Privacy Policy
This page explains, in plain language, what personal information Pepticore collects when you visit pepticore.co or place an order, why we collect it, who we share it with, how long we keep it, and the rights you have over it — including specific rights for California residents.
The short version
We collect only the information we need to ship your order, process your payment, keep pepticore.co running securely, and — if you opt in — send you updates about new peptides and lot releases. We do not sell your personal information, we share it only with the vendors that make an order possible (our payment processor, our shipping carrier, and a small set of analytics tools), and you can request access to, correction of, or deletion of your data at any time.
Pepticore is registered and operated in California, so this policy incorporates the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA) in full — whether or not you live in California.
Who this policy covers and what it applies to
This Privacy Policy is issued by Renaissance Wave LLC, the company that owns and operates Pepticore and pepticore.co (referred to here as “Pepticore,” “we,” “us,” or “our”). It applies to any person who visits our website, creates an account, places an order for a Research Use Only peptide product, contacts our support team, or subscribes to our marketing emails. It does not apply to information collected by third-party websites that we link to, including our payment processor’s own checkout environment, which maintains its own privacy policy.
We ship exclusively within the United States and do not knowingly collect personal information from residents of other countries. If you are located outside the United States and choose to use our website anyway, please be aware that your information will be processed on U.S. servers, under U.S. law, as described throughout this page.
Categories of information we collect
We collect information directly from you (when you place an order, create an account, or contact us) and automatically (through your browser, as you use the site). The table below lists every category we collect and where it comes from.
| Category | Examples | How it’s collected |
|---|---|---|
| Identity & contact data | Full name, email address, shipping and billing address, phone number | Entered by you at checkout or account creation |
| Payment data | Card type and last four digits, billing zip code, transaction status | Collected and tokenised by our PCI-compliant payment processor — we never receive or store full card numbers |
| Order & account data | Order history, quantities purchased, account preferences, support correspondence | Generated when you place an order or message support |
| Technical data | IP address, browser type, device type, operating system | Collected automatically by our web server and security tools |
| Browsing behavior | Pages viewed, time on page, referring URL, links clicked, cart activity | Collected automatically via cookies and analytics scripts — see our Cookie Policy |
| Marketing preferences | Email opt-in status, campaign engagement (opens, clicks) | Recorded when you subscribe, and updated when you engage with or unsubscribe from campaigns |
How we use your information
Order processing & fulfillment
Verifying your age and research-purpose acknowledgment, charging your payment method, packing and shipping your order, sending order and tracking confirmations, and handling any return or refund claim.
Marketing communications
Sending new-lot announcements, restock alerts, and promotional offers to customers and site visitors who have affirmatively opted in, as described in Section 12.
Analytics & site improvement
Understanding which pages and products are most useful to researchers, diagnosing checkout errors, and improving page load speed and site security using aggregated browsing data.
Third parties we share information with
Payment processor
Your payment details are transmitted directly to our PCI-DSS-compliant payment processor to authorise and settle transactions. We receive only a transaction status and the last four digits of your card — never the full card number.
Shipping carrier
Your name, shipping address, and phone number are shared with our domestic shipping carrier solely to deliver your order and provide tracking updates.
Analytics & email service providers
We use website analytics tools to understand aggregated site traffic, and an email service provider to send order confirmations and, where you have opted in, marketing messages. These vendors process data under contract and only for the purposes we direct.
We do not sell your personal information to any third party, and we do not share it with advertisers for cross-context behavioral advertising. We disclose information only as described above, to comply with a valid legal request such as a subpoena or court order, to protect the rights, property, or safety of Pepticore or others, or in connection with a merger, acquisition, or sale of business assets, in which case this policy would continue to apply to your information under the new owner.
Data retention periods
| Data type | Retention period | Why |
|---|---|---|
| Order & transaction records | 7 years from the transaction date | Federal and California tax and accounting record-keeping requirements |
| Account information | For as long as your account remains active, plus 24 months after your last order | To support order history, returns, and repeat-purchase convenience |
| Marketing contact data | Until you unsubscribe or request deletion | To honor your subscription and immediately stop on opt-out |
| Support correspondence | 3 years from the date of your last message | To maintain a service history in case of a follow-up claim or dispute |
| Browsing & analytics data | Up to 26 months, then aggregated or deleted | Standard analytics-platform retention window |
When a retention period ends, we delete or irreversibly anonymise the corresponding data unless a longer period is required by law, or you have made an active deletion request under Section 6, which we honor sooner where legally permitted.
Your privacy rights, wherever you live
Right to access
Request a copy of the personal information we hold about you and how it has been used and shared.
Right to correction
Ask us to correct inaccurate or outdated information, such as a shipping address or phone number on file.
Right to deletion
Request that we delete your personal information, subject to the record-keeping exceptions described in Section 5.
To exercise any of these rights, email contact@pepticore.co with the subject line “Privacy Request” and tell us which right you would like to exercise. We will verify your identity using the email address and order details on file before acting on a request, and we will respond within 45 days, consistent with California law described in Section 7.
CCPA, CPRA, and CalOPPA rights
Pepticore is operated by Renaissance Wave LLC, a company registered and headquartered in California. Because of this, we apply the full protections of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA) — and, as a matter of practice, we extend the same rights to every customer in every state, not just California residents.
Right to know
You may request the specific categories and pieces of personal information we have collected about you in the preceding 12 months, the sources it came from, and the purposes for collecting it.
Right to delete
You may request deletion of personal information we have collected from you, subject to legal retention exceptions such as tax record-keeping.
Right to correct
You may request that we correct inaccurate personal information we maintain about you.
Right to opt out of sale or sharing
We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of today. If this ever changes, we will post a “Do Not Sell or Share My Personal Information” link and honor opt-out requests, including via the Global Privacy Control signal where technically supported.
Right to non-discrimination
We will never deny you goods or services, charge you a different price, or provide a different level of service because you exercised a privacy right under this section.
Authorized agents & Shine the Light
You may designate an authorized agent to submit a privacy request on your behalf, provided we can verify the agent’s authority. California residents may also request, once per calendar year and free of charge, a list of any personal information disclosed to third parties for their own direct marketing purposes in the prior calendar year under California’s “Shine the Light” law (Civil Code § 1798.83) — as noted in Section 4, we currently make no such disclosures.
All requests under this section can be submitted to contact@pepticore.co or by calling +1 (571) 688-3488. We will confirm receipt within 10 business days and substantively respond within 45 calendar days, with one 45-day extension available where reasonably necessary and disclosed to you.
Other state consumer privacy laws we honor
A growing number of states have enacted comprehensive consumer privacy laws similar to California’s. Rather than tracking which specific law applies to each customer’s state, we extend the same core rights — access, correction, deletion, and no sale or sharing of data — to every customer nationwide.
VCDPA, CPA & CTDPA
These states grant residents rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising and sale. We honor all of these rights for every customer, regardless of state.
Emerging comprehensive privacy laws
Additional states have passed or are implementing similar consumer privacy statutes. As these laws take effect, we apply their access, correction, and deletion standards to residents of those states as a matter of policy, without waiting for a formal effective date.
State data breach notification laws
Every state requires notification to affected residents in the event of a qualifying data breach. If we ever experience a breach involving your personal information, we will notify you in accordance with the law of your state of residence and, where applicable, relevant state attorneys general.
Children’s privacy and COPPA compliance
Pepticore.co is not directed at, marketed to, or intended for use by anyone under the age of 18, and checkout requires an affirmative acknowledgment that the buyer is at least 21, consistent with our Legal Notice. We do not knowingly collect personal information from children under 13, in compliance with the Children’s Online Privacy Protection Act (COPPA), and we do not knowingly collect personal information from anyone under 18.
If we learn that we have inadvertently collected personal information from a child under 13, we will delete that information promptly. If you believe a child has provided us with personal information, please contact contact@pepticore.co immediately so we can investigate and remove it.
How we secure your information
We use industry-standard SSL/TLS encryption to protect data in transit between your browser and our servers, including at checkout. Payment card data is tokenised and handled directly by our PCI-DSS-compliant payment processor, so full card numbers never touch our own servers.
Internally, access to customer data is restricted to employees and contractors who need it to do their jobs — fulfilling orders, providing support, or maintaining the site — and is protected by access controls and regular account reviews. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work continuously to protect your information using current, reasonable safeguards.
encrypted
Every session, every page
Encryption applies site-wide, not only at checkout.
Cookies and similar technologies
We use cookies and similar tracking technologies to keep your cart working across pages, remember your preferences, and understand aggregated site traffic through analytics tools. Cookies do not give us access to your device beyond the specific data they are designed to collect.
For a full breakdown of every cookie category we use, how long each one persists, and how to manage or disable them in your browser, please see our dedicated Cookie Policy, which forms part of, and should be read alongside, this Privacy Policy.
Marketing email opt-in and opt-out
or on-site signup
emails
one click
We only send marketing email to customers and visitors who have affirmatively checked an opt-in box at checkout or through an on-site signup form — placing an order alone does not automatically enroll you in marketing email, though you will still receive transactional messages such as order and shipping confirmations, which are necessary to fulfil your purchase and are not optional. Every marketing email includes a one-click “unsubscribe” link at the bottom, consistent with the federal CAN-SPAM Act, and we process opt-out requests promptly, typically within 10 business days as required by that Act. You may also unsubscribe by emailing contact@pepticore.co directly.
Do Not Track and Global Privacy Control
Some browsers offer a “Do Not Track” (DNT) setting. Because there is no accepted industry standard for how to respond to DNT, our site does not currently change its behavior when it detects a DNT signal. We do, however, recognize the Global Privacy Control (GPC) signal as a valid opt-out-of-sale-or-sharing preference under the CCPA/CPRA — though as described in Section 7, we do not sell or share personal information for cross-context behavioral advertising in the first place, so a GPC signal does not currently change what data you receive from us.
International data transfers — not applicable
Pepticore operates exclusively within the United States. Our servers, our warehouse, our payment processor, and our shipping carrier all operate domestically, and we currently ship only to addresses within the United States. As a result, your personal information is not transferred outside the United States in connection with your use of pepticore.co, and cross-border data transfer frameworks such as the EU-U.S. Data Privacy Framework do not apply to our operations.
Changes to this policy
We review this Privacy Policy regularly and update it whenever our data practices, vendor relationships, product catalog, or applicable law change. The “last updated” date at the top of this page always reflects the current version. For a material change — one that expands how we use previously collected personal information — we will post a prominent notice on our website and, where you have provided one, email active account holders at least 14 days before the change takes effect. Continued use of pepticore.co after an update constitutes acceptance of the revised policy.
Talk to a real person, weekdays
To exercise any right described on this page, ask a question about our data practices, or report a concern, our support team responds within one business day.