What's on the label is the measured result — net peptide mass, not gross powder weight, plus RP-HPLC purity, on a lot-numbered COA for every batch.
Net peptide mass and RP-HPLC purity — a lot-numbered COA for every batch.
Net peptide mass + HPLC purity, per lot.
PCAC will review 7 peptides for the 503A bulks list, BPC-157, KPV, TB-500, MOTS-c, Emideltide, Semax, Epitalon. Read our briefing →
PCAC will review 7 peptides for the 503A bulks list. Read →
FDA PCAC reviews 7 peptides in July. Read →
Legal
The plain-English account of what we do with the details you send when you browse the catalog or submit a sourcing inquiry — and the rights you keep over them.
Effective date: May 16, 2026
PeptideXpo is the catalog-and-sourcing storefront operated by PeptideXpo from Shanghai, China. This policy describes what happens to the information you hand us when you browse peptidexpo.com or send a sourcing inquiry — nothing more. Our buyers are compounding pharmacies, research institutions, biotech and pharmaceutical R&D teams, medical-aesthetic and cosmetic brands, and licensed distributors; this is a B2B desk, not a consumer storefront.
In plain terms: we collect the minimum we need to quote your order, we don't sell it, and you can ask us to show, correct, or delete it. The detail below exists so the policy holds up under the General Data Protection Regulation (EU GDPR), the California Consumer Privacy Act (CCPA/CPRA), China's Personal Information Protection Law (PIPL), and comparable laws in the markets we ship to.
Roles, for the record: under the GDPR, PeptideXpo is the data controller for what you submit here; under the PIPL, PeptideXpo is the personal-information processor (handler).
We split the data we hold into two buckets: what you type into an inquiry, and what the infrastructure records automatically.
You give us directly, when you submit an inquiry or request a sample COA:
The platform records automatically, for security and measurement:
We do not knowingly gather special-category data — health, biometric, racial, political, religious, or sexual-orientation information — through this Site, and we ask that you not send it.
Each thing we do with your data rests on one of these lawful bases:
The information above is used to:
We never sell, rent, or trade your personal information to anyone for their own marketing.
A handful of vendors process this information on our behalf. Each is under a written data-processing agreement that requires confidentiality and security at least as strong as our own:
There are no marketing-data brokers, ad-tech retargeting networks, or social-media tracking pixels on this Site.
We're based in China and several of our processors sit in the United States and elsewhere, so your information will move across borders. Here's the legal cover for each leg:
Want to see the underlying transfer agreements? Write to the contact in the closing section and we'll provide copies.
We keep your data only as long as the purpose — or the law — requires:
Once a retention window closes, we securely delete or irreversibly anonymize the data.
Depending on which law covers you, you may hold some or all of these rights over your personal information:
To use any of these, email info@peptidexpo.com with the subject "Privacy Request" and tell us which right you want to exercise. We reply within 30 calendar days and may ask you to verify your identity first.
Three smaller points, grouped together:
Marketing — beyond directly answering your inquiry, we email you sourcing intelligence, regulatory briefings, or new-SKU announcements only if you explicitly opted in. Every such email carries a one-click unsubscribe, honored within 5 business days.
Cookies — we run a deliberately minimal set of cookies and similar technologies; our Cookies Policy lists each one with its duration and how to manage it.
Minors — this Site is for qualified business buyers and is not aimed at anyone under 18. We don't knowingly collect data from minors; if you think one has reached us, tell us and we'll delete it.
Your information sits behind industry-standard safeguards:
No system is ever 100% secure. We work hard to protect your data but can't guarantee the impossible, so we suggest your own safeguards (encrypted email, secure file transfer) when sending sensitive commercial or regulatory documents.
Should we discover a breach affecting your personal data, we notify the relevant supervisory authority within 72 hours where the law requires it (GDPR Article 33), and we tell you directly, without undue delay, whenever the breach is likely to put your rights and freedoms at high risk (GDPR Article 34, PIPL Article 57).
Questions, requests, or anything privacy-related:
We may revise this policy as the law or our operations change. When we do, we update the Effective Date above and, for material changes, post a notice on the Site. Continuing to use the Site after that date means you accept the updated policy.