UFREECARE’s Responsible Disclosure Policy
UFREECARE takes the security of our systems and data privacy very seriously. We constantly strive to make our systems safe for our customers to use. However, if in the rare case a security researcher or member of the general public discovers a security vulnerability in our systems and responsibly shares the details with us, we appreciate their contribution and work closely with them to address any reported issue with urgency. Further, we are happy to acknowledge your contributions publicly.
Process to report an issue
- E-mail your findings to us. Please share your contact information with your mobile number.
- Do provide enough information to reproduce the problem, so we will be able to resolve it as quickly as possible.
- Screenshots or video recordings explaining the process in any detail would be greatly helpful.
Terms and Guidelines
- No user/customer data is modified, deleted or misused without prior explicit permission
- The finding of vulnerabilities should not cause any disruption of services and thus a deprecated user experience for any user
- You shall not expose the findings on any medium – including but not limited to social media, research papers and blogs (personal or otherwise)
- Any and all information and/or finding(s) regarding the vulnerability shall be kept confidential between you and Nykaa and not disclosed to any third party by you at any time
- Exploiting vulnerability for personal gains will lead us to take strict legal action against you
- In case of an inadvertent privacy breach, ensure that you notify us with immediate effect
- You shall allow us time to close the vulnerabilities identified
- Please remember that law of the land is always withheld and while conducting your research, you shall refrain from violating applicable laws and regulation, including but not limited to applicable information technology and data privacy laws
- Assist in mitigation of the vulnerability if required
- You hereby agree to the above mentioned Responsible Disclosure Guidelines and any deviation therefrom will entitle us to take appropriate legal action against you
-
AcknowledgementsWe are not part of a cash/bug bounty program but are happy to issue a certificate of recognition to individuals who report security issues responsibly and help us make UFREECARE systems more secure