Security & Data Protection
How we handle your information, and why this store collects less of it than most.
No card data on this site
Payment is arranged by emailed invoice. We never ask for, receive, or store card numbers on this website.
Encrypted in transit
Every connection uses TLS with HSTS enforced, so traffic to this site is always encrypted.
Authenticated email
Our mail is signed with SPF, DKIM, and DMARC so you can trust that a message from us is really from us.
Verifiable lots
Every vial's QR code resolves to its own permanent COA record, so you can confirm what you received.
What we collect — and what we don't
When you place an order we collect only what is needed to review, fulfill, and support it: your name, email, shipping address, order contents, and your research-use certification (phone, institution, and research field are optional). We do not collect payment card numbers on this site — payment is handled separately, by invoice — and we run no third-party advertising trackers. Full detail is in our Privacy Policy.
How your data is protected in transit
The entire site is served over HTTPS with HTTP Strict Transport Security enabled, so browsers are instructed to connect only over an encrypted channel. The site also ships a strict content-security policy and standard hardening headers (frame-blocking, MIME-sniffing protection, a locked-down referrer policy) to reduce the surface for common web attacks.
Payment handling
Placing an order on this site does not charge you and does not transmit card numbers, bank account numbers, or wallet keys through these web pages. After review we email an itemized invoice. Bank transfer / ACH is paid to the receiving bank named on the invoice. If cryptocurrency is offered on your invoice, it is paid through a hosted invoice from the processor named there — we do not host wallets on this site. There is no cardholder data on our storefront to be exposed.
Email you can trust
Our domain publishes SPF, DKIM, and DMARC records, and our outbound mail is cryptographically signed. If you receive a message claiming to be from Gold Tide Research that fails these checks, treat it as suspicious. We will only ever contact you from an @goldtideresearch.com address, and we will never ask you to send payment to a personal account or a different domain.
Product integrity
Each production lot has a unique batch number and a QR code printed on the vial that resolves to that lot's permanent record on our COA page. We do not ship a lot whose certificate has not been posted. This lets you independently confirm that the material you received matches the batch we shipped.
Reporting a concern
If you believe you have found a security issue with this website, or received a suspicious message using our name, please tell us at [email protected]. Email is monitored Monday through Friday.
