Security

How we safeguard customer and seller data, how payments are protected, and how to report a security issue.


1) Overview

This section explains our security approach and commitments.

Mediaplusin uses layered technical and organizational controls to protect information from unauthorized access, loss, or misuse. We continually review and improve these controls.


2) Platform & Infrastructure

  • Hosted on Shopify’s secure cloud with 24/7 monitoring and hardened infrastructure.

  • Encryption in transit via TLS 1.2+ and encryption at rest (AES-256) where supported.

  • Access to production systems is restricted to authorized personnel using MFA and least-privilege permissions.

  • Regular patching, vulnerability scanning, and third-party risk evaluations.


3) Payment Security

Payments are handled by PCI DSS–compliant processors (e.g., Shopify Payments, PayPal).
Mediaplusin does not store full credit card numbers or CVV codes. Tokenization is used for repeat payments where applicable.


4) Data Handling & Retention

We only collect data necessary for order fulfillment, customer support, fraud prevention, and legal compliance.
Personal data is retained only as long as required for these purposes and then deleted or anonymized.

For data access or deletion requests, email: Mediaplusin@outlook.com


5) Marketplace Data Sharing

For third-party-fulfilled orders, we share only essential information (name, shipping address, order details) with sellers for fulfillment.
All sellers must protect this information under our Seller Agreement and applicable privacy laws.


6) Incident Response & Notifications

We maintain a full incident response plan.
In the event of a data breach, we will contain, investigate, and remediate the incident, and notify affected users and regulators if required by law.


7) Responsible Disclosure

If you find a security vulnerability, please email: Mediaplusin@outlook.com

Please:

  • Do not publicly disclose until fixed.

  • Do not access, modify, or download customer data.

  • Avoid service disruption or privacy impact during testing.

We acknowledge all valid good-faith reports.


8) Compliance & Standards

  • PCI DSS Level 1 (via Shopify and payment processors)

  • GDPR + CCPA/CPRA rights supported (access, deletion, portability, opt-out)

  • Regular audits of third-party apps and integrations


9) Contact

Mediaplusin
Email: Mediaplusin@outlook.com