Security and Vulnerability Disclosure Policy
1. Purpose
The Mining Shop UK Limited welcomes responsible reports that help us protect www.theminingshop.co.uk, customer accounts and connected services. This policy explains how to report a suspected security vulnerability and the limits that apply to any testing.
This policy is not permission to access systems or data and does not provide legal immunity. Activity must remain lawful, authorised and within the boundaries below.
2. How to report
Email [email protected] with the subject SECURITY VULNERABILITY REPORT. Initially provide only the minimum information needed:
- affected URL, feature or service;
- vulnerability type and likely impact;
- safe, reproducible steps using your own account or non-sensitive test data;
- relevant timestamps, request identifiers and redacted evidence;
- whether you believe customer data or active exploitation is involved; and
- a contact method for coordinated follow-up.
Do not email passwords, private keys, payment-card data, live customer information, malware or a large exploit archive. Ask us for a suitable secure transfer method if sensitive evidence is genuinely necessary.
3. What you can expect
We aim to acknowledge a credible report within two business days, conduct initial triage within five business days and provide a status update within ten business days. These are targets, not guaranteed resolution times.
We will validate and prioritise the issue, involve the relevant provider where necessary and coordinate remediation and disclosure proportionately. Complex or third-party issues may take longer. We may ask for clarification or evidence that the activity stayed within this policy.
4. Permitted good-faith activity
Permitted activity is limited to observation and minimal, non-destructive verification on public pages or an account and data you own or are expressly authorised to use. Stop as soon as a vulnerability or unintended access is demonstrated.
You must minimise requests, avoid persistence, preserve evidence securely and give us a reasonable opportunity to investigate before public disclosure.
5. Prohibited activity
Do not:
- access, copy, alter, delete or disclose another person's data;
- attempt to obtain passwords, session tokens, private keys, payment details or authentication codes;
- use social engineering, phishing, impersonation, spam or physical intrusion;
- deploy malware, ransomware, persistence, backdoors or command-and-control infrastructure;
- perform denial-of-service, stress, load, high-volume automated scanning or resource-exhaustion testing;
- test live payments, refunds, chargebacks, bank transfers, cryptocurrency transfers or orders without written permission;
- alter prices, stock, orders, analytics, consent records, search indexing, email or administrative settings;
- test Cloudflare, Stripe, Google, hosting providers, plugins, couriers or another third party without that party's permission;
- exploit beyond the minimum needed to demonstrate the issue; or
- demand payment, threaten disclosure or retain data as leverage.
6. Data encountered accidentally
If you encounter personal, payment, authentication or confidential data, stop immediately. Do not download more, retain unnecessary copies, contact the affected person or include the data in ordinary email. Tell us what type of data was encountered and request secure handling instructions.
Delete retained copies when we confirm they are no longer required, unless law requires preservation.
7. Recognition and rewards
We do not operate a public bug-bounty programme and do not promise payment. Any acknowledgement or reward is entirely discretionary and must never be assumed before written agreement.
We will not normally identify a reporter publicly without consent. We may decline acknowledgement where a report is duplicate, low quality, automated without validation, outside scope or connected with prohibited activity.
8. Legal and third-party matters
Nothing in this policy authorises conduct prohibited by the Computer Misuse Act 1990, data-protection law, intellectual-property law, contract or another applicable rule. If activity exceeds this policy, causes harm or appears malicious, we may preserve evidence, restrict access and report it to the relevant provider or authority.
Third-party products and services are governed by their own disclosure policies. Report an issue to us only where it affects The Mining Shop's implementation or customers.
9. Privacy and disclosure
Reporter information is used to investigate, communicate, protect systems, establish or defend claims and comply with law under our Privacy Policy. Reports may be shared with affected service providers, professional advisers, insurers or authorities where necessary.
Do not publish details until we agree a coordinated disclosure date or enough time has passed for a proportionate response, taking account of active exploitation and customer risk.
Questions About These Terms?
Contact The Mining Shop UK Limited through our Contact page or call 01429 408034. Please quote the relevant order, hosting or repair reference.