Drop-USA

Security Incident Response Policy

Last updated: July 21, 2026

Drop-USA (“we”, “us”) takes the security of merchant and customer data seriously. This policy describes how we detect, respond to, and recover from security incidents, and how we notify affected parties. It applies to all systems, data, and personnel involved in operating the Drop-USA platform.

1. Definitions

2. Roles & responsibilities

The platform owner is the Incident Response Lead and is responsible for coordinating detection, containment, assessment, notification, and recovery. Where needed, the Lead engages our infrastructure providers (hosting and database) and, when a merchant or their customers may be affected, communicates with Shopify and the affected merchants.

3. Detection & reporting

We monitor application logs, infrastructure/access logs, error alerts, and provider notifications. Anyone who becomes aware of a suspected incident must report it immediately to sales@drop-usa.com. Every report is triaged promptly.

4. Response phases

5. Notification

When an incident affects, or is reasonably likely to affect, personal data we process on behalf of merchants:

6. Safeguards we maintain

7. Review

We review and update this policy periodically and after any significant incident.

8. Contact

Report a security concern or incident: sales@drop-usa.com.