Security Incident Response Policy

DropScan Local · BaseStation Private Limited
Effective: 20 July 2026 · Version 1.0
Contact: [email protected]

1. Purpose

This policy describes how BaseStation Private Limited (“we”) detects, responds to, and recovers from security incidents that may affect DropScan Local, including unauthorized access to or disclosure of protected customer data processed on behalf of Shopify merchants.

2. Scope

This policy covers:

3. Roles and responsibilities

Role Responsibility
Incident Lead Founder (Rohit Gupta). Owns classification, containment decisions, merchant/Shopify notification, and post-incident review.
Responders Engineering staff with production access. Execute containment, evidence collection, and remediation under the Incident Lead.
Merchants Report suspected misuse of their store’s data via the contact email above or in-app Help.

4. What we process (context for incidents)

DropScan Local stores the minimum delivery fields needed for local handoffs: destination name, phone, and address; Shopify order identifiers; line-item summaries for stickers; and staff delivery-proof scan GPS/IP. We do not sell this data. We do not store customer email or payment details for delivery ops.

5. Incident severity scale

Severity Examples Initial response target
Sev-1 — Critical Confirmed exfiltration of protected customer data; active unauthorized production access; ransomware / widespread outage with data integrity risk Acknowledge within 1 hour; contain ASAP
Sev-2 — High Credible unauthorized access without confirmed exfiltration; leaked API tokens or database credentials; significant privilege escalation Acknowledge within 4 hours
Sev-3 — Medium Suspected intrusion; misconfiguration exposing non-public data; failed but serious attack attempts that require investigation Acknowledge within 1 business day
Sev-4 — Low Phishing reports with no confirmed access; policy violations without data impact; low-risk vulnerability disclosures Acknowledge within 2 business days

6. Response procedure

6.1 Detect & report

6.2 Triage & classify

The Incident Lead assigns severity, opens an incident record (time, reporter, systems involved, data types at risk), and decides whether to escalate to Sev-1/Sev-2 war-room mode.

6.3 Contain

6.4 Collect evidence

6.5 Eradicate & recover

6.6 Notify

6.7 Post-incident review

Within 10 business days of closing a Sev-1 or Sev-2 incident, the Incident Lead documents timeline, root cause, customer impact, and corrective actions (technical and process). Lessons learned feed into access controls, monitoring, and this policy.

7. Escalation path

  1. Reporter → Incident Lead (email / on-call)
  2. Incident Lead → Responders (containment) and, if needed, legal counsel
  3. Incident Lead → affected merchants, then Shopify / authorities as required

8. Testing & review

We review this policy at least annually, and after any Sev-1/Sev-2 incident. Tabletop exercises may be run periodically to validate roles, notification drafts, and credential rotation steps.

9. Related merchant information

Merchants can also read a plain-language summary of what data we process in the DropScan Local Help FAQ (Privacy & data section) inside the embedded app.