1. Current data scope
The pre-launch site does not currently provide customer account creation, live payment collection, or newsletter enrollment. During Sandbox testing, PepX may record test-order information supplied through Stripe Checkout and messages submitted through the order-linked PepX Support system.
2. Browser storage
PepX uses browser storage for the saved cart, the research-use acknowledgment, and a secure support-session token after a customer opens an order-linked support conversation. Support tokens are used to return the same browser to the correct conversation and are not payment credentials.
3. Support conversations
PepX Support verifies an order number against the email used for that order before opening a customer conversation. Support messages, conversation status, related order identifiers, and message timestamps are stored in Supabase so authorized PepX administrators can respond. Email may be used to notify a customer that PepX has replied; the conversation itself remains inside PepX Support.
4. Administrative access
The private PepX Admin interface uses Supabase authentication and database authorization. Administrative access is separate from the public research-use gate and is restricted through the existing admin authorization rules.
5. Payment information
Current checkout testing uses Stripe Sandbox and Stripe-hosted Checkout. PepX does not receive or store full card numbers or CVC values. The PepX backend may store Stripe Sandbox session/payment references, order amount and currency, customer name and email, shipping address, and fulfillment information needed to operate the test order workflow.
6. Future production policy
A final production Privacy Policy should be reviewed and published before live commerce begins. That policy should reflect the final payment, fulfillment, analytics, retention, support, and customer-service practices actually used at launch.