Security incident response policy

This page covers the HideMyDrop application served at app.hidemydrop.com. It describes what the service does to protect the data it processes and how it reacts when that protection fails. It complements the privacy policy and the data processing agreement. The French version of this page is the authoritative one.

Who responds

The service is published by GRT Ventures OÜ, a company incorporated in Estonia. It is run by a single operator, the company's legal representative, who handles incident response from start to finish. That person can be reached at support@hidemydrop.com, repeated at the bottom of this page. There is no on-call team: this page describes what one person does, in what order and within what deadlines.

What the service calls an incident

A security incident is any event, confirmed or suspected, that leads to the destruction, loss, alteration or unauthorised disclosure of data processed by the service, or to unauthorised access to that data or to the accounts holding it. The following fall under that definition, without the list being exhaustive:

Data concerned

On the merchant side, the service holds the contact e-mail address, the password in hashed form, the shop domain and shop name, the API keys, the Shopify access token, the subscribed plan with its usage data, and the sign-in history of the account. On the buyer side, for each order sent by the shop, it holds the e-mail address and name, the destination country code, the order number, amount and currency, the carrier tracking numbers and the masked tracking identifier, and the parcel's transport events. The service neither receives nor stores the buyer's postal address or phone number. The detail of each category and the retention periods are set out in the privacy policy.

Measures in place

The measures below exist in the code and on the server as of the date shown at the bottom of this page. They are described as they are, without certification or external audit.

Detection and reporting

The service has no monitoring centre. Detection rests on four sources: the service's logs (technical log, account event log, sign-in history), the operator's regular reading of the back office, reports received at support@hidemydrop.com, and notices from the hosting provider, from Shopify or from a sub-processor.

Anyone, merchant, buyer or third party, who notices abnormal behaviour of the service or believes they have found a flaw can write to support@hidemydrop.com. The message can stay anonymous and it is read by the operator in person. The service pays no discovery bounty. It only asks that the flaw not be exploited and that the data it would expose not be circulated before it is fixed.

Qualification within 24 hours

A report or an anomaly is examined within 24 hours of its receipt. The examination answers four questions: is this an incident within the meaning of this page, which data and which accounts are affected, since when, and is the exposure still ongoing. An incident file is opened at that point, with a reference, the time the service became aware and the timeline of the known facts. A report that turns out to be unfounded is recorded all the same, with the reason.

Containment

Containment aims first to stop the exposure, even before its cause is understood. Depending on the case, the operator:

Return to service follows the correction of the cause, then a check that the exposure has stopped.

Notification

Merchants. When an incident affects a merchant's data or that of their buyers, the merchant is informed at the e-mail address of their account no later than 72 hours after the service became aware of it, as provided in section 6 of the data processing agreement. The message describes the nature of the incident, the categories of data and of persons concerned, the likely consequences, the measures taken and those the merchant can take on their side. For the data of their buyers, the merchant is the data controller: notifying their supervisory authority and, where applicable, the buyers is their responsibility. The service provides them with the material needed.

Supervisory authority. For the data of which GRT Ventures OÜ is the controller, that is, the data of merchant accounts, the breach is notified to the competent supervisory authority, the Andmekaitse Inspektsioon, the Estonian data protection authority, within 72 hours of becoming aware of it, in accordance with Article 33 of the General Data Protection Regulation, unless the breach is unlikely to result in a risk to the persons concerned. If the notification cannot be complete within that period, it is made in phases. Where a high risk exists for the persons, they are informed directly, in accordance with Article 34 of the same regulation.

Shopify. When data obtained through Shopify is concerned (shop data, order data or access token), Shopify is informed of any breach, actual or suspected, within 24 hours of the service becoming aware of it, through a report to Shopify Support (partner contact form), as required by section 6.2.10 of the Shopify API terms of use.

Post-mortem and incident file

Once the incident is closed, the operator writes a report: timeline, cause, data and accounts affected, containment measures, notifications made, corrections applied to the code or to operations, and what would have allowed earlier detection. That report joins the incident file.

The file is kept by GRT Ventures OÜ, as required by Article 33(5) of the regulation, which asks for every breach, its effects and the measures taken to be documented. It is made available to the supervisory authority and, for what concerns them, to the merchant.

Certifications and availability

The service holds no security certification and commits to no numerical availability rate. The measures described here are the ones that exist. Their list evolves with the code, and the date at the bottom of this page indicates the state described.

Changes

This page may evolve with the service. The date of the last update is shown at the bottom.