Security & Responsible Disclosure
How We Protect Your Data
- Payments: We never receive or store full card numbers. Card payments are tokenised in your browser and processed by Stripe, PayPal, or Afterpay under PCI-DSS. Our servers reject raw card data.
- Encryption: All traffic between your browser and our site is encrypted (HTTPS/TLS).
- Accounts: Passwords are stored using strong one-way hashing, and two-factor authentication is available on customer accounts.
- Fraud prevention: Orders are screened using transaction security logging (IP address and approximate location), as described in our Privacy Policy.
- Data breaches: We follow the Australian Notifiable Data Breaches scheme — if a breach likely to cause serious harm occurs, we will notify affected customers and the OAIC.
Responsible Disclosure Policy
We appreciate the work of security researchers. If you believe you have found a vulnerability in this website, please report it to us:
- Email hello@brandonparkgifts.com.au with the subject line "Security Report", including steps to reproduce the issue.
- Give us a reasonable opportunity to investigate and fix the issue before any public disclosure.
- Do not access, modify or delete other customers' data; if you encounter personal data, stop and report it immediately.
- Do not perform testing that degrades the service (denial of service, spam, physical attacks or social engineering).
We commit to acknowledging good-faith reports promptly, keeping you informed of progress, and not pursuing legal action against researchers who act in good faith within this policy. Our machine-readable disclosure details are published at /.well-known/security.txt.