Security
At Thorn & Crown, protecting your data and your payments is a priority. This page explains the measures we take to keep your information safe.
1. Payment Security
All payments are processed by [PAYMENT PROVIDER], a PCI-DSS compliant payment provider. We do not store your full card details on our servers. Transactions are protected by 3-D Secure authentication where available.
2. Data Encryption
Our entire website is served over HTTPS, encrypting data in transit with TLS. Sensitive data stored on our systems is protected using industry-standard encryption.
3. Access Controls
Access to customer data is restricted to authorised personnel on a least-privilege basis and protected by strong authentication.
4. Infrastructure
Our site is hosted with [HOSTING PROVIDER] and protected by firewalls, continuous monitoring, and regular encrypted backups.
5. Software Updates
We keep our platform, plugins, and dependencies up to date and apply security patches promptly to reduce vulnerabilities.
6. Your Account Security
- Use a strong, unique password for your account.
- Never share your login credentials with anyone.
- Log out after using shared or public devices.
- Contact us immediately if you notice suspicious activity.
7. Responsible Disclosure
If you believe you have found a security vulnerability, please report it to [SECURITY EMAIL]. We ask that you give us a reasonable opportunity to address the issue before public disclosure. We will not pursue action against researchers acting in good faith.
8. Incident Response
In the event of a data breach affecting your personal data, we will notify the relevant supervisory authority and affected users in line with our legal obligations (within 72 hours where required under the GDPR).
9. Contact
For any security question, contact [SECURITY EMAIL].