Yeni: Müşterileriniz artık paketinin nerede olduğunu sizin mağaza adınızla açılan bir sayfadan görebiliyor.Göz atın →

Security and Abuse Policy

Custombull applies and continuously monitors security standards for its panels, your connected stores and your buyers' data. This policy explains the consequences of attacks and abuse against our systems and how to report a vulnerability to us.

Last updated: Version: 1.0AKIN INDUSTRIES LLCTürkçe sürüm

In short

  • Security standards are applied across Custombull panels; access and security logs are monitored continuously.
  • Unauthorized access, altering systems or data, disrupting the service and unauthorized scanning are prohibited and are crimes.
  • When we detect an attack or unauthorized access attempt, we preserve the relevant records as evidence and report it to the competent authorities without delay, as permitted by law.
  • The attacker's account is closed immediately, and we pursue legal remedies for damage to us and to our users.
  • If you find a vulnerability, report it to us; we will not take legal action against good-faith research that follows this policy.

This summary is for convenience only and is not binding. The full text below governs.

Contents
  1. 1. Scope
  2. 2. Security standards we apply
  3. 3. Prohibited actions
  4. 4. Legal consequences
  5. 5. What we do when attacked
  6. 6. Reporting a vulnerability
  7. 7. Your responsibilities
  8. 8. Contact

1. Scope

This policy covers every Custombull system operated by AKIN INDUSTRIES LLC, including the Custombull panel, API, Chrome extension, order tracking pages, partner and producer portals and this website. It applies together with the Terms of Service and the Acceptable Use Policy.

2. Security standards we apply

  • Traffic is encrypted in transit (TLS). Credentials and marketplace access tokens are stored encrypted; passwords are hashed.
  • Seller accounts use two-step verification. Sub-user permissions are closed by default: anything not granted is denied.
  • We connect to marketplaces only with the store owner's authorization and automatically respect each platform's request limits.
  • Access, security and error logs are kept and monitored. Repeated failed logins, unusual request volumes and automated attack attempts are rate limited and blocked.
  • Design and production files are served only through short-lived signed links.
  • Access to production systems is restricted, logged and reviewed. Backups are encrypted. Security updates for the software components we use are applied regularly.

No system is completely secure. How we notify you of a breach affecting personal data is described in our Privacy Policy.

3. Prohibited actions

The following actions are prohibited without our written permission:

  • Accessing or attempting to access another user's account, data or store connection.
  • Unauthorized access to our systems, source code, databases or admin tools; attempting to bypass security measures such as authentication, authorization or rate limits.
  • Altering, deleting or corrupting systems, data, orders, prices, payments or content without authorization.
  • Attacks intended to disrupt or slow the service (DoS/DDoS), excessive automated requests, credential stuffing and brute-force attempts.
  • Unauthorized vulnerability scanning, penetration testing or social engineering; uploading or distributing malware.
  • Reverse engineering the panel, API or extension; systematically copying the interface, workflows or data, or harvesting them with automated tools.
  • Impersonating Custombull, its staff or partners; abusing the service with fake accounts.

5. What we do when attacked

  1. We stop the attack, protect the affected systems and secure user accounts.
  2. We preserve the related records (IP addresses, timestamps, requests, accounts and device information used) unaltered as evidence.
  3. We report the attack or unauthorized access attempt to the competent authorities without delay, as permitted by law: the FBI and relevant law enforcement in the United States, the Public Prosecutor's Office and cybercrime units in Türkiye, and authorities in other countries where needed.
  4. We share information and evidence that helps identify the attacker with those authorities and support investigations and prosecutions.
  5. If your personal data was affected, we notify you and the relevant supervisory authorities as described in our Privacy Policy.

We share data of innocent users affected by an attack only when a legal obligation or a request from a competent authority requires it, and only to the extent necessary; such sharing remains subject to our privacy policy.

6. Reporting a vulnerability

If you believe you have found a security vulnerability in our systems, email hello@custombull.com with "Security" in the subject line. Explain how to reproduce it and its possible impact.

We will not take legal action against good-faith research that follows these rules:

  • Use only your own account and data; do not access, download or modify other people's data.
  • Do not run tests that slow down or disrupt the service (no DoS, heavy automated scanning or social engineering).
  • After reporting, do not disclose the issue to anyone until it is fixed or for at least 90 days.
  • Do not exploit the issue for your own benefit or make threats in exchange for payment.

We do not currently run a paid bug bounty program. We review every report and tell you the outcome.

7. Your responsibilities

  • Do not share your password or two-step verification codes with anyone.
  • Give team members only the permissions they need, and remove access for people who leave.
  • Tell us immediately if you see an action you do not recognize or anything suspicious in your account.

8. Contact

AKIN INDUSTRIES LLC, 11500 Main St. Suite 126, Houston, TX 77025, United States of America. Email: hello@custombull.com.

Contact

For any question or request about this document, email hello@custombull.com. Postal address: AKIN INDUSTRIES LLC, 11500 Main St. Suite 126, Houston, TX 77025, United States of America.

Other legal documents

The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.

Back to top

Ücretsiz başla