Réponse aux incidents
Ce que nous faisons en cas de fuite de données, et quand vous en êtes informé.
Ces politiques sont publiées en anglais. Le texte anglais fait foi ; les traductions sont fournies à titre indicatif.
Dernière mise à jour: 2026-08-01
Les informations d'immatriculation de la société exploitant ce service ne sont pas encore publiées. Elles apparaîtront ici et dans le pied de page dès leur confirmation.
Our commitment
If personal data held by ShelfTap is accessed, disclosed, altered or lost without authorisation, we will notify every affected account holder by email within 72 hours of confirming the incident. Where the customer is a controller and we are their processor, notification is sent without undue delay and in any event inside the same window, so they can meet their own regulatory deadline.
What the notification will contain
- What happened and when we became aware of it.
- Which categories of data and roughly how many records are affected.
- The likely consequences.
- What we have already done to contain it.
- What, if anything, you need to do.
- A named contact for follow-up.
If we do not yet know the full scope, we send what we have inside the window and follow up rather than delaying the first notification until the investigation is complete.
How we handle an incident
- Triage. Confirm the report, classify severity, and decide whether personal data is in scope.
- Contain. Revoke sessions, rotate credentials and block the vector. A password reset already invalidates every session for that account through the security-stamp check.
- Assess. Establish what data was reachable, for how long, and by whom, using application and access logs.
- Notify. Affected users, then the relevant supervisory authority where the law requires it — the KVKK Board in Türkiye, the lead EEA authority or the ICO in the United Kingdom.
- Remediate and record. Fix the cause, write it up, and publish a summary if customer data was affected.
Reporting a vulnerability or a suspected incident
Write to support@shelftap.com with "SECURITY" in the subject. We will acknowledge within 48 business hours. We do not currently operate a bug-bounty programme and we do not offer a monetary reward, but we will not pursue anyone who reports a finding in good faith, does not access more data than is needed to demonstrate it, and gives us a reasonable window before disclosing.
What we do not promise
We do not publish an uptime SLA, we do not have a 24/7 on-call rotation, and — as stated on the Aperçu de la sécurité page — we make no commitment about backup restore times, because no backup schedule is currently implemented in the deployed service.