Trust, Security & Privacy
This page is maintained by PeptX to answer common security and privacy questions about the PeptX platform. It is app-owned editable content, not an independent certification or audit.
Shared responsibility
PeptX is built on Lovable Cloud (managed Supabase) for authentication, database, storage, and serverless functions. The underlying platform provides infrastructure controls; PeptX, as the app owner, configures access rules, business logic, and data handling. Customers are responsible for keeping their credentials safe and using the platform within our Terms.
Access & authentication
- Email and password sign-in, plus Google and Apple sign-in
- Sessions secured with rotating JWT access tokens
- Role-based access (Buyer, Supplier, Admin) enforced server-side
- Row-level security applied to every data table in the application database
Platform & hosting
- Hosted on Lovable Cloud, which runs on managed Supabase and Cloudflare
- All traffic served over HTTPS (TLS 1.2+)
- Database encrypted at rest; backups managed by the platform provider
Data we collect & use
See our Privacy Policy for the full breakdown of what we collect, why, and how long we retain it. In short, we collect account, order, shipping, and basic usage data to operate the B2B platform and fulfil orders.
Subprocessors & integrations
- Supabase, Cloudflare: hosting, database, auth, edge functions, CDN
- Fena, Tide, NOWPayments: payment processing
- Twilio: SMS notifications for orders and shipping
- Resend / notify.peptx.co.uk: transactional email
- Google Search Console: SEO performance data
Cookies & analytics
We use essential cookies for sign-in, cart state, and currency selection, plus first-party analytics to understand aggregate usage. Manage cookie behaviour via your browser settings.
Retention & deletion
Account data is retained while your account is active. Transaction records are retained for a minimum of 6 years for legal and tax compliance. You can request account and data deletion at any time by contacting privacy@peptx.co.uk.
Privacy requests
UK/EEA users may request access, correction, deletion, portability, or restriction of their personal data. Email privacy@peptx.co.uk and we will respond within statutory timeframes.
Reporting a security issue
If you believe you have found a vulnerability in the PeptX platform, please email security@peptx.co.uk with a description and reproduction steps. Please do not publicly disclose the issue until we have had a chance to investigate and remediate.
Compliance posture
PeptX operates under UK GDPR and applicable consumer protection law. We do not currently hold independent certifications such as SOC 2 or ISO 27001. If you need additional assurance documentation for procurement, contact support@peptx.co.uk.
General contact: support@peptx.co.uk