PHP. This is a known weakness in PHP's bcrypt implementation. From Wikipedia, "Many implementations of bcrypt truncate the password to the first 72 bytes." I would hope that they're using a competent implementation that either supports longer passwords or throws an error if it's asked to hash a longer password.
Besides, bcrypt takes the salt as a separate parameter anyway. So it doesn't really make sense in context that the salt, pepper, and password were concatenated and passed to bcrypt. Perhaps he was talking about the SHA-1 stretching; perhaps they hash the passwords with SHA-1 before passing it to bcrypt.
I don't think we know enough to conclude that they were definitely doing it wrong, but it would be nice to know more details about the algorithm, though.