Security & Data Handling

How SMAERD protects information, handles client and advertising data, and responds to security issues.

Information Security

SMAERD implements administrative, technical, and physical safeguards to protect client data and the systems we develop and operate.

ACCESS CONTROL

Role-based access with least-privilege principle. System and data access restricted to authorized personnel on a need-to-know basis.

CREDENTIAL MANAGEMENT

API credentials, tokens, and keys are stored securely. Secrets are never hardcoded or exposed in client-facing systems or repositories.

ENCRYPTION

HTTPS/TLS for all data in transit. Data at rest is encrypted where applicable to the sensitivity and requirements of the data.

LOGGING & MONITORING

Access and operations logging for audit purposes. System monitoring to detect unauthorized access or anomalous activity.

DATA MINIMIZATION

We collect and process only the data necessary to deliver our services. Data no longer required is securely deleted.

ENVIRONMENT SEPARATION

Development, testing, and production environments are logically separated. Client data is isolated between engagements.

Advertising Data Handling

When processing advertising data on behalf of clients — including data accessed through the Amazon Ads API — we apply the following additional safeguards:

Minimum necessary accessWe access only the advertising data required to deliver the authorized services.
Client isolationEach client's advertising data is logically separated. Data from one client is never shared with or accessible to another.
No sale or unauthorized sharingAdvertising data is not sold, rented, licensed, or disclosed to unauthorized third parties. Where service providers are required, data is processed only in accordance with applicable platform requirements and under appropriate confidentiality safeguards.
Need-to-know accessWithin SMAERD, only personnel directly involved in delivering the client's services may access their advertising data.
Data deletionUpon termination of services, client request, or platform request, advertising data is promptly deleted.
Authorization revocationClients may revoke data access at any time through their advertising platform account settings.

For details on the specific types of advertising data we access and how authorization works, see Section 10 of our Privacy Policy.

Security & Privacy Issue Reporting

If you discover a security vulnerability, data privacy concern, or suspect any unauthorized access or misuse of data handled by SMAERD, please report it immediately.

Contact: [email protected]

Please include: A description of the issue or vulnerability, steps to reproduce (if applicable), and any relevant supporting information.

Our Response Process

1. Submission & Acknowledgment — We acknowledge receipt of the report within 2 business days.

2. Internal Logging & Tracking — Reports are documented internally and tracked through investigation, remediation, and resolution.

3. Assessment — We assess the reported issue, determine its scope and severity, and begin investigation.

4. Remediation — We take appropriate steps to address and resolve the issue.

5. Notification — For incidents involving advertising platform data (such as Amazon Data), we will report and notify the affected client and relevant platforms in accordance with applicable agreements, policies, and laws.

6. Resolution & Follow-up — We communicate the resolution to the reporter and implement measures to prevent recurrence.