Shoprocket Security Policy
We take the security of Shoprocket, our merchants and their customers seriously. If you believe you have found a security issue, please tell us so we can fix it.
How to report
Email [email protected] with a description of the issue, the affected URL and the steps to reproduce it. Please keep the details private until we have confirmed a fix.
What is not permitted
Our Acceptable Use Policy and Terms of Service apply to everyone who uses Shoprocket, including anyone testing its security. Without our prior written permission you may not:
- Run automated scanners, fuzzers or brute-force tools against any Shoprocket service.
- Submit scripts, code or other attack payloads into any form, field, store, product, order or account.
- Run any test that executes against, or collects data from, Shoprocket staff, other merchants or their customers, including blind cross-site scripting payloads and "callback" or data-collection services.
- Access, copy, keep or publish data that does not belong to you.
- Degrade or disrupt the service, including denial of service and spam.
- Use social engineering, phishing or physical attacks against Shoprocket, its staff or its merchants.
If you come across data that is not yours, stop, do not keep it, and tell us.
What happens next
We review every report and fix confirmed issues. We do not run a paid bug bounty programme and do not pay for reports, and we do not agree disclosure timelines in exchange for payment or credit.
Activity that breaks this policy is a breach of our Terms. We may suspend the accounts involved, block the sources used, and take any further action available to us.