Payments are where peptide businesses actually die. Not the FDA letter, not the domain, not the marketing - the day the processor freezes the account and the store can't take money. This page is the full picture: why the mainstream rails ban the category, what BRAM and VAMP actually are, and the architecture that survives. We run this stack in production across 50+ research-use-only storefronts, so this is operations, not theory.
Why Stripe, PayPal, and Square all say no - it's the category, not you
New operators burn their first two weeks discovering the same fact one platform at a time: Stripe's restricted-business list bans "pseudo-pharmaceuticals" and research chemicals. PayPal's Acceptable Use Policy prohibits drug-adjacent products not approved for sale. Square's prohibited-goods list covers the same ground. Shopify Payments inherits Stripe's rules, so a peptide store on Shopify usually loses payments and the storefront in one email.
None of these are judgment calls made about your specific site. They're category bans written into terms of service, enforced by automated scans of your product catalog and your public pages. The scan does not care that your copy is careful or your COAs are real. It matches "BPC-157" or "peptide" against a keyword list and files the account for review. If Stripe already shut your store down, that's the mechanism - and the typical outcome is termination plus funds held 90-180 days as a chargeback reserve.
So the useful question is not "how do I get Stripe to approve me" - you won't, not durably - it's "what does the payments world look like one level down, where the rules actually come from."
BRAM and VAMP in plain English, including the April 2026 drop to 1.5%
Two Visa programs explain most of what happens to peptide merchants.
BRAM - Business Risk Assessment and Mitigation - is Visa's brand-protection program. It defines categories of "illegal or brand-damaging" transactions and fines the acquiring bank when one of its merchants is caught selling them. Fines run to five figures per violation, and the acquirer eats them, not you. Unapproved pharmaceuticals and drug-like products sit squarely in BRAM's scope. This is the single most important fact in peptide payments: your processor's bank is personally on the hook for what you sell. That's why underwriting is paranoid and why terminations are instant rather than negotiated.
VAMP - the Visa Acquirer Monitoring Program - is the newer dispute-ratio regime that replaced the old chargeback monitoring programs in April 2025. It measures a merchant's combined fraud and dispute count against settled transactions. The number that matters: the threshold that puts a merchant in "excessive" territory dropped to 1.5% in the April 2026 step-down (from 2.2% at launch), with acquirer-level thresholds far tighter. Above the line, the acquirer faces per-transaction enforcement fees and pressure to cut the merchant loose.
Do the arithmetic on a small store: at 200 card transactions a month, four disputes is 2% - over the line. Peptide customers dispute more than average (packages seized, buyer's remorse, "my spouse saw the charge"), which is exactly why the category is priced and monitored as high-risk even at processors willing to touch it.
Why a "research use only" label doesn't move a card network
Operators assume the RUO framing that matters to the FDA also matters to Visa. It doesn't. Card networks aren't parsing intended-use doctrine - they're managing brand risk and fine exposure. A product that a regulator could call an unapproved drug is BRAM-scoped regardless of the disclaimer on the bottle. The RUO framing governs your regulatory posture (and it has to be built properly - see the compliance checklist); it buys you nothing at underwriting for a mainstream processor whose terms ban the category outright.
Where RUO discipline does matter for payments: the high-risk processors who will take the category underwrite the totality of your site, and sloppy human-use copy is the fastest way to fail their review or trigger a later termination. Same copy, two enforcement audiences.
What underwriters actually check
A high-risk acquirer reviewing a peptide merchant application looks at, in rough order:
- The site, read like a regulator. Product pages, blog, FAQ, emails. Human-use language, dosing guidance, or disease claims are an auto-decline - they convert "gray-area research supplies" into "unapproved drugs," which is BRAM territory.
- The catalog. GLP-1 compounds and other actively-enforced substances get applications declined even at processors comfortable with the broader category. What you list is a payments decision, not just an FDA one.
- MATCH. Mastercard's terminated-merchant file. If a previous processor filed you, most acquirers won't proceed - here's how MATCH works and what to do about it.
- Processing history. Three months of statements showing a dispute ratio under about 1% is the strongest asset a peptide merchant can bring. No history means higher reserves.
- The boring corporate stack. Registered entity, EIN, business bank account, a signer with clean personal credit. Missing basics stall files for weeks.
Expect the offer, when it comes, to carry high-risk economics: roughly 4-8% per transaction, a 5-10% rolling reserve held around six months, and a monthly minimum. That's the market rate for a category where the acquirer is absorbing BRAM exposure. The full walkthrough of getting approved is in the peptide merchant account guide.
The three-layer payment architecture
No single rail is reliable enough to bet the business on, so don't. Every store we run ships with three layers, and the store keeps taking orders when any one of them goes down:
- Layer 1 - high-risk card processing. The conversion layer. Card checkout converts best, so you want it - but you treat it as the layer most likely to disappear. Underwritten honestly, monitored for dispute ratio, never lied to about the catalog. Our comparison of the processors actually worth applying to covers the current field.
- Layer 2 - ACH and crypto. Bank-transfer checkout (via a high-risk-tolerant ACH provider) plus self-hosted crypto checkout. Slightly worse conversion, dramatically better survivability - there's no card network in the loop, so BRAM and VAMP don't apply. A serious share of category volume runs here.
- Layer 3 - manual rails. Zelle, wires, mailed payment - order placed, payment instructions issued, a human (or in our stack, an automated email-watcher) confirms receipt and marks the order paid. Ugly, unkillable, and the reason a processor termination is a bad week instead of a dead company.
The architecture only works if the storefront treats rails as swappable modules - add one, lose one, reorder them - without a rebuild. That's a software decision you make on day one, and it's much cheaper then.
Your copy is the #1 termination trigger
Here's the part almost nobody prices in: approval is not the finish line. High-risk processors re-scan merchant sites on a schedule, and the thing their scans catch is copy drift - a product description edited to mention what a compound "helps with," a blog post about benefits, an email flow that reads like a supplement brand. One page is enough. The same sentence that would draw an FDA warning letter also violates your processing agreement, because your acquirer's BRAM exposure is defined by exactly that language.
This is why we treat a copy linter as payment-continuity insurance, not a compliance nicety. In our stack every copy surface - product pages, emails, admin edits - passes through an automated linter that blocks human-use, dosing, and benefit language before it publishes. Enforced in code, not memory, and watched by a human monthly, because the rules keep moving and a rule set from January is stale by July. If you want to know what a processor's scan would flag on your site today, the free 60-second audit reads your storefront the same way they do - takes about a minute, grade on screen.
What a shutdown actually costs
Operators budget for the fee difference between Stripe and a high-risk processor and conclude high-risk is expensive. Wrong baseline. Price the shutdown instead:
- Frozen funds: 90-180 days of your recent card volume held as reserve. For a store doing $40k/month, that's routinely $30k+ locked up while your suppliers still want paying net-15.
- Dead revenue: 2-6 weeks with no card checkout while you scramble for a replacement - unless layers 2 and 3 already exist.
- MATCH: if the termination gets filed, a five-year handicap on every future application.
- The panic tax: decisions made in week two of no revenue are the worst decisions - decoy domains, misdeclared catalogs, "a guy who knows a guy." Each one converts a payments problem into a fraud problem.
A shutdown costs more than the store ever did. The architecture above exists to cap that cost at "annoying."
Where to start based on where you are today
- Not launched yet: build the three layers into the store before day one, and write every word of copy to pass an underwriter's read. Retrofits cost multiples.
- Live on a mainstream processor: you're on borrowed time - the scan hasn't found you yet. Stand up layers 2 and 3 now, then apply for real high-risk processing before the termination email, not after.
- Just terminated: switch checkout to your surviving rails today, confirm whether you were MATCH-filed, and fix whatever the site said before the next application - the next underwriter reads the same pages.
- On high-risk and stable: your job is the dispute ratio and copy discipline. Under 1% disputes and a clean quarterly self-audit keeps you boring, and boring merchants keep their accounts.
Questions, answered straight
Can I just use a personal Stripe or PayPal account quietly?
You can, briefly. The catalog scan or the first dispute finds you, the account is terminated, and funds are held up to 180 days. Worse, a termination for prohibited goods can follow you into MATCH. It's not a rail, it's a countdown.
Is there any processor that "approves peptides" outright?
No mainstream one, and any provider promising guaranteed approval is selling you something. What exists: high-risk acquirers who will underwrite a clean RUO site case-by-case, at high-risk pricing with reserves. That's the honest ceiling.
Does crypto solve this completely?
It solves the card-network problem - no BRAM, no VAMP, no MATCH. It doesn't solve conversion: crypto-only stores leave meaningful revenue on the table, which is why it's a layer, not the whole stack.
What dispute ratio should I hold?
Under 1%, with headroom below the 1.5% VAMP line. Practical levers: clear billing descriptors, tracking on every order, fast refunds on the fence-sitters, and a dispute-alert service so you refund before the chargeback files.
Does cleaning up my copy actually change payment outcomes?
Yes - it's the highest-leverage fix available. Copy is the evidence underwriters decline on and the trigger re-scans terminate on. Same pages, same words, two enforcement audiences. Fix it once, in code, and both risks drop together.
This is general information for store operators, not legal or financial advice. Nothing here is legal advice.
STONEGATE SYSTEMS