RetaGrade shieldRetaGrade

Your information

Privacy Policy

This policy explains in plain language what RetaGrade collects, why we need it, who may receive it, and how you can ask us to access, correct, or delete information about you.

Last updated July 28, 2026

No data sales

We do not sell personal information or use third-party advertising pixels.

Limited payment data

Full card numbers and security codes are handled by payment providers.

Privacy signals honored

First-party analytics stops when DNT or Global Privacy Control is enabled.

Who and what this policy covers

This Privacy Policy applies to personal information RetaGrade processes through retagrade.com, customer accounts, checkout, order support, research-document lookup, and related communications. RetaGrade is a New Jersey-based research-supply business and is the controller of the information described here unless a service provider states that it acts independently.

It does not govern a third party’s own website, account, or service simply because we link to it. Those providers publish separate notices for their processing.

Not a healthcare service

RetaGrade does not provide medical care and is not a HIPAA-covered healthcare provider. Please do not send medical records, diagnoses, dosing questions, or other health information through support channels.

Information we collect

  • Account and identity information: Name, email address, password credential in protected form, account role, profile image if supplied through Google, account dates, and sign-in/session security details such as IP address and user agent.
  • Order and fulfillment information: Email, recipient name, shipping and billing addresses, items, quantities, prices, tax and delivery selections, order status, support history, refunds, and research-use acknowledgement.
  • Payment references: Transaction status and identifier, payment provider, card brand and last four digits, and—only if you choose a saved card—expiration, billing profile, and a provider vault identifier. RetaGrade does not receive or store a full card number or security code.
  • Communications: Information you include in support email, return documentation, photographs, privacy requests, or other correspondence.
  • Site and device activity: Random visitor and session identifiers, page path, referring site without its query string, campaign tags, browser/device category, viewport, approved button labels, click position, scroll depth, and active duration.
  • Information from providers: Basic profile information you authorize Google to share, payment and fraud results from a payment provider, normalized address suggestions, and carrier delivery events when available.

We do not intentionally collect Social Security numbers, government identification, precise device location, biometric information, or medical records through the storefront.

How we use information

  • Create and secure accounts, authenticate sessions, and provide customer-requested account features.
  • Price checkout, process payment, validate delivery information, fulfill orders, provide tracking, handle returns, and maintain transaction records.
  • Respond to support and privacy requests and send transactional messages such as order, refund, and security notices.
  • Protect customers and RetaGrade by preventing fraud, abuse, unauthorized access, and violations of our Terms.
  • Understand aggregate storefront performance, diagnose errors, improve navigation, and measure which first-party content is useful.
  • Comply with tax, accounting, consumer-protection, legal-process, and other lawful obligations, and establish or defend legal claims.

We process this information as needed to provide a requested service or perform a contract, for legitimate operational and security purposes, with consent where required, and to comply with law.

When information is disclosed

We disclose only the information reasonably needed for the recipient to perform its role. Depending on the feature you choose and the production configuration, recipients may include:

  • Payment providers: PayPal or NMI processes payment and fraud information. Review the PayPal Privacy Statement and NMI Privacy Policy.
  • Authentication and address services: Google may process basic profile information if you choose Google sign-in and may validate an address when that service is configured. Google handles that information under its Privacy Policy.
  • Store operations: Hosting, database, email, storage, fraud-prevention, and technical vendors process data under service arrangements.
  • Delivery: Carriers and fulfillment providers receive recipient and parcel information needed to deliver and investigate claims.
  • Legal and business events: Information may be disclosed to advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a merger, financing, reorganization, or transfer of the business subject to appropriate safeguards.

What we do not do

RetaGrade does not sell personal information for money, share it for cross-context behavioral advertising, or use third-party advertising pixels. If those practices change, we will update this policy and provide any notice and opt-out required by law before doing so.

Cookies, local storage, and first-party analytics

The site uses cookies and browser storage that are necessary to keep a cart, maintain sign-in and security state, preserve checkout continuity, and remember limited storefront analytics identifiers. Blocking essential storage may prevent account, cart, or checkout features from working.

Our first-party analytics measures page views, approved navigation actions, scrolling, and active time. Query strings are removed from stored page paths and referrers, order-access pages are excluded, and a raw source IP address is not written to the analytics database. Hosting security logs and authenticated sessions may process IP addresses separately for security and operations.

The analytics tracker does not send events when your browser exposes Do Not Track = 1 or enables Global Privacy Control. You can also clear the site’s cookies and local storage through browser settings, though doing so resets the cart and random analytics identifiers and may sign you out.

Retention and security

We keep personal information only for as long as reasonably necessary for the purposes above, including providing an account or order, resolving disputes, preventing fraud, and satisfying tax, accounting, warranty, and legal obligations. Retention therefore varies by record:

  • Raw first-party analytics: Targets deletion after 90 days; aggregate reporting may be retained without direct account identifiers.
  • Guest order links: Expire after 180 days and can be revoked earlier; the order record remains subject to business and legal retention needs.
  • Accounts and saved payment references: Remain while the feature is active or until removal is requested, subject to transaction records we must retain and provider requirements.
  • Order and payment records: Are retained for fulfillment, support, fraud prevention, financial reporting, and applicable limitation or recordkeeping periods.

We use administrative, technical, and organizational safeguards designed for the nature of the information, including access controls, protected authentication credentials, tokenized or provider-hosted payment fields, and limited collection. No internet transmission or storage system can be guaranteed completely secure.

Your privacy choices and rights

Depending on where you live and subject to legal exceptions, you may ask to access, confirm, correct, delete, or obtain a portable copy of personal information about you. You may also have rights to opt out of sale, targeted advertising, or certain profiling. RetaGrade does not currently perform those opt-out activities.

Send a request to orders@retagrade.com with the subject “Privacy request” and describe the right you want to exercise. We may request information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where applicable, but we may require proof of authorization and direct identity confirmation.

We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right. If we deny an appealable request, our response will explain the reason and how to appeal. A deletion request may not erase records we must keep for a transaction, security, fraud prevention, legal compliance, or legal claims.

Account controls

You can review profile, address, order, and saved-payment information from your account where those controls are available. Removing a saved card deletes the local reference and requests removal from the configured secure vault; it does not erase historical transaction records held by RetaGrade or the payment provider.

Children and users outside the United States

The site and products are intended for adults acting for authorized research purposes. We do not knowingly collect personal information from children under 13, and no one under 18 may create an account or place an order. If you believe a child provided information, contact us so we can review and delete it as appropriate.

RetaGrade operates from and currently ships only within the United States. If you access the site from another jurisdiction, information may be transferred to and processed in the United States and other locations where our service providers operate. Those locations may have different privacy laws.

Policy updates and contact

We may update this policy when site features, providers, or legal requirements change. The “Last updated” date identifies the current version. If a change materially affects how we use information already collected, we will provide additional notice when required.

Questions, complaints, and privacy requests can be sent to orders@retagrade.com. For other customer-service routes, visit Contact. Our Terms of Service govern use of the site and purchases.