Legal
Last updated: April 8, 2026
Consumer Lead Data: We receive consumer data from upstream e-commerce platforms and partner networks, including names, email addresses, phone numbers, mailing addresses, purchase history, and product interest signals. This data originates from consumers who have transacted on peptide and supplement retail platforms.
Buyer Account Data: When you apply for access to Pepleadz, we collect your name, business email, company name, business type, and intended use case. We also store payment information through our processor (Stripe) — we never store card details directly.
All consumer data in our marketplace includes timestamped consent records and, where available, consent proof URLs. Records that lack valid consent documentation are quarantined and never made available for purchase. Our data is sourced from platforms where consumers have opted in to marketing communications as part of their purchase flow.
All personally identifiable information (PII) is encrypted at rest using AES-256-GCM encryption. PII is only decrypted at the point of CSV delivery to an authorized buyer. Email addresses are stored as SHA-256 hashes for deduplication purposes — the original email is only accessible in the encrypted PII blob.
Access to our database is restricted to authorized personnel. All buyer sessions use encrypted, httpOnly cookies with short-lived JWT tokens. All data transmission occurs over TLS.
Purchased lead data may be used for direct marketing purposes including email campaigns, direct mail, telephone outreach, and digital advertising audience building. Buyers agree to comply with all applicable laws including CAN-SPAM, TCPA, and state privacy regulations. Redistribution or resale of purchased data is strictly prohibited.
Standard leads may be sold to a maximum of three (3) buyers. Exclusively purchased leads are permanently removed from inventory after sale. We retain lead data for a maximum of 18 months from the date of ingestion, after which records are permanently deleted.
If you are a consumer whose data may be in our system and you wish to opt out, please contact us at privacy@pepleadz.com with your name and email address. We will remove your record within 30 days and add your email hash to our permanent suppression list to prevent re-ingestion.
We use Stripe for payment processing, Resend for transactional email delivery, and Fly.io for infrastructure hosting. Each service processes data in accordance with their own privacy policies. We do not sell buyer account data to any third party.
For privacy-related inquiries, contact privacy@pepleadz.com.