1. What counts as a security incident
A security incident is any event that puts the confidentiality, integrity, or availability of Zelari or merchant data at risk. For example:
- Someone accessing merchant data without permission
- Data being lost, changed, or exposed by mistake
- A leaked password, API key, or access token
- A security incident at one of our providers that affects Zelari
- An attack that takes Zelari offline or affects how it works
2. Who is responsible
Zelari's founder is the incident lead and is responsible for running the response, making decisions, and communicating with merchants, Shopify, and our providers. As we grow, this role may be shared with other team members, and we will update this policy when it is.
3. How to report an issue
If you think you have found a security problem, email support@zelari.io with "Security" in the subject line. Please include as much detail as you can, and do not access, change, or share data that isn't yours. We aim to acknowledge reports within 2 business days.
4. Severity levels
| Level | Meaning |
|---|---|
| Critical | Merchant or personal data confirmed exposed, or an attacker has active access |
| High | Data exposure is likely, or Zelari is unavailable for most merchants |
| Medium | A security weakness exists, but there is no sign it has been used |
| Low | A minor issue with little or no risk to data |
5. How we respond
- Detect and record. We log the report or alert, with the time we became aware of it.
- Assess. We confirm what happened and set a severity level.
- Contain. We stop the damage from spreading, for example by rotating keys, revoking access, or pausing affected features.
- Investigate. We find the cause and work out which merchants and data are affected.
- Fix and recover. We remove the cause, restore normal service, and check that the fix works.
- Notify. We tell the people who need to know, as described in section 6.
- Review. We write up what happened and what we changed so it does not happen again.
6. Who we notify, and when
- Affected merchants: without undue delay, and no later than 72 hours after we become aware of an incident affecting their data. We will explain what happened, what data is affected, what we are doing, and what you may need to do.
- Shopify: as required by the Shopify Partner Program Agreement and API terms.
- Authorities and individuals: merchants are the controllers of their store data, so we will support you with any notices you need to make. Where the law requires us to notify directly, we will.
If we don't yet have all the details, we will share what we know and send updates as we learn more.
7. Records
We keep a record of every security incident, including what happened, its impact, the actions we took, and when we notified people.
8. Prevention
We reduce risk by limiting who can access production data, keeping credentials out of browsers and code repositories, rotating credentials when needed, keeping dependencies up to date, and monitoring for problems.
9. Reviewing this policy
We review this policy at least once a year and after any significant incident.
10. Contact
Security reports: support@zelari.io (use "Security" in the subject line)
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 Current | September 27, 2026 | Initial version. |