account-terms

Last updated · 2026-05-16 · Version 2026-05-16-v2

By creating or signing in to a USPP account, you agree to these Account Terms. If you do not agree, do not create an account; site access is restricted to registered account holders other than for a set of public, informational pages enumerated in our Terms of Use.

1. Identity and Accuracy

You represent that the email address used to open the account is yours to control and that any information you provide on your account record (default shipping address, default billing address, display name) is accurate. If you are creating an account on behalf of a research entity, you represent that you have authority to bind that entity. You are responsible for keeping your account information current.

2. Authentication: Password or Magic-Link

(a) Password. When you create an account you set a password. The password must be at least twelve (12) characters. USPP screens your chosen password against the Have I Been Pwned ("HIBP") Pwned Passwords API using a k-anonymity method (only a five-character SHA-1 prefix of your password is transmitted to HIBP) and rejects any password that has appeared in more than 100,000 prior known data breaches. Passwords are stored in USPP databases only as bcrypt one-way hashes (cost factor 12); the raw value is never persisted.

(b) Magic-link sign-in (alternative). As an alternative to password sign-in, you may request a single-use, time-limited "magic-link" URL that USPP emails to your verified address. Magic-links expire fifteen (15) minutes after issuance and can be used once. Requesting a new link automatically supersedes any prior unconsumed link for the same address. The "Forgot password" reset flow uses the same magic-link mechanism.

(c) Your responsibility. You are responsible for the confidentiality of your password and for the security of the email inbox associated with your account. USPP cannot recover an account if you lose both your password and access to your email and do not have a recovery alias still active (see Section 5). Where possible, USPP recommends that you protect your inbox with multi-factor authentication and avoid using shared inboxes for your USPP account.

(d) Bot verification. Account registration requires solving a Cloudflare Turnstile challenge. Turnstile receives limited browser signals (described in our Privacy Policy, Section 2.1(h)) for that purpose only. Turnstile is fail-closed: if Cloudflare's verification endpoint is unavailable, registration is rejected and you should try again later.

3. Session Cookie and "Keep Me Signed In"

Successful sign-in sets a single first-party cookie (uspp_customer_session; HttpOnly; SameSite=Lax; Secure). The default lifetime is a ninety (90) day rolling expiry that refreshes on each authenticated request. If you check the "Keep me signed in on this device" box at sign-in, the cookie lifetime is extended to one (1) year. The cookie is strictly necessary for account functionality and is not subject to consent. The raw cookie value is never persisted in USPP databases; only its SHA-256 hash is stored.

From your account settings, you can review the time, IP address, and truncated user-agent of each active session and can revoke any session (or all sessions) at any time. Successful password reset automatically revokes all active sessions for that account. Account UI does not load advertising or analytics tracking pixels not already permitted under your Privacy Policy choices.

3A. Email Verification (Seven-Day Grace)

USPP sends a single-use email-verification link to your registered email address immediately after registration. You may use the Site as a verified account holder for a grace window of seven (7) days from registration without claiming the link; during this window, an unobtrusive banner reminds you that verification is pending. If the grace window elapses without verification, your account remains in our records but Site access is restricted to a "verification required" page from which you can request a fresh verification link. Successful verification clears the grace state and restores Site access.

3B. Site-Access Registration

Other than a set of public, informational pages enumerated in our Terms of Use (currently the homepage, the Certificates of Analysis library, this and other policy pages, the FAQ, the verification standards page, and the account-access page itself), Site access requires a registered account in good standing. Attempts to access restricted pages without a valid session redirect to the account-access page. USPP may revise the list of public pages at any time without notice.

4. Sign-In Alert Emails

An email is sent to your account address on every successful sign-in, containing the timestamp, IP address, and a truncated user-agent string. This is a security signal and is not promotional. Sign-in alert emails cannot be disabled in this version of the product. Do not unsubscribe from your transactional sender; doing so will block these alerts.

4A. Force-Complete for Pre-Existing Accounts

USPP account holders who created an account before the introduction of the password-based authentication path (D-V3-65) will be prompted, on their next sign-in, to complete their account by (i) setting a password meeting the requirements in Section 2(a), (ii) re-affirming that they are 21 years of age or older, and (iii) accepting these revised Account Terms. The prompt blocks further Site access until completion. The version of the Account Terms in force at the time you complete this prompt is recorded in your account profile, superseding the version recorded at original account creation. Successful completion does not require a separate email-verification round-trip because possession of the prior magic-link inbox already proved control of the email address.

5. Linking of Past Orders; Email Change

(a) Linking of past orders. The first time you successfully sign in, USPP will link any past orders placed under the same email address (case-insensitive match) to your account. By signing in, you confirm that you are the rightful recipient of those orders. If a prior order was placed by someone else from the same email address (for example, a shared lab inbox), do not sign in to claim those orders; instead, contact support@usprecisionpeptides.com.

(b) Self-service email change. You can change the email address on your account from your account settings. The change requires confirmation links to be clicked from BOTH the current email address AND the new email address within the same fifteen-minute window. Both halves are required; clicking only one does not change the email.

(c) Recovery alias. When the email address changes, the previous address is retained as a recovery alias for thirty (30) days. During that window, sign-in links sent to the previous address remain valid. After thirty days, the previous address is permanently dropped from the account record.

6. Per-Order Affirmations Remain Mandatory

Account creation does not store a profile-level affirmation of Research Use Only ("RUO"), age (21+), or shipping eligibility. Each order placed through your account presents the same RUO, age, and shipping affirmations as a guest checkout, and you must complete each affirmation per order. This preserves the per-transaction audit trail required by USPP's compliance posture.

7. Data Retention and Deletion

Account profile information, session records, and the account audit log are retained until you request deletion. To request deletion, email privacy@usprecisionpeptides.com. After verification of identity, USPP will:

(a) Place a thirty (30) day grace period during which you may rescind the request;

(b) Hard-delete the account profile, all sessions, and the active recovery alias at the end of the grace period;

(c) Retain the account audit log entries necessary for fraud prevention, legal claim defense, and tax/accounting recordkeeping in accordance with the timelines disclosed in our Privacy Policy; these audit entries do not include account credentials and reference only the events that occurred while the account existed.

Order history records associated with the account are retained per the Privacy Policy retention schedule and applicable tax/accounting law, regardless of account deletion.

8. Termination by USPP

USPP may revoke an account at any time for fraud, abuse, violation of these Account Terms or any other USPP policy, or any other reason it determines in good faith. Revocation does not waive USPP's right to retain transaction records as required by law.

9. Changes to These Terms

USPP may update these Account Terms from time to time. Material changes will be communicated through an email to your account address and through an updated version on this page. Continued use of your account after the effective date of the revised Account Terms constitutes your acceptance of the changes. The version of the Account Terms in force at the time you created the account is recorded in your account profile.

10. Contact

For questions about these Account Terms, contact:

US Precision Peptides
Attn: Account Support
9901 Brodie Lane, Suite 160 PMB893
Austin, TX 78748
support@usprecisionpeptides.com

For privacy-specific requests, see Section 7 of our Privacy Policy.