KDD Brands

KDD BrandsStore Integration → Security

Security & incident commitments

What we commit to if something goes wrong with Store Integration: how fast we start, who we tell, and when.

Why this page is a summary

We maintain a full incident-response runbook internally. It is deliberately not published, because it enumerates our credentials and where they are rotated — publishing it would hand an attacker a checklist. What is published here are the commitments a merchant can hold us to. The security weaknesses that affect merchants are disclosed in full in the privacy policy’s known-gaps section, not hidden behind this page.

Reporting a vulnerability or incident

Email security@kddbrands.com. If the report concerns personal data, copy privacy@kddbrands.com. Please include what you observed, when, and how to reproduce it. We will acknowledge and tell you what we are doing about it. We will not pursue action against anyone who reports a genuine issue to us in good faith and does not exfiltrate data or degrade service while finding it.

Severity and response times

Severity is assigned within one hour of detection. Where the call is borderline, we assign the higher level.

SeverityDefinitionResponse starts
S1 Confirmed or suspected exposure of personal data or credentials, or unauthorised access. Immediately
S2 Money or subscription contracts affected, no data exposure — for example incorrect charges or a stalled billing run. Within 2 hours
S3 App broken for merchants, no money or data impact. Same day
S4 Degraded but working — elevated latency, a non-critical background job failing. Next working day

An S1 is treated as a personal-data breach until proven otherwise. The notification clock below starts immediately, not after the investigation concludes.

Who we notify, and when

Shopify

We notify Shopify of a security incident affecting Shopify merchant or customer data without undue delay and no later than 24 hours after becoming aware of it, as the Shopify Partner Program terms require. We treat 24 hours as a hard ceiling, not a target. We send what is known, mark the unknowns, and follow up — we do not delay notification to finish investigating.

Merchants

We notify every affected merchant without undue delay — for an S1, the same day — by email to the store contact. You will get what you need to make your own regulatory decision: the categories of data involved, approximate record counts, the time window, and whether data was accessed or merely exposed.

Regulators and data subjects

For personal data we process on a merchant’s behalf, we are the processor and the merchant notifies — GDPR Article 33 gives them 72 hours from their awareness, which starts when we tell them. Our delay eats their budget, which is why the timelines above are tight. We will not attempt to notify a supervisory authority on a merchant’s behalf.

For data where we are the controller (merchant staff records held in the app’s session store), we notify the relevant supervisory authority within 72 hours where the breach is likely to result in risk to those individuals.

Customers

Only via the merchant. The app never contacts a merchant’s customers directly about an incident.

After an incident

Within five working days of closing any S1 or S2 we write a post-incident review covering the timeline, the root cause, the data impact with record counts, and the follow-up actions with owners and dates — including at least one detection improvement, because “a merchant told us” is itself a finding.

If the review shows that anything stated in our privacy policy or data retention policy was inaccurate, we correct those documents as part of the same change.

What we do not claim

Store Integration is run by a single operator without a formal 24/7 on-call rota, and there is no intrusion-detection system in front of it. We do not hold SOC 2 or ISO 27001 certification and do not claim to. The known gaps section of the privacy policy lists the specific technical weaknesses so that anyone relying on this app can price the risk accurately.


Last reviewed 2026-07-26 · KDD Brands LTD (company 16411950) · security@kddbrands.com