PeppermintProfile information
Account Security
PeppermintProfile representatives will not ask for your password or one-time security code.
Protecting your account also means protecting the email address, devices, passwords, and recovery information connected to it. Use this page to recognize common account threats, preserve useful evidence, and choose the right place to report a problem.
Protect your account access
- Use a unique password that you do not use for another account. PeppermintProfile passwords must be at least eight characters; a longer password is safer.
- Keep the email account and devices connected to your PeppermintProfile account secure.
- Do not let another person sign in as you or keep your account signed in on a shared or public device.
- Sign out and close the browser when you finish using PeppermintProfile on a device you do not control.
- Enter account credentials only after you have opened PeppermintProfile through a trusted address or bookmark.
Passwords and recovery information
Treat passwords, recovery links, recovery codes, security answers, and access to your email account as private account credentials. Anyone who obtains them may be able to act as you.
Do not send a password, verification code, recovery link, or full payment credential through a profile, message, report, email reply, or support conversation. Legitimate support should not require your password to investigate an account problem.
If a password has been exposed or reused on another compromised service, stop using it and change it through a verified account control or with assistance from the appropriate support provider. Secure the connected email account as well.
Phishing and verification-code scams
Be cautious when a message, call, profile, or website claims that your account will be suspended, verified, refunded, paid, or restored only if you act immediately.
- Do not share a password or verification code, even when someone claims to represent PeppermintProfile.
- Do not approve an unexpected sign-in, password, payment, or recovery request.
- Avoid opening unexpected links or attachments. Open PeppermintProfile directly when you need to check your account.
- Check the sender, destination, spelling, and request itself rather than trusting a logo, display name, or urgent warning.
- Stop the interaction and report it when someone requests credentials, payment, or sensitive information to fix an account problem.
Suspicious or unauthorized activity
Warning signs may include profile, business, listing, message, transaction, email, or account changes you did not make; credentials that unexpectedly stop working; or communications sent from your account without your permission.
- Stop responding to suspicious messages and do not approve additional requests.
- Secure the connected email account and any other account that used the same password.
- Review the information you can safely access for changes you did not make.
- Preserve relevant evidence before correcting or removing visible unauthorized content when practical.
- Use Report a Concern under Support and clearly state that you suspect unauthorized account access.
Impersonation and fake support
A profile name, business name, logo, badge, or copied message does not by itself prove that someone is PeppermintProfile staff or the person or business they claim to represent.
Report profiles, businesses, messages, or websites that impersonate you, your business, PeppermintProfile, or another person or organization. Include the relevant profile or listing address and explain what is false or misleading.
Preserve evidence and report safely
When available, preserve the account or profile address, sender information, messages, dates and times, screenshots, transaction or listing details, and a factual description of changes or requests you did not authorize.
Do not include your password, verification code, recovery link, full payment-card number, or other secret credential in a report. Do not reopen a suspicious link merely to collect more evidence.
A report does not automatically prove unauthorized access or impersonation. Reports are reviewed under the applicable rules and available evidence. No response time, account restoration, reimbursement, or enforcement outcome is guaranteed before review.