Flip Shopper Website Security PolicyFlip Shopper Global Solution Private LimitedBrand: Flip ShopperWebsite: www.flipshopper.inEffective Date: [Insert Effective Date]Last Updated: [Insert Last Updated Date]This Security Policy explains the administrative, technical, and organizational measures Flip Shopper Global Solution Private Limited (“Flip Shopper,” “we,” “us,” or “our”) uses to protect the Flip Shopper website, www.flipshopper.in, related services, systems, accounts, transactions, and information from unauthorized access, misuse, alteration, disclosure, loss, or destruction.This policy applies to Flip Shopper’s website, applications, customer-support channels, internal systems, technology infrastructure, service providers, and business processes to the extent applicable.1. Security ObjectivesFlip Shopper is committed to maintaining the confidentiality, integrity, availability, and resilience of its information systems and business operations.Our security objectives include:- Protecting customer, employee, seller, and business information- Preventing unauthorized access to accounts, systems, and data- Detecting, investigating, and responding to security incidents- Maintaining secure payment and transaction processes- Reducing security risks associated with employees, vendors, and service providers- Supporting compliance with applicable Indian laws and regulatory requirements- Continuously improving our security controls and practices2. Information Security GovernanceFlip Shopper maintains security responsibilities appropriate to the size, nature, and complexity of its business.Security responsibilities may include:- Establishing and maintaining security policies and procedures- Assigning responsibility for information security and incident response- Reviewing security risks and implementing reasonable safeguards- Monitoring compliance with internal security requirements- Coordinating with technology, legal, operations, customer-support, and management teams- Reviewing and updating security practices when business operations, technology, or legal requirements changeAccess to sensitive systems and information is granted based on business need, role, and authorization.3. Information We ProtectDepending on the services used, Flip Shopper may protect information such as:- Customer names, contact details, and delivery addresses- Account credentials and authentication information- Order, payment, refund, return, and transaction details- Customer-support communications- Seller, supplier, logistics, and business-partner information- Website usage, device, and technical information- Employee and contractor information- Confidential business, operational, financial, and commercial informationFlip Shopper seeks to collect, use, retain, and disclose information in accordance with its Privacy Policy and applicable law.4. Access ControlFlip Shopper uses access-control measures designed to limit access to systems and information to authorized individuals.These measures may include:- Role-based access permissions- Unique user accounts and credentials- Multi-factor authentication where appropriate- Least-privilege access- Periodic access reviews- Prompt removal or modification of access when roles change or employment ends- Restrictions on access to sensitive customer, payment, operational, and administrative information- Logging and monitoring of access to critical systemsPersonnel must not share passwords, authentication tokens, access keys, or other security credentials.5. Account SecurityCustomers are responsible for protecting their account credentials and devices.Customers should:- Use a strong and unique password- Avoid reusing passwords across websites- Keep login credentials confidential- Enable available additional authentication protections- Log out from shared or public devices- Keep devices, browsers, and operating systems updated- Notify Flip Shopper promptly of suspected unauthorized access- Avoid responding to suspicious messages requesting passwords, PINs, CVVs, UPI PINs, or banking credentialsFlip Shopper will not request confidential authentication information through unsolicited calls, messages, or emails.6. Data ProtectionFlip Shopper implements reasonable safeguards to protect information against unauthorized access, alteration, disclosure, loss, or destruction.Depending on the nature of the information and the relevant system, safeguards may include:- Encryption in transit using appropriate secure communication protocols- Encryption or equivalent protection for sensitive information at rest where appropriate- Secure storage and controlled access- Data minimization and purpose-based access- Backup and recovery controls- Secure deletion or disposal procedures- Monitoring for unusual or unauthorized activity- Protection against malware, unauthorized code, and common application threatsNo method of transmission, storage, or processing is completely secure. Accordingly, Flip Shopper cannot guarantee absolute security.7. Payment SecurityPayments may be processed through authorized payment gateways, banks, card networks, wallet providers, UPI providers, or other payment-service providers.Flip Shopper generally does not store complete card numbers, CVVs, UPI PINs, banking passwords, or similar confidential payment credentials unless expressly stated and lawfully required. Payment information may be collected and processed directly by authorized payment providers under their own security practices, terms, and privacy policies.Customers must not share:- Card PINs- CVVs- UPI PINs- Internet-banking passwords- One-time passwords- Account passwords- Authentication codesFlip Shopper will not ask customers to disclose such information to process an order, refund, return, cancellation, or delivery.8. Application and Website SecurityFlip Shopper seeks to incorporate security into the design, development, testing, deployment, and maintenance of its website and related systems.Security practices may include:- Secure development procedures- Code review and change-management controls- Vulnerability assessment and remediation- Security testing before significant releases- Protection against common web and application vulnerabilities- Secure configuration of servers, databases, networks, and cloud services- Monitoring of critical systems and services- Restrictions on production access- Use of security updates and patches within a reasonable timeframeSecurity controls may vary depending on the system, service, technology, risk level, and operational requirements.9. Network and Infrastructure SecurityFlip Shopper may use technical controls designed to protect its infrastructure and communications, including:- Firewalls and network segmentation- Intrusion detection or prevention capabilities- Secure remote-access controls- Endpoint protection- Malware detection and prevention- Traffic monitoring and rate limiting- Secure configuration standards- Availability and performance monitoring- Redundancy and resilience measures where appropriateFlip Shopper may restrict, block, or investigate traffic or activity that appears malicious, abusive, automated, fraudulent, or inconsistent with normal website use.10. Security Monitoring and LoggingFlip Shopper may collect and review security-related logs and technical information to:- Detect unauthorized access or suspicious activity- Investigate security incidents- Protect accounts, systems, and transactions- Maintain service availability and reliability- Prevent fraud and abuse- Meet legal, regulatory, audit, and operational requirementsSecurity logs may include account activity, authentication events, device information, IP addresses, system events, transaction activity, and other technical information, subject to applicable law and the Privacy Policy.11. Employee and Contractor SecurityFlip Shopper may provide security and privacy guidance to employees, contractors, and authorized personnel whose work involves access to systems or information.Personnel may be required to:- Maintain confidentiality- Use systems only for authorized business purposes- Follow access-control and password requirements- Protect devices and credentials- Report suspected security incidents- Complete relevant security or privacy training- Comply with disciplinary or contractual requirements for violationsAccess may be restricted or revoked where a person no longer has a legitimate business need or presents a security risk.12. Vendor and Service-Provider SecurityFlip Shopper may use third-party providers for hosting, cloud infrastructure, payment processing, logistics, customer support, communications, analytics, fraud prevention, security, and other business functions.Where appropriate, Flip Shopper may assess service providers based on:- The nature and sensitivity of information involved- Security capabilities and controls- Contractual confidentiality and data-protection obligations- Incident-notification commitments- Access restrictions- Compliance requirements- Business continuity and recovery capabilitiesThird-party providers remain responsible for their own systems and practices, subject to their contractual obligations and applicable law.13. Fraud Prevention and Abuse DetectionFlip Shopper may use automated and manual controls to identify and prevent:- Account takeover- Payment fraud- Identity misuse- Coupon, promotion, refund, or return abuse- Fake orders or unauthorized transactions- Bot activity and scraping- Suspicious delivery or address activity- Unusual account or transaction behaviorThese controls may result in additional verification, temporary restrictions, order cancellation, account suspension, or referral to relevant authorities where permitted by law.14. Security Incident ResponseFlip Shopper maintains procedures for identifying, assessing, containing, investigating, resolving, and documenting suspected security incidents.Incident-response activities may include:- Monitoring and alert review- Initial assessment and classification- Containment of affected accounts, systems, or services- Preservation and analysis of relevant evidence- Remediation and recovery- Notification to affected individuals, service providers, regulators, or authorities where required- Post-incident review and corrective actionFlip Shopper may temporarily restrict access, disable features, suspend accounts, cancel transactions, or take other protective measures during an investigation.15. Customer Security Incident ReportingCustomers, sellers, service providers, and other users should report suspected security issues promptly.Reports may include:- Unauthorized account access- Suspicious login activity- Phishing or impersonation attempts- Fraudulent payment or refund requests- Exposure of personal or confidential information- Malware, malicious links, or suspicious website behavior- Vulnerabilities affecting the Flip Shopper website or servicesReports should include relevant details such as the affected account or order, date and time, screenshots, suspicious messages or links, and steps already taken. Do not include passwords, PINs, CVVs, UPI PINs, or other confidential authentication information.Security Contact: [Insert official security email or contact details]16. Responsible Vulnerability DisclosureIf you identify a potential vulnerability in the Flip Shopper website or services, please report it responsibly and allow Flip Shopper reasonable time to investigate and address the issue.You must not:- Access, modify, copy, or disclose data belonging to another person- Disrupt or degrade website or service availability- Conduct denial-of-service testing- Use social engineering, phishing, or physical attacks- Install malware or persistent access mechanisms- Publicly disclose a vulnerability before Flip Shopper has had a reasonable opportunity to respond- Use a vulnerability to obtain financial benefit or access information unrelated to the issueFlip Shopper may request additional information to validate and investigate a report. Submission of a report does not create an employment, contractual, or compensation relationship unless separately agreed in writing.17. Business Continuity and RecoveryFlip Shopper seeks to maintain reasonable continuity and recovery capabilities for critical systems and services.Measures may include:- Data backups- Recovery procedures- Redundant infrastructure where appropriate- Disaster-recovery planning- Service monitoring- Incident escalation procedures- Periodic testing or review of recovery arrangementsRecovery times and service availability may vary depending on the nature and severity of an incident, technical limitations, third-party dependencies, and events beyond Flip Shopper’s reasonable control.18. Data Retention and Secure DisposalFlip Shopper retains information only for as long as reasonably necessary for business, legal, regulatory, security, dispute-resolution, fraud-prevention, and record-keeping purposes, subject to its Privacy Policy and applicable law.When information is no longer required, Flip Shopper may delete, anonymize, aggregate, or securely dispose of it using reasonable procedures appropriate to the type of information and storage medium.Some information may remain in backups or legally required records for a limited period before being deleted or overwritten.19. Physical and Environmental SecurityWhere applicable, Flip Shopper and its service providers may use physical and environmental safeguards for facilities and equipment that process or store information.These safeguards may include:- Restricted facility access- Visitor controls- Monitoring and surveillance- Secure equipment storage- Environmental controls- Power and connectivity protections- Secure disposal of physical records and devicesThe specific controls may vary depending on the facility, service provider, location, and operational requirements.20. Customer ResponsibilitiesSecurity is a shared responsibility. Customers must:- Provide accurate information- Protect account credentials and devices- Use secure networks where possible- Keep software and browsers updated- Avoid suspicious links, attachments, and communications- Verify official Flip Shopper contact channels- Report suspected fraud or security incidents promptly- Not attempt to bypass security controls- Not access or use another person’s account or information without authorizationFlip Shopper is not responsible for security issues caused by a customer’s failure to protect credentials, devices, payment information, or account access, except where liability cannot lawfully be excluded.21. Privacy and Personal InformationSecurity measures relating to personal information are described together with data-collection, use, disclosure, retention, and rights information in the Flip Shopper Privacy Policy.This Security Policy does not replace the Privacy Policy, Terms of Use, Refund and Return Policy, or any product-specific or transaction-specific terms.22. LimitationsAlthough Flip Shopper uses reasonable security measures, no website, application, network, payment system, storage environment, or electronic transmission can be guaranteed to be completely secure.Security risks may arise from:- Internet and telecommunications failures- Malware, phishing, or social engineering- Third-party systems and service providers- Customer devices or networks- Unauthorized acts by third parties- Software or hardware vulnerabilities- Human error- Events beyond reasonable controlFlip Shopper will respond to security issues in accordance with applicable law and its incident-response procedures.23. Policy UpdatesFlip Shopper may update this Security Policy from time to time to reflect changes in technology, business operations, security practices, legal requirements, or services.The updated policy will be posted on the website with a revised “Last Updated” date. Continued use of the website after an update may constitute acceptance of the revised policy to the extent permitted by law.24. Contact InformationFlip Shopper Global Solution Private LimitedBrand: Flip ShopperWebsite: www.flipshopper.inCIN: [Verify and insert official CIN]PAN: [Verify and insert official PAN]GSTIN: [Verify and insert official GSTIN]Registered Office: [Insert official registered address]Security Contact: [Insert official security email or contact details]Customer Care: [Insert official customer-care details]Privacy Contact: [Insert official privacy contact details]Working Hours: [Insert working hours]When contacting us about a security concern, please provide your name, contact details, affected account or order information where applicable, a description of the issue, relevant dates and times, and supporting evidence. Do not send passwords, PINs, CVVs, UPI PINs, or other confidential authentication information.25. Important NoticeThis Security Policy describes Flip Shopper’s general security framework and should be reviewed and finalized based on Flip Shopper’s actual technology architecture, payment systems, hosting arrangements, seller model, logistics processes, data practices, vendor relationships, incident-response procedures, and applicable Indian laws and regulations.Flip Shopper may maintain additional internal security standards, procedures, technical controls, contractual requirements, and operational guidelines that are not publicly disclosed for security reasons.Flip Shopper Global Solution Private LimitedSmart Shopping. Better Choices. Bigger Possibilities.