Security Incident Response Policy
1. Purpose
This policy describes how BaseStation Private Limited (“we”) detects, responds to, and recovers from security incidents that may affect DropScan Local, including unauthorized access to or disclosure of protected customer data processed on behalf of Shopify merchants.
2. Scope
This policy covers:
- Production systems that store or process merchant and customer delivery data (application servers, databases, backups, queues, logging)
- Credentials and secrets used to access Shopify APIs and DropScan infrastructure
- Staff accounts with access to production systems or protected customer data
3. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Incident Lead | Founder (Rohit Gupta). Owns classification, containment decisions, merchant/Shopify notification, and post-incident review. |
| Responders | Engineering staff with production access. Execute containment, evidence collection, and remediation under the Incident Lead. |
| Merchants | Report suspected misuse of their store’s data via the contact email above or in-app Help. |
4. What we process (context for incidents)
DropScan Local stores the minimum delivery fields needed for local handoffs: destination name, phone, and address; Shopify order identifiers; line-item summaries for stickers; and staff delivery-proof scan GPS/IP. We do not sell this data. We do not store customer email or payment details for delivery ops.
5. Incident severity scale
| Severity | Examples | Initial response target |
|---|---|---|
| Sev-1 — Critical | Confirmed exfiltration of protected customer data; active unauthorized production access; ransomware / widespread outage with data integrity risk | Acknowledge within 1 hour; contain ASAP |
| Sev-2 — High | Credible unauthorized access without confirmed exfiltration; leaked API tokens or database credentials; significant privilege escalation | Acknowledge within 4 hours |
| Sev-3 — Medium | Suspected intrusion; misconfiguration exposing non-public data; failed but serious attack attempts that require investigation | Acknowledge within 1 business day |
| Sev-4 — Low | Phishing reports with no confirmed access; policy violations without data impact; low-risk vulnerability disclosures | Acknowledge within 2 business days |
6. Response procedure
6.1 Detect & report
- Anyone may report to [email protected] with subject “Security incident — DropScan Local”.
- Monitoring signals (error spikes, auth failures, unusual query volume, host alerts) are reviewed by the Incident Lead.
6.2 Triage & classify
The Incident Lead assigns severity, opens an incident record (time, reporter, systems involved, data types at risk), and decides whether to escalate to Sev-1/Sev-2 war-room mode.
6.3 Contain
- Revoke or rotate compromised credentials and Shopify access tokens
- Isolate affected hosts or revoke network access where needed
- Disable compromised staff accounts; force password resets
- Preserve volatile evidence before rebuilding systems when safe
6.4 Collect evidence
- Capture relevant application logs, activity logs, access logs, and timestamps
- Record actions taken and who performed them
- Avoid altering original logs; work from copies when investigating
6.5 Eradicate & recover
- Remove malware, backdoors, or unauthorized accounts
- Patch the root cause; restore from clean backups if integrity is in doubt
- Validate that services and data integrity are restored before closing
6.6 Notify
- Affected merchants: For Sev-1/Sev-2 incidents involving their protected customer data, we notify the store contact without undue delay once we understand scope, and no later than required by applicable law.
- Shopify / regulators: We notify Shopify and any competent authority when legally required or when Partner Program / API terms obligate disclosure.
- Notifications include known facts, data categories involved, steps taken, and recommended merchant actions (e.g. rotate staff passwords).
6.7 Post-incident review
Within 10 business days of closing a Sev-1 or Sev-2 incident, the Incident Lead documents timeline, root cause, customer impact, and corrective actions (technical and process). Lessons learned feed into access controls, monitoring, and this policy.
7. Escalation path
- Reporter → Incident Lead (email / on-call)
- Incident Lead → Responders (containment) and, if needed, legal counsel
- Incident Lead → affected merchants, then Shopify / authorities as required
8. Testing & review
We review this policy at least annually, and after any Sev-1/Sev-2 incident. Tabletop exercises may be run periodically to validate roles, notification drafts, and credential rotation steps.
9. Related merchant information
Merchants can also read a plain-language summary of what data we process in the DropScan Local Help FAQ (Privacy & data section) inside the embedded app.