Legal & compliance

Privacy Policy

This page explains, in plain language, what personal information Pepticore collects when you visit pepticore.co or place an order, why we collect it, who we share it with, how long we keep it, and the rights you have over it — including specific rights for California residents.

Effective 22 September 2026 Last updated 22 September 2026 Applies to every visitor and customer of pepticore.co
Your data, secured
Never sold to advertisers

The short version

We collect only the information we need to ship your order, process your payment, keep pepticore.co running securely, and — if you opt in — send you updates about new peptides and lot releases. We do not sell your personal information, we share it only with the vendors that make an order possible (our payment processor, our shipping carrier, and a small set of analytics tools), and you can request access to, correction of, or deletion of your data at any time.

Pepticore is registered and operated in California, so this policy incorporates the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA) in full — whether or not you live in California.

Overview

Who this policy covers and what it applies to

This Privacy Policy is issued by Renaissance Wave LLC, the company that owns and operates Pepticore and pepticore.co (referred to here as “Pepticore,” “we,” “us,” or “our”). It applies to any person who visits our website, creates an account, places an order for a Research Use Only peptide product, contacts our support team, or subscribes to our marketing emails. It does not apply to information collected by third-party websites that we link to, including our payment processor’s own checkout environment, which maintains its own privacy policy.

We ship exclusively within the United States and do not knowingly collect personal information from residents of other countries. If you are located outside the United States and choose to use our website anyway, please be aware that your information will be processed on U.S. servers, under U.S. law, as described throughout this page.

Data categories

Categories of information we collect

We collect information directly from you (when you place an order, create an account, or contact us) and automatically (through your browser, as you use the site). The table below lists every category we collect and where it comes from.

CategoryExamplesHow it’s collected
Identity & contact dataFull name, email address, shipping and billing address, phone numberEntered by you at checkout or account creation
Payment dataCard type and last four digits, billing zip code, transaction statusCollected and tokenised by our PCI-compliant payment processor — we never receive or store full card numbers
Order & account dataOrder history, quantities purchased, account preferences, support correspondenceGenerated when you place an order or message support
Technical dataIP address, browser type, device type, operating systemCollected automatically by our web server and security tools
Browsing behaviorPages viewed, time on page, referring URL, links clicked, cart activityCollected automatically via cookies and analytics scripts — see our Cookie Policy
Marketing preferencesEmail opt-in status, campaign engagement (opens, clicks)Recorded when you subscribe, and updated when you engage with or unsubscribe from campaigns
Purpose

How we use your information

Order processing & fulfillment

Verifying your age and research-purpose acknowledgment, charging your payment method, packing and shipping your order, sending order and tracking confirmations, and handling any return or refund claim.

Marketing communications

Sending new-lot announcements, restock alerts, and promotional offers to customers and site visitors who have affirmatively opted in, as described in Section 12.

Analytics & site improvement

Understanding which pages and products are most useful to researchers, diagnosing checkout errors, and improving page load speed and site security using aggregated browsing data.

Disclosure

Third parties we share information with

Payment processor

Your payment details are transmitted directly to our PCI-DSS-compliant payment processor to authorise and settle transactions. We receive only a transaction status and the last four digits of your card — never the full card number.

Shipping carrier

Your name, shipping address, and phone number are shared with our domestic shipping carrier solely to deliver your order and provide tracking updates.

Analytics & email service providers

We use website analytics tools to understand aggregated site traffic, and an email service provider to send order confirmations and, where you have opted in, marketing messages. These vendors process data under contract and only for the purposes we direct.

We do not sell your personal information to any third party, and we do not share it with advertisers for cross-context behavioral advertising. We disclose information only as described above, to comply with a valid legal request such as a subpoena or court order, to protect the rights, property, or safety of Pepticore or others, or in connection with a merger, acquisition, or sale of business assets, in which case this policy would continue to apply to your information under the new owner.

How long we keep data

Data retention periods

Data typeRetention periodWhy
Order & transaction records7 years from the transaction dateFederal and California tax and accounting record-keeping requirements
Account informationFor as long as your account remains active, plus 24 months after your last orderTo support order history, returns, and repeat-purchase convenience
Marketing contact dataUntil you unsubscribe or request deletionTo honor your subscription and immediately stop on opt-out
Support correspondence3 years from the date of your last messageTo maintain a service history in case of a follow-up claim or dispute
Browsing & analytics dataUp to 26 months, then aggregated or deletedStandard analytics-platform retention window

When a retention period ends, we delete or irreversibly anonymise the corresponding data unless a longer period is required by law, or you have made an active deletion request under Section 6, which we honor sooner where legally permitted.

Every U.S. customer

Your privacy rights, wherever you live

Right to access

Request a copy of the personal information we hold about you and how it has been used and shared.

Right to correction

Ask us to correct inaccurate or outdated information, such as a shipping address or phone number on file.

Right to deletion

Request that we delete your personal information, subject to the record-keeping exceptions described in Section 5.

To exercise any of these rights, email contact@pepticore.co with the subject line “Privacy Request” and tell us which right you would like to exercise. We will verify your identity using the email address and order details on file before acting on a request, and we will respond within 45 days, consistent with California law described in Section 7.

California residents

CCPA, CPRA, and CalOPPA rights

Pepticore is operated by Renaissance Wave LLC, a company registered and headquartered in California. Because of this, we apply the full protections of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA) — and, as a matter of practice, we extend the same rights to every customer in every state, not just California residents.

Right to know

You may request the specific categories and pieces of personal information we have collected about you in the preceding 12 months, the sources it came from, and the purposes for collecting it.

Right to delete

You may request deletion of personal information we have collected from you, subject to legal retention exceptions such as tax record-keeping.

Right to correct

You may request that we correct inaccurate personal information we maintain about you.

Right to opt out of sale or sharing

We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of today. If this ever changes, we will post a “Do Not Sell or Share My Personal Information” link and honor opt-out requests, including via the Global Privacy Control signal where technically supported.

Right to non-discrimination

We will never deny you goods or services, charge you a different price, or provide a different level of service because you exercised a privacy right under this section.

Authorized agents & Shine the Light

You may designate an authorized agent to submit a privacy request on your behalf, provided we can verify the agent’s authority. California residents may also request, once per calendar year and free of charge, a list of any personal information disclosed to third parties for their own direct marketing purposes in the prior calendar year under California’s “Shine the Light” law (Civil Code § 1798.83) — as noted in Section 4, we currently make no such disclosures.

All requests under this section can be submitted to contact@pepticore.co or by calling +1 (571) 688-3488. We will confirm receipt within 10 business days and substantively respond within 45 calendar days, with one 45-day extension available where reasonably necessary and disclosed to you.

Beyond California

Other state consumer privacy laws we honor

A growing number of states have enacted comprehensive consumer privacy laws similar to California’s. Rather than tracking which specific law applies to each customer’s state, we extend the same core rights — access, correction, deletion, and no sale or sharing of data — to every customer nationwide.

Virginia, Colorado & Connecticut

VCDPA, CPA & CTDPA

These states grant residents rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising and sale. We honor all of these rights for every customer, regardless of state.

Utah, Texas, Oregon & others

Emerging comprehensive privacy laws

Additional states have passed or are implementing similar consumer privacy statutes. As these laws take effect, we apply their access, correction, and deletion standards to residents of those states as a matter of policy, without waiting for a formal effective date.

All 50 states

State data breach notification laws

Every state requires notification to affected residents in the event of a qualifying data breach. If we ever experience a breach involving your personal information, we will notify you in accordance with the law of your state of residence and, where applicable, relevant state attorneys general.

Age restriction

Children’s privacy and COPPA compliance

Pepticore.co is not directed at, marketed to, or intended for use by anyone under the age of 18, and checkout requires an affirmative acknowledgment that the buyer is at least 21, consistent with our Legal Notice. We do not knowingly collect personal information from children under 13, in compliance with the Children’s Online Privacy Protection Act (COPPA), and we do not knowingly collect personal information from anyone under 18.

If we learn that we have inadvertently collected personal information from a child under 13, we will delete that information promptly. If you believe a child has provided us with personal information, please contact contact@pepticore.co immediately so we can investigate and remove it.

Protection

How we secure your information

We use industry-standard SSL/TLS encryption to protect data in transit between your browser and our servers, including at checkout. Payment card data is tokenised and handled directly by our PCI-DSS-compliant payment processor, so full card numbers never touch our own servers.

Internally, access to customer data is restricted to employees and contractors who need it to do their jobs — fulfilling orders, providing support, or maintaining the site — and is protected by access controls and regular account reviews. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work continuously to protect your information using current, reasonable safeguards.

TLS
encrypted

Every session, every page

Encryption applies site-wide, not only at checkout.

Tracking technologies

Cookies and similar technologies

We use cookies and similar tracking technologies to keep your cart working across pages, remember your preferences, and understand aggregated site traffic through analytics tools. Cookies do not give us access to your device beyond the specific data they are designed to collect.

For a full breakdown of every cookie category we use, how long each one persists, and how to manage or disable them in your browser, please see our dedicated Cookie Policy, which forms part of, and should be read alongside, this Privacy Policy.

Your inbox, your choice

Marketing email opt-in and opt-out

Opt in at checkout
or on-site signup
Receive lot & restock
emails
Unsubscribe anytime,
one click

We only send marketing email to customers and visitors who have affirmatively checked an opt-in box at checkout or through an on-site signup form — placing an order alone does not automatically enroll you in marketing email, though you will still receive transactional messages such as order and shipping confirmations, which are necessary to fulfil your purchase and are not optional. Every marketing email includes a one-click “unsubscribe” link at the bottom, consistent with the federal CAN-SPAM Act, and we process opt-out requests promptly, typically within 10 business days as required by that Act. You may also unsubscribe by emailing contact@pepticore.co directly.

Browser signals

Do Not Track and Global Privacy Control

Some browsers offer a “Do Not Track” (DNT) setting. Because there is no accepted industry standard for how to respond to DNT, our site does not currently change its behavior when it detects a DNT signal. We do, however, recognize the Global Privacy Control (GPC) signal as a valid opt-out-of-sale-or-sharing preference under the CCPA/CPRA — though as described in Section 7, we do not sell or share personal information for cross-context behavioral advertising in the first place, so a GPC signal does not currently change what data you receive from us.

Data location

International data transfers — not applicable

Pepticore operates exclusively within the United States. Our servers, our warehouse, our payment processor, and our shipping carrier all operate domestically, and we currently ship only to addresses within the United States. As a result, your personal information is not transferred outside the United States in connection with your use of pepticore.co, and cross-border data transfer frameworks such as the EU-U.S. Data Privacy Framework do not apply to our operations.

Revisions

Changes to this policy

We review this Privacy Policy regularly and update it whenever our data practices, vendor relationships, product catalog, or applicable law change. The “last updated” date at the top of this page always reflects the current version. For a material change — one that expands how we use previously collected personal information — we will post a prominent notice on our website and, where you have provided one, email active account holders at least 14 days before the change takes effect. Continued use of pepticore.co after an update constitutes acceptance of the revised policy.

  Privacy questions or requests

Talk to a real person, weekdays

To exercise any right described on this page, ask a question about our data practices, or report a concern, our support team responds within one business day.

Legal entityRenaissance Wave LLC — B20260145556
Registered address2108 N St Ste N, Sacramento, CA 95816, United States
Privacy & support emailcontact@pepticore.co
Support hoursMon–Fri, 9:00 AM – 6:00 PM PT · replies within one business day