KDD Brands → Store Integration → Security
Security & incident commitments
What we commit to if something goes wrong with Store Integration: how fast we start, who we tell, and when.
We maintain a full incident-response runbook internally. It is deliberately not published, because it enumerates our credentials and where they are rotated — publishing it would hand an attacker a checklist. What is published here are the commitments a merchant can hold us to. The security weaknesses that affect merchants are disclosed in full in the privacy policy’s known-gaps section, not hidden behind this page.
Reporting a vulnerability or incident
Email security@kddbrands.com. If the report concerns personal data, copy privacy@kddbrands.com. Please include what you observed, when, and how to reproduce it. We will acknowledge and tell you what we are doing about it. We will not pursue action against anyone who reports a genuine issue to us in good faith and does not exfiltrate data or degrade service while finding it.
Severity and response times
Severity is assigned within one hour of detection. Where the call is borderline, we assign the higher level.
| Severity | Definition | Response starts |
|---|---|---|
| S1 | Confirmed or suspected exposure of personal data or credentials, or unauthorised access. | Immediately |
| S2 | Money or subscription contracts affected, no data exposure — for example incorrect charges or a stalled billing run. | Within 2 hours |
| S3 | App broken for merchants, no money or data impact. | Same day |
| S4 | Degraded but working — elevated latency, a non-critical background job failing. | Next working day |
An S1 is treated as a personal-data breach until proven otherwise. The notification clock below starts immediately, not after the investigation concludes.
Who we notify, and when
Shopify
We notify Shopify of a security incident affecting Shopify merchant or customer data without undue delay and no later than 24 hours after becoming aware of it, as the Shopify Partner Program terms require. We treat 24 hours as a hard ceiling, not a target. We send what is known, mark the unknowns, and follow up — we do not delay notification to finish investigating.
Merchants
We notify every affected merchant without undue delay — for an S1, the same day — by email to the store contact. You will get what you need to make your own regulatory decision: the categories of data involved, approximate record counts, the time window, and whether data was accessed or merely exposed.
Regulators and data subjects
For personal data we process on a merchant’s behalf, we are the processor and the merchant notifies — GDPR Article 33 gives them 72 hours from their awareness, which starts when we tell them. Our delay eats their budget, which is why the timelines above are tight. We will not attempt to notify a supervisory authority on a merchant’s behalf.
For data where we are the controller (merchant staff records held in the app’s session store), we notify the relevant supervisory authority within 72 hours where the breach is likely to result in risk to those individuals.
Customers
Only via the merchant. The app never contacts a merchant’s customers directly about an incident.
After an incident
Within five working days of closing any S1 or S2 we write a post-incident review covering the timeline, the root cause, the data impact with record counts, and the follow-up actions with owners and dates — including at least one detection improvement, because “a merchant told us” is itself a finding.
If the review shows that anything stated in our privacy policy or data retention policy was inaccurate, we correct those documents as part of the same change.
What we do not claim
Store Integration is run by a single operator without a formal 24/7 on-call rota, and there is no intrusion-detection system in front of it. We do not hold SOC 2 or ISO 27001 certification and do not claim to. The known gaps section of the privacy policy lists the specific technical weaknesses so that anyone relying on this app can price the risk accurately.
Last reviewed 2026-07-26 · KDD Brands LTD (company 16411950) · security@kddbrands.com