Privacy Policy.
Last updated 24 August 2026
The short version.
We take what an order requires and nothing else. There are no advertising pixels and no third-party trackers on this site — nothing here reports to Google, Meta or an ad network. Visits are counted on our own server, with no cookie and nothing written to your device. The only cookies we set keep you signed in and remember your language. Nothing is sold or rented to anyone.
Who is responsible.
The controller for everything described here is YOUNGLAB, shipping from inside the European Union. Anything on this page: write to [email protected].
What we take, and why.
- To fulfil an order — name, email, phone, delivery address and any note you add, plus the vials, prices and payment method. Without them nothing can be shipped or confirmed. Legal basis: performance of the contract.
- If you open an account — email, name and a hashed password (we never see the password itself), so you can sign in and read your order history.
- Payment — for a bank transfer, whatever your bank shows on it; for crypto, the invoice, the address, the amount and the transaction hash. Card details are never seen or stored, because we do not take cards.
- Server logs — the ordinary request records our server and Cloudflare keep, IP addresses included, used to keep the site up and block abuse. Legal basis: legitimate interest in a working, non-abused shop.
Cookies.
One functional cookie set at sign-in so the next page knows it is still you, and one remembering the language you picked. It ends when you sign out or the session expires. There is nothing to consent to because there is nothing else — no advertising or profiling cookies, and the visit counting below needs no cookie at all.
How we count visits.
We keep our own basic statistics — which pages are read and for how long, which link led here, roughly which country, phone or laptop. A shop that cannot see what visitors are looking for cannot improve at answering them. All of it runs on the same server as the shop: nothing reaches Google Analytics or any other company, and none of it leaves the European Union.
No cookie is set and nothing is written to your device, so there is nothing to consent to and nothing to clear. To separate one visit from another we store a one-way hash of your IP and browser mixed with a secret that rotates every midnight — it cannot be reversed into your address, and the same visitor yields a different value tomorrow, so the records cannot follow anyone across days. They delete automatically after 180 days. Legal basis: legitimate interest in a working shop, using the least identifying method we could build.
Who else touches it.
- Contabo GmbH — provides the server the shop and its database run on, located in France, within the EU.
- Cloudflare — sits in front of the site for security and speed, so requests travel through it.
- Resend — sends the order and account emails, so it processes your address and their contents.
- The carrier — receives the name and address on the parcel, and nothing about the contents beyond what the label legally requires.
Cloudflare and Resend are US companies, so some data reaches the United States under the standard contractual clauses in their data-processing terms. There are no other processors, and nothing goes to advertisers or data brokers.
How long it is kept.
Orders and invoices stay as long as accounting law requires. Account data stays until you ask for deletion. Server logs rotate away within weeks.
Your rights.
Under the GDPR you can request a copy of your data, have it corrected or deleted, restrict or object to its use, and receive it in portable form. Write to [email protected] and you have an answer within one month. If you believe we have handled it badly, you can complain to the data protection authority in your country.
One limit, plainly: deleting an account does not remove an order we are legally required to keep on file.