Security Incident Response Policy
Last updated: 14 July 2026 · COD Fraud Guard
This policy describes how SC COVERED SRL (trading as TrackWise, CUI: RO47818139, Str. Principală nr. 98, Strei, Hunedoara county, Romania), operator of the COD Fraud Guard app, detects, handles and communicates security incidents affecting the app or the personal data it processes on behalf of merchants.
1. What counts as an incident
- Unauthorised access to production systems, the database or provider accounts (Shopify Partner, Railway, SMS/tracking providers)
- Accidental or unlawful destruction, loss, alteration or disclosure of personal data
- Compromise of secrets (API keys, signing secrets, database credentials)
- Vulnerabilities reported by merchants, researchers or providers that expose personal data
2. Detection
- Application and infrastructure logs on Railway are reviewed on alerts and after every deployment
- Shopify Partner and provider dashboards provide anomaly and usage alerts
- Merchants and researchers can report issues at support@trackwise.studio (acknowledged within 24 hours)
3. Response steps
1. Identify and classify: confirm the incident, assess scope — which shops, which data categories, which time window
2. Contain: revoke and rotate affected credentials and signing secrets, block unauthorised access, take affected components offline if needed
3. Eradicate and recover: patch the root cause, restore from encrypted backups where necessary, redeploy from reviewed source
4. Document: timeline, root cause, data affected, actions taken
4. Notification
- Affected merchants (data controllers) are notified without undue delay after confirmation of a breach affecting their customers' data — at the latest within 72 hours — with the information they need for their own GDPR notifications: nature of the breach, categories and approximate number of data subjects, likely consequences, measures taken
- Where the Operator acts as controller (merchant account data), the supervisory authority (ANSPDCP) is notified within 72 hours where required by Art. 33 GDPR
- Shopify is informed where the incident affects platform integrations
5. Post-incident
Every incident ends with a written post-mortem: what happened, why, what was changed to prevent recurrence. Corrective actions are tracked to completion. This policy is reviewed after every incident and at least annually.
6. Contact
Security contact: support@trackwise.studio. Please include "SECURITY" in the subject line for priority handling.