Security Vulnerability Disclosure Policy

Last updated: 12 September 2026

At Joes Pet Supplies, we take the security of our website, online store, and customer information seriously. If you believe you have discovered a security vulnerability affecting joespetsupplies.store, we encourage you to report it responsibly so that we can investigate and address the issue where appropriate.

Please read this policy carefully before submitting a security report.

1. Purpose of This Policy

This policy explains how security researchers, customers, and members of the public can responsibly report potential security vulnerabilities affecting Joes Pet Supplies.

We welcome good-faith reports that may help us protect our website, customers, orders, and online services.

2. Responsible Reporting Principles

When investigating or reporting a potential security issue, we ask that you act responsibly, lawfully, and in good faith.

In particular, please:

  • Give us reasonable time to investigate and address a reported issue before considering public disclosure.
  • Do not access, copy, modify, download, delete, or disclose customer information, order information, personal data, or other confidential information.
  • Do not attempt to gain unauthorised access to customer accounts, administrative systems, payment information, passwords, or other restricted areas.
  • Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate that a potential issue exists.
  • Do not intentionally disrupt, damage, overload, or degrade our website or services.
  • Do not conduct denial-of-service attacks or stress testing.
  • Do not use malware, phishing, spam, social engineering, or physical attacks.
  • Do not perform automated high-volume scanning that could negatively affect our website or services.
  • Make reasonable efforts to prevent privacy violations, data loss, service disruption, or damage.
  • Comply with all applicable laws and regulations.

Nothing in this policy authorises unlawful activity or access to information, accounts, systems, or services that you do not have permission to access.

3. How to Report a Vulnerability

If you believe you have identified a security vulnerability affecting joespetsupplies.store, please contact us at:

Email: support@joespetsupplies.store

Please provide enough information for us to understand and, where appropriate, safely reproduce the issue.

Your report may include:

  • The affected page, URL, feature, or section of our website
  • A clear description of the suspected vulnerability
  • Safe steps for reproducing the issue
  • Screenshots or screen recordings where useful
  • A description of the potential security impact
  • Your contact information if you would like us to follow up with you

Please do not include passwords, complete payment information, customer personal information, or other unnecessary sensitive data in your report.

If you accidentally encounter sensitive or confidential information, stop testing and notify us.

4. What You Can Expect From Us

After receiving a security report, Joes Pet Supplies will aim to:

  • Review the information provided
  • Determine whether the reported issue can be reproduced
  • Assess the potential security and privacy impact
  • Take appropriate action where reasonably necessary
  • Request additional information if needed

Response and resolution times may vary depending on the severity and complexity of the reported issue and the information available to us.

5. Scope

This policy applies to security vulnerabilities directly affecting systems and services that are owned or controlled by Joes Pet Supplies, including:

  • joespetsupplies.store
  • Pages and features operated as part of our online store
  • Customer-facing account functionality associated with our website
  • Checkout-related functionality under our control
  • Order or customer-data security issues associated with systems under our control

Our store may rely on third-party ecommerce, payment, delivery, hosting, analytics, application, or other technology providers.

This policy does not give you permission to test third-party systems or services that Joes Pet Supplies does not own or control.

6. Out-of-Scope Reports

Reports that are generally outside the scope of this policy include:

  • Theoretical vulnerabilities without a demonstrated security impact
  • Automated vulnerability scanner reports without meaningful explanation or evidence
  • Missing security headers without a demonstrated security risk
  • Clickjacking on pages where no sensitive action can be performed
  • Rate-limiting observations without a demonstrated security impact
  • Self-XSS affecting only the reporter's own browser or account
  • Social engineering
  • Phishing
  • Spam or bulk-email testing
  • Physical security testing
  • Denial-of-service or stress testing
  • Issues limited to obsolete or unsupported browsers or devices

We may review reports of this nature at our discretion but cannot guarantee a response.

7. No Guaranteed Reward or Bug Bounty

Joes Pet Supplies does not currently operate a guaranteed paid bug bounty programme.

We appreciate responsible reports that help improve the security of our online store. However, submitting a vulnerability report does not create an entitlement to payment, compensation, employment, a contract, or any other reward.

Any reward or recognition, if offered, is entirely at our discretion and must be expressly agreed by us.

8. Public Disclosure

Please do not publicly publish, disclose, or distribute details of a suspected or confirmed vulnerability without our prior written permission.

We ask that you provide us with reasonable time to investigate and, where appropriate, resolve a confirmed security issue before disclosure is considered.

9. Confidentiality

Information obtained or exchanged as part of a vulnerability report should be handled responsibly and confidentially.

You must not intentionally collect, retain, disclose, or distribute:

  • Customer personal information
  • Order information
  • Account credentials
  • Payment information
  • Screenshots containing private customer information
  • Confidential business information
  • Technical information that could unnecessarily enable others to exploit a vulnerability

If you accidentally access confidential information, please stop testing and contact us promptly.

10. Legal Considerations

Joes Pet Supplies supports responsible and good-faith vulnerability reporting carried out in accordance with this policy.

However, this policy does not provide permission to:

  • Violate applicable laws or regulations
  • Access information that you are not authorised to access
  • Gain unauthorised access to customer or administrative accounts
  • Damage, modify, or delete systems or data
  • Disrupt the operation of our website or services
  • Conduct fraudulent or malicious activities
  • Test third-party systems without the relevant owner's permission

Joes Pet Supplies reserves its legal rights in relation to malicious activity, fraud, extortion, deliberate service disruption, data theft, unauthorised access, or other activity conducted outside the scope of this policy.

11. Contact Information

For security vulnerability reports or security-related questions concerning our website, please contact:

Joes Pet Supplies
Flat 29, Knowles House
51 Longstone Avenue
London, NW10 3AZ
United Kingdom

Website: joespetsupplies.store
Email: support@joespetsupplies.store
Phone: +44 7868 244635