1. Purpose and Scope
This policy describes the practices Smar7 Apps LLC (“Skup”, “the Company”) follows to protect the confidentiality, integrity, and availability of company systems and the data of our customers, partners, and platform integrations, including data accessed through third-party APIs such as the TikTok Shop Partner Center.
This policy applies to all employees, contractors, and systems used to develop, operate, and support Skup’s software products.
2. Data Classification
The Company classifies data into the following categories:
3. Access Control
Access to Restricted and Confidential data is intended to be granted on a least-privilege basis — employees and systems are given only the access required to perform their role or function.
4. Network and System Security
Company systems are hosted on DigitalOcean, which provides network segregation between development, staging, and production environments.
5. Account and Device Security Baseline
The Company enforces the following baseline practices for accounts with access to Confidential or Restricted data:
6. Data Encryption
Sensitive data, including personal data obtained through platform integrations, is encrypted in transit using TLS and at rest, using the encryption features provided by the Company’s database and hosting infrastructure.
7. Incident Response
In the event of a suspected or confirmed security incident involving Confidential or Restricted data, the Company will:
Incidents should be reported immediately to support@skup.net.
8. Vulnerability and Threat Management
The Company applies security patches and dependency updates to production systems on an as-needed (ad hoc) basis and reviews third-party integrations, including API access scopes, periodically to ensure access remains limited to what is necessary. The Company is working toward establishing a more formal, scheduled patching cadence.
9. Policy Review
This policy is reviewed at least annually, or sooner if there is a material change to the Company’s systems, infrastructure, or applicable legal requirements.
10. Contact
Questions regarding this policy may be directed to Devin Zander, Skup (support@skup.net).