Privacy Policy
Last updated: 10 October 2026
Pepped is operated by Pepped LLC, a South Carolina limited liability company. This policy says what we do with personal information: what we collect, why we have it, who else sees it, how long we keep it, and how to have it removed.
Pepped is a platform, not a shop. Independent vendors run their own stores on it, each at its own address under pepped.io. If you are buying something, the vendor is who you are doing business with. They decide what to ask you for and what to do with it. We hold that information for them and act on their instructions. This policy describes what we do with it as the platform underneath. A vendor may publish a policy of their own covering their side; ask them for it.
The two roles we play
For vendors and their staff, we decide how the accounts that sign in to Pepped work, and we answer for that ourselves.
For a vendor's customers, we do not decide anything. The vendor does. We store, transmit and process their customers' information on the vendor's behalf, and we do not use it for our own purposes.
What we collect
If you run a store on Pepped
Your name, your email address, and a password we store only as a bcrypt hash — we never hold the password itself and cannot recover it. We record when your email address was confirmed, which stores you have access to, your role in each, which permissions you have been granted, and which notifications you have chosen to receive. If you turn on two-factor sign-in, we hold its secret and recovery codes encrypted. You can also sign in with Google or Apple, as described below.
If your store subscribes, Stripe holds your card and billing address. We keep the reference Stripe gives your store, the card's type and last four digits as Stripe reports them, and your trial and subscription dates.
If you buy from a store on Pepped
The vendor's store collects, and we hold on their behalf:
- Your first and last name, email address, and phone number if you give one.
- Any delivery addresses you save, and the address each order was actually sent to. An order keeps a copy of the name and address it was placed with, frozen at that moment, because it is a record of a transaction that happened.
- Your orders: what was ordered, quantities, prices, tax and shipping, the state the order is in, and tracking numbers where a shipment has one.
- Payment and refund records: the method, the amount, the state, and the reference the vendor's payment provider gave it or the vendor's staff typed. A card payment is taken on the payment provider's own page, under the vendor's own account with that provider. We send the provider the order number, the amount and the store's name, never your details; you enter those on the provider's page, not on Pepped.
- Any statement you agreed to — for example that you are 18 or over, that a product is for research use only, or that someone will receive and refrigerate a cold shipment. We keep what the statement said, when you agreed, and whether a member of staff took it on your behalf.
- Notes the vendor's staff write about you on their own copy of your record.
We do not collect or store card numbers, bank details, dates of birth or government identification anywhere on Pepped. No payment card touches our systems.
Automatically, when you use the site
A session cookie, your IP address, your browser's user agent string, and timestamps of activity. This is what keeps you signed in and your basket intact between pages.
Signing in with Google or Apple
Some stores let you sign in with Google or with Apple instead of setting a password. This is worth describing exactly, because it is the one place your information passes through us before it reaches the vendor.
What we ask for. Only your name, your email address, and basic profile information — in Google's terms, the openid, email and profile scopes. Nothing else. We never ask for offline access, so we are never issued a refresh token and cannot reach your account when you are not actively signing in.
What we receive. Your email address, whether the provider says it has verified that address, and your name. From Apple, a name only the first time you authorise, and an address that may be Apple's private relay rather than your real one — which is fine, and works the same way.
What we do with it. We use it for one thing: to establish that the address is really yours, and to fill in your name and email on the vendor's registration form so you do not have to type them. If you already have an account at that store, we sign you in.
How it reaches the vendor. Sign-in is handled once at pepped.io for every store, because Google and Apple each require an exact, registered return address. Nothing is written to a database there — no account, no log entry, no cookie. Your details are held in temporary server-side storage for at most ten minutes, retrieved once by the store you were signing in to, and destroyed on retrieval. The link that carries you back to the store carries a single-use token and no details at all, so your address never appears in a web address or a server log.
What we never do with it. We do not use information from Google or Apple for advertising. We do not sell it. We do not share it with anyone other than the vendor whose store you were signing in to, and the infrastructure providers named below that operate Pepped. We do not use it to build a profile of you, and we do not combine what one vendor knows about you with what another vendor knows — a person shopping at two stores is two separate records that we never join. Our use of Google user data follows Google's Limited Use requirements.
Cookies
Pepped itself sets one cookie, plus the token that protects forms against cross-site submission. The cookie keeps you signed in and holds your basket. It expires after 120 minutes of inactivity, and it is marked so that scripts cannot read it. A vendor's staff who tick "remember me" when signing in to a store's admin get a second cookie that keeps them signed in, and nothing else.
Pepped runs no analytics of its own on any store. No store's admin carries advertising, tracking pixels, a tag manager or session recording. A store's own pages carry analytics or advertising only where its vendor has chosen them, as described under Advertising below: Plausible and Fathom set no cookies, and Google Analytics, the Meta Pixel and the TikTok Pixel set their providers' own cookies only after you accept them on the store's banner. A store that asks keeps your answer in a cookie of its own for 12 months. Beyond those tags, no store loads fonts or scripts from anyone else's servers, with two exceptions you will see happen. A store whose payment provider is Authorize.net shows that provider's payment page inside its own, and a store that embeds a video loads it from YouTube's privacy-enhanced service or from Vimeo with tracking turned off.
Our own pages about Pepped — the home page, pricing and signup on pepped.io — carry Meta's Pixel for visitors in the United States, which sets Meta's own cookies there, also described under Advertising below. pepped.io has no cookie banner: the one cookie Pepped itself sets is what makes the site work, and Meta's cookies are never set outside the United States or when your browser sends Global Privacy Control.
A store's admin and pepped.io carry Crisp's chatbox, through which store owners and staff reach our support. Crisp sets its own cookie to keep the conversation.
Advertising
On pepped.io
We advertise Pepped to vendors on Facebook and Instagram, and we measure those ads with Meta's tools, to see which ads work and show them to people more likely to open a store.
For visitors in the United States only, on pepped.io's home page, pricing and signup, we use the Meta Pixel. It tells Meta that the page was viewed and sets Meta's own cookies on pepped.io. When someone in the United States opens a store, we tell Meta through its Conversions API that a signup happened, with the new owner's email address hashed (so Meta can match it to an account it already knows without us sending the address itself), their IP address, their browser, and those cookies. Meta handles what it receives under its own policy.
Visitors outside the United States get neither: the Pixel does not load and a signup is not reported.
Our own Pixel never runs on a store: nothing a customer does on a vendor's store is reported to Meta for Pepped's advertising.
On a vendor's store
A vendor may add analytics and advertising tags to their store, to see their store's traffic and measure their own ads. The vendor decides which tags their store carries, and Pepped renders them on the vendor's behalf. The vendor types only their account ID with each provider; the code that runs is Pepped's own for that provider, so a vendor cannot add any other script to a store. The providers a store may use are:
- Plausible and Fathom, which count page views and the total of an order without cookies and without identifying you, and share nothing for advertising. A store that uses either loads it for every visitor.
- Google Analytics, the Meta Pixel and the TikTok Pixel, which set their providers' own cookies and can be used to target advertising. A store that uses any of them asks you first, on a banner where Accept and Decline carry equal weight, and none of them loads until you accept. Your answer is kept for 12 months, and a Cookie preferences link at the foot of every page of the store lets you change it. Once you accept, they receive the pages you view, the products you look at and add to your basket, that you started checkout, and your order: the products, its value, and its number.
Each provider handles what it receives under its own policy and its agreement with the vendor. Because the pages of a peptide store can say something about your health, a store never sends anything to Google, Meta or TikTok without your consent.
Tags never run on the page where you pay by card, or in a store's admin.
We honour Global Privacy Control everywhere. If your browser sends it, no store loads any of these tags or shows you the banner, and on pepped.io the Pixel does not load and your signup is not reported.
To opt out, turn on Global Privacy Control in your browser or use one that sends it, decline on a store's banner, or block third-party scripts. You can also limit what Meta does with this in your Meta account, under "Your activity off Meta technologies".
Email from Pepped is transactional only. If you buy from a store, the store sends you, through us, what your account and your orders need: confirming your email address, sign-in codes, password resets, invitations, and updates on an order you placed, from placing it to shipping or refunding it. If you run a store, we send you sign-in codes and invitations, notice of your trial and subscription, and the alerts you choose about orders, stock, payments and your domain. There is no marketing list, no newsletter, and nothing to unsubscribe from.
Who else sees it
We use a small number of service providers to run Pepped. Each one is listed here with what it actually receives.
| Provider | What it handles | Where |
|---|---|---|
| Laravel Cloud (on Amazon Web Services) | Hosting, the application database, and file storage — everything Pepped holds | AWS us-east-1, United States |
| Amazon Simple Email Service | Delivery of the transactional emails above: recipient address and message | United States |
| Laravel Nightwatch | Application monitoring — errors, request and query records, and mail events, used to keep the platform working | United States |
| Stripe | Our billing of stores that subscribe: the subscribing owner's email address, billing address and card | United States |
| The store's payment provider (Stripe or Authorize.net) | Only when you pay a store by card, on the provider's own page, under the store's own account and the store's agreement with that provider | Per the provider's own policy |
| YouTube or Vimeo | Only when a store's page embeds a video and you view that page | Per their own policy |
| Crisp | Our support chat with vendors: in a store's admin, the signed-in owner's or staff member's name and email address, the store's name and plan, and what they write; on pepped.io, what a visitor writes | European Union |
| Meta | US visitors only, on pepped.io's home page, pricing and signup, as described under Advertising: page views, and a signup's hashed email address, IP address and browser | Per Meta's own policy |
| Plausible | Only on a store whose vendor uses it: page views and order totals, without cookies | Per Plausible's own policy |
| Fathom | Only on a store whose vendor uses it: page views and order totals, without cookies | Per Fathom's own policy |
| Google Analytics | Only on a store whose vendor uses it, and only after you accept: the pages you view, the products you look at and add to your basket, checkout, and your order | Per Google's own policy |
| Meta Pixel (on a store) | Only on a store whose vendor uses it, and only after you accept: the pages you view, the products you look at and add to your basket, checkout, and your order | Per Meta's own policy |
| TikTok Pixel | Only on a store whose vendor uses it, and only after you accept: the pages you view, the products you look at and add to your basket, checkout, and your order | Per TikTok's own policy |
| Only when you choose to sign in with Google | Per Google's own policy | |
| Apple | Only when you choose to sign in with Apple | Per Apple's own policy |
We share information with a vendor about their own customers, because it is theirs. We do not share one vendor's information with another vendor, ever.
We will share information where the law requires it of us.
We do not sell personal information. The one thing we share for our own advertising is a signup on pepped.io from the United States, reported to Meta to measure our own ads as described under Advertising, and Global Privacy Control turns that off. Nothing from any store is shared for Pepped's advertising. A vendor whose store carries Google Analytics, the Meta Pixel or the TikTok Pixel shares what you do on that store with that provider for the vendor's own purposes, only after you accept on the store's banner and never when your browser sends Global Privacy Control.
Where your information is stored
In the United States, in Amazon Web Services' us-east-1 region. If you are outside the United States — which is possible, because a vendor can choose to ship internationally — using a store on Pepped means your information is transferred to and stored in the United States.
How long we keep it
We keep a store's records for as long as that store operates on Pepped. We do not delete a vendor's business records on our own initiative; they are the vendor's to keep or to remove.
Two things have a fixed life:
- Server logs held by Laravel Cloud are kept for 7 days.
- Sign-in details passing through pepped.io last at most 10 minutes and are destroyed as soon as the store retrieves them.
Everything else is held until it is removed as described below.
Having your information removed
Ask the vendor whose store you shopped at. They can remove it directly, and Pepped gives them a single tool that does it: your name, email address, phone number, saved addresses and any staff notes are permanently overwritten, and your password and email confirmation are erased. It cannot be undone.
Two things this deliberately does not touch, and it is worth being straight about why:
- Orders keep the name and delivery address they were placed with. An order is a record of a transaction, and both the vendor and their tax authority need it to still say what it said. It is frozen at the moment of the order and is not updated afterwards.
- Records of statements you agreed to — an age or research attestation — remain, because their point is to record that the statement was made.
A vendor cannot remove your details while you have an order still in progress. Once every order is finished, cancelled or refunded, they can.
Backups taken before a removal will still contain the earlier information until those backups age out.
If a vendor will not act, or you are not sure who to ask, write to us at hello@pepped.io and we will make sure your request reaches them. If their store is no longer operating on Pepped, we will act on it ourselves.
Who at Pepped can see your information
Our staff can access a vendor's data when it is needed to operate the platform or to answer a support request. That access happens through a recorded sign-in as a specific person, and the vendor can review the record of it.
We never copy real data from the live platform into testing or development environments.
Age
Pepped is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18. Where a vendor's product category calls for it, a customer confirms they are 18 or over and we record that confirmation. If you believe a person under 18 has given us information, write to hello@pepped.io and we will remove it.
Security
Passwords are stored only as bcrypt hashes and are never recoverable. The site is served over HTTPS. Session cookies cannot be read by scripts. Files such as lab certificates are held in private storage reachable only through links that expire in minutes.
No system is perfectly secure, and we do not claim otherwise.
Changes to this policy
If we change how we handle personal information, we will update this page and change the date at the top. If a change is significant, we will say so here rather than quietly editing.
Contact
Pepped LLC
hello@pepped.io