Last Updated: August 21, 2026
Direct Research Supply (“DRS,” “we,” “us,” or “our”) respects the privacy of visitors and customers who use our website and services. This Privacy Policy explains how we collect, use, store, disclose, and otherwise process personal information in connection with the Direct Research Supply website (the “Site”), customer accounts, orders, payments, communications, and related services.
By accessing or using the Site, you acknowledge the practices described in this Privacy Policy.
This Privacy Policy should be read together with our Terms & Conditions and any other policies applicable to your use of the Site.
1. Information We Collect
The information we collect depends on how you interact with DRS and the Site.
Information You Provide
We may collect information you voluntarily provide, including:
- Name
- Email address
- Billing address
- Shipping address
- Telephone number, if provided
- Account username and account information
- Order and transaction information
- Products ordered and quantities
- Information submitted during checkout
- Communications sent to DRS
- Customer service inquiries
- Information submitted through contact forms
- Information provided in connection with an order, cancellation, refund, dispute, or other request
- Research eligibility or intended-use information when requested
- Age, Research Use Only, Terms & Conditions, or other acknowledgments made through the Site
Information you provide may be associated with your customer account, orders, and communications with DRS.
Information Collected Automatically
When you access or interact with the Site, certain technical information may be collected automatically by our website, hosting infrastructure, security systems, plugins, cookies, and related technologies.
This may include:
- Internet Protocol (IP) address
- Browser type and version
- Device type
- Operating system
- Approximate location derived from an IP address
- Referring URL
- Pages requested or visited
- Date and time of requests
- Login and authentication activity
- Cookie and session identifiers
- Cart and checkout activity
- Security-related events
- Server and application logs
- Information regarding errors, failed requests, or suspected malicious activity
We may use this information to operate, secure, troubleshoot, maintain, and improve the Site.
2. Customer Accounts
DRS uses WordPress and WooCommerce to provide website, ecommerce, and customer-account functionality.
When you create or use an account, information associated with that account may include your:
- Name
- Email address
- Username
- Billing information
- Shipping information
- Order history
- Account preferences
- Related account activity
Passwords are handled through the authentication mechanisms provided by our website platform. DRS does not have access to customer passwords in plain-text form.
You are responsible for maintaining the confidentiality of your account credentials and for activity occurring through your account. You should contact DRS promptly if you believe your account has been accessed without authorization.
3. Orders and Checkout
When you place or attempt to place an order, we may collect and retain information reasonably necessary to process, review, fulfill, document, and administer the transaction.
This may include:
- Name
- Email address
- Billing information
- Shipping information
- Products and quantities ordered
- Order value
- Payment method
- Payment status
- Transaction reference information
- Shipment and tracking information
- Checkout acknowledgments
- Communications relating to the order
WooCommerce may store customer, account, billing, shipping, checkout, and order information within our WordPress database and related server infrastructure.
We may retain transaction records when reasonably necessary for fulfillment, accounting, fraud prevention, dispute resolution, security, policy enforcement, legal compliance, or other legitimate business purposes.
4. Age and Research-Use Acknowledgments
DRS products are offered exclusively for legitimate laboratory and research purposes and are restricted to customers who satisfy our applicable age and research-use requirements.
Visitors may be required to acknowledge that they are at least 18 years of age and understand the Research Use Only restrictions before accessing or continuing to use portions of the Site.
We may use cookies or similar technologies to remember that a visitor has completed the Site’s age and Research Use Only acknowledgment.
Customers will also be required to make appropriate acknowledgments during checkout, including confirmation that they are at least 18 years of age and agreement to applicable Terms & Conditions and Research Use Only requirements.
We may retain records indicating that these acknowledgments were made, together with information reasonably associated with the transaction, such as the order, account, date, time, or other relevant transaction information.
Age Affirmation Versus Identity Verification
Our current age acknowledgment process relies on information and representations made by the customer. Unless expressly stated otherwise during the verification process, it does not constitute independent verification of a customer’s identity or age through government-issued identification or a third-party identity-verification service.
Providing false information or falsely affirming eligibility may violate our Terms & Conditions and may result in refusal or cancellation of an order, restriction of purchasing privileges, or suspension or termination of an account.
DRS may introduce additional age, identity, fraud-prevention, research-eligibility, or account-verification procedures in the future.
If we introduce a system that materially changes the personal information we collect or causes additional information to be processed by a third-party verification provider, we will update our privacy disclosures as appropriate.
5. Payments
DRS may offer cryptocurrency and other payment methods.
Cryptocurrency Payments
DRS currently uses a self-hosted PayRam implementation for supported cryptocurrency payments.
When cryptocurrency payment functionality is used, we may process or retain information associated with the transaction, including:
- Order or transaction reference
- Payment amount
- Cryptocurrency selected
- Blockchain network
- Payment address
- Blockchain transaction identifier
- Payment status
- Transaction timestamps
- Other information reasonably necessary to associate and reconcile a payment with an order
Cryptocurrency transactions may involve information permanently recorded on public or distributed blockchain networks. Information recorded on a public blockchain may be publicly accessible and may be outside DRS’s ability to alter or delete.
DRS does not request customers’ cryptocurrency private keys or seed phrases.
Future Payment Methods
DRS may introduce additional payment methods in the future, including credit cards, debit cards, or other third-party payment services.
When a third-party payment provider is used, information necessary to process a transaction may be provided directly to or processed by that provider according to its own privacy practices and contractual relationship with DRS.
We may update this Privacy Policy when materially different payment-processing systems are introduced.
6. Shipping and Fulfillment
DRS uses separate fulfillment processes for domestic and international orders.
Orders delivered to U.S. addresses are fulfilled through our U.S. fulfillment location. Orders delivered outside the United States are fulfilled through our international fulfillment location.
We may provide information reasonably necessary to fulfill and deliver an order to fulfillment facilities, shipping carriers, postal services, logistics providers, customs authorities, or other parties involved in delivery.
Such information may include:
- Recipient name
- Shipping address
- Contact information when required for delivery
- Order or shipment reference information
- Information required for customs processing
- Other information reasonably necessary to prepare, route, track, or deliver a shipment
International fulfillment may require information to be transmitted to or processed in countries other than the country where the customer resides.
7. Website Hosting and Infrastructure
DRS uses cloud server infrastructure provided by Vultr.
Our website, databases, server logs, applications, backups, and related information may therefore be stored or processed using infrastructure provided by Vultr or associated data-center infrastructure.
Cloud infrastructure providers may process or have technical access to information as reasonably necessary to provide, maintain, secure, troubleshoot, or support their services.
8. WordPress and WooCommerce
The Site is built using WordPress and WooCommerce.
These systems process information necessary to provide website functionality, customer accounts, authentication, shopping carts, checkout, order management, and related ecommerce functionality.
Some WordPress and WooCommerce functionality operates within our own server environment. The use of these platforms does not necessarily mean that all customer information is automatically transmitted to WordPress.org, WooCommerce.com, Automattic, or another external party.
Additional extensions, integrations, or services associated with these platforms may process information when necessary to provide their functionality.
9. Cookies and Similar Technologies
The Site uses cookies and similar technologies.
Cookies may be used for purposes including:
- Account authentication
- Maintaining login sessions
- Shopping-cart functionality
- Checkout functionality
- Security
- Fraud prevention
- Remembering preferences
- Remembering age and Research Use Only acknowledgment
- Recording cookie-consent preferences
- Website functionality
- Performance
- Analytics, if enabled
Some cookies are necessary for the Site to function correctly. Disabling necessary cookies may interfere with account, login, shopping cart, checkout, security, age-gate, or other functionality.
10. Age-Gate Cookie
DRS currently uses an entrance notice that requires visitors to acknowledge applicable age and Research Use Only requirements.
A cookie may be placed on the visitor’s device after acknowledgment so that the notice does not need to be displayed repeatedly during the cookie’s validity period.
The presence of this cookie indicates that the acknowledgment was completed through that browser or device. It does not independently establish or verify the visitor’s identity or actual age.
Deleting cookies, using another browser or device, or using private-browsing functionality may cause the acknowledgment to appear again.
11. Cookie Consent
DRS uses SureCookie to assist with cookie detection and consent management.
Depending on our configuration and applicable requirements, the Site may allow visitors to accept, reject, or modify certain categories of non-essential cookies.
Consent information may include:
- Consent choices
- Cookie categories accepted or rejected
- Date and time of consent
- Technical information associated with the consent record
Where consent logging is enabled, consent records may be retained within our website infrastructure.
Necessary cookies may operate regardless of optional consent where they are reasonably required to provide functionality requested by the visitor or otherwise permitted by applicable law.
12. Popup and Site-Notice Functionality
DRS uses website software, including Popup Maker, to display notices and acknowledgment interfaces.
This functionality may use cookies or similar technologies to determine whether a notice has been displayed, dismissed, acknowledged, or should be displayed again.
Information generated by these systems may be stored within the visitor’s browser or our WordPress installation depending on the functionality being used.
13. Website Security
DRS uses administrative, technical, and organizational measures intended to protect our website, systems, accounts, and information.
These measures may include:
- HTTPS encryption
- Server access controls
- Authentication controls
- Firewalls
- Security monitoring
- Malware detection
- Login protection
- Logging
- Backups
- Fraud and abuse detection
DRS currently uses Wordfence as part of our WordPress security infrastructure.
Security systems may process information such as IP addresses, browser and device information, requested URLs, login attempts, request information, and other technical information to identify malicious activity, unauthorized access, fraud, abuse, or other security threats.
No internet-connected system, transmission method, or storage system can be guaranteed to be completely secure. DRS therefore cannot guarantee absolute security.
14. Communications and Contact Forms
When you contact DRS by email, website form, or another supported communication method, we may collect and retain information you provide.
This may include:
- Name
- Email address
- Message contents
- Order information
- Account information
- Attachments
- Related correspondence
Communications may be retained when reasonably necessary for customer service, dispute resolution, security, fraud prevention, policy enforcement, recordkeeping, or legal compliance.
15. How We Use Information
We may use personal information to:
- Operate and maintain the Site
- Create and administer customer accounts
- Authenticate users
- Process, review, and fulfill orders
- Process and reconcile payments
- Provide shipping and fulfillment
- Communicate with customers
- Provide customer support
- Record age, Terms, and Research Use Only acknowledgments
- Enforce age and research-use requirements
- Evaluate eligibility to purchase
- Prevent fraud, abuse, and unauthorized activity
- Detect and investigate security incidents
- Protect DRS, customers, and third parties
- Maintain transaction and business records
- Troubleshoot technical problems
- Maintain and improve website functionality
- Respond to disputes, claims, and chargebacks where applicable
- Comply with applicable legal obligations
- Establish, exercise, or defend legal claims
- Enforce our Terms & Conditions and other policies
We may also use information for additional purposes disclosed when it is collected or as otherwise permitted by applicable law.
16. How We Disclose Information
DRS does not sell customer information in exchange for money.
We may disclose personal information when reasonably necessary to service providers and other parties involved in operating our business, including:
- Hosting and infrastructure providers
- Fulfillment facilities
- Shipping and logistics providers
- Payment-processing systems
- Website and technical service providers
- Security and fraud-prevention providers
- Professional advisers such as attorneys or accountants
- Government authorities, regulators, courts, or law-enforcement authorities when required or permitted by law
We may also disclose information where reasonably necessary to investigate fraud or abuse, enforce our agreements, protect our rights, protect the security of our services, or protect DRS, our customers, or others.
If DRS undergoes a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be disclosed or transferred as part of that transaction where permitted by law.
17. We Do Not Sell Customer Lists
DRS does not sell customer lists, account information, shipping information, order histories, or customer communications to data brokers or unrelated third parties for their independent marketing purposes.
If our practices materially change, we will update this Privacy Policy and provide any additional notices required by applicable law.
18. Data Retention
We retain personal information for as long as reasonably necessary for the purposes for which it was collected and for legitimate operational, accounting, security, fraud-prevention, dispute-resolution, legal, regulatory, and recordkeeping purposes.
Different categories of information may be retained for different periods.
Closing or deleting a customer account does not necessarily result in deletion of every record associated with that customer. We may retain order, transaction, shipping, payment, acknowledgment, fraud-prevention, security, accounting, tax, legal, or related records where retention is reasonably necessary or legally required.
Information recorded on public blockchain networks may be permanent and outside DRS’s ability to modify or delete.
We may delete, anonymize, or aggregate information when it is no longer reasonably necessary to retain it.
19. Privacy Rights
Depending on your location and applicable law, you may have certain rights concerning personal information about you.
These may include rights to:
- Request information about personal information we maintain
- Request access to certain personal information
- Request correction of inaccurate information
- Request deletion of eligible personal information
- Obtain a portable copy of certain information
- Withdraw certain consent previously provided
- Object to or restrict certain processing where applicable
- Opt out of certain uses or disclosures where applicable
- Appeal certain decisions concerning a privacy request where applicable
These rights are subject to applicable exceptions and limitations.
For example, DRS may be permitted or required to retain information necessary to complete transactions, maintain business records, detect fraud, protect security, comply with legal obligations, enforce agreements, or establish or defend legal claims.
We may take reasonable steps to verify the identity and authority of anyone submitting a privacy request before fulfilling the request.
DRS will not unlawfully discriminate against a customer for exercising applicable privacy rights.
20. Children and Minors
The Site and DRS products are not directed to children or minors.
Customers must be at least 18 years old to purchase products from DRS.
We do not knowingly solicit orders from individuals under 18.
If we become aware that information has been provided by a minor in circumstances where it should not have been collected, we may delete or restrict that information as appropriate, subject to applicable legal, security, transaction, and recordkeeping obligations.
21. International Users and Data Transfers
DRS operates from the United States and uses infrastructure, fulfillment services, carriers, and other service providers that may operate in multiple jurisdictions.
If you access the Site or place an order from outside the United States, your information may be transferred to, processed in, or stored in the United States or other countries.
Privacy and data-protection laws in those jurisdictions may differ from those applicable in your country of residence.
Where required by applicable law, DRS will use appropriate measures concerning international transfers of personal information.
22. Third-Party Services and Websites
The Site may interact with or contain links to services operated by third parties, including payment services, shipping providers, blockchain networks or explorers, and other external resources.
DRS does not control the independent privacy practices of third parties.
Information you provide directly to another organization or service may be governed by that organization’s own privacy policy and terms.
Customers should review the privacy practices of third-party services before providing personal information directly to them.
23. Legal Requests and Required Disclosures
DRS may preserve, access, or disclose information when we reasonably believe doing so is required or permitted by applicable law, regulation, subpoena, court order, legal process, or other lawful governmental request.
We may also preserve or disclose information when reasonably necessary to:
- Protect our legal rights
- Investigate suspected fraud or abuse
- Enforce our Terms & Conditions or other policies
- Protect the security of our Site or systems
- Respond to disputes or claims
- Prevent harm
- Protect DRS, our customers, or others
Nothing in this Privacy Policy is intended to restrict obligations or rights arising under applicable law.
24. Changes to This Privacy Policy
We may modify this Privacy Policy periodically to reflect changes in:
- Our business practices
- Website functionality
- Technology
- Service providers
- Payment methods
- Age or identity-verification procedures
- Security practices
- Applicable legal requirements
The revised Privacy Policy will be posted on this page with an updated Last Updated date.
Where required by applicable law, we may provide additional notice or obtain consent before materially different processing begins.
Continued use of the Site following an update does not waive any rights that cannot legally be waived.
25. Contact and Privacy Requests
Questions, concerns, or requests regarding this Privacy Policy or personal information may be directed to:
Direct Research Supply
Email: hello@directresearchsupply.com
Please provide sufficient information for us to understand and respond to your request.
For requests involving access, correction, deletion, or other privacy rights, DRS may request additional information reasonably necessary to verify your identity, confirm your authority to make the request, locate the relevant information, and protect customer information from unauthorized disclosure.

