Coaching Blog About Us Support
Course Login Watch the free training →
Coaching Blog About Us Support Course Login Watch the free training →
Legal

Information Security Policy

Home » Information Security Policy

1. Purpose and Scope

This policy describes the practices Smar7 Apps LLC (“Skup”, “the Company”) follows to protect the confidentiality, integrity, and availability of company systems and the data of our customers, partners, and platform integrations, including data accessed through third-party APIs such as the TikTok Shop Partner Center.

This policy applies to all employees, contractors, and systems used to develop, operate, and support Skup’s software products.

2. Data Classification

The Company classifies data into the following categories:

  • Public — marketing content, published course material
  • Internal — business operations data, internal communications
  • Confidential — customer account data, financial records
  • Restricted — personal data obtained via third-party platform integrations (e.g., creator/affiliate data accessed through the TikTok Shop API), authentication credentials, and payment information

3. Access Control

Access to Restricted and Confidential data is intended to be granted on a least-privilege basis — employees and systems are given only the access required to perform their role or function.

  • Access to production systems and customer/affiliate data is limited to designated team members.
  • The Company does not currently perform periodic access reviews. This is an identified area for improvement, and the Company plans to establish a scheduled review process (e.g., at each new API integration or role change) going forward.

4. Network and System Security

Company systems are hosted on DigitalOcean, which provides network segregation between development, staging, and production environments.

  • Firewall rules restrict inbound traffic to required services only.
  • Company-owned endpoints run current operating-system security features and anti-malware protection.

5. Account and Device Security Baseline

The Company enforces the following baseline practices for accounts with access to Confidential or Restricted data:

  • Multi-factor authentication (MFA) is required for all team members on core business systems (e.g., cloud hosting, email, financial platforms)
  • Minimum password complexity requirements
  • Automatic screen locking on idle devices

6. Data Encryption

Sensitive data, including personal data obtained through platform integrations, is encrypted in transit using TLS and at rest, using the encryption features provided by the Company’s database and hosting infrastructure.

7. Incident Response

In the event of a suspected or confirmed security incident involving Confidential or Restricted data, the Company will:

  • Investigate and contain the incident promptly
  • Notify affected parties and applicable regulatory authorities as required by law
  • Document the incident and remediation steps taken

Incidents should be reported immediately to support@skup.net.

8. Vulnerability and Threat Management

The Company applies security patches and dependency updates to production systems on an as-needed (ad hoc) basis and reviews third-party integrations, including API access scopes, periodically to ensure access remains limited to what is necessary. The Company is working toward establishing a more formal, scheduled patching cadence.

9. Policy Review

This policy is reviewed at least annually, or sooner if there is a material change to the Company’s systems, infrastructure, or applicable legal requirements.

10. Contact

Questions regarding this policy may be directed to Devin Zander, Skup (support@skup.net).

Real operators since 2013. The software, coaching and community to turn a Shopify store into a brand you're proud of.

Products

  • AvatarIQ
  • Apparel Cloning System
  • The Incubator

Company

  • About
  • Blog
  • Support

Follow

  • Facebook
  • Instagram
  • Course Login
© 2026 Skup. 689 Central Ave. Suite 100-J, Saint Petersburg, FL 33701 Privacy · Terms · Earnings Disclaimer