How to judge any tool in this category
Three questions sort tools faster than any feature comparison, and they are the same three at every layer of the stack.
- What does its written policy say? Not the sales page: the acceptable use policy, the restricted business list or the terms. Those are the words quoted back at you when an account is reviewed.
- Can you export your data, today, without asking? Customer records, order history, unsubscribes and bounces. If the answer involves a support ticket, you do not have an exit.
- Who controls the account? Whose name is on it, who the upstream provider is, and how many vendors sit between you and the customer.
One thing to settle before the layers: no tool in this list changes what you are allowed to say. That is set by the regulators. The FDA publishes a list of bulk drug substances used in compounding that “may present significant safety risks”, and it names compounds a peptide catalog will recognize. The 2026 warning letters turned on copy, not infrastructure: one letter states “Despite statements on your product labeling marketing your products "for research use only" and "not for human or veterinary use," evidence obtained from your website establishes that your products are intended to be drugs for human use,” checked 7 October 2026. Picking better software narrows a vendor's discretion over your account. As the payments section below shows, even a written approval can be revoked, so narrowing is the honest word. It does not change what your copy is allowed to say, and the wider picture is in our compliance landscape piece.
Storefront
The storefront is the one layer where self-hosting is usually the right call, and WooCommerce on your own hosting is the option that keeps that decision with you. The reason is not cost. It is that a hosted storefront can decide you are no longer welcome, and your catalog, your customer records and your checkout all live inside it when that happens.
Read the hosted option's wording before you assume it bans you, though, because the common claim about it is wrong. Shopify's acceptable use policy does not list research chemicals at all. It is written as principles: “You can't use Shopify to do anything that's illegal where you do business,” and “We don't like to see people try to ‘game’ systems to avoid constraints they don't agree with,” as of 23 September 2026. A principles-based policy is not a safer policy. It means the judgment is made case by case, by a person, after your store is already live. Why that pattern repeats, and what tends to trigger it, is in our post on Shopify account closures.
Self-hosting moves that judgment to you and hands you the upkeep: hosting, updates, backups, PCI scope and a developer who can be reached. What it does not move is the payment layer.
Payments
Payments is the layer where the wording is most specific, so read it closely. Stripe publishes a page titled Prohibited and Restricted Businesses. The distinction in that title matters. It carries two lists with two different consequences, and an item in one is not an item in the other.
The Prohibited list opens “You must not use Stripe's services for any illegal activities or for the businesses or product types listed below,” and the item “Incorrectly labeled research chemicals” sits in that list. The Restricted list opens “Businesses in these categories require additional due diligence by Stripe in order to confirm our ability to support them,” and the item “Card-not-present prescription-only products and pharmaceuticals” sits there. Stripe also states that where it does approve a business, “the approval is specific to each service offer, and it may be modified or revoked by Stripe at any time per the terms of the Stripe Services Agreement.” All three were checked on the live page on 7 October 2026.
Note what the page does not say. The word peptide does not appear on it. The qualifier in that first item is “incorrectly labeled,” a statement about your labeling rather than about the compound. A revocable approval is a real answer rather than a loophole. Read the current list, then ask the processor directly about your own catalog and keep the answer in writing. Options beyond the default are in our payments post.
Email is the layer where the category is named outright, and only once. Brevo's anti-spam policy lists, under content it does not accept regardless of legality, “Peptide-based products for injectable or oral human therapeutic, weight-loss, or performance use (e.g. GLP-1 analogues, growth hormone peptides), including those labeled "research use only", whether or not sold under prescription or legal in the recipient's jurisdiction,” as of 23 September 2026.
Every other mainstream platform is broader and quieter. Klaviyo's acceptable use policy says “You may not use the Services to offer products or services related to: ... Prescription medications, pharmaceutical products or services, medical therapies, telehealth, and other related technologies, products, or services,” as of 23 September 2026. The word peptide is not in it. That is the whole problem with judging this layer on features: two platforms can look identical in the demo and sit at opposite ends of the policy question. Every clause we track, quoted in full, is in the policy table for email platforms, and the live tracker is at platform policies.
What to require at this layer: a policy that accepts the category in writing, sending from your own domain, and an export that includes your suppression list. That last one decides how expensive a future move is. This is the layer Amino Engine is, so the specifics are ours. You get flows, campaigns, a drag-and-drop builder and segments. Signup forms come as a popup, flyout, embedded form or hosted page, with double opt-in built in. Mail sends from your own domain, on servers and IP addresses we run, and new senders are warmed up over 42 days. The flow library has 82 ready-made flows. There is a WooCommerce plugin today and Shopify is next, which is what makes the self-hosted storefront above a practical choice. Full detail is on the email marketing for peptide brands page, and the WooCommerce specifics are on the WooCommerce page.
If you are weighing running the mail yourself instead, the costs are compared option by option in own email server versus a platform. The authentication requirements that apply to every sender are in our deliverability guide.
SMS
SMS is the layer where the rules sit furthest from the vendor you buy from. Your messages travel over carrier networks. The provider sits between you and the carriers, so it passes their requirements through to you in its own terms. The policy that covers Twilio and SendGrid is a single acceptable use policy that states in its own words “The prohibited conduct in this AUP is not exhaustive,” and that “If Customer or any End User violates this AUP, Twilio may suspend Customer's use of the Services,” checked on 7 October 2026.
Read that pair together: the list of banned conduct is explicitly open-ended, and the consequence is suspension. So the questions to ask a messaging provider are the boring ones. Does your consent record show when and where each number opted in? Can you export it? Which campaign type did the provider register you under? None of that is a feature anyone demos, and all of it is what you are asked for when a campaign is reviewed.
CRM and wholesale
Many brands sell two ways at once: direct to customers, and to clinics or resellers on terms. If you do, those are different records, and the stack usually grows a CRM when the second one outgrows a spreadsheet.
What to look for, in order. First, the record model: can it hold an account with several contacts, its own pricing and its own terms, rather than forcing every buyer into a single customer row? Second, roles, so a fulfillment contractor can see shipping without seeing the whole customer list. Third, and the one people skip, a full export on demand in a readable file.
Judge an export by trying it before you commit, not by reading that it exists. A tool that exports customers but not order history has told you something about who owns your data.
Four shapes of tool show up here, and the right one depends on how much of your volume is wholesale. The order records your store already keeps are often enough for a while. A spreadsheet works until two people need to edit it at once. A general-purpose CRM is built around accounts and contacts, and usually knows nothing about your stock. An inventory or ERP system is built around stock and lots, and is heavier to run. We do not rank or price other vendors here, because their written policies decide more than their feature lists do.
Two neighboring layers read the same records, so settle them at the same time. Inventory: whether stock is tracked per lot and per unit, and whether a sale deducts it without anyone retyping it. Books: whether orders, costs and invoices reconcile without re-entry, so margin is readable per order rather than per quarter.
Documentation and lot records
This is the layer a feature comparison will not decide for you, and it is the most peptide-specific decision you will make. A wholesale buyer eventually asks which lot a shipment came from. Answering that from a search through email is not a system.
Decide three things and write them down. Where the certificate of analysis for each lot lives, and whether it is the version you actually shipped against. Whether an order record can name its lot, so the question goes one way and back again: which lots went to this account, and which accounts got this lot. And who is allowed to change a document after it has been attached to an order, because an audit trail that anyone can edit answers nothing.
Lot documents outlive the tool you first put them in. Keep them somewhere you can export in bulk, named with the lot and the date, whatever system points at them.
Analytics and tracking
Two things to get right here, and both are about honesty rather than dashboards. The first is consent. Record what each visitor agreed to, when, and on which form, and keep that record where you can read it later. Checkout consent and a marketing opt-in are not the same permission, and treating them as one is a common reason a brand cannot prove consent when it needs to. Our compliance checker walks the email side of that.
The second is attribution you can explain. Browser-side tracking loses events to blockers and privacy settings, which is why server-side events from your store are worth the setup. More important is knowing the rule each number is counted under. Ours is stated rather than implied: revenue is attributed to the last email click within five days, and opens never count. Any tool reporting a revenue figure should be able to name its window and its trigger in one sentence. If it cannot, you are comparing two numbers that measure different things.
Shipping and support
Shipping holds one stack decision: whether labels and tracking write back into the order record automatically. If they do not, support reads two systems to answer one question, and the lag shows up in replies. For support itself, keep the inbox on your own domain and the history exportable, the same two tests as every other layer.
A starter stack checklist
Layer by layer, the question to settle before you buy, and the thing most brands get wrong.
| Layer | The question to settle first | The common mistake |
|---|---|---|
| Storefront | Who can switch it off, and what leaves with you if they do | Assuming a principles-based policy is a safer policy |
| Payments | Which of the processor's two lists your products fall under, in writing | Quoting an item from the prohibited list as though it were merely restricted, or the reverse |
| Whether the written policy accepts the category, and whether suppression exports | Choosing on features, then reading the acceptable use policy after the account review | |
| SMS | Whether your consent record is exportable and shows when and where each number opted in | Treating a checkout tick as marketing consent |
| Ads (our ads launcher) | Who owns the ad account and the pixel, and whether every change is written down | Buying tooling to work around a review decision instead of fixing the copy that triggered it |
| CRM and wholesale | Whether an account can hold several contacts, its own terms and its own lots | Testing the export after signing rather than before |
| Inventory and stock | Whether stock is tracked per lot and per unit, and whether a sale deducts it automatically | Running stock in a spreadsheet the storefront cannot see |
| Books and invoicing | Whether orders, costs and invoices reconcile without re-entry | Working out margin once a quarter from exports instead of per order |
| Documentation and lot records | Whether an order record can name its lot, and who may change a document after it is attached | Keeping lot documents only in email or only inside one tool |
| Analytics | What window and trigger each revenue number is counted under | Comparing two attribution models as if they were one metric |
| Shipping and support | Whether tracking writes back to the order, and whether the archive moves with you | Leaving support on a vendor domain |
On the ads row: access to ours is by request to support@aminoengine.com. Worth saying plainly, because the question comes up. No tool at that layer is a way around an ad review decision. Anything sold to you on that basis is selling you a bigger problem. The policy wording that applies to peptide advertising is quoted on our tracker of ad and email platform policy clauses.
Where to start
Building from nothing, the order that wastes least work is storefront, then payments, then email, then the rest. The first two are hardest to change later and have the clearest written policies to read first. Email is third because it is the layer that earns.
For teams that want to build with an agent rather than click through screens, there is an API and an MCP server on our side. An AI agent can build flows and emails as drafts, and a person switches them live. Migration does not cost you your history either: you import from Klaviyo or Brevo by CSV, and unsubscribes and bounces carry over as unsubscribes and bounces. Plan detail, including email volume by plan: See pricing.
If you would rather not assemble this yourself, start at our build and grow pages.
This is general information, not legal advice.