Home / Privacy Policy
Forge LX Labs · Privacy, Security, and Data Rights

Privacy Policy

This Privacy Policy explains what information Forge LX Labs collects, why we collect it, how we use and disclose it, how long we retain it, and the choices and privacy rights that may be available to you.

Effective: August 2, 2026Policy version: 2026-08-02-v1Minimum account age: 21United States operations
Do not submit patient or personal health information

Forge LX Labs is not a health-care provider and the website is not designed to receive medical records, diagnoses, treatment details, dosing information, protected health information, or data about a patient or research subject. Do not include such information in an application, order, support message, review, or other submission.

01

Scope and the organization responsible for your information

This Policy applies to information processed through the Forge LX Labs website, access gate, customer-account application, account review and approval process, product catalog, Cart, Checkout, orders, payments, fulfillment, certificates, support, security, fraud prevention, and related communications.

Forge LX Labs is responsible for deciding why and how the personal information described in this Policy is processed, except when an independent provider acts under its own privacy policy.

This Policy does not apply to information processed solely by an unrelated third party on its own website, platform, or service.

02

Categories of information we collect

CategoryExamplesPrimary purpose
Identifiers and contact informationName, username, email address, telephone number, billing address, shipping address, organization name, website, and account identifiers.Registration, verification, communication, ordering, delivery, support, and records.
Professional and research informationApplicant classification, role or title, laboratory or organization affiliation, facility-access confirmation, research-purpose description, and supporting verification information.Research-account qualification, manual review, compliance, fraud prevention, and account administration.
Transaction and commercial informationProducts viewed or ordered, quantities, prices, coupons, order status, payment status, returns, claims, shipping information, and order history.Order processing, accounting, customer service, fraud prevention, and business records.
Payment-related informationPayment method type, transaction identifier, authorization status, limited billing details, and fraud-screening results provided by a payment processor.Payment processing, reconciliation, refunds, disputes, fraud prevention, and legal compliance.
Internet, device, and usage informationIP address, browser and device information, operating system, referring page, pages viewed, timestamps, login activity, cookie identifiers, and security logs.Website operation, authentication, security, troubleshooting, analytics when enabled, and abuse prevention.
Communications and submissionsSupport requests, contact messages, application statements, order notes, consent acknowledgments, policy versions, complaints, and correspondence.Responding to requests, documenting consent, reviewing eligibility, resolving disputes, and enforcing policies.
Inferences and risk signalsAccount, order, device, address, communication, or transaction signals used to identify suspected fraud, prohibited use, diversion, account circumvention, or security risk.Protecting customers and the business, enforcing research-use restrictions, and preventing misuse.

We do not ask you to provide Social Security numbers, passport numbers, driver’s-license numbers, biometric identifiers, genetic data, patient information, or medical records through ordinary registration or Checkout. We may request limited additional verification information only when reasonably necessary and will describe the request at that time.

03

Sources of personal information

  • Directly from you when you enter the website, apply, register, order, contact us, or submit documentation.
  • Automatically from your browser, device, cookies, server logs, and website-security systems.
  • From your organization, laboratory, employer, authorized representative, or another account administrator.
  • From payment processors, fraud-prevention providers, carriers, hosting providers, email providers, and other service providers.
  • From public business, professional, organizational, or government records used to verify information you provide.
  • From communications or information reasonably related to account security, prohibited use, fraud, or policy enforcement.
04

How we use personal information

  • Operate, maintain, secure, troubleshoot, and improve the website and customer-account functions.
  • Review research-account applications and verify organization, affiliation, role, facility access, and research purpose.
  • Create and manage accounts, passwords, approvals, suspensions, reverification, and access permissions.
  • Process orders, payments, refunds, shipping, delivery, claims, customer service, and transaction records.
  • Record electronic acknowledgments, policy versions, dates, times, account identifiers, order identifiers, IP addresses, and browser information.
  • Detect and prevent fraud, chargebacks, misuse, diversion, unauthorized resale, prohibited use, account circumvention, security incidents, and unlawful activity.
  • Communicate about applications, approvals, account status, orders, policies, security, support, and legally required notices.
  • Maintain accounting, tax, audit, insurance, quality, legal, and compliance records.
  • Enforce the Terms and Conditions, Research Use Policy, and other policies.
  • Analyze website performance and usage when compatible analytics are enabled.
  • Comply with law, legal process, regulatory obligations, and lawful requests.
05

When and with whom information is disclosed

We disclose personal information only as reasonably necessary for the purposes described in this Policy, subject to contracts and safeguards where appropriate.

  • Hosting and website providers: providers that host, maintain, secure, back up, or support WordPress, WooCommerce, and the website.
  • Payment and fraud providers: processors that authorize transactions, prevent fraud, issue refunds, and manage payment disputes.
  • Shipping and fulfillment providers: carriers and service providers that prepare, route, track, insure, or deliver an order.
  • Email and communications providers: services that deliver registration, approval, password, order, support, and marketing messages when enabled.
  • Professional advisers: lawyers, accountants, insurers, auditors, consultants, and compliance professionals.
  • Public authorities and legal recipients: courts, regulators, law enforcement, government agencies, payment networks, or other parties when disclosure is required or reasonably necessary to protect rights, safety, security, or prevent unlawful activity.
  • Business transactions: a buyer, investor, lender, successor, or adviser involved in a proposed or completed merger, financing, reorganization, sale, bankruptcy, or transfer of business assets.
  • At your direction: a person or organization you instruct us to contact or disclose information to.

Service providers are permitted to process information only for the services they provide to us or as otherwise allowed by applicable law.

06

Sale, targeted advertising, and profiling

Current practice

Forge LX Labs does not sell personal information for money. We do not currently share personal information for cross-context behavioral advertising or use it to make decisions producing legal or similarly significant effects through automated profiling.

If our practices change, we will update this Policy, provide any required notice and consent or opt-out mechanism, and honor legally recognized universal opt-out signals where applicable.

Disclosing information to a service provider to operate the website, process an order, deliver email, prevent fraud, or perform another service on our behalf is not treated as a sale by us when the provider is contractually restricted and the disclosure otherwise complies with applicable law.

07

Cookies and similar technologies

Cookies are small files or identifiers stored by a browser or device. The website uses necessary technologies to operate account, Cart, Checkout, authentication, preferences, security, and session functions.

Strictly necessaryRequired for website operation, account login, Cart, Checkout, security, fraud prevention, consent records, and load balancing. Disabling these may prevent important functions from working.
FunctionalRemember choices such as access-gate acceptance, account state, language, or display preferences.
AnalyticsMeasure traffic and website performance if analytics are enabled. We will configure consent and disclosures as required before using nonessential analytics technologies.
AdvertisingThe website does not currently use advertising cookies for cross-site targeted advertising. We will update this Policy and provide required controls before enabling them.

Browser controls may allow you to block or delete cookies. Blocking necessary cookies may interfere with login, Cart, Checkout, access acknowledgments, and security functions.

08

Payments, order processing, and fulfillment

When payment processing is enabled, payment-card or financial information may be collected directly by an independent payment processor through its secure interface. We do not intend to store full payment-card numbers or card security codes on the Forge LX Labs website.

We may receive limited transaction information such as payment method type, token, transaction identifier, authorization result, billing information, fraud score, dispute information, and refund status. Payment processors and carriers may process information under their own privacy policies and legal obligations.

09

Research-account screening and policy enforcement

Purchasing requires manual approval. We use account, organization, role, facility, research-purpose, address, order, device, communication, and transaction information to evaluate eligibility and consistency with the Research Use Policy.

We may document and review communications or activity indicating personal use, human or animal administration, dosing, injection, treatment, weight-management, bodybuilding, resale, relabeling, diversion, fraud, or another prohibited purpose. This information may be used to reject an application, request clarification, restrict quantity, hold or cancel an order, suspend an account, or preserve records relating to suspected misuse.

Decisions are not based solely on an automated system. Manual review may use automated fraud, security, or risk indicators as supporting information.

10

Consumer health data and information you must not submit

Forge LX Labs is not a health-care provider, health plan, pharmacy, or HIPAA-covered treatment service. The website is intended for professional research transactions and is not designed to collect information about a consumer’s health condition, diagnosis, treatment, prescription use, symptoms, bodily functions, or attempt to obtain health care.

  • Do not submit patient or research-subject names, records, identifiers, samples, or medical information.
  • Do not submit diagnoses, symptoms, treatment plans, medication history, dosing plans, side effects, laboratory results, genetic data, biometric data, or protected health information.
  • Do not submit information about personal use or an intended health, cosmetic, weight, performance, or therapeutic outcome.

We do not sell consumer health data. We do not use geofencing around health-care facilities. If future activities require collection or sharing of consumer health data, we will first provide any separate notice, consent process, privacy policy, and rights mechanism required by applicable law.

If you submit prohibited health information, we may delete it, restrict access to it, or retain limited records when reasonably necessary for security, policy enforcement, legal compliance, or prevention of prohibited use.

11

Transactional and marketing communications

We may send transactional or relationship communications about registration, account approval, password security, orders, shipping, policy changes, support, and other requested services. You may not be able to opt out of messages necessary to administer an active account or transaction.

We will not send optional marketing email unless we have an appropriate legal basis and an operational unsubscribe process. Marketing messages will identify the sender and provide a method to unsubscribe. An opt-out does not prevent necessary transactional, security, legal, or account messages.

We may retain a minimal suppression record, such as an email address and opt-out date, to honor an unsubscribe request.

12

Information security

We use administrative, technical, and physical safeguards designed to protect personal information in light of its nature, volume, sensitivity, and the risks involved. Measures may include access controls, password hashing, encrypted transmission, security monitoring, backups, software updates, least-privilege access, service-provider review, and incident-response procedures.

No website, transmission, storage system, or security control is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.

You are responsible for choosing a strong password, protecting credentials, restricting device access, and notifying us promptly of suspected account compromise.

13

Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including account administration, orders, tax, accounting, fraud prevention, security, legal compliance, dispute resolution, and enforcement.

Record typeStandard retention target
Approved account, research application, verification, policy acknowledgments, and related order recordsDuring the active relationship and generally up to seven years after the last transaction or account closure.
Orders, payments, refunds, taxes, accounting, shipment, and dispute recordsGenerally seven years, or longer when required by law, audit, litigation hold, payment dispute, or insurance obligation.
Rejected, incomplete, or withdrawn applicationsGenerally up to three years for fraud prevention, duplicate review, security, and policy enforcement.
Security, access, device, and server logsGenerally up to twenty-four months, unless needed longer for an incident, investigation, legal requirement, or active dispute.
Support and policy-enforcement communicationsGenerally three to seven years depending on the subject, transaction, risk, and legal need.
Marketing preferences and suppression recordsUntil consent is withdrawn or the purpose ends; a minimal suppression record may be retained as necessary to honor the opt-out.

Retention periods may be shortened or extended when reasonably necessary to comply with law, preserve evidence, resolve a dispute, investigate fraud or misuse, protect security, or respond to a valid legal hold. When information is no longer needed, we delete, anonymize, or securely dispose of it as appropriate.

14

Your privacy rights and choices

Depending on your location, relationship with us, and applicable law, you may have rights to:

  • Confirm whether we process personal information about you.
  • Access or obtain a copy of personal information.
  • Correct inaccurate personal information.
  • Delete personal information, subject to legal and operational exceptions.
  • Receive certain information in a portable format.
  • Opt out of sale, targeted advertising, or certain profiling if those activities apply.
  • Limit certain uses or disclosures of sensitive personal information where applicable.
  • Withdraw consent for processing based on consent.
  • Appeal a denial of a privacy request where applicable.
  • Exercise rights without unlawful discrimination or retaliation.

Submit a request through the Contact page and clearly state that it is a privacy request. We may ask you to verify your identity through your existing account, verified email, transaction details, or other reasonable information. Do not send passwords, full payment-card numbers, Social Security numbers, or medical information with the initial request.

An authorized agent may submit a request where permitted by law. We may require proof of authorization and direct identity verification. We will respond within the time required by applicable law, generally within 45 days where that period applies, and will explain any permitted extension or denial.

15

California and other U.S. state privacy notices

Residents of California and certain other states may have additional rights regarding access, categories and specific pieces of information, sources, purposes, third-party disclosures, correction, deletion, portability, sensitive information, sale or sharing, targeted advertising, profiling, appeals, and nondiscrimination.

The categories of personal information we collect, sources, purposes, and disclosures are described in Sections 2 through 6. We do not sell personal information for money and do not currently share personal information for cross-context behavioral advertising.

We do not knowingly sell or share personal information of anyone under 16. The website and purchasing functions are restricted to adults age 21 or older.

If a state law applies to our business and requires an additional opt-out link, notice at collection, appeal process, universal opt-out mechanism, or other control, we will provide that mechanism and update this Policy.

16

Children and the 21-and-older restriction

The website, accounts, and products are not directed to children or minors. Access and registration require the user to confirm that the user is at least 21 years old.

We do not knowingly collect personal information from children under 13. If we learn that we collected personal information from a child under 13, we will take reasonable steps to delete it. A parent or guardian may contact us through the Contact page.

We may reject, suspend, or delete an account when we learn that the account holder is under 21 or provided false age information.

17

International access and data transfers

The website is operated from the United States and is intended primarily for U.S. research customers. If you access the website from another country, your information may be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your location.

International ordering, export, and account approval may be restricted or unavailable. Accessing the website does not guarantee that products or services are available in your jurisdiction.

18

Third-party websites and independent privacy practices

The website may link to carriers, payment processors, laboratories, social platforms, or other independent websites. We do not control their privacy, security, cookie, or data-retention practices.

Review the privacy policy of each third party before providing information. A link or integration does not mean that Forge LX Labs endorses every third-party practice.

19

Changes to this Privacy Policy

We may update this Policy to reflect changes in our technology, providers, products, business, legal obligations, or information practices. The effective date and policy version at the top identify the current version.

We may provide additional notice or request renewed consent when a material change requires it. Earlier versions may be retained for compliance and recordkeeping.

Privacy requests and questions

Submit a privacy request through the Contact page. Include your name, account email, state of residence, the right you wish to exercise, and enough information to identify the relevant account or transaction.

Do not include passwords, full payment-card information, Social Security numbers, government identifiers, medical records, patient information, or other unnecessary sensitive information in the initial request.

We may keep a record of the request and our response as necessary to demonstrate compliance, prevent fraud, and protect security.

Submit a Privacy Request
Scroll to Top