Legal
Responsible Disclosure
Last updated: July 24, 2026
This policy explains how to report a suspected security vulnerability affecting products, websites or public documentation owned and operated by Digital Florists.
For account support, privacy requests or suspected fraud affecting your shop, use our normal contact page instead.
Reporting a Security Issue
Email our monitored company mailbox at hello [at] digitalflorists.com with the subject Security report. Include:
- the affected page, product or service;
- a clear description of the issue and its likely impact;
- the steps needed to reproduce it;
- supporting screenshots or request details with personal data removed; and
- a safe way for us to contact you.
Do not include passwords, access tokens, payment information or customer data in your first report. If sensitive evidence is needed, tell us first and we will arrange a safer way to transfer it.
What to Expect
We aim to acknowledge every report, look into it and tell you when it is being dealt with. If the fix takes time, we aim to keep you updated and to tell you when we consider the report closed. We are a small team, so we do not commit to a fixed response time. We do not require a non-disclosure agreement before accepting a report.
Responsible Testing
This policy provides a reporting route. It does not grant permission to test a system, account, data or device that you do not own or are not already authorised to use. Stop testing and report the issue if you encounter personal data, customer data or access beyond your own account.
You must not:
- access, copy, change, download or delete another person's data;
- disrupt our services or use denial-of-service, high-volume or destructive testing;
- use social engineering, phishing, physical intrusion or attacks against our staff or suppliers;
- install malware, maintain access or move beyond the minimum proof needed to explain the issue;
- test third-party services or integrations without their permission; or
- demand payment or threaten disclosure, data loss or disruption.
If You Report in Good Faith
If you follow this policy, stay within the Responsible Testing limits above, report promptly and do not exploit what you find, we will treat your research as authorised for the purposes of our terms of use. We will not bring a claim against you under those terms, and we will not report you to the authorities, for that research. If someone else brings a claim about research that followed this policy, tell us and we will make clear that your work was authorised.
This protection covers only systems we own and operate, and only conduct within this policy. It cannot bind a third party, and it does not make lawful anything that is unlawful in itself. If you are unsure whether something is in scope, ask us before you test it.
Coordinated Disclosure
Please keep the issue and any related information confidential while we investigate it. Coordinate any proposed publication with us and give us a reasonable opportunity to investigate and remediate the issue first.
We review reports made in good faith and may contact you for more information. This policy does not promise a reward or create a bug bounty.
Other Reports
Send privacy concerns to privacy [at] digitalflorists.com. Use our contact page for spam, abuse, account access or other support issues.