limited set of identifiers and activity — the Snapchat pixel to Snap Inc., the TikTok pixel to TikTok Inc., and the Meta pixel to Meta Platforms, Inc. — so that our advertising can be measured. Two of them wait for your consent and Meta's does not; Section 4 sets out that difference. You have the right to opt out of all of that sharing, one control covers all three, it is the “Do Not Sell or Share My Personal Information” link in the site footer, and we treat a Global Privacy Control signal as the same request.
| Category | Sold | Shared for behavioral advertising |
|---|---|---|
| A. Identifiers | No | Yes, limited — your IP address, which Snapchat's script, TikTok's script, and Meta's script each receive inherently. Never your name, email address, postal address, or account identifier |
| B. Customer records | No | No |
| D. Commercial information | No | Yes, limited — the value and currency of an item added to a cart, the value and currency of the cart at the moment a checkout begins, and our own order identifier on a completed order, to all three networks. Never what was ordered: no product name, compound, lot, category, or description |
| F. Internet or network activity | No | Yes, limited — your user-agent string, cookies set by Snapchat's, TikTok's, and Meta's own scripts, and the occurrence of a page view, product view, sign-up, cart addition, checkout start, or order |
| L. Sensitive personal information | No | No |
| Categories C, E, G, H, I, J, K | Not collected | Not collected |
We have not sold personal information in the preceding twelve months. Sharing for cross-context behavioral advertising began when the Snapchat pixel went live in August 2026, the TikTok pixel was added in the same month, and the Meta pixel in the same month again; before those dates there was no sharing at all, and this policy said so.
No money changes hands for any of this — we pay Snapchat, TikTok, and Meta to run advertisements, not the other way around. Under these laws an advertising technology can count as a sale or a share even when no money changes hands, and a live advertising pixel generally does count as a share, which is why this section reports all three of ours as shares rather than relying on the absence of payment.
The "Do Not Sell or Share My Personal Information" link in the site footer is the opt-out for the sharing described above — one control, covering all three networks, and it works. Setting it stops any further event being sent to Snapchat or TikTok or Meta immediately, and stops any of the three pixels being loaded at all from your next page load onward. Two honest limits: a script that has already loaded on the page you are reading when you opt out is not removed from that page until you navigate or reload; and cookies Snapchat has already set stay in your browser until you clear them, as do TikTok's and Meta's. We honor the Global Privacy Control browser signal in exactly the same way, automatically, with nothing for you to click — and because that signal is read before anything is fetched, a browser that sends it never loads any of the three, including Meta's. ⚠️ THIS LINK IS NOW THE PRIMARY WITHDRAWAL ROUTE, and it matters more than it used to. Consent for Snapchat and TikTok is given by entering the site (Section 4), so there is no cookie banner for a new visitor to decline afterwards; this footer link, and the Global Privacy Control signal, are how that decision is reversed. Both take precedence over the consent recorded at entry — an opt-out recorded here suppresses those two pixels even though you accepted at the door. For the Meta pixel they are not merely the primary route, they are the only one: it never asked for consent, so there is no consent to withdraw, and these two controls are what stop it.
We do not knowingly sell or share the personal information of anyone under 16. This site is restricted to customers 21 and older.
Disclosures for a business purpose are a different thing from a sale or a share. Section 9 lists everyone we disclose personal information to and why, and marks which of them are third parties rather than service providers acting on our instructions.
8. Sensitive Personal Information and the Right to Limit
The only sensitive personal information we collect is your account log-in credentials — your email address in combination with the password you set. We use it for one thing: to authenticate you and keep the account secure.
Under the CPRA, you may direct a business to limit its use of sensitive personal information to purposes the regulations permit without a right to limit. Authenticating you and securing the account are among those permitted purposes, so there is nothing further to limit. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for advertising of any kind — including any of the three pixels in Section 10. All three networks offer us a way to upload it and we take none of them: Snapchat's own installation snippet offers a field for uploading a hashed email address so it can match a visitor to a Snapchat account; TikTok's script offers an identification call that takes a hashed email address and phone number for the same purpose; and Meta's installation snippet offers an advanced matching object, passed alongside the pixel identifier when the pixel starts, into which a site is invited to put your email address, phone number, first and last name, and an account identifier of its own. We deliberately do not pass it to Snapchat, we never make that call to TikTok, and we start the Meta pixel with the pixel identifier and nothing beside it. Your email address is never sent to an advertising platform in any form, hashed or otherwise, and neither is your phone number or your name. If we ever collect sensitive personal information for a purpose that carries the right to limit, we will publish a “Limit the Use of My Sensitive Personal Information” control before doing so.
9. How We Share Information
With three exceptions, which are named first and marked as such, we disclose personal information for business purposes only. The recipients are:
- Advertising platform — Snap Inc. (a third party, not a service provider): If you accept non-essential cookies and have not opted out, Snapchat's advertising pixel runs in your browser and receives your IP address, your user-agent string, cookies its own script sets, and the occurrence of a page view, product view, sign-up, cart addition, checkout start, or order — plus the cart value on an addition and on a checkout start, and our order identifier on a purchase. It receives no product identity and no email or phone number. Snap Inc. uses what it receives for its own advertising purposes under its own privacy policy, which is what makes it a third party rather than a service provider, and what makes this a “share” under Section 7. This is one of only three recipients on this list you can switch off, and Section 7 says how.
- Advertising platform — TikTok Inc. (a third party, not a service provider): On the same terms and behind the same controls, TikTok's advertising pixel runs in your browser and receives your IP address, your user-agent string, cookies its own script sets, and the occurrence of a page view, product view, sign-up, cart addition, checkout start, or order — plus the cart value on an addition and on a checkout start, and our order reference on a purchase. It receives no product identity and no email or phone number. TikTok Inc. uses what it receives for its own advertising purposes under its own privacy policy, which is what makes it a third party rather than a service provider, and what makes this a “share” under Section 7 as well. It is the second of the three recipients on this list you can switch off, with the same control.
- Advertising platform — Meta Platforms, Inc. (a third party, not a service provider): Meta's advertising pixel runs in your browser and receives your IP address, your user-agent string, cookies its own script sets, and the occurrence of a page view, product view, sign-up, cart addition, checkout start, or order — plus the cart value on an addition and on a checkout start, and our order identifier on a purchase. It receives no product identity and no email, phone number, or name. Meta Platforms, Inc. uses what it receives for its own advertising purposes under its own privacy policy, which is what makes it a third party rather than a service provider, and what makes this a “share” under Section 7 too. It differs from the two above it in one way that we would rather state than bury: it is the only recipient on this list that begins receiving anything before you have accepted anything, because it loads with the page rather than after the research-use confirmation. It is the third recipient on this list you can switch off, and for it the Section 7 controls are the only way to do so.
- Shipping carriers: Your name and shipping address are shared with carriers (FedEx, UPS, USPS) to fulfill delivery of research orders.
- Payment processor: PayPal receives what it needs to take the payment and returns a payment identifier to us. Its handling of your payment details is governed by PayPal's own privacy policy.
- Hosting, database, and authentication providers: The site is hosted on a cloud platform, and account and order records are held in a managed Postgres database that also provides authentication. These providers process the data on our instructions.
- Email provider: Order confirmations, shipment notices, password resets, and any research updates you subscribed to are sent through a transactional email provider, which receives your email address and the contents of the message.
- Security and reliability providers: Where enabled, an error-monitoring service receives diagnostic reports about failures. It is configured to strip cookies, request bodies, email addresses, and query strings before an event is sent, and session replay is switched off. An abuse-prevention data store may hold a short-lived counter keyed to your IP address for the length of a rate-limit window.
- Legal compliance: We may disclose information if required by law, court order, or regulatory authority, or if we believe disclosure is necessary to protect our legal rights or the safety of others. Given the nature of our products, we take regulatory compliance seriously and will cooperate fully with lawful requests.
- Business transfers: If Meridian Research is acquired or merged, customer information may transfer to the successor entity under the same privacy commitments.
Every recipient above except Snap Inc., TikTok Inc., and Meta Platforms, Inc. is engaged as a service provider under the CCPA and as a processor under the GDPR, and is not permitted to use your information for its own purposes. We require a data processing agreement with each of them. Those three are deliberately excluded from that sentence: each does use what it receives for its own purposes, and calling any of them a service provider would be the exact mischaracterization this section exists to avoid.
Snapchat, TikTok, and Meta are the only advertising networks we disclose anything to, and what each receives is bounded by Sections 7 and 10. We do not sell or disclose your information to data brokers, and we do not buy from them.
10. Analytics and Measurement — What Actually Runs
This section describes the measurement that exists on this site, in detail, because vague analytics language is how privacy policies become untrue.
There are five measurement mechanisms. Every one of them is off if you have recorded the sale/share opt-out, and every one of them is off if your browser sends the Global Privacy Control signal — those two conditions bind all five without exception. Four of the five additionally wait until you have accepted non-essential cookies; the fifth, the Meta pixel, does not, and the difference is set out in its own part below rather than averaged into this sentence. Since August 23, 2026 that acceptance is collected at the entrance rather than by a separate cookie banner: the research-use confirmation you complete before the site opens states above its button that entering accepts cookies used to measure our advertising, so those four start on that first visit rather than on a second click. Section 4 describes that arrangement, and Section 7 describes how to withdraw it. The first is a page-view beacon. The second is campaign attribution. The third is the Snapchat advertising pixel, the fourth is the TikTok advertising pixel, and the fifth is the Meta advertising pixel — those three are the only ones that involve a third party, and the only ones that constitute a “share” under Section 7. They are described separately below because they are separate scripts, run by separate companies, on separate conditions, and any one of them can be switched on or off without the others.
1. The page-view beacon.
A first-party beacon posts to our own server when you move between pages. Each recorded page view holds exactly four things:
- the path of the page you viewed, with any query string removed before it is stored;
- the host of an external site that referred you, if any — never the full referring URL, and never our own host;
- an opaque random marker that lives in your tab's session storage and is destroyed when you close the tab; and
- the time of the visit, truncated to the hour.
It does not record your IP address — not even a hashed one — your user agent, your account identifier, your name, or anything you typed. The table these rows land in has no column for any of them. An exact timestamp beside a page path can be correlated back to a person through other logs; an hour bucket cannot, which is why the coarsening is deliberate.
2. Campaign attribution.
If you arrive on a link that carries campaign parameters (the “utm” values a link builder adds) or an advertising click identifier issued by Google, Meta, TikTok, or Snap, we store those values, the page you landed on, and the host of an external referring site in a first-party cookie named mrm_attr. It lasts 60 days. If you place an order in that time, the record is copied onto the order.
This exists for one question, which we could not previously answer at all: which advertising produced a sale. Four things bound it, and each of them is enforced in code rather than promised here:
- It is first-touch and write-once. If the cookie already exists we do not overwrite it, so a later click cannot replace the record — and re-visiting the site does not extend it.
- It is an allowlist. Only the named campaign parameters and click identifiers are read; every other value in the link is discarded rather than stored, each stored value is truncated, and the whole record is size-capped.
- The cookie itself is not sent anywhere. Its contents stay in our own cookie and our own database. The values in it — your campaign parameters, your click identifier, the page you landed on, the referring host — are not transmitted to Google, Meta, TikTok, Snapchat, or any other platform. The three advertising pixels described below are separate mechanisms; none of them reads this cookie or sends any part of it.
- It records where a visit came from, not what you did. There is no page-by-page history in it, no identifier we can use to recognize you on another site, and nothing about the products you looked at.
You can stop it. Opting out through the “Do Not Sell or Share My Personal Information” link, or sending the Global Privacy Control signal, prevents the cookie being written at all — not merely its use afterwards. Clearing your cookies deletes it.
3. The Snapchat advertising pixel.
This is a third-party script, supplied and controlled by Snap Inc., that runs in your browser so that advertising we buy on Snapchat can be measured against what happened on this site. It is one of the three places on this site where personal information leaves us for a party that uses it for its own purposes, so it is described here in the same detail as the rest.
When it loads, and only then, it reports six things, and nothing else:
- that a page was viewed;
- that a product page was viewed — not which product;
- that an account was created;
- that an item was added to a cart, with the value of that addition and the currency;
- that checkout was begun, with the total value of the cart at that moment and the currency; and
- that an order was completed, with our own order identifier.
What travels alongside those events is bounded by an allowlist of exactly four fields — a price, a currency, and two forms of our order identifier — that is enforced in code at the moment of sending. Any other field is dropped before the call is made, whether or not anyone anticipated it. The practical effect is the thing worth stating plainly: no product name, compound name, catalog identifier, lot number, category, or description is ever sent to Snapchat. Snapchat is told that somebody viewed a product page; it is never told which one. What you are researching is not disclosed by this pixel.
Nor is your identity. Snapchat's own installation snippet offers a field for uploading a hashed email address so it can match a visitor to a Snapchat account, and we deliberately leave it out. No email address, no phone number, and no other Advanced Matching identifier is passed, in any form.
What Snapchat does receive, and we will not pretend otherwise, is what any third-party script receives by the fact of being loaded at all: your IP address, your browser's user-agent string, and cookies its own script sets in your browser. We control what we send it. We do not control the existence of the connection, and once made, that connection carries those things. Snapchat's use of them is governed by Snapchat's own privacy policy, not this one.
Four limits bound it, and each is enforced in code rather than promised here:
- It does not load without consent. The script is not requested until you accept non-essential cookies, which since August 23, 2026 you do by entering the site (Section 4) — so on a visit that begins with an advertisement, it loads on that first page rather than on a later one. If you have recorded the sale/share opt-out, or if your browser sends a Global Privacy Control signal, nothing is fetched from Snapchat at all — not fetched and suppressed, not fetched.
- Every event passes the same gate again. Consent, opt-out, and Global Privacy Control are re-checked at each individual event, so an opt-out recorded mid-visit takes effect on the next event rather than at the next page load.
- The parameters are an allowlist, not a filter. Four fields are permitted and everything else is dropped by construction, so a field nobody anticipated cannot be sent by accident.
- A purchase is counted once. Re-opening or refreshing your order confirmation page — from a bookmark, or from the link in your confirmation email weeks later — does not report a second order.
You can decline it, and you can change your mind. Section 7 gives the controls and states honestly what an opt-out does and does not undo.
4. The TikTok advertising pixel.
This is a second third-party script, supplied and controlled by TikTok Inc., and it exists for the same reason as Snapchat's: so that advertising we buy on TikTok can be measured against what happened on this site. It is a separate script from a separate company, loaded from TikTok's own domain, and it is governed by exactly the same three conditions — you have accepted non-essential cookies, you have not recorded the sale/share opt-out, and your browser is not sending a Global Privacy Control signal. Fail any one of those and nothing is fetched from TikTok at all.
When it loads, and only then, it reports the same six occurrences to TikTok Inc., in TikTok's own vocabulary, and nothing else:
- that a page was viewed, once when its script loads and once more each time you move to another page here;
- that a product page was viewed, without which product it was;
- that an account was created, which TikTok records as a completed registration;
- that an item was added to a cart, carrying that item's value and the currency;
- that you reached the checkout page, which TikTok calls an initiated checkout, carrying the running total of the cart and the currency; and
- that an order was completed, carrying our own order reference and no amount at all.
What travels alongside those events is bounded by an allowlist of exactly two fields — a value and a currency — plus our own order reference on a completed order, which TikTok takes separately as an event identifier so that a future server-side report of the same order is recognized as the same order rather than counted twice. Everything else is dropped before the call is made. Stated plainly, and it is the same promise as Snapchat's: no product name, compound name, catalog identifier, lot number, category, or description is ever sent to TikTok. TikTok is told that somebody viewed a product page; which product it was is never sent.
That refusal is deliberate and it is worth naming, because TikTok asks for the opposite. TikTok's own documentation and its Events Manager ask an integrator to supply a content identifier, a content name, a content type, a list of cart contents, a description, and the search terms a visitor typed, and TikTok will report our events as low quality for lacking them. On this catalog every one of those fields would carry a compound name, which is a health inference about the person who viewed it. None of them is sent, the code permits only the two fields named above, and we accept the reduced measurement quality that follows.
Nor is your identity sent. TikTok's script offers an identification call that takes a hashed email address and a hashed phone number so it can match a visitor to a TikTok account. That call is not made anywhere on this site, and no email address, phone number, or other advanced matching identifier is passed to TikTok in any form.
What TikTok does receive, and we will not pretend otherwise, is the same thing Snapchat receives by the fact of being loaded at all: your IP address, your browser's user-agent string, and cookies its own script sets in your browser. We control the payload; we do not control the connection, and once it exists it carries those things. TikTok's use of them is governed by TikTok's own privacy policy, not this one, and TikTok Inc. is part of a corporate group with operations outside the United States — see Section 18.
The same four limits bound it as bound Snapchat's, and each is enforced in code rather than promised here: it is not requested at all without consent; consent, the opt-out and Global Privacy Control are re-checked at every individual event rather than once at load; the parameters are an allowlist rather than a filter, so a field nobody anticipated cannot be sent by accident; and a completed order is reported once, by one durable per-order marker shared with the other two pixels, so reloading or re-opening your confirmation page does not report a second order to any of the three networks.
5. The Meta (Facebook) advertising pixel.
This is a third pixel, built and operated by Meta Platforms, Inc., loaded from Meta's own domain, and it exists so that advertising we buy across Meta's properties can be measured against what happened here. Everything in this part is the same as the two above it except for when it starts, and that one difference is significant enough that it is written out rather than left for you to notice.
It does not wait for you to accept anything. Snapchat's pixel and TikTok's are not requested until the research-use confirmation has been answered. This one is requested as the page loads, and the first thing it reports is that you arrived — before that confirmation is answered, and therefore also on a visit that never gets past it. The reason is that the confirmation stands in front of every visit to this site, so a person who arrives from an advertisement and leaves at that screen produces no record anywhere else: not in our own page-view counts, not in the campaign attribution, and not in either of the other two pixels. Without this, that visit is indistinguishable from an advertisement nobody clicked. We would rather tell you that plainly than describe three pixels as though they behaved alike.
What it does not do is escape the two controls that matter most. If you have recorded the sale/share opt-out, or your browser sends a Global Privacy Control signal, this pixel is never fetched — the check happens before the request, so there is nothing to suppress afterwards. Those two are read from your browser and from a choice you have already made, so consulting them requires no consent and takes nothing from you. Section 7 is where you set them, and for this pixel they are the whole of your control.
When it loads, it reports those same six occurrences to Meta Platforms, Inc., under Meta's own event names, and nothing else:
- that a page was viewed — including the very first one, reported before you have entered the site;
- that a product page was viewed, with no indication of which product;
- that an account was created, which Meta files under its standard registration event;
- that an item was added to a cart, together with what that item cost and the currency;
- that a checkout was started, together with what the cart was worth at that instant; and
- that an order was completed, tagged with our own order identifier and carrying no amount.
Everything travelling alongside those events is bounded to two fields and two only — the money value and its currency — enforced in code at the moment of sending, plus our own order identifier on a completed order, which Meta accepts separately as an event identifier so that any later server-side report of the same order is recognized as the same order instead of counted twice. Everything else is dropped before the call is made. Said plainly, and it is the third time this section says it: no product name, compound name, catalog identifier, lot number, category, or description is ever sent to Meta. Meta learns that a product page was viewed; which product it was never leaves this site.
That refusal costs us something visible and we are choosing to pay it. Meta's own documentation asks a site to attach a list of content identifiers, a content name, a content type, a content category, an array of cart contents, and a count of items to exactly these events, and Meta's Events Manager will report our setup in its diagnostics as missing those parameters, and will separately flag a completed order for arriving without a purchase value. On this catalog every one of those content fields would carry a compound name, which is a health inference about the person who viewed it. None of them is sent, the code permits the two fields named above and no others, and the diagnostics warnings stand.
Your identity is not sent either. Meta's installation snippet invites a site to pass an advanced matching object at the moment the pixel starts — your email address, your phone number, your first and last name, and an account identifier of the site's own choosing, hashed in your browser. We start the pixel with the pixel identifier alone and pass no such object, anywhere, ever. Meta's snippet also offers a no-script fallback image that would report a page view for visitors with JavaScript switched off; we deliberately do not ship it, because an image tag cannot consult your opt-out or your Global Privacy Control signal before it fires.
What Meta receives regardless is what any third-party script receives simply by being fetched: your IP address, your browser's user-agent string, and cookies its own script sets in your browser. The payload is ours to decide; the request itself is not, and once it exists it carries those things. Because this pixel loads before the confirmation is answered, its cookies are also set at that earlier moment — Section 13 says so in the table rather than implying they appear only afterwards. Meta's use of any of it is governed by Meta's own privacy policy, not by this one.
Four limits bound it too, and the first of them reads differently from the other two pixels' and is the reason this part exists: it is fetched without waiting for consent, but never for a browser sending Global Privacy Control and never for someone who has recorded the sale/share opt-out; those two are re-checked at every individual event as well as before the script is requested, so setting either mid-visit stops the next event rather than the next page; the parameters are an allowlist rather than a filter, so a field nobody anticipated cannot be sent by accident; and a completed order is reported once, through the same durable per-order marker that covers Snapchat and TikTok, so re-opening a confirmation page does not report a second order to Meta any more than it does to them.
One asymmetry in that last limit is worth stating rather than leaving to be inferred: only the completed order is remembered across visits. Reaching the checkout page on two separate occasions is reported to all three networks twice, because it genuinely is two occasions on which a checkout was begun, and nothing about it is stored on your device to make it otherwise. Within a single visit to that page it is reported once.
The consequence of four of the five mechanisms being consent-gated is that our own numbers undercount: visitors who opt out are invisible to us, an order from someone who opted out records no campaign at all, and our advertising reporting is correspondingly incomplete. We accept that. There is nothing in the page-view record to sell, and nothing personal in it to disclose or delete in response to a rights request; the attribution record is attached to an order, so a request about that order reaches it like everything else on the row — which is what makes the opt-out honest rather than decorative. Since consent is now granted at the entrance, that opt-out carries the whole weight: it is re-checked at every individual event, so setting it takes effect on the visit you set it on rather than at the next page load. And for the fifth mechanism, the Meta pixel, the opt-out is not merely the heaviest control but the only one, which is why Sections 4, 7 and 15 all point at the same two ways to use it.
11. Artificial Intelligence
We use AI tools in how this site is built and written, and the U.S. Federal Trade Commission expects that to be disclosed plainly rather than buried. Plainly, then:
- Written content: Editorial content on this site — including research notes on the blog, FAQ answers, product descriptions, and drafts of policy pages including this one — was drafted or edited with the assistance of AI writing tools. Nothing drafted that way is published without human review.
- Imagery: Some product images are computer-generated renderings rather than photographs of the specific vial or lot you will receive. Images are illustrative.
- Analytical data is never AI-generated: Purity, identity, molecular weight, and every other analytical value shown on this site is read from a certificate-of-analysis record produced by a testing laboratory. No such value is ever produced, estimated, or completed by an AI model — the platform will not display a test claim that has no backing laboratory record.
- No automated decisions about you: We do not use AI, or any other automated process, to make decisions about you that produce legal or similarly significant effects. There is no automated eligibility scoring, no personalized pricing (prices come from a fixed formula that is identical for every customer), and no profiling within the meaning of Article 22 GDPR.
- No AI chatbot: Support messages are read and answered by a person.
- Your data is not fed to AI providers: Our systems do not send your personal information, order history, or support messages to any AI service. No such integration exists in this site. If that ever changes, we will disclose it here first.
12. Data Security
We implement reasonable technical and organizational measures to protect your information. Passwords are stored only as one-way hashes, never in a readable form. All traffic is transmitted over HTTPS. Because payment is handled by external networks and providers, we never handle or store your card or bank details. Administrative areas of the site require a separate secret and are excluded from search engines.
No method of transmission or storage is 100% secure. In the event of a data breach that affects your rights or interests, we will notify affected users, and any supervisory authority we are required to notify, as applicable law requires.
13. Cookies and Local Storage
We use a small number of cookies and browser storage entries. All but three groups are our own: written by this site, read only by this site, and never sent to an advertising network. That includes mrm_attr, which holds the campaign information the link you clicked already carried. The exceptions are Snapchat, TikTok, and Meta. Snapchat's and TikTok's pixels load, and set their own third-party cookies, only if you accept non-essential cookies and have not opted out of sale or sharing — and because that acceptance is now given by entering the site, they are set on the first visit. Meta's pixel sets its cookies earlier still: it loads with the page, so its cookies are written before you answer the research-use confirmation, on the very first page you land on. If you opt out, or send a Global Privacy Control signal, none of the three pixels loads and none of those cookies are set, Meta's included.
| Name | Kind | Purpose | Lifetime |
|---|---|---|---|
| mrm_session | Cookie (httpOnly) | Keeps you signed in. Signed so it cannot be tampered with; not readable by scripts | About 30 days |
| mrm_ref | Cookie (httpOnly) | Remembers which affiliate referred you so a referral can be credited | 60 days |
| mrm_attr | Cookie (readable by page scripts) | Remembers which advertising campaign or referring link brought you here, so an order can be credited to it. Written only if you accept non-essential cookies, and only if the link carried campaign parameters or a click identifier. First one only — never overwritten. Not sent to any advertising platform | 60 days |
| Snapchat pixel cookies (_scid and related) | Cookie — set by Snapchat's script, not by us | Snapchat's own advertising and measurement identifiers, used to attribute an advertisement to what happened here and to build Snapchat's own audiences. Set only if you accept non-essential cookies and have not recorded the sale/share opt-out or sent a Global Privacy Control signal; the script is not loaded otherwise, so nothing is set. Their names, contents, and purposes are determined by Snap Inc., not by us, and are governed by Snapchat's privacy policy rather than this one. Clearing your browser cookies removes them | Set by Snapchat and outside our control; the principal one, _scid, is documented by Snap as about 13 months at the time of writing |
| TikTok pixel cookies (_ttp and related) | Cookie — set by TikTok's script, not by us | TikTok's own advertising and measurement identifiers, used to attribute an advertisement to what happened here and to build TikTok's own audiences. Set only if you accept non-essential cookies and have not recorded the sale/share opt-out or sent a Global Privacy Control signal; the script is not loaded otherwise, so nothing is set. Their names, contents, and purposes are determined by TikTok Inc., not by us, and are governed by TikTok's privacy policy rather than this one. Clearing your browser cookies removes them | Set by TikTok and outside our control; TikTok documents the principal one, _ttp, as about 13 months at the time of writing |
| Meta pixel cookies (_fbp, and _fbc when you arrive from a Meta advertisement) | Cookie — set by Meta's script, not by us | Meta's own advertising and measurement identifiers. _fbp is a browser identifier Meta uses to attribute an advertisement to what happened here and to build Meta's own audiences; _fbc stores the click identifier that Meta appends to the link when you arrive from one of its advertisements. ⚠️ THESE ARE WRITTEN BEFORE YOU ANSWER THE RESEARCH-USE CONFIRMATION, unlike every other third-party entry in this table: Meta's pixel loads with the page (Sections 4 and 10), so _fbp exists from the first page you land on whether or not you go on to enter the site. They are NOT set if you have recorded the sale/share opt-out or your browser sends a Global Privacy Control signal — in that case the script is never fetched, so nothing is written. Their names, contents, and purposes are determined by Meta Platforms, Inc., not by us, and are governed by Meta's privacy policy rather than this one. Clearing your browser cookies removes them | Set by Meta and outside our control; Meta documents both _fbp and _fbc as about 90 days at the time of writing |
| mrm_admin | Cookie (httpOnly) | Administrator access to the internal admin area. Never set for customers | Session |
| mrm-analytics-consent | Local storage | Records your analytics consent — set when you enter the site, or by the Allow/Decline banner if you entered before August 23, 2026 | Until you clear it |
| mrm-do-not-sell | Local storage | Records your Do Not Sell or Share opt-out | Until you clear it |
| mrm-age-gate-v2 | Local storage | Records that you confirmed you are 21 or older and are purchasing for research use | Until you clear it |
| mrm-cart-v1 | Local storage | Your cart contents, held in your browser | Until you clear it |
| mrm-theme | Local storage | Your light or dark theme choice | Until you clear it |
| mrm-pv-session | Session storage | Opaque marker that separates one visit from another for consented page views | Destroyed when the tab closes |
You can clear or block cookies and browser storage in your browser settings. Blocking the session cookie will sign you out; blocking local storage will empty your cart and re-show the age confirmation; blocking or clearing mrm_attr, the Snapchat cookies, the TikTok cookies, or the Meta cookies costs you nothing at all — nothing on the site behaves differently without them, and recording the sale/share opt-out, or sending a Global Privacy Control signal, prevents all of them from ever being set.
14. Your Privacy Rights (California)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, sell, or share, including the specific pieces we hold about you. We do not sell; Section 7 sets out exactly what we share, with whom, and why.
- Delete personal information we collected from you, subject to the exceptions in the statute (we must keep order and compliance records).
- Correct inaccurate personal information we hold about you.
- Opt out of the "sale" or "sharing" of personal information. Use the "Do Not Sell or Share My Personal Information" link in the site footer, or send the Global Privacy Control signal. There is real sharing to opt out of — the Snapchat, TikTok, and Meta pixels in Sections 7 and 10 — so this is a live right on this site, not a formality, and the one control covers all three. For the Meta pixel it is the only control, because that one does not wait for consent; exercising it before you browse is what stops it being fetched at all.
- Limit the use and disclosure of sensitive personal information — see Section 8 for why there is currently nothing to limit.
- Not be discriminated or retaliated against for exercising any of these rights. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
To exercise a right, email support@meridianresearchllc.net from the address on your account, or tell us the address on your account so we can verify you. We will not ask for more information than we need to verify. An authorized agent may submit a request on your behalf with written permission that we can verify. We respond within 45 days, and will tell you if we need a further 45 days.
15. Your Privacy Rights (EEA and UK)
If you are in the European Economic Area or the United Kingdom, you have the right to access your personal data; to have inaccurate data rectified; to have data erased; to restrict processing; to object to processing carried out on the basis of legitimate interests, including at any time to direct marketing; and to receive data you gave us in a portable form.
Where we rely on consent, you may withdraw it at any time — for analytics and advertising measurement by using the “Do Not Sell or Share My Personal Information” link in the site footer or by sending a Global Privacy Control signal (analytics consent is given by entering the site, so that link is the withdrawal route; see Sections 4 and 7), and for email by writing to support@meridianresearchllc.net and asking to be removed. We are adding a one-click unsubscribe link to marketing messages; until it is live, the support address is the way to unsubscribe and we action it manually.
One mechanism does not rely on consent and so there is no consent to withdraw for it: the Meta advertising pixel described in Section 10 loads before the entry confirmation is answered, and Section 5 records both the basis we have provisionally recorded for it and our view that the question is unresolved. The same footer link and the same Global Privacy Control signal stop it, and because that signal is read before anything is fetched, sending it means the pixel is never requested on any page. You may also object to it under Article 21 by writing to the address below, and we will act on that objection.
You also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office if you are in the United Kingdom. We would appreciate the chance to address your concern first.
To make any of these requests, contact support@meridianresearchllc.net.
16. Data Retention
We retain account information for as long as your account is active. Order records of research compound purchases, and the attestation records attached to them, are retained for a minimum of seven years for tax, legal, and regulatory compliance purposes. Email subscription records are kept until you unsubscribe. Affiliate referral records are kept for as long as needed to calculate and audit commission. The campaign attribution described in Section 10 lives on your device for 60 days; where it has been copied onto an order it is part of that order record and is kept for as long as the order is.
Page-view records contain no personal identifiers, so they are retained as aggregate traffic history. Retention of provider-side security and operational logs is set by those providers. The events the Snapchat pixel sends are held by Snap Inc., the events the TikTok pixel sends are held by TikTok Inc., and the events the Meta pixel sends are held by Meta Platforms, Inc., each on its own systems under its own retention policy; we cannot delete them on your behalf, and we hold no copy of any of them — a request about that data goes to the network that holds it, and opting out under Section 7 stops any more of it being created by any of the three.
You may request deletion of your account and associated personal data at any time; we will delete what we are not legally required or permitted to retain, and tell you what we kept and why.
17. Age and Eligibility Restriction
Meridian Research is strictly for users 21 years of age and older who are purchasing for research, scientific, or experimental purposes. We do not knowingly collect personal information from anyone under 21 or from individuals purchasing outside of a legitimate research context. If we become aware that we have collected information from someone under 21, we will delete it promptly.
18. International Transfers and Safeguards
Meridian Research is operated in the United States. Our service providers process personal information in the United States, and Snap Inc., TikTok Inc., and Meta Platforms, Inc. — the three third-party recipients named in Section 9 — are all United States companies. TikTok Inc. is part of a corporate group whose ultimate parent is outside the United States, and where it moves the data its pixel collects is determined by TikTok's own privacy policy rather than by this one. Meta Platforms, Inc. likewise operates infrastructure outside the United States, and where it moves the data its pixel collects is determined by Meta's own privacy policy rather than by this one. If you use the site from outside the United States, your information will be transferred to the United States.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum for transfers from the United Kingdom, incorporated into our agreements with the providers listed in Section 9. Where a transfer is strictly necessary to perform a contract with you — shipping an order you placed, for example — Article 49(1)(b) may also apply.
We do not rely on your consent alone as the safeguard for these transfers.
You may request a copy of the safeguards that apply to a transfer by contacting us.
It remains your responsibility to ensure that purchasing research chemicals from Meridian Research is lawful in your jurisdiction.
19. Changes to This Policy
We may update this policy from time to time. The current version will always be posted on this page with a revised date. Material changes will be communicated via email to registered users where feasible.
20. Contact
Privacy questions or rights requests: support@meridianresearchllc.net
Postal: [ENTITY NAME], [REGISTERED ADDRESS].
For research use only · Not for human or animal consumption · Not for therapeutic, diagnostic, or preventive use · Must be 21+