Short answer: no. Peptides are prohibited under Shopify's Acceptable Use Policy, and Shopify Payments is built on Stripe, which prohibits them separately. Nothing stops you at signup, which is exactly why so many founders find out the expensive way.
The verdict first: prohibited, enforced mid-flight, no appeal that works
Shopify's AUP bans "restricted items," a category its enforcement teams read to include research chemicals, non-FDA-approved substances, and injectables. Research-use-only peptides tick all three. There is no license you can upload, no compliance packet you can attach, no plan tier that changes it. This isn't a gray area you can lawyer your way through - it's a business decision Shopify made about chargeback exposure and card-network risk, and they enforce it with software plus a human review queue.
The part that costs people real money: enforcement is not at signup. Shopify happily takes your $39/mo, lets you install a theme, load 40 products, and start selling. Detection typically comes later - triggered by a payment-risk review, a chargeback, a competitor report, or a periodic content scan. By then you have revenue in the pipeline, ad spend committed, and customers mid-order. We wrote up the full teardown pattern in what actually happens when Shopify bans a peptide store - if you're already staring at a termination email, start there.
Two layers of ban - Shopify's AUP plus Stripe under Shopify Payments
Here's the piece most founders miss. Shopify Payments is not Shopify's own processor - it's Stripe, white-labeled. So a peptide store on Shopify is violating two prohibited-lists at once:
- Layer 1: the platform. Shopify's AUP governs what you can list at all. Violate it and the storefront itself gets suspended - products, pages, customer accounts, everything behind their domain.
- Layer 2: the processor. Stripe's restricted-business list bans pharmaceuticals and "products that make health claims without approval," which is how their risk team files peptides regardless of your RUO disclaimers. Violate it and the money stops - even if the storefront were somehow allowed to stand.
Either layer alone kills the business. Together they mean "solving" one buys you nothing. Founders sometimes bolt a third-party gateway onto Shopify thinking they've dodged Stripe - the AUP still applies, and now they're paying Shopify's 0.6%-2% third-party transaction fee for the privilege of waiting for the ban. Others try a peptide-friendly gateway on a platform that allows it - the right instinct, wrong half of the stack. The full processor landscape, including what a real high-risk merchant account looks like, is in our guide to peptide payment processing.
How the ban actually lands: the mid-flight termination pattern
Across the operators we've worked with, the sequence is remarkably consistent:
- Weeks 1-6: nothing. The store runs. Money moves. You conclude the AUP must not really apply to you.
- The trigger. A payout review, a single chargeback, a spike in volume, or a manual report. High-risk detection is event-driven, not calendar-driven.
- The email. "Your store has been found in violation of our Acceptable Use Policy." Storefront offline same day. Shopify Payments payouts paused.
- The hold. Funds in the payout pipeline get held against future chargebacks - typically 90-180 days, at the processor's discretion, with 120 being the number we see most.
- The appeal. You can file one. For a category-level prohibition it does not work, because there is nothing to argue - you sell the thing they ban. The appeal exists for miscategorized stores, and you aren't one.
Total damage is rarely just the held funds. It's the domain reputation, the pixel and ad-account history, the email list stuck in their export queue, and every product URL you'd built links to. A shutdown costs more than the store ever did.
WooCommerce: free, but you inherit three separate fragilities
WooCommerce is the reflex answer, and it's half right. WordPress itself has no AUP - it's software you run, not a platform that hosts you. But "self-hosted" doesn't mean "nobody can shut you down." You've traded one landlord for three:
- Hosting AUPs. Managed WordPress hosts publish their own acceptable-use policies, and the premium ones enforce them. Several name pharmaceuticals and unapproved substances explicitly. A VPS you administer yourself is safer, and now you're a sysadmin.
- Gateway plugins. The Woo checkout everyone installs first is the Stripe plugin or PayPal - the same two processors with peptide sellers on their prohibited lists. Same ban, different logo. PayPal adds its own flavor: the permanent limitation with funds held 180 days.
- Plugin drift. A real Woo store runs 15-25 plugins. Every update cycle is a chance for the checkout to silently break, and there's no vendor on the hook when it does. That's not a compliance risk, it's an operational tax you pay monthly, forever.
WooCommerce can work - some peptide stores run on it - but only when someone deliberately chose the host, the gateway, and the maintenance plan for this exact category. Defaults will kill it.
BigCommerce, Swell, and the case-by-case platforms
BigCommerce's terms prohibit illegal products and reserve broad discretion over "high-risk" categories rather than publishing a peptide-specific ban. In practice that means case-by-case: some stores live for a while, some get the same mid-flight review Shopify runs, and you can't get an approval in writing beforehand. Headless or API-first platforms like Swell and Medusa sit in similar territory - Medusa is open source and self-hostable (genuinely no platform layer), Swell is hosted and retains termination discretion like anyone else.
The honest framing: any platform that can terminate you may terminate you, and no sales rep's verbal "should be fine" survives contact with the risk team. If your business depends on a discretion call staying favorable forever, you don't have a platform, you have a probation officer.
Wix and Squarespace - the short version
Same disease, smaller ecosystems. Wix Payments and Squarespace Commerce both run on mainstream processing (Stripe among them) and both platforms' terms prohibit the category. They're also weaker stores at the same price point: thinner checkout control, weaker structured-data handling, and no path to the kind of compliance tooling this niche needs. There is no version of the Wix-or-Squarespace question where the answer improves on Shopify's - it's the same two-layer ban with fewer features. Skip them.
The owned stack: zero platform risk because there is no platform
The alternative isn't a friendlier landlord. It's no landlord. The stack that survives in this category looks like this:
- Your own storefront code on commodity infrastructure - a standard Node host, your DNS, your database. Infrastructure providers sell compute, not category approval; there is no AUP clause about what your checkout sells because there is no commerce platform in the loop.
- A high-risk merchant account that underwrote your business knowing exactly what it sells - so approval happened before the first sale, not as a bet against a future review. What that underwriting actually requires is covered in the processing guide.
- Compliance enforced in code, not memory. RUO framing, banned-compound guardrails, and copy linting built into the product pipeline - because the FDA reads the totality of a site, and processors read it right after them. The rules keep moving; a human keeps up.
- Ownership of everything. Brand, customers, data, and domain - always exportable, never locked in. When you own the stack, "termination" isn't a thing that can happen to you at the platform layer, because there is no platform layer.
The trade-off is honest: you can't spin it up in an afternoon with a theme store, and it costs more up front than $39/mo. That's the price of the risk actually going away instead of hiding. The full build-vs-platform decision, with numbers, is in which website builder works for a peptide store.
The comparison table, honestly scored
| Option | Platform risk | Payments risk | Honest verdict |
|---|---|---|---|
| Shopify | Banned by AUP | Banned (Stripe underneath) | Dies mid-flight. Not if, when. |
| Wix / Squarespace | Banned by terms | Banned (mainstream rails) | Shopify's problems, fewer features. |
| WooCommerce | None (software) - but host AUP applies | Banned on default gateways; survivable with the right one | Workable only with deliberate host + gateway choices and permanent upkeep. |
| BigCommerce / Swell | Case-by-case discretion | Depends on gateway | You're on probation, not approved. |
| Owned stack | None - no platform exists | Underwritten up front, high-risk account | Highest setup cost, only structure with no termination lever. |
Note what the table doesn't say: it doesn't say the owned stack is risk-free. Processors can still exit you, the FDA can still write letters, and anyone promising you a regulatory outcome is selling you something. What the owned stack removes is the one risk that's certain on the platforms - the AUP termination - and it's the one risk that takes your data hostage when it fires. If you're earlier in the journey than platform selection, start with how to start a peptide company - platform choice is step four, not step one.
Questions, answered straight
Can I just not mention peptides in the product names?
No, and this is the move that turns a ban into something worse. Risk teams read product pages, images, alt text, and order data, not just titles - and the FDA pierced code-named listings in its 2026 warning letters. Obfuscation reads as intent to deceive, which converts "prohibited category" into "fraud risk," lengthens fund holds, and can land you on the MATCH list, which follows you to every future processor.
My friend's peptide store has run on Shopify for a year. Doesn't that prove it works?
It proves detection hasn't fired yet. Enforcement is event-driven - a chargeback, a volume spike, a payout review, a report. Every terminated store we've talked to ran fine right up until the day it didn't, and the ones that ran longest lost the most, because the held-funds figure scales with monthly volume.
What about using Shopify for the site and a separate high-risk gateway for checkout?
The gateway solves layer 2 and leaves layer 1 fully armed. Shopify's AUP governs the listings themselves, so the storefront still gets suspended on review - you've just made the funeral cheaper for the processor. If you're going to the trouble of a real high-risk merchant account, put it behind a storefront nobody can switch off.
Is the owned stack overkill if I'm just testing the market?
Testing on a platform that bans you isn't a test - the variable you're measuring (can this business run?) is rigged to come back "no" on a random date. If budget is the constraint, a deliberately configured WooCommerce build is the cheaper defensible test, with the fragilities above accepted knowingly. What doesn't make sense at any budget is building an asset on land you're already trespassing on.
This guide is general information for store operators, not legal advice.
STONEGATE SYSTEMS