Last Updated: July 15, 2026
TL;DR — not legally binding. This summary helps you skim; it is not part of this Policy and does not modify it. Read the full Policy before relying on anything here. In short:
- We collect what we need to run the Service (IPs, basic device info, your Discord/email for accounts, what you configure in your dashboard).
- Visitors in the EEA, UK, and other strict-consent regions get an opt-in cookie banner; visitors elsewhere get an equally accessible decline option.
- We do not currently sell platform analytics data, nor share it for cross-context behavioral advertising.
- Advertising on bio sites, where enabled, is contextual — we do not build cross-site visitor profiles.
- You can request deletion of your data through our legal & data request form. We act on verified requests promptly, but some records — financial and tax records, and certain fraud- and security-prevention signals — may be retained where the law allows or requires (see §9 and §11).
If anything in this summary conflicts with the full Policy below, the full Policy governs.
1. Introduction
This Privacy Policy ("Policy") describes how netherbio("we," "us," or "our") collects, uses, discloses, and protects information in connection with the netherbio platform (the "Service"), including bio sites hosted at *.netherbio.com, any custom domains pointed at the platform, the admin dashboard, the Listing Bot, and all related APIs and tools.
This Policy supplements and is incorporated into our Terms of Service. Capitalized terms used but not defined here have the meanings given in the Terms.
By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, do not use the Service.
2. Scope
This Policy applies to:
- Visitors who browse a bio site hosted on the platform (including bio sites served from custom domains).
- Site Owners who create and manage a bio site.
- Users of the Listing Bot and related premium features.
- Anyone interacting with the platform via the admin dashboard, APIs, or support channels.
Site Owners may collect additional information through features they configure on their own bio sites (chat widget, ticket forms, etc.). Site Owners are independent controllers of that data on their own pages and are responsible for any additional disclosures required in their jurisdiction or on their custom domain (see Terms §8.4(b)).
3. Information We Collect
3.1 From Visitors to Bio Sites
When you visit a netherbio bio site, we may collect:
- IP address and approximate geolocation (country, region, city) derived from it via ip-api.com.
- Device and browser information: user agent string, screen resolution, language preference, timezone.
- Session and visitor identifiers stored in your browser's localStorage / sessionStorage for the purpose of deduplicating page views and maintaining session continuity.
- Pages viewed and referrer URL for analytics measurement.
- Links and buttons clicked on a bio site (which link was clicked and when), used to provide Site Owners with aggregate click statistics about their own site.
- Consent choices recorded in your browser (per origin) when you interact with the cookie banner.
- Chat fingerprint data (only if you use a tenant's chat widget) including browser, OS, device, hardware, locale, screen properties, WebGL renderer, canvas fingerprint, audio context data, and installed fonts. This is used to maintain chat session continuity and prevent abuse.
3.2 From Site Owners
When you create or manage a bio site, we collect:
- Email address (and verification code interactions) if you sign up via email.
- Discord account information (Discord ID, username, global name, avatar, email if granted) if you sign up via Discord OAuth.
- Self-declared date of birth at account creation, used solely to determine eligibility for features such as ad-revenue payouts. See Terms §3.
- Hashed admin credentials and (optionally) TOTP 2FA secrets.
- Site configuration, content, and uploaded files (avatars, backgrounds, music files, ticket attachments, etc.) you submit through the admin dashboard.
- Activity logs of administrative actions taken on your site.
- Payout details (your cryptocurrency wallet address) if you opt into the revenue-share program. Stored encrypted at rest and never displayed back to you in the clear once saved.
3.3 From Listing Bot Users
If you use the Listing Bot, we may collect:
- Discord IDs of users participating in tickets and listings.
- Message content, attachments, and transcripts within ticket channels. Attachments captured for transcripts are copied to our own storage at the time they are posted so that saved transcripts remain intact after Discord's hosted links expire.
- Subscription/license-key status and payment history (processed by SellAuth; we receive confirmation, not card data).
3.4 From Shop Customers
If you create a customer account on a Site Owner's shop (a Commerce Suite feature), we collect on behalf of that Site Owner:
- Account credentials — email address and a salted password hash (we never store shop-customer passwords in plaintext), or your Discord identity if you sign in with Discord.
- Order history — invoices, purchases, deliveries, and refund/replacement records for that shop.
- Store credit ledger — an append-only record of wallet top-ups and spends for that shop.
- IP address and technical data used for fraud prevention, rate limiting, and account security (e.g., login lockouts).
Shop customer accounts are isolated per shop: one Site Owner cannot see your account or history on another Site Owner's shop. For data collected in connection with a specific shop, the Site Owner acts as an independent controller of their customer relationships, and netherbio processes this data to provide the platform. You may request deletion of a shop customer account through that shop or via the contact in §16; deletion purges your credentials, and financial records may be retained as described in §9.
3.5 Discord Security and Fraud-Prevention Index
As part of our security, fraud, and abuse-prevention program, we maintain a security index of Discord accounts that we source from VaultCord, a third-party Discord verification service. Individuals are added when they verify through our Discord authorization (“OAuth”) flow — which discloses the access requested and links to these Terms — in Discord servers we operate; verification is optional. For each account the data may include Discord profile information, an associated email address, IP address and approximate location, device and network indicators, and connections between accounts. We use it only to detect and investigate fraud, coordinated abuse, ban evasion, and fake or duplicate accounts, and to protect the Service — never for advertising or marketing.
We process this data on the basis of our legitimate interests in security, fraud prevention, and abuse investigation (see §5), supported by the verification authorization described above. It is essential security processing and is not gated by the cookie consent banner (see §6.4). We keep it for as long as necessary for those purposes. VaultCord is listed as a sub-processor in §7; you may object to this processing or request erasure of your records as described in §11, subject to the security and fraud-prevention carve-out.
Separately, and optionally: a Site Owner may connect their own VaultCord account to their dashboard in order to back up and restore their Discord servers and to bring their verified members into a rebuilt server. Where a Site Owner does this, we store the API key and Discord application credentials they supply, encrypted at rest, and a cached copy of metadata and aggregate counts only— server names and IDs, backup dates, schedules, plan tier, and the totals reported for a recovery. We do notreceive, store, or display the member records held in that Site Owner's VaultCord account, including the email addresses and IP addresses VaultCord collects from people who verify: the endpoints that would return them are blocked in our integration. That data remains under the Site Owner's own relationship with VaultCord, in which they act as controller and we act for them only as described in §7.
3.6 Authenticated Discord Users: Identity and Login-Security Index
To keep accounts working and protect the platform from fraud and abuse, whenever anyone authenticates through Discord — to manage a bio site, sign in to a shop, leave a review, or use any other feature that relies on Discord sign-in — we keep a sign-in and security record tied to that Discord account. We use it to keep accounts working, detect fraud and multi-account abuse, and protect the platform. It may include:
- Discord profile data — Discord ID, username, global/display name, discriminator, avatar history, email address (if you granted it), and a log of changes to these over time.
- Every IP address we have observed the account authenticate from (we retain the complete set, not only the most recent), together with the user-agent string and the browser, operating system, and device type derived from it.
- Precise geolocation and network data derived from each login IP via ip-api.com — country, region, city, postal/ZIP code, approximate latitude and longitude, timezone, and the internet service provider, organization, and network (ASN).
- A sign-in history recording each authentication event with the details above. We keep this for as long as necessary for security and abuse-prevention purposes; older entries beyond what we keep in our primary store are moved to archive storage rather than deleted (see §9).
We rely on our legitimate interest in security, fraud detection, and abuse prevention for this processing (see §5). It is part of our essential, security-related processing and is not gated by the cookie consent banner (see §6.1 and §6.4). You may request erasure of this record as described in §11, subject to the fraud- and security-prevention carve-out in §9 and §11.
4. How We Use Information
We use information for the following purposes:
- Operating and improving the Service — rendering bio sites, authenticating users, serving content, debugging, capacity planning.
- Analytics — measuring traffic, page views, and aggregate visitor characteristics to provide Site Owners with usage statistics about their own sites.
- Advertising and revenue share — serving and measuring contextual advertising on bio sites where enabled, counting impressions and clicks, attributing revenue to Site Owners per Terms §8.4, detecting advertising fraud and invalid traffic.
- Security and abuse prevention — rate-limiting, detecting brute-force or scraping behavior, investigating suspected violations of the Terms.
- Communications — sending verification codes, account notifications, security alerts, and (rarely) product updates to Site Owners. We do not send marketing email to visitors.
- Legal compliance — responding to lawful requests, enforcing the Terms, defending claims.
5. Legal Bases for Processing (EEA / UK Visitors)
If you are located in the European Economic Area or the United Kingdom, our processing of your personal data relies on one of the following legal bases:
- Consent — non-essential analytics, advertising measurement, and any future advertising-related tracking. You provide consent via the cookie banner and may withdraw it at any time by clicking "Decline" on the banner or by clearing your browser's localStorage for the site you are visiting.
- Contract — processing necessary to provide the Service to Site Owners under our Terms (account creation, hosting their site, billing, etc.).
- Legitimate interests — essential security measures (rate-limiting, fraud detection, bot and abuse prevention), basic operation of the Service (session continuity, error logging), and limited contextual non-tracking analytics that do not rely on personal identifiers. Our legitimate interests expressly include building and retaining a security and fraud-prevention record of IP addresses, precise geolocation derived from those IP addresses, device and browser fingerprint data, and login history for authenticated Discord users (see §3.6), and maintaining the Discord security and fraud-prevention index derived from VaultCord (see §3.5) — in each case to detect and investigate fraud, bots, ban evasion, multi-account abuse, and other security threats. We have assessed that these interests do not override your fundamental rights, and you may object as described in §11.
- Legal obligation — responding to lawful requests from authorities, retaining records where required by law.
6. Cookies, Local Storage, and Tracking Technologies
6.1 Essential
These are necessary for the Service to function and are not gated by the cookie banner:
admin_session— authenticates admin dashboard sessions.platform_session— maintains platform user sessions (signed, contains session data).super_admin_session— authenticates super-admin sessions.discord_oauth_state/platform_oauth_state— prevents cross-site request forgery during OAuth flows.nb_consent_v1(in localStorage) — stores your cookie consent choice, per origin._track_session/_track_visitor/_tracked_pages(in localStorage / sessionStorage) — deduplicate page-view counting; created only after consent in strict-consent regions.
Separately from cookies and non-essential tracking, certain processing that we carry out on the basis of legitimate interest for security, fraud, and abuse prevention is not gated by the cookie consent banner and does not depend on your consent choice. This includes device and browser fingerprint fraud checks, the IP blocklist and repeat-offender index (§6.3), the authenticated-user identity and login-security index (§3.6), and the Discord security and fraud-prevention index derived from VaultCord (§3.5). These functions are essential to protecting the Service, Site Owners, and visitors, and they operate whether or not you accept non-essential cookies. Declining the banner suppresses non-essential analytics and advertising measurement only; it does not disable security processing.
6.2 Analytics
Gated by the cookie banner. Used to measure aggregate site usage and provide statistics to Site Owners:
- Google Analytics (
_ga,_gid, and related cookies set by gtag.js). Loaded only after consent in strict-consent regions, and not loaded at all if you declined. Cookie scope is pinned to the host you are viewing, so analytics identifiers do not propagate across tenant subdomains or custom domains.
6.3 Advertising
Where a Site Owner has opted into advertising on their bio site, we may display first-party sponsorship creatives served directly by netherbio. These sponsorships render as static images linked through a netherbio redirect endpoint; they do not load third-party scripts, set cookies on your device, or build cross-site behavioral profiles.
Impression and click counts associated with sponsorships are aggregated server-side on a per-domain basis and used only for advertiser reporting and Site Owner revenue attribution. To detect invalid traffic such as duplicate or fraudulent impressions, the impression path also derives a short-lived, pseudonymous correlation hash — a daily-rotating salted SHA-256 of your IP address and user-agent. Because the salt rotates every day, the hash is bounded in time, cannot be reversed to your IP address, and is not linked across days; it is used solely for fraud and abuse detection, is not a persistent identifier, and is not shared with advertisers or Site Owners. We do not currently serve third-party ad-network creatives.
We additionally maintain aggregate fraud-detection counters per bio site — for example, counts of bot user-agent hits, duplicate-impression suppressions, invalid-Referer rejections, and honeypot triggers. These counters are aggregate totals and do not themselves store your IP address or a device fingerprint. Together they exist solely to detect invalid traffic and protect Site Owner revenue attribution and advertiser delivery quality.
To block IP addresses engaged in fraud or abuse, we also maintain an IP blocklist and a repeat-offender index. For an individual address these store a stable, keyed one-way hash(HMAC-SHA256) — never the raw IP. An administrator may also block a network range (CIDR), in which case we store the operator-chosen network and prefix (e.g. “203.0.113.0/24”) — a range, not an individual address — so the block can be displayed and managed. Unlike the daily-rotating correlation hash described above, the block hash is deliberately stable over time so that a blocked or repeatedly-abusive address can be recognized across days; that is its purpose. The repeat-offender index records only addresses that trip an unambiguous fraud signal (a honeypot beacon, or an excessive per-IP daily impression count) and is retained for up to 30 days. Blocklist entries persist until an administrator removes them, or, for temporary blocks, until an administrator-set expiry. These values cannot be reversed to your IP address, are used solely for fraud and abuse enforcement, and are not shared with advertisers or Site Owners.
Where a Site Owner purchases advertising through the self-serve advertiser dashboard (see Terms §8.5), they receive aggregate performance reports for their campaigns (total impressions, clicks, click-through rate, spend). They do NOT receive per-recipient-tenant impression or click breakdowns. Recipient tenant identity is therefore not disclosed to the purchasing advertiser through the advertising program.
6.4 Consent Controls
Visitors in the European Economic Area, the United Kingdom, and other strict-consent jurisdictions (or in any location where geolocation cannot be determined) are presented with an opt-in banner: non-essential cookies and tracking will not occur until you explicitly accept.
Visitors in jurisdictions that permit opt-out models are presented with a banner that defaults to allow but offers an equally accessible decline option. Declining suppresses non-essential cookies and tracking on subsequent navigations on the same origin.
Consent is recorded per-origin: each tenant's bio site, including any custom domain, is treated as a distinct site for the purpose of consent.
The consent banner governs only non-essential cookies and tracking (analytics and advertising measurement). It does not gate essential or security-related processing that we carry out on the basis of legitimate interest, including the security and fraud-prevention processing described in §3.5, §3.6, and §6.3.
7. Third-Party Services and Sub-Processors
We share information with the following categories of third parties as necessary to operate the Service. The specific providers may change from time to time:
- Vercel — web hosting, serverless functions, edge functions, blob storage. Receives all traffic to the Service.
- Upstash / Vercel KV — key-value storage for site configuration, sessions, counters, and other data described in §3.
- Hetzner Online GmbH — server infrastructure (Germany/EU) hosting a replicated copy of the key-value data store described above.
- Cloudflare — object storage (R2) for encrypted data-store backups; may also provide SSL issuance and edge routing for certain custom domains connected to the Service.
- Discord — OAuth, bot operations, webhooks for administrative notifications, reputation syncing.
- SellAuth — payment processing for netherBio Pro subscriptions. We do not receive card data.
- SMTP2GO — transactional email delivery (verification codes, notifications).
- Google Analytics — gated analytics measurement, where consent is granted.
- ip-api.com — IP-to-geolocation lookup used for analytics and consent-banner geo classification.
- Hypixel APIs, DonutSMP — game-data lookups for in-platform tools. These services do not receive personal information about visitors.
- Elite (api.elitebot.dev) — Hypixel SkyBlock farming-statistics lookups for listing tools. This service receives no personal information about visitors.
- VaultCord — third-party Discord verification and analytics service that is the source of the Discord security and fraud-prevention index described in §3.5, used for security, fraud, and abuse investigation. Where a Site Owner has separately connected their own VaultCord account (§3.5), VaultCord is that Site Owner's own processor rather than ours, and we transmit their instructions to it on their behalf; the credentials they supply for that purpose are held encrypted and are used for no other site.
- Advertising providers — in the current implementation, all advertising is served first-party by netherbio. If we add third-party advertising providers in the future, this Policy will be updated to identify them generically and to describe any additional consent requirements.
Each provider has its own privacy practices. We select providers we believe maintain appropriate safeguards, but we are not responsible for their independent processing.
8. Sharing and Sale of Information
We do not currently sell platform analytics data to third parties for monetary consideration, nor share platform analytics data for cross-context behavioral advertising (as those terms are defined under U.S. state comprehensive privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act).
We disclose information only in the following circumstances:
- To the sub-processors listed in §7, strictly to operate the Service on our behalf.
- To Site Owners, in the form of aggregate analytics about visitors to their own bio sites.
- To advertisers, only in the form of aggregate impression and click counts for sponsorships they purchased — never individual visitor data.
- To law enforcement or in response to legal process, where we believe in good faith that disclosure is required by law.
- To protect our rights, property, or safety, or that of our users or the public, where we believe disclosure is necessary.
- In connection with a merger, acquisition, or sale of all or substantially all of our assets, subject to confidentiality and continued protection of your information.
If our data-sharing practices change in the future, we will update this Policy and, where required by law, provide additional notice and choices (including but not limited to a "Do Not Sell or Share My Personal Information" mechanism).
9. Data Retention
We retain personal information for as long as needed to operate the Service and as required by applicable law:
- Account data — for the lifetime of your account, plus a reasonable period after termination for backup, legal, and operational purposes (typically up to 12 months).
- Site content — for the lifetime of the bio site; deleted or anonymized after account termination on the same schedule.
- Analytics — aggregate daily metrics (views, sessions, visitors, link clicks) are retained for up to 90 days; lifetime totals and aggregate breakdowns are retained indefinitely. The per-visitor recent-activity log is capped to the most recent entries per site. Cached IP-geolocation lookups expire within 30 days.
- Commerce records — shop invoices, order history, and store-credit ledgers are retained for the lifetime of the associated shop and thereafter as required for financial record-keeping, even if the customer account itself is deleted.
- Consent records — retained for up to 24 months for compliance audit purposes.
- Payout records — retained as required by tax and accounting law (typically 7 years).
- Security and abuse logs — the general security/activity logs are retained for up to 90 days unless flagged for investigation.
- Authenticated-user identity and login-security data — the identity and login-history record described in §3.6 (including IP addresses, IP-derived geolocation, and device data) is retained for as long as necessary for security, fraud, and abuse-prevention purposes. Because it functions as a security signal, this retention is not subject to a fixed deletion window and may be indefinite; login records beyond the amount kept in our primary store are moved to archive storage rather than deleted.
- Discord security and fraud-prevention index (VaultCord) data — the index described in §3.5 is refreshed on a recurring basis and kept for as long as necessary for security, fraud, and abuse investigation under our legitimate-interest basis, for so long as that security purpose persists.
- Site Owner VaultCord connection data — where a Site Owner has connected their own VaultCord account (§3.5), the encrypted credentials and the cached server, backup, and schedule metadata are kept for as long as that connection exists. Disconnecting the account removes the stored credentials immediately, and deleting the site removes the connection and its cached metadata along with everything else held for that site.
- Fraud and security signals — the keyed one-way hashed (HMAC) IP blocklist and repeat-offender index (§6.3), per-customer fraud flags, and abuse reports are retained under the legitimate-interest and legal-claims carve-out described below. Hashed blocklist entries persist until an administrator removes them (or, for temporary blocks, until an administrator-set expiry) and may be retained indefinitely for security purposes; they never contain a raw IP address.
Fraud, security, and financial-record carve-out. When you request erasure (see §11), we remove identifying personal information as described there. However, consistent with GDPR Article 17(3)(b) and (e) and comparable laws, we may retain, even after an erasure request: (i) the keyed one-way hashed (HMAC) IP blocklist and repeat-offender index, which never contain a raw IP address; (ii) per-customer fraud flags and abuse reports; and (iii) commerce, payout, tax, and other financial records for the periods described above. We retain these categories where necessary for security and fraud prevention, for the establishment, exercise, or defense of legal claims, and for compliance with our legal obligations.
You may request deletion of your account data at any time (see §11).
10. Security
We implement reasonable technical and organizational measures intended to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include password hashing, TLS encryption in transit, session signing, rate limiting, optional two-factor authentication for Site Owners, encrypted storage of payout details, and limited access controls within netherbio.
No system is perfectly secure. While we take steps designed to protect your information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your credentials and for the activity that occurs under your account.
11. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — request that inaccurate or incomplete information be corrected.
- Deletion (erasure)— request that we delete your personal information, subject to the legal retention requirements and the fraud, security, and financial-record carve-out described in §9. On a verified erasure request (see below), we remove identifying personal information across our stores, including: your Discord identity record (raw IP addresses, IP-derived geolocation, and login history described in §3.6); the username, display-name, and by-IP indexes derived from it; the login-history archives held in blob storage; the full Discord security and fraud-prevention (VaultCord) dataset for you (§3.5); matching entries in our analytics and administrative-activity logs; and the per-user transcript-intelligence index. As permitted by GDPR Article 17(3)(b)/(e) and comparable laws, we retain the fraud- and security-prevention signals and financial records described in §9 (the keyed one-way hashed IP blocklist and repeat-offender index, per-customer fraud flags, abuse reports, and commerce/financial records). Raw ticket transcripts are retained under legitimate interest because they contain other participants' messages and dispute records; only the per-user index derived from them is deleted. Where a Site Owner has connected their own VaultCord account (§3.5), the member records held in that account are not ours to delete and we hold no copy of them; an erasure request for those should be made to that Site Owner or to VaultCord directly, and we will pass on a request addressed to us. Log days that have been moved to immutable archive storage are purged on their normal retention cycle rather than individually rewritten.
- Restriction or objection — request that we restrict or stop certain processing.
- Portability — request that we provide your information in a structured, machine-readable format.
- Withdraw consent — for any processing based on consent, including analytics and advertising measurement. You may withdraw consent at any time without affecting the lawfulness of earlier processing.
- Lodge a complaint — with your local data protection authority if you believe we have violated applicable law.
To exercise any of these rights, submit our legal & data request form (or email legal@netherbio.com). Platform-wide erasure is carried out by our administrators on request; it is not a self-service or automated feature. We will acknowledge and respond to your request within the timeframe required by applicable law (typically within 30 days, extendable where the law permits). This response window is the time in which we act on your request; it is separate from (a) how long data is retained under §9 (for example, up to 12 months of post-termination retention, and longer for financial records), (b) the time it takes for deletions to propagate out of routine backups, and (c) the fraud-, security-, and financial-record carve-out in §9 and above, which we may retain beyond any deletion request. We may need to verify your identity before responding.
Site Owners can also delete much of their own data directly from the admin dashboard (resetting site configuration, removing reputations, etc.) without contacting us.
12. Children's Privacy
The Service is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. Age is self-declared at registration; we do not require government-ID or documentary age verification. Users aged 13 to 17 may use the Service only with the consent and supervision of a parent or legal guardian and must affirm that consent at registration, per Terms §3.
We actively block registration by anyone under 13. If a prospective Site Owner self-declares an age under 13, we do not create or retain the account: the platform account is terminated and its personal information purged, and a one-way suppression marker blocks immediate re-registration. On the shop-customer side, a registration self-declaring an age under 13 is rejected before any account is created, so no customer record is stored. Users under 18 may not make purchases or receive advertising-revenue payouts (see Terms §3 and §8.4).
We do not knowingly engage in behavioral or interest-based advertising directed at children, and we do not currently process visitor data for the purpose of building behavioral profiles regardless of age (see Terms §10.8).
If you believe that a child under 13 has provided personal information to us, please tell us through our legal & data request form (or email legal@netherbio.com) and we will take reasonable steps to delete it.
13. International Data Transfers
The Service is operated from the United States. Information you provide may be transferred to, processed in, and stored in the United States and other countries where our service providers operate. These jurisdictions may have data protection laws that differ from those of your country.
Where required by applicable law, we rely on legally recognized transfer mechanisms (such as the European Commission's Standard Contractual Clauses for transfers from the EEA, or the UK Addendum thereto for transfers from the United Kingdom) to provide appropriate safeguards for international transfers.
14. U.S. State Privacy Rights
Residents of certain U.S. states (including California, Colorado, Connecticut, Virginia, Utah, and others) may have specific rights under their state's comprehensive privacy law, in addition to the rights described in §11.
As stated in §8, we do not currently sell personal information for monetary consideration or share it for cross-context behavioral advertising. If our practices change such that those activities occur, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism as required by law.
California residents may also designate an authorized agent to exercise their rights on their behalf. We may require verification of the agent's authority and the resident's identity before acting on the request.
15. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top and may provide additional notice through the Service. Material changes will take effect no sooner than 14 days after posting, except for changes addressing legal requirements or security concerns, which may take effect immediately.
Your continued use of the Service after a change to this Policy constitutes acceptance of the updated Policy.
16. Contact
For privacy questions, requests, or complaints, contact:
netherbio
Legal & data requests: netherbio.com/legal
Email: legal@netherbio.com
Website: netherbio.com
Please include sufficient detail (and verification information if relevant) so we can locate your records and respond appropriately.
