Skip to content

Privacy Policy

Effective date
October 3, 2026
Last updated
October 3, 2026

1. Who we are

Lab Tested Foods ("LTF," "we," "us") publishes third-party laboratory testing results — Certificates of Analysis — for consumer food and supplement products. This policy covers https://labtestedfoods.com and every page on it.

The controller of the personal data described here is Lab Tested Foods LLC, 449 E Nelson St, Unit #502, Lexington, VA 24450.

For any privacy question or request, write to info@labtestedfoods.com. This inbox is monitored and we aim to respond within 30 days.

2. What we collect

The following, and nothing else.

Usage analytics. Pages you view, searches you run, which products and brands you look at, and which links you click. This is collected through PostHog and is only stored on your device after you accept analytics in our consent banner. If you decline, we still count the page view, but without a cookie: PostHog's servers compute a hash of your IP address and browser with a value that changes every day, so the count cannot be tied back to you across days. Analytics data includes technical information sent by your browser: approximate location derived from IP address, browser and device type, referring page, and timestamps. We do not store your full IP address with analytics.

Security records. To protect our data from automated collection, our servers record when certificates and test results are opened, under a short-lived reader session and a keyed hash of your IP address. The hash key changes every day, so one day's hash cannot be matched to the next, and the address itself is not stored. We use these records to rate-limit and block automated collection, and we keep them whatever you choose in the consent banner.

Email address. Only if you type it into a signup form yourself. We use it to send you the updates you signed up for. We do not buy email lists and we do not append data to the addresses we hold.

Terms of Service acceptances. Before a Certificate of Analysis opens, we ask you to accept our Terms of Service and give an email address. We record that acceptance: the email address you gave, an anonymous visitor identifier, the version of the Terms you accepted, the time, your full IP address, and your browser's user agent. We keep this as a record that the Terms were accepted, because the Terms charge fees for automated collection of our data. We may use the email address to contact you about the Terms of Service, and we do not use it for anything else unless you separately sign up for updates.

Affiliate interaction logs. When you click an affiliate link or copy a promo code, we record which product or brand it was, which merchant it pointed to, and when. This is recorded on our own servers so that we can reconcile the commissions merchants report to us. Where you have accepted analytics, this record also carries a session identifier that lets us see the browsing path that led to the click.

3. What we do not collect

We are a transparency company. It would be strange to be vague here, so specifically:

  • No visitor accounts. There is no sign-up, no login, and no profile for site visitors. The only accounts that exist are a small number of staff administrator accounts, which are IP-restricted and used to publish COA data.
  • No passwords. Because there are no visitor accounts, there is nothing for you to set a password on.
  • No payment information. We never process a transaction. Purchases happen entirely on the merchant's own site, under the merchant's own privacy policy and payment processing.
  • No health information. We do not ask what conditions you have, what you take, why you are researching a product, or anything else about your health. Searching our catalog for a product is not a health disclosure to us, and we do not treat it as a signal about you as a person.
  • No cross-site tracking pixels. We do not run advertising pixels, retargeting tags, or social media trackers. There is no Meta pixel, no Google Ads tag, no TikTok pixel on this site.
  • No session replay. We do not record your screen, your mouse movements, or your keystrokes.
  • No data brokers. We do not enrich, append, or resolve your identity against any third-party dataset.

We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We earn money through affiliate commissions, which is disclosed on every page carrying an affiliate link. Note that when you click through to a merchant, that merchant will see the referral and may set its own cookies — that is the merchant's own processing, governed by its policy, not ours.

Affiliate relationships do not influence our test results, our Testing Score, our Ingredient Score, or which products we list.

4. Cookies and local storage

This inventory is built from our actual codebase, not a template. We update it when our storage changes.

KeyTypePurposeDurationSet when
ltf_consentlocalStorageRemembers your consent choice so we don't ask againPersistent until clearedAlways — strictly necessary
ltf-record-themelocalStorageRemembers your light/dark display preferencePersistent until clearedAlways — strictly necessary
ltf.orientation.dismissedlocalStorageRemembers that you dismissed the product-list orientation notePersistent until clearedAlways — strictly necessary
ltf_tosCookieRecords that you accepted the current Terms of Service, signed so it cannot be forged, and carries the anonymous visitor identifier your acceptance was logged under12 months, or until the Terms changeWhen you accept the Terms — strictly necessary
ltf_tos_vCookieTells the page which version of the Terms you accepted, so you are not asked again12 months, or until the Terms changeWhen you accept the Terms — strictly necessary
ltf_vsCookieA reader session, signed so it cannot be forged: a random session identifier and a daily hash of your IP address, which test results and certificates require so that we can limit automated collection30 minutes, renewed while you keep readingWhen you open a product, category or certificate page — strictly necessary
ph_<token>_posthogCookiePostHog analytics identifier and session state~12 monthsOnly after you accept analytics
ltf_sessionsessionStorageLinks a browsing path to an affiliate click for attributionCleared when the tab closesOnly after you accept analytics
sb-<project-ref>-auth-token and sb-<project-ref>-auth-token-code-verifierCookieKeeps a signed-in staff administrator authenticated and enforces access permissionsSession, with periodic refreshStaff sign-in only — never set for site visitors

The three strictly necessary localStorage items above are stored on your device without consent because the site cannot function correctly without them: one of them is the record of your consent choice itself. None of them contain an identifier, and none of them are transmitted to us or to anyone else.

The two Terms of Service cookies are strictly necessary too, and are set whatever you choose in the consent banner: we cannot show you a Certificate of Analysis without a record that you accepted the Terms. ltf_tos is sent to us with each certificate request and carries the anonymous visitor identifier described in Section 2.

The reader session cookie, ltf_vs, is strictly necessary as well, and is set whatever you choose in the consent banner: test results and certificates do not load without it. Its session identifier is random, lasts half an hour, and is not linked to your Terms acceptance or your email address.

To withdraw analytics consent, open Cookie settings in the footer of any page and choose Decline. Withdrawing takes effect immediately and is no harder than accepting was. Clearing your browser's site data for this domain removes every item in the table above.

6. Third parties who process data for us

We use a small number of processors. Each is bound by a data processing agreement and none of them may use your data for their own purposes.

ProcessorWhat it doesRegionPrivacy policy
PostHogProduct analyticsUnited States (PostHog US Cloud)https://posthog.com/privacy
SupabaseDatabase, storage, and staff authenticationCanada (AWS ca-central-1, Montréal)https://supabase.com/privacy
VercelWebsite hosting and content deliveryGlobal edge networkhttps://vercel.com/legal/privacy-policy

We do not send email updates yet, so no email provider holds your address. Before we send the first one, we will add the provider to this table.

Where a processor stores data outside the UK or EEA, the transfer is covered by the European Commission's Standard Contractual Clauses.

Merchants and affiliate networks that you click through to are not our processors. They are independent controllers, and once you land on their site you are subject to their privacy policy.

7. How long we keep things

DataRetention
PostHog analytics events12 months, on a rolling basis
Affiliate interaction logs24 months — affiliate networks dispute and adjust payouts on long lags
Email addressesUntil you unsubscribe or ask us to delete you, then removed within 30 days
Terms of Service acceptances12 months, or until the Terms of Service are next updated, whichever comes first
Security records24 hours in our database, or until a block placed on a session expires; the copies sent to PostHog follow its 12 months
Server logs at our hostPer Vercel's standard retention, typically 30 days

8. Your rights, and what we can honestly do about them

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to opt out of sale or sharing. You may also complain to your data protection authority — in the UK, the Information Commissioner's Office; in the EU, your national supervisory authority.

We want to be straightforward about how those rights work on a site with no accounts:

If you have never given us your email address, we cannot identify you. We hold no name and no account. The identifiers we do use — the anonymous visitor identifier in ltf_tos, the half-hour reader session in ltf_vs, and the daily hash of your IP address — are random or rotate, and none of them names you. If you have accepted our Terms of Service, we hold the email address you gave with that acceptance, and the full IP address it came from; write to us from that address and we can find it. If you write to us asking what data we hold about you, there is nothing for us to look up — not because we are refusing, but because the data genuinely is not associated with you in any way we can query. We would rather tell you that than describe a lookup process we cannot actually perform.

What you can do instead, at any time and without contacting us:

  • Opt out of analytics through the consent banner or the cookie settings link. This stops device-side analytics storage immediately.
  • Clear your site data in your browser, which erases everything listed in Section 4.

If you are an email subscriber, you are the exception. We can find your record by email address. Write to info@labtestedfoods.com from the subscribed address, or use the unsubscribe link, and we will delete you from the list and confirm. We do not require you to create an account or verify your identity beyond controlling that mailbox.

California residents: we do not sell or share personal information, so there is no "Do Not Sell or Share My Personal Information" mechanism to operate. We will not discriminate against you for exercising any privacy right.

9. Children

This site is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has submitted an email address to us, write to info@labtestedfoods.com and we will delete it.

10. Changes to this policy

If we change what we collect, add a processor, or change a retention period, we will update this page and move the effective date at the top. Material changes will also be announced on the site. Previous versions are available on request.