Privacy Policy
Last updated July 18, 2026
1. Scope
This Privacy Policy explains how Pepfides LLC ("we," "our," or "us") collects, uses, shares, and protects personal information when you visit pepfides.com, create an account, place an order, or communicate with us. It applies to this website and to the services offered on it. It does not apply to third-party websites we link to.
By using this website you acknowledge this Policy. This Policy is incorporated into, and forms part of, our Terms and Conditions of Purchase.
2. Information We Collect
Information you give us:
- Identity and contact data — name, email address, mobile phone number, and shipping and billing addresses.
- Account data — your login credentials (passwords are stored only as salted hashes by our authentication provider; we never see them in plain text) and your account preferences.
- Order data — the products you buy, order value, order history, and any notes you send with an order.
- Payment data — payment method details are collected and processed by our third-party payment processor. Where you pay by ACH/e-Check, your bank routing and account numbers are transmitted to and held by that processor. We do not store full bank account numbers or full payment card numbers on our own systems; we retain only limited payment metadata such as the last four digits, the payment status, and the processor's transaction reference.
- Qualification and compliance data — your age confirmation, your qualified-researcher attestation, and any identity or KYC verification information we or our processor request in connection with an order or payout.
- Communications — the content of emails, support messages, and SMS messages you exchange with us, and your consent records for each policy you accept.
Information collected automatically:
- Device and connection data — IP address, browser type and version, operating system, device type, and language.
- Usage data — pages viewed, referring and exit pages, links and buttons clicked, time on page, and session timestamps.
- Cookies and similar technologies — see Section 6.
- Session recordings — see Section 7. This is the most privacy-sensitive category of data we collect and we describe it separately for that reason.
We do not knowingly collect information from anyone under 21. See Section 13.
3. How We Use Your Information
We use personal information to accept and fulfill your orders; to take payment and detect and prevent payment fraud; to ship products and provide tracking; to create and maintain your account; to verify age, buyer qualification, and identity where required; to record and evidence the policies you have consented to; to respond to support requests; to send transactional messages about your orders and account; to send marketing messages where you have consented; to operate, secure, debug, and improve the website; and to comply with law, tax obligations, and lawful requests.
We rely on your consent for marketing email and SMS, and you may withdraw that consent at any time without affecting the lawfulness of anything we did before you withdrew it. Withdrawing marketing consent does not stop transactional messages about orders you have placed.
4. How We Share Your Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We are not in the business of monetizing customer data and we do not license, rent, or trade it.
We share personal information only with service providers who process it on our instructions to run this business, and only as needed for that purpose:
- Payment processing — to charge your payment method, validate bank account details, and perform legally required identity, sanctions, and anti-money-laundering screening.
- Shipping and fulfillment — to produce labels and deliver your order, which requires sharing your name and address with the carrier.
- Hosting, database, and authentication — to run the website and your account.
- Email and messaging delivery — to send transactional and consented marketing messages.
- Analytics and product measurement — see Sections 6 and 7.
We may also disclose information where we are legally required to, to comply with a subpoena, court order, regulator, or other lawful request; to enforce our terms; to protect our rights, property, or safety, or that of our customers; or in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or notify you of any material change.
5. Mobile Information and SMS
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories described in Section 4 exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We share your mobile number with our messaging provider solely to deliver the messages you have asked for. We do not sell it, rent it, or pass it to anyone else's marketing list.
Full details of the messaging program — message frequency, rates, and how to get help or stop messages — are in our SMS Terms.
6. Cookies, Analytics, and Tracking
We use cookies and similar technologies that are strictly necessary to operate the site — keeping you signed in, holding your cart, remembering your age and preview acknowledgements, and protecting against fraud and abuse. The site does not work without these.
We also use analytics to understand how the site is used so we can improve it:
- PostHog — product analytics and session recording, processed on PostHog's United States infrastructure. See Section 7.
- Microsoft Clarity — session recording and heatmaps, processed by Microsoft. It helps us see where pages are confusing or broken (for example, repeated clicks on something that isn't working). See Section 7.
- Google Tag Manager — a tag container we use to manage measurement tags. Where it loads Google analytics or advertising tags, those tags may set their own cookies and receive your device and usage data, subject to Google's own policies.
You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will break sign-in and checkout.
7. Session Recording
We record browsing sessions on this website through PostHog and Microsoft Clarity. A session recording reconstructs how a page was used — pointer movement, scrolling, clicks, and page changes — so we can find and fix usability and technical problems. It is not a video of you, your camera, or your screen outside this website.
We configure session recording to mask text entered into form fields, so the characters you type are not captured in the recording. This is deliberately set on our side rather than left to a default. Recordings are retained by our recording providers subject to the retention period in Section 9.
We do not use session recordings to build advertising profiles and we do not sell them.
We do not record sessions for visitors in the European Economic Area or the United Kingdom. We determine this from your browser's time zone, and where it indicates the EEA or the UK we do not load session recording or product analytics at all — there is nothing to opt out of, because nothing is collected. This is a deliberately cautious check: it also excludes some countries outside the EEA, which we accept because we do not ship outside the United States.
If you would prefer not to be recorded, see Section 10 for how to opt out, and Section 11 if you are a California resident.
8. Data Security
We use HTTPS/TLS for data in transit, encryption at rest through our hosting and database providers, hashed credentials, scoped access controls, and PCI-compliant third-party payment processors that keep full card and bank numbers off our systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.
9. Data Retention
We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires:
- Order, payment, and tax records — at least seven (7) years, to meet tax, accounting, and audit obligations.
- Consent records (age, terms, researcher attestation, SMS) — for as long as your account exists and at least seven (7) years afterward, because the point of a consent record is to evidence what you agreed to and when.
- Account data — for as long as your account is open, then deleted or de-identified within a reasonable period after closure, subject to the retention above.
- Support communications — three (3) years from the last message.
- Session recordings and raw analytics — no more than twelve (12) months.
- Marketing and SMS opt-out records — kept indefinitely, because we must retain a suppression record to honor your opt-out.
Where we are required to keep a record you have asked us to delete, we will restrict it to that legal purpose rather than continue using it.
10. Your Choices
Marketing email — use the unsubscribe link in any marketing email, or contact us.
SMS — reply STOP to any message. See the SMS Terms for detail.
Cookies — use your browser settings.
Session recording — we honor the Global Privacy Control (GPC) browser signal. If your browser or extension sends GPC, we do not load session recording or product analytics at all, and we treat the signal as a valid opt-out request under California law. We also honor the legacy Do Not Track header. You can email us to be excluded by any other means.
Account — you can update your details in your account, or ask us to correct or delete them.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to access a copy of it; to correct inaccurate information; to delete it, subject to legal exceptions; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights.
Sale and sharing — we do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA as amended by the CPRA. We have not done so in the preceding twelve (12) months. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" mechanism; we honor GPC signals regardless.
Sensitive personal information — where we collect identity or KYC verification data, we use it only to perform the service you requested, to verify eligibility, to prevent fraud, and to meet legal obligations. We do not use it to infer characteristics about you. We therefore do not use or disclose it for purposes that would trigger the right to limit.
Categories — in the preceding twelve (12) months we have collected identifiers, customer records, commercial information, internet and network activity, geolocation inferred from IP address, and, where requested, identity verification information. We disclosed these categories to the service-provider types listed in Section 4 for business purposes only.
Exercising your rights — email [email protected]. We will verify your request against information already in your account, and we may ask for additional information where we cannot otherwise confirm your identity. We respond within forty-five (45) days and may extend once by a further forty-five (45) days with notice. An authorized agent may submit a request on your behalf with written permission signed by you, and we may still ask you to verify your own identity.
12. Other State Privacy Rights
Residents of Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, and other states with comprehensive privacy laws have broadly similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not sell personal information, do not conduct targeted advertising as those laws define it, and do not profile in a way that produces legal or similarly significant effects.
Use the same contact channel in Section 11 to make a request, and tell us which state you reside in. If we deny your request, you may appeal by replying to our decision; we will respond to the appeal within the period your state's law allows and, where required, tell you how to contact your state Attorney General.
13. Age of Users
This website and the products sold on it are intended solely for qualified researchers aged 21 or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 21. If we learn that we hold information from someone under 21, we will delete it and close any associated account. If you believe a person under 21 has given us information, contact [email protected].
14. Third-Party Links
This website may link to sites we do not control. We are not responsible for their content or their privacy practices, and this Policy does not apply to them. Read the privacy policy of any site you visit.
15. Changes to This Policy
We may update this Policy. When we do, we will post the updated version here with a new "Last updated" date. If a change materially affects how we use your personal information, we will provide additional notice — by email to your address of record or by a notice on the website — before the change takes effect where the law requires it. Continued use of the website after the effective date means you accept the updated Policy.
16. Contact Us
Privacy questions and rights requests: [email protected] — please put "Privacy Request" in the subject line so it reaches the right team. Postal requests can be sent to the mailing address on our contact page; please mark them "Privacy Request" so they reach the right team.
All products sold by Pepfides LLC are for laboratory and research use only and are not for human consumption. You must be 21 or older to purchase.