Privacy Policy
Last updated: April 2026
1. Introduction
steroiduck ("we", "us", "our") takes your privacy seriously. This Privacy Policy explains what information we collect when you use steroiduck.com, how we use it, how we protect it, and what choices you have.
By using our website and placing orders, you consent to the practices described in this policy. If you do not agree, please do not use our services.
2. Information We Collect
2.1 Information You Provide
- Account information: name (or alias), email address, password (stored hashed with Argon2)
- Shipping details: US delivery address and phone number (used solely for carrier handoff)
- Payment information: payment method selected and transaction references. We do NOT store full card numbers; card data is tokenized by our payment processor (Stripe)
- Cryptocurrency data: wallet address and transaction hash for crypto payments (only visible on the public blockchain)
- Communications: messages sent through our chat support, email, or contact form
- Reviews: product reviews and ratings you submit
2.2 Information Collected Automatically
- Device information: browser type, operating system, device fingerprint (used for fraud prevention only)
- Usage data: pages visited, products viewed, search queries, session length
- IP address: for security, rate limiting, and approximate geolocation (state-level)
3. How We Use Your Information
We use your personal information strictly for these purposes:
- Order processing: to fulfil and dispatch your orders from our US warehouses
- Payment verification: to process and confirm card, Apple Pay, Google Pay, Zelle, or crypto payments
- Customer support: to respond to your inquiries via chat or email
- Account management: to maintain your account, order history, and referral programme
- Transactional email: to send order confirmations, shipping notifications, and delivery updates
- Marketing: to send newsletters and promotional offers (only with your explicit opt-in consent)
- Fraud prevention: to detect and prevent unauthorized access, chargebacks, and abuse
- Service improvement: to analyse anonymized usage patterns and improve our platform
4. Discretion & Anonymity
We understand that discretion is paramount. We take several steps to protect your privacy beyond legal minimums:
- Card charges appear anonymously on your billing statement with no reference to the product category
- All packages ship in plain, unmarked boxes with no external labels indicating the contents
- Shipping labels use our neutral dispatch brand name, not "steroiduck"
- No signature is required on delivery by default
5. Data Storage & Security
We take the security of your data seriously and implement the following measures:
- Passwords are hashed using industry-standard Argon2id
- Sensitive personal data is encrypted at rest (AES-256)
- All data is transmitted over HTTPS with TLS 1.3
- Access to customer data is restricted to authorised staff with two-factor authentication required
- Regular security audits and penetration tests are conducted
- Automated backups are encrypted and stored in geographically separated US data centers
We retain your personal information for as long as your account is active or as needed to provide services, comply with legal obligations, and resolve disputes.
6. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We share your data only with:
- Delivery couriers (USPS, UPS, FedEx): your name and shipping address to fulfil orders
- Payment processors (Stripe, NOWPayments): transaction details required for payment authorization
- Transactional email provider: your email address to deliver order updates
- Legal authorities: if compelled by a valid subpoena, court order, or to protect our rights
All third-party service providers are contractually obligated to protect your data and to use it only for the specified purposes.
7. Cookies & Tracking
Our website uses essential cookies and session storage for:
- Authentication (keeping you logged in)
- Shopping cart persistence
- Device fingerprinting for fraud prevention
- Age-gate verification (so you do not see the 21+ popup on every page)
We do not use third-party advertising cookies, Google Analytics, or tracking pixels. All analytics are self-hosted and anonymized.
8. Your Rights (CCPA & GDPR)
Under the California Consumer Privacy Act (CCPA) and, where applicable, the General Data Protection Regulation (GDPR), you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your account and personal data (subject to legal retention requirements)
- Portability: request your data in a machine-readable format
- Objection: opt out of marketing communications at any time
- Restriction: request that we limit processing of your data
- Non-discrimination: we will not deny service or charge different prices for exercising these rights
To exercise any of these rights, contact us via privacy@steroiduck.com. We will respond within 30 days.
9. Newsletter & Marketing
If you subscribe to our newsletter or promotional emails, we collect your email address and subscription preferences. You can unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting us directly.
We will never send marketing emails without your explicit opt-in consent.
10. Age Requirement
Our website is intended only for individuals aged 21 years or older. We do not knowingly collect personal information from anyone under 21. If we become aware that we have collected data from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email and on this page with an updated revision date. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your data, reach us via the on-site chat or by email at privacy@steroiduck.com.
