Responsible Disclosure

We take our responsibility seriously. Do you?

At Touch Local Loyalty, we take the security of our systems very seriously. Despite our efforts to ensure the security of our systems, vulnerabilities may still exist. If you have discovered a vulnerability in one of our systems, please let us know. This will allow us to take action as quickly as possible. We would like to work with you to better protect our customers and our systems.

We ask you:

  • Please email your findings to privacy@touchincentive.com;
  • Do not exploit the vulnerability by, for example, downloading more data than is necessary to demonstrate the vulnerability, or by viewing, deleting, or modifying third-party data;
  • Do not share the vulnerability with others until it has been resolved, and immediately after patching the vulnerability, delete all confidential data that was obtained;
  • Do not use attacks targeting physical security, social engineering, distributed denial of service, spam, or third-party applications;
  • Please provide enough information to reproduce the vulnerability so that we can resolve it as quickly as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability are sufficient, but more information may be needed for more complex vulnerabilities.

 

What we promise:

  • We will respond to your report within 5 days. We will let you know whether or not it is a vulnerability that is currently unknown to us;
  • If it is an unknown vulnerability, we will assess the risk and decide whether to implement the solution you proposed. If so, we will keep you informed of the progress made in resolving the issue;
  • As a thank you for your help, we offer a reward of €25 for each report of a vulnerability previously unknown to us for which we decide to implement the solution you proposed;
  • If you have complied with the above conditions, we will not take any legal action against you in connection with your report;
  • We will treat your report confidentially and will not share your personal information with third parties without your consent, unless it is necessary to comply with a legal obligation. You may submit a report using a pseudonym. When publicizing the reported vulnerability, we will credit you as the discoverer only if you wish.