1. Purpose & Scope
This Information Security Policy defines the security standards and practices adopted by British Craft Studio ("the Company") to protect customer, seller, and business data accessed through our e-commerce platform and TikTok Shop API integration. This policy applies to all employees, contractors, and authorised personnel with access to Company systems.
2. Access Control
- Access to administrative systems is restricted to authorised personnel via role-based access control (RBAC).
- Two administrator roles exist: Admin and User. Only Admin accounts can access customer or seller data.
- All accounts require email and password authentication with strong password complexity enforcement.
- Multi-factor authentication (MFA) is enabled on all administrative accounts.
- Access is granted on the principle of least privilege — personnel only access data necessary for their role.
- User accounts are reviewed periodically and revoked immediately upon role change or departure.
3. Data Encryption
- In transit: All data transmitted between users and our platform is encrypted using TLS (HTTPS).
- At rest: Data stored in our database is encrypted at rest by our cloud platform provider (Base44).
- Payment card data is never stored on Company systems. All payment processing is handled by Stripe (PCI-DSS Level 1 certified).
- API credentials and secrets are stored securely as environment variables and are never exposed in client-side code.
4. Network Security
- All application hosting, database infrastructure, and network security are managed by Base44, a managed cloud platform.
- Network segregation, firewalls, and intrusion detection are handled at the platform level.
- The Company does not operate on-premise servers; all infrastructure is cloud-hosted.
- IP-based access restrictions are enforced on TikTok Shop API credentials.
5. Endpoint Security
- All company endpoints (laptops, desktops) use built-in OS-level anti-malware protection (Windows Defender or macOS XProtect) with automatic definition updates enabled.
- Automatic screen lock is enforced after a period of inactivity on all devices.
- A clear-desk policy is maintained; no sensitive data is left unattended in physical form.
- Devices are password-protected and encrypted where the operating system supports it (BitLocker / FileVault).
6. Data Classification
- Public: Product information, marketing content, published privacy and terms.
- Internal: Business operations data, stock levels, supplier information.
- Confidential: Customer personal data (names, addresses, emails), order history, TikTok Shop seller data.
- Restricted: API credentials, payment keys, authentication secrets.
- Confidential and Restricted data is encrypted in transit and at rest, and access is logged.
7. Vulnerability & Threat Management
- Infrastructure vulnerability patching is managed by our cloud platform provider (Base44).
- The Company monitors for unusual account activity and unauthorised access attempts.
- Third-party integrations (Stripe, Royal Mail, TikTok Shop) are reviewed for security compliance before integration.
- Software dependencies are kept up to date as part of the platform's managed update cycle.
8. Incident Response
The Company maintains a documented Incident Response Plan (see separate document) covering breach detection, notification timelines, roles, and communication channels. In the event of a data breach, affected parties including TikTok Shop will be notified within 72 hours in accordance with UK GDPR Article 33.
9. Data Retention & Deletion
- Customer data is retained only for as long as necessary to fulfil orders and meet legal/accounting obligations.
- Upon termination of a contractual relationship, all collected customer data will be deleted within 30 days, except where retention is legally required (e.g. HMRC tax records: 6 years).
- TikTok Shop seller data accessed via API will be deleted upon request or contract termination.
10. Policy Review
This policy is reviewed at least annually and updated as necessary to reflect changes in business operations, technology, or regulatory requirements. The latest version is maintained internally and made available to relevant stakeholders and partners upon request.