Effective Date: Crux Labs USA Last Updated: August 5th, 2026
Crux Labs USA (Crux Labs, Crux Labs USA, we, our, or “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy (“Policy”) explains how we collect, use, disclose, and safeguard information when you visit our website, request product or catalog information, request a quote, or place an order through
https://cruxlabsusa.com/ (the “Site”), interact with our sales or customer-support teams, or receive our communications, and it describes the choices and rights available to you.
By using the Site or otherwise providing information to us, you acknowledge that you have read and understood this Policy and agree to the collection, use, and disclosure of information as described here. If you do not agree with our practices, please do not use the Site or provide information to us.
In this Policy, “personal information” (used interchangeably with “personal data”) means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. It does not include publicly available information or information that has been de-identified or aggregated so that it can no longer reasonably be associated with you.
1. About Our Products and This Policy
Crux Labs USA manufactures and supplies research compounds and related products labeled For Research Use Only (“RUO”). Our products are not intended for human or veterinary diagnostic, therapeutic, or consumption use, and are sold only to laboratories, research institutions, and qualified professionals for non-clinical research purposes. This Policy governs the personal information we collect in connection with operating our business and Site — it does not itself constitute, and should not be read as, a statement about product use; please refer to our Terms of Sale and product labeling for those restrictions.
Scope. This Policy applies to personal information we collect through:
What this Policy does not cover. This Policy does not apply to:
If you are a business or institutional customer, you are responsible for ensuring that any individual whose personal information you provide to us (for example, a colleague listed as a shipping or billing contact) has been informed of, and where required has consented to, the processing described in this Policy.
2. Information We Collect
We collect personal information directly from you, automatically as you interact with the Site, and from third parties. The specific information we collect depends on how you interact with us and the type of order or product involved.
2.2 Information Collected Automatically
2.3 Information From Third Parties
2.4 Categories of Personal Information (Notice at Collection)
The following table summarizes the categories of personal information we may collect, consistent with the categories used under the California Consumer Privacy Act, as amended (the “CCPA”), and similar U.S. state laws. Not every category applies to every individual.
| Category |
Examples |
Typical Sources |
Primary Purposes |
Disclosed To (categories) |
| Identifiers |
Name, address, email, phone, IP address, account username |
You; automatically; partners |
Order fulfillment, account management, support, security |
Carriers; processors; IT/hosting; analytics; advisors |
| Customer records / commercial information |
Billing/shipping details, orders, quotes, purchase history, payment records |
You; payment processors |
Fulfillment, billing, support, recordkeeping |
Carriers; processors; advisors |
| Professional / institutional information |
Institution name, department, role, resale/tax or research-use documentation |
You; institutional sources |
Eligibility verification, RUO compliance, tax handling |
Advisors; compliance-screening services |
| Internet/network activity |
Site usage, cookie data, catalog/search queries, clickstream |
Automatically |
Site operation, analytics, marketing measurement |
Analytics; advertising partners; IT/hosting |
| Approximate geolocation |
City/state/country derived from IP or shipping |
Automatically; you |
Fraud prevention, routing, localization |
IT/hosting; carriers |
| Communications content |
Emails, chats, call logs, support tickets |
You |
Support, quality, recordkeeping |
IT/hosting; advisors |
| Inferences |
Product interests and preferences drawn from the above |
Derived |
Personalization, catalog improvement, marketing |
Analytics; advertising partners |
Sensitive personal information. We do not intend to collect, and ask that you not provide, sensitive categories of personal information about yourself — such as government identifier numbers (e.g., Social Security, driver’s-license, or passport numbers), financial-account log-in credentials, precise geolocation, biometric identifiers, or information about your health, race, religion, sexual orientation, or similar characteristics. If you provide such information in a message to us, you do so at your own initiative. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit its use under applicable law; if this changes, we will update this Policy and provide any required notice and controls. (Information about your organization’s research use of our products is business information, not sensitive personal information about you, and is addressed in Section 5.)
3. How We Use Your Information
We use personal information for the following purposes:
- Order and quote fulfillment — to process, fulfill, ship, invoice, and confirm orders; prepare and respond to quotes; and manage wholesale/bulk purchase requests, returns, and credits.
- Eligibility verification — to verify institutional, professional, or research-use eligibility where required for a given product or order, and to meet related RUO compliance obligations (see Section 5).
- Account creation and management — to create, authenticate, secure, and service your account and saved preferences.
- Customer support — to respond to technical, COA, documentation, complaint, and other support requests and to maintain records of those interactions.
- Transactional communications — to send order confirmations, shipping and delivery updates, invoices, recalls or product notices, and service or policy announcements.
- Marketing communications — to send catalog updates, promotions, and event invitations where you have opted in or as otherwise permitted by law, and to measure and improve those communications.
- Site, catalog, and service improvement — to operate, maintain, analyze, personalize, and improve the Site, catalog, and services, including through aggregated and de-identified analytics.
- Fraud prevention, safety, and security — to detect, investigate, and prevent fraud, misuse of our products, security incidents, and unauthorized or unlawful transactions, and to screen against sanctions/denied-party and export-control requirements.
- Legal and regulatory compliance — to comply with legal, tax, accounting, customs/export, and RUO-related recordkeeping obligations, respond to lawful requests, and establish, exercise, or defend legal claims, including enforcing our Terms of Sale.
- Other disclosed purposes — as otherwise described to you at the point of collection or with your consent.
We may de-identify or aggregate personal information and use it for any lawful business purpose. We do not use personal information for automated decision-making that produces legal or similarly significant effects about you without appropriate safeguards (see Section 11.5).
Legal bases (where applicable, e.g., for visitors in the UK/EEA). Where UK or EU data-protection law applies, we rely on one or more of the following legal bases, depending on the processing:
4. Payment Information
All payment card transactions are processed through secure, third-party payment processors that maintain compliance with the Payment Card Industry Data Security Standard (“PCI DSS”). Crux Labs USA does not store full credit card numbers, CVV/CVC codes, or other complete payment card data on our own servers. When you enter payment details, they are transmitted directly to, and handled by, our payment providers under their own applicable privacy and security practices. We receive from our processors only limited information, such as confirmation of authorization or decline, a transaction reference, and, for our records, billing name and address and a truncated card identifier (for example, the last four digits and card type). For customers approved for invoicing or credit terms, we retain the billing and accounts-receivable records reasonably necessary to administer those terms and meet our accounting and tax obligations.
5. Institutional and Researcher Verification
Because our products are sold strictly for research use, we may ask you to provide information confirming your affiliation with a laboratory, research institution, or other qualified organization, or to attest to your intended research use, before completing certain orders or opening certain accounts.
What we may request. Depending on the product and order type, verification information may include your institution or business name and address, department or laboratory, professional title or role, a business or institutional email domain, an account application or purchase order, a resale or tax-exemption certificate, and/or a signed research-use attestation.
How we use it. We use this information solely to (a) confirm eligibility to purchase RUO products, (b) support our RUO and related legal-compliance obligations, (c) administer tax-exempt or resale treatment where applicable, and (d) prevent misuse of our products. We may cross-check the information against compliance-screening resources (such as sanctions and denied-party lists) and retain records of verification as part of our compliance recordkeeping.
Safeguards. Verification records are handled with the protections described throughout this Policy, are accessible only to personnel who need them for order processing and compliance, and are retained for the period required by applicable law or our compliance practices (see Section 8). We do not use this information to make claims about, or to verify, any individual’s health status, medical condition, or personal use of our products.
6. Cookies and Tracking Technologies
We and our service providers and partners use cookies, pixels, tags, software development kits, local storage, and similar technologies (“cookies”) to operate the Site and understand and improve how it is used.
6.1 Types of Cookies We Use
| Category |
Purpose |
Examples |
| Strictly necessary |
Enable core functions such as security, network management, cart, and log-in; cannot be switched off in our systems |
Session, authentication, and load-balancing cookies |
| Performance / analytics |
Help us understand traffic, usage, and errors so we can improve the Site |
First- and third-party analytics cookies |
| Functional |
Remember your preferences, region, and prior selections |
Preference and language cookies |
| Targeting / advertising |
Deliver and measure business-to-business marketing and advertising, and limit ad repetition |
Advertising-network and conversion cookies |
6.2 Analytics and Advertising
We use analytics providers to measure Site performance and business-to-business advertising partners to promote our catalog and technical resources and to measure campaign performance. These partners may set their own cookies and combine Site data with other information they hold, subject to their own privacy policies.
6.3 Your Controls
6.4 SMS/Text Messaging (if offered)
If we offer and you opt into SMS/text communications, we will send messages only to the number you provide and only for the categories you selected (for example, order updates or marketing). Message and data rates may apply, and message frequency varies. You can opt out at any time by replying STOP to any message (or as otherwise described at sign-up), and you can reply HELP for assistance. We do not share SMS opt-in data or phone numbers with third parties for their own marketing.
7. Sharing Your Information
We do not sell or rent your personal information to third parties for money. We also do not “share” your personal information for cross-context behavioral advertising in a manner requiring opt-out under applicable law except through the advertising cookies described in Section 6, which you can control as described there. We may disclose personal information as follows:
Categories disclosed for a business purpose. In the preceding 12 months, we may have disclosed each category of personal information listed in Section 2.4 to the categories of recipients identified above for the business purposes described in this Policy.
Safeguards on recipients. Service providers and other recipients are engaged under contracts that require them to protect personal information, to use it only to perform services for us or as permitted by law, and — for those that qualify as “service providers” or “processors” under applicable law — that prohibit them from selling it or using it for their own independent purposes. We may share aggregated or de-identified information that cannot reasonably be used to identify you without restriction, and we will maintain and use such information only in de-identified form except as permitted by law.
8. Data Retention
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy — including operating the Site, fulfilling orders, administering accounts, complying with legal, tax, accounting, customs/export, and RUO-related recordkeeping obligations, resolving disputes, and preventing fraud or misuse. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the information, the purposes for which we process it, applicable legal and contractual requirements, and the potential risk of harm from unauthorized use or disclosure.
Illustrative retention practices (actual periods may vary and will be finalized by Crux Labs USA):
| Information |
Illustrative retention |
| Order, invoice, and tax records |
Retained for the period required by applicable tax, accounting, and commercial law (commonly several years) |
| Eligibility / research-use verification records |
Retained for the period required by applicable law and our RUO compliance practices |
| Account information |
Retained while your account is active and for a reasonable period afterward |
| Support and communications records |
Retained for a reasonable period for quality, dispute-resolution, and recordkeeping purposes |
| Marketing preferences |
Retained until you opt out or request deletion, plus a suppression record to honor your opt-out |
| Cookie and analytics data |
Retained for the period stated in our cookie tool or the relevant provider’s settings |
At the end of the applicable retention period, information is deleted, destroyed, anonymized, or de-identified. We may retain de-identified or aggregated information indefinitely.
9. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, loss, or destruction. These measures include:
Your role. You are responsible for keeping any account credentials confidential and for using a secure device and network. Please notify us promptly (using the contact details in Section 14) if you believe your account or information has been compromised.
Incident response. We maintain procedures for responding to suspected security incidents and will notify affected individuals and regulators of a personal-data breach where and as required by applicable law. No method of transmission over the internet or method of electronic storage is completely secure, and while we strive to protect your information, we cannot guarantee absolute security.
10. Children’s Privacy
Our Site and products are intended for use by laboratories, institutions, and qualified professional researchers, and are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children, and we do not offer products or services for purchase by children. If we learn that we have collected personal information from a child under 18 without verified parental consent, we will take reasonable steps to delete that information. If you believe a child has provided us personal information, please contact us using the details in Section 14.
11. Your Privacy Rights
Depending on where you live and the law that applies to you, you may have some or all of the rights described below. These rights are subject to verification and to exceptions permitted by law, including recordkeeping we are required to maintain in connection with RUO sales and our tax, accounting, and compliance obligations.
11.1 Rights Available Under U.S. State Privacy Laws
Residents of California and of other U.S. states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others) may have the right to:
California-specific disclosures. California residents may request the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties and recipients. California’s Shine the Light law also lets California residents request information about disclosures of certain personal information to third parties for those parties’ direct-marketing purposes; we do not disclose personal information to third parties for their own direct marketing.
11.2 How to Exercise Your Rights
To exercise any of these rights, contact us using the information in Section 14, or use any request mechanism we make available on the Site (such as a “Do Not Sell or Share My Personal Information” or privacy-request link, where provided). We will acknowledge and respond within the timeframes required by applicable law (for many U.S. state laws, generally within 45 days, extendable as permitted).
11.3 Verification and Authorized Agents
To protect your information, we may need to verify your identity before completing your request, which may require confirming information we already hold about you. You may designate an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization and may still verify your identity directly.
11.4 Appeals
If we decline to act on your request and you are in a state (or jurisdiction) that provides an appeal right, you may appeal our decision by contacting us using the details in Section 14 and describing the decision you are appealing. We will respond to your appeal within the period required by applicable law and explain the reasons for our decision. Where your appeal is denied, applicable law may allow you to contact your state attorney general or other regulator.
11.5 Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing without a legal basis and, where required, appropriate safeguards such as human review. Where applicable law grants rights regarding profiling or automated decision-making, you may exercise them as described in this Section.
11.6 Rights in the UK/EEA and Other Jurisdictions
If UK or EU data-protection law applies to you, you may have the right to request access to, correction of, or deletion of your personal data; to restrict or object to processing (including direct marketing); to data portability; and, where processing is based on consent, to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority. We will not require you to provide personal data except where necessary to enter into or perform a contract or to comply with law; where data is necessary and you do not provide it, we may be unable to fulfill an order or provide a service.
11.7 Marketing Opt-Out
You can opt out of marketing emails at any time by clicking “unsubscribe” in any marketing message or by contacting us. You may still receive transactional or service messages (such as order and shipping confirmations). For SMS/text, reply STOP as described in Section 6.4.
11.8 Global Privacy Control
Where we detect a GPC signal, we make reasonable efforts to honor it as an opt-out request for the associated browser or device as required by applicable law.
12. International Data Transfers
We are based in the United States, and personal information we collect may be processed and stored in the United States or in other countries where we or our service providers operate. These countries may have data-protection laws that differ from, and may not provide the same level of protection as, the laws of your country of residence.
Where we transfer personal data originating in the UK or EEA to a country that has not received an “adequacy” decision, we implement appropriate safeguards required by applicable law, which may include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and supplementary technical and organizational measures. You may request more information about these safeguards, or a copy of the relevant transfer mechanism, using the contact details in Section 14.
13. Third-Party Websites
Our Site may contain links to third-party websites not operated by us, including technical resources, publications, supplier sites, and social-media pages. Crux Labs USA is not responsible for the privacy practices, security, or content of external websites, and the inclusion of a link does not imply our endorsement. This Policy applies only to information collected by us through the Site and our operations. We encourage you to review the privacy policies of any third-party sites you visit before providing them information.
14. Contact Information
If you have questions about this Policy, wish to exercise a privacy right, or have a concern about how your information is handled, please contact us:
Crux Labs USA
We will respond to your inquiry or request within the timeframe required by applicable law.
15. Changes to This Privacy Policy
We may update this Policy periodically to reflect changes in our practices, technology, products, or legal requirements. When we do, we will post the updated Policy on this page with a revised “Last Updated” date. Where required by law, we will provide additional notice of material changes (such as an email or a prominent Site notice) and, where required, obtain your consent. Changes are effective when posted unless stated otherwise or unless a later effective date is required by law. Your continued use of the Site after an updated Policy is posted constitutes acceptance of the updated Policy to the extent permitted by applicable law. We encourage you to review this Policy periodically.