Information Security Policy
Last updated: June 14, 2026
HAMMR maintains administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of the data processed by our inventory and sales-management application, including data obtained through the TikTok Shop Partner API. This document is our published information security program and is reviewed and updated as our practices evolve.
Access Control & Authentication
- All access to the application requires individual authenticated accounts; there are no shared logins for data access.
- Access follows the principle of least privilege and is restricted by role (e.g., admin, warehouse, auctioneer); personal data is accessible only to roles that require it.
- Each organization’s data is isolated at the database level using row-level security (RLS), so an account can only access its own organization’s records.
Data Classification
We classify the data we process and apply controls accordingly. Sensitive/personal data(e.g., buyer and recipient details contained in orders) and credentials (API keys, OAuth tokens) receive the strictest controls — encryption, least-privilege access, and minimal retention. Operational/business data (inventory, costs, sales totals) is protected by the same authentication and access controls. We collect only the data necessary for the Service to function.
Encryption
Data is encrypted in transit using HTTPS/TLS and encrypted at rest by our database provider. All connections to third-party APIs (including TikTok Shop) are made over TLS, and API requests are signed using TikTok’s required HMAC-SHA256 scheme.
Network & Infrastructure Security
The application is hosted on managed, industry-standard cloud providers (Supabase for database/auth, Vercel for application hosting), which operate on SOC 2-certified infrastructure. These providers enforce network segregation, perimeter protection, DDoS mitigation, and continuous threat monitoring at the infrastructure layer. We do not expose database servers directly to the public internet; database access is mediated through authenticated, row-level-secured APIs.
Endpoint & Operational Baseline
- Company endpoints run operating-system anti-malware protection and receive security updates.
- Endpoints enforce automatic screen locking and strong passwords.
- Multi-factor authentication is enabled on critical accounts (e.g., email, hosting, and the TikTok Shop Partner account).
Credential & Secret Management
- API keys, app secrets, and OAuth access/refresh tokens are stored as protected environment secrets — never committed to source control.
- OAuth access tokens are refreshed automatically and can be revoked at any time by disconnecting the integration.
Sub-processors
We rely on established providers (Supabase, Vercel, and Anthropic for supplier-invoice document processing). We review the security posture of providers before integrating them and limit the data each receives to what is necessary. See our Privacy Policy.
Incident Response & Breach Notification
We maintain an incident response process with clear ownership: the business owner is the designated incident response lead and point of contact. Suspected incidents are detected through application and provider monitoring, then triaged, contained, and remediated. In the event of a confirmed breach affecting personal data, we will notify affected sellers and TikTok Shop, and the relevant regulatory authorities, without undue delay and as required by applicable law. Security issues can be reported to mshenbaum@gmail.com.
Vulnerability & Threat Management
We keep application dependencies up to date, monitor for disclosed vulnerabilities in the components we use, and remediate identified issues in a timely, risk-based manner.
Data Retention & Deletion
We retain data only as long as necessary for operational, accounting, and legal purposes. We will assist sellers and TikTok Shop in responding to end-user requests to access, update, or delete personal data, and upon termination of the integration we will delete the customer data in our possession.
Contact
To report a security concern or request more information about our practices, email mshenbaum@gmail.com.