SuperBio Labs · Last updated: 2026-05-30 · v2.1
Privacy Policy
How we collect, use, and protect your personal data. Aligned with the Ecuador Personal Data Protection Law (LOPDP) and international standards.
SGI LLC, operator of SuperBio Labs, respects the privacy of visitors and customers of superbiolabs.com. This Policy describes what personal data we collect, how we use it, with whom we share it, and what rights the data subject has.
1. Data controller
The controller responsible for the processing of your personal data is:
SGI LLC (operator of SuperBio Labs)
Organized in Wyoming, United States
Operations in Ecuador: Efraín Recalde Lote 31, Urb. Vista Grande, Miravalle, Quito
Privacy contact: hello@superbiolabs.com
2. Data we collect
2.1 Data you provide directly
- Name (first name alone is acceptable).
- Email address.
- WhatsApp / phone number (optional).
- Full shipping address (country, city, street, postal code, references).
- National ID or identification document (when required by local invoicing rules).
- Messages, inquiries, and communications sent to us.
2.2 Transactional data (when making a purchase)
- Order history, products purchased, amounts paid.
- Transaction reference from the payment processor (PayPhone).
- Payment status: approved, pending, rejected, refunded.
- We do not collect or store card numbers, CVV, or expiration dates. That information is handled entirely on the payment processor's PCI-DSS infrastructure.
2.3 Automatic data (when browsing)
- IP address, device type, browser, operating system.
- Pages visited, time spent on each page, traffic source.
- Technical cookies (essential for site operation) and analytics cookies (with consent).
3. Purpose of processing
Your data is used exclusively for:
- Processing orders, coordinating shipments, and managing tracking.
- Communicating order status, payment confirmation, and shipping issues.
- Handling inquiries, technical support, and warranty claims.
- Complying with legal obligations (invoicing, accounting, applicable regulations).
- Preventing fraud and protecting the security of the site.
- Sending commercial communications only with explicit consent (opt-in). You may withdraw it at any time.
4. Sharing data with third parties
We share personal data only with the following third parties, strictly to the extent necessary:
- Couriers / shipping services (DHL, FedEx, Servientrega, Urbano, or others depending on destination): name, address, phone — for delivery only.
- PayPhone payment processor: data necessary to authorize the transaction.
- Resend (email delivery service): email address for the delivery of transactional communications.
- Supabase (database provider): secure storage of account and order data; SOC 2 Type 2 certified.
- Netlify (hosting provider): infrastructure for the website.
- Google (Analytics & Ads): only with your consent, aggregated browsing data (page views, device, traffic source) to measure site usage and, where ad campaigns are active, their performance. No identifying data such as name or email is shared. Policy: policies.google.com/privacy
- Meta (Facebook/Instagram Pixel): only with your consent, browsing events to measure the performance of our campaigns on Facebook and Instagram. No name, email, or health data is shared. Policy: facebook.com/privacy/policy
- Competent authorities when a binding legal request is in place.
We do not sell, rent, or transfer your personal data to third parties for marketing purposes.
5. Data retention
- Account and communications data: for as long as the account is active, plus 2 years after the last activity.
- Transactional data: 7 years (accounting and tax obligations in Ecuador).
- Newsletter subscriptions: until you unsubscribe.
- Browsing data (logs): 90 days.
6. Your rights as a data subject
Under the Ecuador Personal Data Protection Law (LOPDP), you have the right to:
- Access: know what data we hold about you and how we use it.
- Rectification: correct inaccurate or outdated data.
- Erasure: request deletion of your data when it is no longer necessary.
- Objection: object to specific processing activities.
- Portability: receive your data in a structured, machine-readable format.
- Restriction: restrict processing in specific cases.
- Complaint: file complaints with Ecuador's Superintendency for Personal Data Protection.
To exercise these rights, send an email to hello@superbiolabs.com with "LOPDP Request" in the subject line. We will respond within a maximum of 15 business days.
7. Cookies
We use three types of cookies:
- Technical (essential): required for the site to function (session, shopping cart, language preference). They do not require consent.
- Analytics: help us understand how the site is used (most-visited pages, devices). Provider: Google Analytics. They require your consent.
- Marketing / advertising: when active, they measure the performance of our campaigns on Google and Meta (Facebook/Instagram) and may be used to show you relevant ads. Providers: Google Ads and Meta Pixel. They require your consent.
Analytics and marketing cookies load only if you choose "Accept all" in our cookie banner. If you choose "Essentials only," they are not activated. You may withdraw consent at any time by clearing the site's cookies.
8. Security
We implement technical and organizational measures to protect your data:
- Encrypted HTTPS connection (TLS 1.3) across the entire site.
- Infrastructure on certified providers (Netlify, Supabase, Cloudflare — all SOC 2 / ISO 27001).
- Passwordless authentication (magic link), reducing the risk of credential leaks.
- Role-based access control for the internal team.
- Encrypted automated backups.
- Continuous security monitoring.
9. International transfers
Some of our providers (Netlify, Supabase, Cloudflare, Resend) have infrastructure in the United States, Europe, and Latin America. International transfers are carried out under standard contractual clauses and with providers that maintain adequate protection levels.
10. Minors
Our services are intended exclusively for individuals 18 years of age or older. We do not knowingly collect data from minors. If we detect that a minor has provided information, we will delete it.
11. Modifications
This Policy may be updated periodically. The version in force is always the one published at superbiolabs.com/en/legal/privacy/. Material changes will be communicated by email to registered customers.
12. Contact
SuperBio Labs — SGI LLC
Privacy: hello@superbiolabs.com
WhatsApp: +593 98 093 5979
Quito, Ecuador