Privacy Policy

Last updated: 10 October 2026

Pepped is operated by Pepped LLC, a South Carolina limited liability company. This policy says what we do with personal information: what we collect, why we have it, who else sees it, how long we keep it, and how to have it removed.

Pepped is a platform, not a shop. Independent vendors run their own stores on it, each at its own address under pepped.io. If you are buying something, the vendor is who you are doing business with. They decide what to ask you for and what to do with it. We hold that information for them and act on their instructions. This policy describes what we do with it as the platform underneath. A vendor may publish a policy of their own covering their side; ask them for it.

The two roles we play

For vendors and their staff, we decide how the accounts that sign in to Pepped work, and we answer for that ourselves.

For a vendor's customers, we do not decide anything. The vendor does. We store, transmit and process their customers' information on the vendor's behalf, and we do not use it for our own purposes.

What we collect

If you run a store on Pepped

Your name, your email address, and a password we store only as a bcrypt hash — we never hold the password itself and cannot recover it. We record when your email address was confirmed, which stores you have access to, your role in each, which permissions you have been granted, and which notifications you have chosen to receive. If you turn on two-factor sign-in, we hold its secret and recovery codes encrypted. You can also sign in with Google or Apple, as described below.

If your store subscribes, Stripe holds your card and billing address. We keep the reference Stripe gives your store, the card's type and last four digits as Stripe reports them, and your trial and subscription dates.

If you buy from a store on Pepped

The vendor's store collects, and we hold on their behalf:

We do not collect or store card numbers, bank details, dates of birth or government identification anywhere on Pepped. No payment card touches our systems.

Automatically, when you use the site

A session cookie, your IP address, your browser's user agent string, and timestamps of activity. This is what keeps you signed in and your basket intact between pages.

Signing in with Google or Apple

Some stores let you sign in with Google or with Apple instead of setting a password. This is worth describing exactly, because it is the one place your information passes through us before it reaches the vendor.

What we ask for. Only your name, your email address, and basic profile information — in Google's terms, the openid, email and profile scopes. Nothing else. We never ask for offline access, so we are never issued a refresh token and cannot reach your account when you are not actively signing in.

What we receive. Your email address, whether the provider says it has verified that address, and your name. From Apple, a name only the first time you authorise, and an address that may be Apple's private relay rather than your real one — which is fine, and works the same way.

What we do with it. We use it for one thing: to establish that the address is really yours, and to fill in your name and email on the vendor's registration form so you do not have to type them. If you already have an account at that store, we sign you in.

How it reaches the vendor. Sign-in is handled once at pepped.io for every store, because Google and Apple each require an exact, registered return address. Nothing is written to a database there — no account, no log entry, no cookie. Your details are held in temporary server-side storage for at most ten minutes, retrieved once by the store you were signing in to, and destroyed on retrieval. The link that carries you back to the store carries a single-use token and no details at all, so your address never appears in a web address or a server log.

What we never do with it. We do not use information from Google or Apple for advertising. We do not sell it. We do not share it with anyone other than the vendor whose store you were signing in to, and the infrastructure providers named below that operate Pepped. We do not use it to build a profile of you, and we do not combine what one vendor knows about you with what another vendor knows — a person shopping at two stores is two separate records that we never join. Our use of Google user data follows Google's Limited Use requirements.

Cookies

Pepped itself sets one cookie, plus the token that protects forms against cross-site submission. The cookie keeps you signed in and holds your basket. It expires after 120 minutes of inactivity, and it is marked so that scripts cannot read it. A vendor's staff who tick "remember me" when signing in to a store's admin get a second cookie that keeps them signed in, and nothing else.

Pepped runs no analytics of its own on any store. No store's admin carries advertising, tracking pixels, a tag manager or session recording. A store's own pages carry analytics or advertising only where its vendor has chosen them, as described under Advertising below: Plausible and Fathom set no cookies, and Google Analytics, the Meta Pixel and the TikTok Pixel set their providers' own cookies only after you accept them on the store's banner. A store that asks keeps your answer in a cookie of its own for 12 months. Beyond those tags, no store loads fonts or scripts from anyone else's servers, with two exceptions you will see happen. A store whose payment provider is Authorize.net shows that provider's payment page inside its own, and a store that embeds a video loads it from YouTube's privacy-enhanced service or from Vimeo with tracking turned off.

Our own pages about Pepped — the home page, pricing and signup on pepped.io — carry Meta's Pixel for visitors in the United States, which sets Meta's own cookies there, also described under Advertising below. pepped.io has no cookie banner: the one cookie Pepped itself sets is what makes the site work, and Meta's cookies are never set outside the United States or when your browser sends Global Privacy Control.

A store's admin and pepped.io carry Crisp's chatbox, through which store owners and staff reach our support. Crisp sets its own cookie to keep the conversation.

Advertising

On pepped.io

We advertise Pepped to vendors on Facebook and Instagram, and we measure those ads with Meta's tools, to see which ads work and show them to people more likely to open a store.

For visitors in the United States only, on pepped.io's home page, pricing and signup, we use the Meta Pixel. It tells Meta that the page was viewed and sets Meta's own cookies on pepped.io. When someone in the United States opens a store, we tell Meta through its Conversions API that a signup happened, with the new owner's email address hashed (so Meta can match it to an account it already knows without us sending the address itself), their IP address, their browser, and those cookies. Meta handles what it receives under its own policy.

Visitors outside the United States get neither: the Pixel does not load and a signup is not reported.

Our own Pixel never runs on a store: nothing a customer does on a vendor's store is reported to Meta for Pepped's advertising.

On a vendor's store

A vendor may add analytics and advertising tags to their store, to see their store's traffic and measure their own ads. The vendor decides which tags their store carries, and Pepped renders them on the vendor's behalf. The vendor types only their account ID with each provider; the code that runs is Pepped's own for that provider, so a vendor cannot add any other script to a store. The providers a store may use are:

Each provider handles what it receives under its own policy and its agreement with the vendor. Because the pages of a peptide store can say something about your health, a store never sends anything to Google, Meta or TikTok without your consent.

Tags never run on the page where you pay by card, or in a store's admin.

We honour Global Privacy Control everywhere. If your browser sends it, no store loads any of these tags or shows you the banner, and on pepped.io the Pixel does not load and your signup is not reported.

To opt out, turn on Global Privacy Control in your browser or use one that sends it, decline on a store's banner, or block third-party scripts. You can also limit what Meta does with this in your Meta account, under "Your activity off Meta technologies".

Email

Email from Pepped is transactional only. If you buy from a store, the store sends you, through us, what your account and your orders need: confirming your email address, sign-in codes, password resets, invitations, and updates on an order you placed, from placing it to shipping or refunding it. If you run a store, we send you sign-in codes and invitations, notice of your trial and subscription, and the alerts you choose about orders, stock, payments and your domain. There is no marketing list, no newsletter, and nothing to unsubscribe from.

Who else sees it

We use a small number of service providers to run Pepped. Each one is listed here with what it actually receives.

ProviderWhat it handlesWhere
Laravel Cloud (on Amazon Web Services)Hosting, the application database, and file storage — everything Pepped holdsAWS us-east-1, United States
Amazon Simple Email ServiceDelivery of the transactional emails above: recipient address and messageUnited States
Laravel NightwatchApplication monitoring — errors, request and query records, and mail events, used to keep the platform workingUnited States
StripeOur billing of stores that subscribe: the subscribing owner's email address, billing address and cardUnited States
The store's payment provider (Stripe or Authorize.net)Only when you pay a store by card, on the provider's own page, under the store's own account and the store's agreement with that providerPer the provider's own policy
YouTube or VimeoOnly when a store's page embeds a video and you view that pagePer their own policy
CrispOur support chat with vendors: in a store's admin, the signed-in owner's or staff member's name and email address, the store's name and plan, and what they write; on pepped.io, what a visitor writesEuropean Union
MetaUS visitors only, on pepped.io's home page, pricing and signup, as described under Advertising: page views, and a signup's hashed email address, IP address and browserPer Meta's own policy
PlausibleOnly on a store whose vendor uses it: page views and order totals, without cookiesPer Plausible's own policy
FathomOnly on a store whose vendor uses it: page views and order totals, without cookiesPer Fathom's own policy
Google AnalyticsOnly on a store whose vendor uses it, and only after you accept: the pages you view, the products you look at and add to your basket, checkout, and your orderPer Google's own policy
Meta Pixel (on a store)Only on a store whose vendor uses it, and only after you accept: the pages you view, the products you look at and add to your basket, checkout, and your orderPer Meta's own policy
TikTok PixelOnly on a store whose vendor uses it, and only after you accept: the pages you view, the products you look at and add to your basket, checkout, and your orderPer TikTok's own policy
GoogleOnly when you choose to sign in with GooglePer Google's own policy
AppleOnly when you choose to sign in with ApplePer Apple's own policy

We share information with a vendor about their own customers, because it is theirs. We do not share one vendor's information with another vendor, ever.

We will share information where the law requires it of us.

We do not sell personal information. The one thing we share for our own advertising is a signup on pepped.io from the United States, reported to Meta to measure our own ads as described under Advertising, and Global Privacy Control turns that off. Nothing from any store is shared for Pepped's advertising. A vendor whose store carries Google Analytics, the Meta Pixel or the TikTok Pixel shares what you do on that store with that provider for the vendor's own purposes, only after you accept on the store's banner and never when your browser sends Global Privacy Control.

Where your information is stored

In the United States, in Amazon Web Services' us-east-1 region. If you are outside the United States — which is possible, because a vendor can choose to ship internationally — using a store on Pepped means your information is transferred to and stored in the United States.

How long we keep it

We keep a store's records for as long as that store operates on Pepped. We do not delete a vendor's business records on our own initiative; they are the vendor's to keep or to remove.

Two things have a fixed life:

Everything else is held until it is removed as described below.

Having your information removed

Ask the vendor whose store you shopped at. They can remove it directly, and Pepped gives them a single tool that does it: your name, email address, phone number, saved addresses and any staff notes are permanently overwritten, and your password and email confirmation are erased. It cannot be undone.

Two things this deliberately does not touch, and it is worth being straight about why:

A vendor cannot remove your details while you have an order still in progress. Once every order is finished, cancelled or refunded, they can.

Backups taken before a removal will still contain the earlier information until those backups age out.

If a vendor will not act, or you are not sure who to ask, write to us at hello@pepped.io and we will make sure your request reaches them. If their store is no longer operating on Pepped, we will act on it ourselves.

Who at Pepped can see your information

Our staff can access a vendor's data when it is needed to operate the platform or to answer a support request. That access happens through a recorded sign-in as a specific person, and the vendor can review the record of it.

We never copy real data from the live platform into testing or development environments.

Age

Pepped is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18. Where a vendor's product category calls for it, a customer confirms they are 18 or over and we record that confirmation. If you believe a person under 18 has given us information, write to hello@pepped.io and we will remove it.

Security

Passwords are stored only as bcrypt hashes and are never recoverable. The site is served over HTTPS. Session cookies cannot be read by scripts. Files such as lab certificates are held in private storage reachable only through links that expire in minutes.

No system is perfectly secure, and we do not claim otherwise.

Changes to this policy

If we change how we handle personal information, we will update this page and change the date at the top. If a change is significant, we will say so here rather than quietly editing.

Contact

Pepped LLC
hello@pepped.io