How SMAERD protects information, handles client and advertising data, and responds to security issues.
SMAERD implements administrative, technical, and physical safeguards to protect client data and the systems we develop and operate.
Role-based access with least-privilege principle. System and data access restricted to authorized personnel on a need-to-know basis.
API credentials, tokens, and keys are stored securely. Secrets are never hardcoded or exposed in client-facing systems or repositories.
HTTPS/TLS for all data in transit. Data at rest is encrypted where applicable to the sensitivity and requirements of the data.
Access and operations logging for audit purposes. System monitoring to detect unauthorized access or anomalous activity.
We collect and process only the data necessary to deliver our services. Data no longer required is securely deleted.
Development, testing, and production environments are logically separated. Client data is isolated between engagements.
When processing advertising data on behalf of clients — including data accessed through the Amazon Ads API — we apply the following additional safeguards:
| Minimum necessary access | We access only the advertising data required to deliver the authorized services. |
|---|---|
| Client isolation | Each client's advertising data is logically separated. Data from one client is never shared with or accessible to another. |
| No sale or unauthorized sharing | Advertising data is not sold, rented, licensed, or disclosed to unauthorized third parties. Where service providers are required, data is processed only in accordance with applicable platform requirements and under appropriate confidentiality safeguards. |
| Need-to-know access | Within SMAERD, only personnel directly involved in delivering the client's services may access their advertising data. |
| Data deletion | Upon termination of services, client request, or platform request, advertising data is promptly deleted. |
| Authorization revocation | Clients may revoke data access at any time through their advertising platform account settings. |
For details on the specific types of advertising data we access and how authorization works, see Section 10 of our Privacy Policy.
If you discover a security vulnerability, data privacy concern, or suspect any unauthorized access or misuse of data handled by SMAERD, please report it immediately.
Contact: [email protected]
Please include: A description of the issue or vulnerability, steps to reproduce (if applicable), and any relevant supporting information.
1. Submission & Acknowledgment — We acknowledge receipt of the report within 2 business days.
2. Internal Logging & Tracking — Reports are documented internally and tracked through investigation, remediation, and resolution.
3. Assessment — We assess the reported issue, determine its scope and severity, and begin investigation.
4. Remediation — We take appropriate steps to address and resolve the issue.
5. Notification — For incidents involving advertising platform data (such as Amazon Data), we will report and notify the affected client and relevant platforms in accordance with applicable agreements, policies, and laws.
6. Resolution & Follow-up — We communicate the resolution to the reporter and implement measures to prevent recurrence.