Security Incident Response Policy
Last updated: July 21, 2026
Drop-USA (“we”, “us”) takes the security of merchant and customer data seriously. This policy describes how we detect, respond to, and recover from security incidents, and how we notify affected parties. It applies to all systems, data, and personnel involved in operating the Drop-USA platform.
1. Definitions
- Security incident — any event that compromises, or is reasonably likely to compromise, the confidentiality, integrity, or availability of systems or data we process.
- Personal data breach — a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data (including a merchant's customers' names, addresses, or phone numbers).
2. Roles & responsibilities
The platform owner is the Incident Response Lead and is responsible for coordinating detection, containment, assessment, notification, and recovery. Where needed, the Lead engages our infrastructure providers (hosting and database) and, when a merchant or their customers may be affected, communicates with Shopify and the affected merchants.
3. Detection & reporting
We monitor application logs, infrastructure/access logs, error alerts, and provider notifications. Anyone who becomes aware of a suspected incident must report it immediately to sales@drop-usa.com. Every report is triaged promptly.
4. Response phases
- Identify — confirm the incident, its scope, and the systems and data types involved.
- Contain — take immediate action to limit impact (e.g., revoke or rotate compromised credentials and API tokens, disable affected access, isolate systems).
- Assess — determine what data was affected, how many merchants/customers are impacted, and the root cause.
- Notify — see Section 5.
- Eradicate & recover — remove the cause, restore from clean encrypted backups where necessary, and verify systems are secure before returning to normal operation.
- Review — conduct a post-incident review and implement corrective actions to prevent recurrence.
5. Notification
When an incident affects, or is reasonably likely to affect, personal data we process on behalf of merchants:
- We will notify Shopify and the affected merchants without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
- Our notification will describe, to the extent known: the nature of the incident, the categories and approximate volume of data and merchants/customers affected, the likely consequences, and the measures taken or proposed to address it.
- Where required by applicable law, we support merchants in notifying affected individuals and relevant supervisory authorities.
6. Safeguards we maintain
- Encryption of data in transit (TLS) and at rest, with API tokens and credentials additionally encrypted using AES-256-GCM.
- Tenant-scoped data access so each merchant's data is isolated.
- Access limited to authorized personnel, protected by strong authentication.
- Encrypted, automated backups with point-in-time recovery.
- Data minimization and defined retention, including deletion on uninstall and honoring Shopify's data-erasure (redact) webhooks.
7. Review
We review and update this policy periodically and after any significant incident.
8. Contact
Report a security concern or incident: sales@drop-usa.com.
