ShipSaving Company grants nonexclusive, limited license to all visitors for using the platform for personal and commercial applications. Different licenses apply for the corresponding types of use. The licenses are subjected to certain restrictions as follows:
All the content and elements related to ShipSaving in any way must have proper notices and symbols on all the documents including the copies.
ShipSaving Company has all the rights to terminate the site at any given moment without notifying you, the visitor, in any way. All visitors agree that the ShipSaving Company will NOT be held liable for any further changes, improvements, suspensions, or site termination. Visitors also agree that the company has no obligation of any kind to offer customer support for nonrelated businesses or requests.
You agree that all the content found at the ShipSaving at this very moment or in an indefinite future belongs solely to the ShipSaving Company and you do not have any rights, interest, or title to the aforementioned elements. All visitors are granted partial or complete access as aforementioned.
ShipSaving, available at https://shipsaving.com is an e-store management software developed for processing labels, batch label printing, assisting with the shipment, and offering smart scan features.
All users are required to register and pick a pricing plan available on the site’s official page. Each user must create a unique username and password which must not be shared with third parties. From the ShipSaving main menu, the solution can be integrated into any online store to assist with shipments and processing time.
ShipSaving also allows the user to manage the warehouse and manage all the shipments which are sent using the online store.
ShipSaving is currently available for integration in over 20+ e-Commerce platforms. The software allows the users to track shipments and use real-time reporting developed to enhance the overall shipping experience and make the entire process less time-consuming. To get the detailed integration information, please check https://shipsaving.com/en/partners. ShipSaving has the right to add new partners to the list without notifying you or future users about the newly formed partnership. New partners will be available at the official site of the company.
OTHER USERS, ADS, AND THIRD-PARTY LINKS
ShipSaving doesn’t hold responsibility for possible disputes among the other users. ShipSaving will not be held responsible for the loss or damage of the data and content. We are not responsible for any user-created, managed, or imported content in any way. Hereby all visitors to the ShipSaving site agree that the ShipSaving company and all of its employees, managers, agents, developers, testers, and other personnel won’t be held responsible for any loss or damage of the data or the content in any way and ShipSaving’s employees will not be mandated to participate in any disputes. For visitors from California, the United States, you hereby accept the civil code section 1542 which states: "a general release does not extend to claims which the creditor does not know or suspect to exist in his or her favor at the time of executing the release, which if known by him or her must have materially affected his or her settlement with the debtor."
WEB BEACONS AND THE COOKIES OF THE SHIPSAVING
ShipSaving offers multiple types of services. If any, your monthly or yearly service fee will be calculated based on the service presented to you and agreed to by you. In addition, you are responsible for all variable and transactional costs of using the service (including but not limited to: postage, fees for carrier services, package insurance, direct and indirect costs of third-party service providers and carriers, transaction fees charged directly by ShipSaving for shipping or other services, or other special services in addition to your applicable service fee, if any. The total shipping fees quoted may include third-party carrier fees and fees charged directly by ShipSaving Rates for services charged will be based on the rates that are available for your account and may be updated by ShipSaving at its sole discretion. ShipSaving may, at its discretion, offer substitute services for any selected services.
CARRIER SERVICE REGULATION
ShipSaving offers shipping services. You will strictly abide by the service provider terms (including USPS, FedEx, UPS, DHL Express) and services regulations provided by the carrier. Any fines caused by the violation of the carrier's regulations will be borne by you. All the arrears due to the fines must be paid by the user within 7 days. ShipSaving won't be providing the original invoice due to the sensitive information contained. ShipSaving reserves the right to pursue its legal liability if it refuses to pay within the time limit.
You may only access ShipSaving’s carrier accounts through ShipSaving’s system at the precise address as https://s.shipsaving.com/ after signing up as a ShipSaving user, and you may only purchase shipping labels through ShipSaving’s accounts for your own shipments, integrated store orders, and upload tracking information through ShipSaving’s system. You may not lend, sell, and by any means share access to ShipSaving’s accounts with an unauthorized third party. Shipments must be shipped from warehouses authorized by ShipSaving, and you may not share access to ShipSaving’s carrier accounts with unauthorized warehouses. ShipSaving reserves the right to pursue its legal liability if accounts were accessed by an unproven third party.
You may request a refund for unused postage through ShipSaving but such refund is subject to the policies of the applicable Courier. If a Courier refuses to issue a refund, ShipSaving will not be responsible for refunding any postage amount paid to such Courier. ShipSaving may, at its discretion, issue a refund of any fees paid in addition to the Courier’s postage fees. If a refund is issued, it will be provided no earlier than 30 calendar days after the order date. USPS postage fee refund claims must be filed within 23 calendar days after the postage or order has been created. Any other postage or fee refund claims must be filed within 30 calendar days after the postage or the order has been created.ShipSaving shall not be responsible for any local customs charges, import taxes or duties fees, or any other similar charge(s) incurred through the carriage and/or delivery of any shipments and you must satisfy yourself as to whether any of these charges will become due, and if so in what amounts, before completing an order with us. If any such charges become due as a result of a carriage and/or delivery of a shipment on your behalf and are charged to us by any competent authority, you agree to reimburse us fully in respect of the same within 30 calendar days of our demand.
In the event that the ShipSaving user would like to void their shipping label purchase under the provision of the ShipSaving software, the user must nullify their order within the specified time period allotted from the integrated carrier of the order. To specify, the time periods allotted from ShipSaving’s four integrated carriers require the user to void their order within: i) 23 calendar (twenty-three) days from the date of purchase (USPS). ii) 30 (thirty) calendar days from the date of purchase (UPS/FEDEX/DHL). It is within the jurisdiction of ShipSaving to deny any requests to void an order past the aforementioned time periods allotted by the four integrated carriers. ShipSaving is not responsible for any type of refund or reimbursement for all efforts to void an order after the aforementioned time periods allotted by the four integrated carriers. ShipSaving is not responsible for the user’s claims for any fiscal or legal losses past the aforementioned time periods allotted by the four integrated carriers.
ACCOUNT SERVICES AND DURATION
ShipSaving reserves the right to suspend or terminate your account for lack of use, lack of payment, or breach of Terms. In general, all ShipSaving user accounts are maintained perpetually until terminated by the user.
ACCOUNT CANCELLATION/ TERMINATION
METHOD OF PAYMENT
By providing your credit card details and agreeing to these Terms you authorize us to charge your credit card with any amounts due to us under these Terms. Without limiting this, if you incorrectly describe the dimensions and/or weight of your package, we may charge you any additional amounts we incur as a result, plus a $10 administration fee per case.
We will use reasonable efforts to keep any payment information we have about you secure and ensure that our employees or agents who have access to this information do not make any unauthorized use, modification, reproduction, or disclosure of it. We may engage a third party to provide a secure payment transaction facility that allows you to pay online and, in this case, we will not receive your payment information.
Billing – ShipSaving's service fee and any other applicable fees due, including fees for postage or shipping (if applicable), will be automatically charged to the account holder's credit card or collected via direct account withdrawal from the account holder's bank account.
The billing entity for part or all of the services provided by ShipSaving may be that of an affiliate or partner of ShipSaving and you hereby consent to any such billing, including changes to the billing entity from time to time.
SHIPPING RESTRICTED ITEMS
ShipSaving does not allow nor encourage the shipping of prohibited and restricted items. Items that are strictly prohibited and their shipping is punished by the law are: Ammunition · Airbags · Gasoline · Marijuana · Explosives
The aforementioned items are prohibited from any form of shipping within the United States borders. ShipSaving is not responsible for potential users neglecting the recommended page and shipping the prohibited items.
Items that are restricted for shipping within the United States are also restricted for use alongside ShipSaving. Those items may be possessed by the officials and properly handled or destroyed. ShipSaving does not allow shipping of: Aerosol · Alcohol beverages in any amount · Cigarettes or tobacco in general · Cremated remains · Dry Ice · Guns and firearms · Glues · Lithium-ion batteries · Live animals · Matches · Prescription drugs · Medicine · Nail polishes · Paint · Perfumes of any size · Perishable objects and items · Poisons, etc.
ShipSaving users must also comply with the regulations for prohibited items of the integrated carrier companies (USPS/DHL/FEDEX/UPS). The failure to comply with the rules and regulations of the aforementioned carrier companies regarding prohibited and restricted items may result in both monetary and legal penalties which ShipSaving is not responsible for.
ShipSaving may make an API (Application Program Interface) available to Customers at ShipSaving’s sole discretion. Customers may access their ShipSaving account data via an API. Any use of the API, including use of the API through a third-party product that accesses ShipSaving, is bound by this agreement.
ShipSaving will not be liable for any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to, damages for loss of profits, goodwill, use, data, or other intangible losses (even if ShipSaving has been advised of the possibility of such damages), resulting from your use of the API or third-party products that access data via the API; Abuse or excessively frequent requests to ShipSaving via the API may result in the temporary or permanent suspension of your account’s access to the API. We will, in our sole discretion, determine abuse or excessive usage of the API and we will make a reasonable attempt to warn you (or that account holder if that is not you) prior to suspension.
We reserve the right at any time to modify or discontinue, temporarily or permanently, your access to the API (or any part thereof) with or without notice.
Under this term, you agree that ShipSaving will not be liable for any of your damages unrelated to your shipping costs during the period when ShipSaving is found to be responsible for the malfunction of its site, services, or its software.
A written statement in which you suspect the distribution, posting, or cooperating with harmful data or physical items.
A written statement in which you provide actual facts and honest claims of the issue in question.
Note that all false accusations will result in you being subjected to the layer cost, fees, and potential loss of the accused user. ShipSaving does not hold any responsibility for the matter and doesn’t have any connections with both parties.
NO UNLAWFUL OR PROHIBITED USE
As a condition of your use of this Site, you are contractually obligated to ShipSaving that you will not use the Site for any purpose that is unlawful or prohibited by these Terms, or the laws and regulations of the jurisdiction in which you are located or to which your envelope/parcel was sent. You may not use the Site in any manner that could damage, disable, overburden, or impair the Site or ShipSaving. You may not obtain or attempt to obtain any materials or information through any means not intentionally made available or provided through the Site. ShipSaving reserves the right at all times to disclose any information as necessary to enforce any applicable law, regulation, legal process, or governmental request.
Use and Applications
All disputes between the user and the ShipSaving company that cannot be resolved using informal resolutions will be finalized by the following Arbitration Agreement. All the details, claims, and procedures under the Arbitration Agreement are processed in the English language and no other languages are available at this very moment. If or when the available language occurs, ShipSaving may inform you through the provided email address once your account is created. The Arbitration Agreement you are reading applies to all the visitors and users of ShipSaving and all connections, partners, and other personnel involving the company and the relationship between the two.
Before proceeding with any dispute or claim, the first party must send a written notification to the other party. The official claim or dispute to ShipSaving must be sent through the contact form on the Site. All disputes will tend to be resolved within 30 business days (during peak season might take longer). In the case where a dispute/claim cannot be resolved, both parties may start the arbitration process immediately. The arbitration process may be started only 30 (thirty) days after the last attempt to resolve the dispute informally.
Rules of Arbitration
All the disputes that are covered by the following arbitration agreement will be taken to the American Arbitration Association or AAA. If the mentioned provider is unable to consider or take or accept the dispute another ADR will be selected. Both parties must agree on the new ADR provider without exceptions of any kind. American Arbitration Association is available online and either of the two parties can contact the AAA at any given moment using the online form.
Non-appearance arbitration may be selected when agreed by both parties or when specified by the American Arbitration Association. In the mentioned case scenario, online, telephone or written means will be used to access the dispute and solve it. American Arbitration Association will not involve additional witnesses or any appearances unless specified by both parties. Time limits do apply to the arbitration and they are specified by the AAA and by the statute of limitations. All the deadlines and the time limits in any form of theirs are specified and applied by the AAA.
If or when the arbitration is selected, an arbitrator will specify all the liabilities and all the rights of the user and the company, ShipSaving. The dispute will be handled by itself and there won’t be any merges with other disputes or other parties in any form possible. The selected arbitrator will have the right to award monetary compensation, non-monetary solution of the dispute, and to use the full list of rules and laws specified by the AAA terms and rules. The arbitrator has full rights as a judge at the court of law and he or she has the right to make the award permanent and final.
JURY OR WAIVER TRIAL TERMS AND REGULATIONS
EMERGENCY EQUITABLE RELIEF
According to the arbitrary agreement, both parties in a dispute have the right to request emergency equitable relief. The sole purpose of this request is to maintain the status quo and can be used in the federal or state court of law. This request will not be considered as a waiver of any obligations or rights of a party.
DISPUTES THAT ARE NOT ELIGIBLE FOR ARBITRATION
All computer frauds, forging of the data, abuse act, copyright violation, trade, or any use of the other party patent are not eligible for the arbitration agreement. In the aforementioned circumstances, both parties agree on seeking professional legal help to understand specific actions that are needed to resolve this at the local court. ShipSaving may be eligible from arbitration for the import and export laws from the United States and the same rules in other countries, based on the user location and the local law. ShipSaving is an online located company available for users globally.
You agree to defend, hold harmless and indemnify ShipSaving, its officers, directors, employees, and agents, from and against all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to attorney’s and administrative fees) arising from: (i) your use of and access to the Site, Services, and Software; (ii) your violation of any term of these Terms; (iii) your violation of any third-party right, including without limitation any copyright, property, or privacy right; or (iv) any claim that one of your submissions caused damage to a third-party. This defense and indemnification obligation will survive these Terms and your use of the Site.
In a case of dispute or a potential dispute, both parties, ShipSaving, and you must use proper means of communication. They are telephone, email or letters if possible. A user visiting the site and using the ShipSaving services consent to: accept emails and letters from the company in the use of notifications; accept emails and telephone calls in the formal updates regarding the new or completed dispute; accept email communication, written communication, and telephone calls. ShipSaving has the full right to contact the user using any forms of the aforementioned means. If the formal writing medium is unable to reach the user, other mediums will be used in a specific order, email and telephone call.
Account Access——All transactions originating from your account are your responsibility, the account holder is responsible for all charges incurred.
Account Delinquency——If the attempt to deposit any balance into the user’s account becomes void, ShipSaving will automatically deduct that specific amount from the user’s account. Until the account is updated with a sufficient balance, your ShipSaving account will be suspended or terminated when reached a negative balance. If you fail to pay your service fee multiple times or you maintain a negative account balance, ShipSaving may elect, in its sole and absolute discretion, to terminate your account. In this event, along with all other arrearages, ShipSaving may charge a $25 processing fee.
Authority——By completing the registration process, you agree to pay all fees incurred on your account under the terms of the service plan selected by you. If a ShipSaving account is established for a business or other entity, the person establishing the account represents that he or she has all necessary authority to establish an account with ShipSaving on behalf of the business or other entity who is the responsible account holder.
Collection——Each party agrees that if any amount due is not made on time, the aggrieved party may pursue the past due amounts directly or assign a collection agency to pursue the collection of the past due amounts and any interest or cost of collection permitted by law.
Credit Verification——ShipSaving reserves the right to verify the credentials of all personnel or companies applying for services.
No Minors——You may not register for Services if you are under 18 years of age. By registering for Services you represent to ShipSaving that you are 18 years of age or older.
Order Acceptance/Rejection——ShipSaving reserves the right at any time after receipt of an order for products or services to accept or decline the order for any reason.
Relocation——You agree to provide an updated and valid address and registration information to ShipSaving in the event of relocation or other changes.
Risk of Loss——ShipSaving is not responsible for any risk of loss. Please refer to the carrier’s policy for further information.
Service Changes——ShipSaving reserves the right, periodically and at any time, to modify or discontinue, temporarily or permanently, any functions and features of its services, in its sole discretion, with or without notice, except otherwise prohibited by law. ShipSaving reserves the right, in its sole discretion, to offer selected products from its third-party partners, to each customer and does not warrant or represent that a full complement of services from each partner will be available through ShipSaving’s services. ShipSaving may, at its discretion, offer substitute services for any selected services.
If any provision of these Terms is held to be invalid or unenforceable, such provision will be deemed to be restated to reflect as nearly as possible the original intention in accordance with applicable law, and the remainder of the Terms will remain in full force and effect. These Terms constitute the entire agreement between the parties with respect to the subject matter hereof and supersede and replaces all prior or contemporaneous understandings or agreements, written or oral, regarding such subject matter. Any waiver of any provision of the Terms will be effective only if in writing and signed by ShipSaving. The failure to enforce any right under these Terms shall not be a waiver of the provision or the right to enforce it at a later time.
Although we make reasonable efforts to provide accurate pricing information and product descriptions, errors regarding product availability may occur. We reserve the right to be held responsible for any of your damages unrelated to shipping costs.
THIRD-PARTY TERMS AND CONDITIONS
You are responsible for following the terms and conditions of all carriers and partners accessed through the Site. Please visit each individual site to obtain and review their terms and conditions. Use of carrier services via the ShipSaving platform is at your own risk. ShipSaving is not responsible for your use of carrier services. Your use of carrier services is as a direct customer relationship to the specific carrier of your choosing and you agree to be bound by the terms and conditions of that carrier for use of services, including the payment of any fees associated and a carrier’s right to open, inspect and assess your package before and after collection.
VIOLATIONS OF LAW
ShipSaving services may not be used in violation of any law or in any way that unduly interferes with others' use of the services.
AGREEMENT BETWEEN USERS AND SHIPSAVING.COM
PERSONAL INFORMATION COLLECTED
In order to access the features provided by ShipSaving.com, it is necessary for Users to provide us with Personal Information. It is the User’s voluntary decision whether or not to provide the request information to use ShipSaving.com. If no information or data is provided then use of ShipSaving.com would be severely limited as a result. ShipSaving.com collects personal information such as name, address, telephone numbers, email addresses, shipping information and payment details as part of your registration and use of ShipSaving.com’s products and services.
NON-PERSONAL INFORMATION COLLECTED
ShipSaving.com may collect information on User based on use of ShipSaving.com. ShipSaving.com may store “cookies” in your computer to better serve you. Cookies can gather non-personal information such as the internet site that you have previously visited before ShipSaving.com, the website you visited after ShipSaving.com, the browser you are viewing ShipSaving.com from your IP address, location tracking and more. The purpose is to improve the quality of ShipSaving.com and increase ShipSaving.com’s marketing initiatives. You may limit the usage of cookies from your browser settings.
HOW INFORMATION IS SHARED
THIRD PARTY PRIVACY POLICIES AND DATA COLLECTION
OTHERS TERMS AND USAGE AGREEMENTS
User consent to receive electronic communications and user agree that all agreements, notices, disclosures and other communications that we provide to you electronically, via email and on the Site, satisfy any legal requirement that such communications be in writing upon visiting ShipSaving.com
ShipSaving.com follows industry standards to protect the personal information and data submitted by Users to the Website. However, no method of security is 100% secure. User is responsible for maintaining the confidentiality of User’s account or password and accepting responsibility for all activities that occur under User’s account or password. User acknowledges that ShipSaving.com is not responsible for third party access to accounts that results from theft or misappropriation of User’s account. ShipSaving.com and its associates reserve the right to refuse or cancel service, terminate accounts, or remove or edit content at our sole discretion.
You may close your account at any time, upon the fact that your account has no pending or negative balance. When you terminate or stop using your account, we may continue to communicate with you about our services, updates, and products. We may also continue to use some of your information for business purposes and to improve our business. We will retain and use your information as required by applicable law. ShipSaving.com’s information management policies will comply with legal and reporting obligations, resolve disputes, and enforce our agreements.
LINKS TO THIRD PARTY SITES/THIRD PARTY SERVICES
ShipSaving.com may contain links to other websites ("Linked Sites"). The Linked Sites are not under the control of ShipSaving.com and ShipSaving.com is not responsible for the contents, links, terms of usage or services of any Linked Site. Certain services made available via ShipSaving.com are delivered by third party sites and organizations. By using any product, service or functionality originating from the ShipSaving.com domain, you hereby acknowledge and consent that ShipSaving.com may share such information and data with any third party with whom ShipSaving.com has a business relationship to provide the requested service on behalf of ShipSaving.com users and customers. By using any services or functionality of ShipSaving.com, you hereby acknowledge and comply with terms and conditions from any other third Party Businesses/Services/Websites/Companies/Organizations, including but not limited to: FedEx,UPS,USPS,eBay and Amazon.
The Service is controlled, operated and administered by ShipSaving.com from our offices within the USA. If you access ShipSaving.com outside the USA, you are responsible for compliance with all local laws. You agree that you will not use the ShipSaving.com in any country or in any manner prohibited by any applicable laws, restrictions or regulations.
You agree to indemnify, defend and hold harmless ShipSaving.com, its officers, directors, employees, agents and third parties, for any losses, costs, liabilities and expenses (including reasonable attorneys' fees) relating to or arising out of your use of or inability to use the Site or services. Any actions committed by User in violation of any terms of this ShipSaving.com’s, terms of a third party, any applicable laws, rules or regulations will result in ShipSaving.com the right, at its own cost, to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which event you will fully cooperate with ShipSaving.com in asserting any available defenses.
THIRD PARTY ACCOUNTS
In the event that You will be able to connect your ShipSaving.com account using a third party accounts, you acknowledge and agree that you are consenting to the continuous release of information about you to others (in accordance with your privacy settings on those third party sites). If you do not want information about you to be shared in this manner, do not connect your ShipSaving.com account using a third-party account.
LIABILITY DISCLAIMERThe information, software, products, and services included in or available through the site may include inaccuracies or typographical errors. Changes are periodically added to the information herein. ShipSaving.com and associates may make improvements and/or changes in the site at any time. ShipSaving.com and it’s partners make no representations about the reliability, usefulness, accuracy of the information, services, software and graphics contained on this site for any purpose. To the maximum extent permitted by applicable law, ShipSaving.com operates “as is” without warranty or condition of any kind for ShipSaving.com’s contents. This “as is” without warranty extends to all implied warranties or conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by applicable law, in no event shall ShipSaving.com and it’s partners be liable for any direct, indirect, punitive, incidental, special, consequential damages or any damages whatsoever including, without limitation, for loss of use, data or profits, arising out of or in any way connected with the use or performance of the site, with the delay or inability to use the site or related services, the provision of or failure to provide services, or for any information, software, services and contents obtained through the site, or otherwise arising out of the use of the site, whether based on contract, tort, negligence, strict liability or otherwise, even if ShipSaving.com and it’s partners has been advised of the possibility of damages. If you are dissatisfied with ShipSaving.com in any way, please discontinue using the site.
ShipSaving works diligently to ensure the confidentiality, integrity, and availability of your data.
· Encryption in transit protects the confidentiality, integrity, and authenticity of your data. As an industry best-practice, we use HTTPS to encrypt customer data sent and received by our servers. This includes, but is not limited to, all data transmitted over the RESTful JSON API that communicates with our backend microservice architecture. This protects your information from tampering and unauthorized disclosure. We also implement AES-GCM (an authenticated encryption algorithm based on a pre-shared key) to protect both the confidentiality and integrity of data transmissions.
· Database access controls restrict access to authorized users and IP addresses. Developers undergo strict account management. Auditing and robust log records provide relevant insights to personnel who regularly review database access for signs of malicious operation. Database passwords must adhere to internal standards for complexity. Database contents are encrypted both at rest and in transit.
· Field-level encryption with the AES-GCM algorithm protects sensitive database entries from unauthorized tampering or disclosure. When the application writes data to the database, sensitive fields are encrypted with an additional key. When the contents of an encrypted database field are retrieved, the results cannot be deciphered without the respective key. This second line of defense significantly reduces the potential impact of leaked data. Our software developers and database administrators (DBAs) operate by default on encrypted fields. Access to the original contents of encrypted fields is granted to staff only on a "need-to-know" basis.
· Data desensitization protects sensitive customer data such as phone numbers, email addresses, and payment card information. Predefined rules tokenize, hide, or mask this data. For extremely sensitive data such as payment card information, we only persist a subset of the original, significantly increasing customer safety.
Role-based access control (RBAC) assigns functional and data permissions to designated roles, and one or more roles to individual user accounts. A "super administrator," for instance, not only possesses global access to all actions and data, but will also typically customize other roles as needed and assign them to users. Our system administrators apply specific role assignments to customers. This ensures that customers possess functional authority and data authority over only their own data. Malicious actions may attempt to tamper with input parameters to conceal executable commands or cross trust boundaries. This can lead to the unauthorized acquisition of server permissions and the unauthorized disclosure of customer data. The system addresses these concerns as follows:
· Buffer overflows occur when a system receives input of a length that overflows the memory area designated for its storage. A malicious user who succeeds at this attack may tamper with or expose data, or possibly gain system root access. To avoid receiving data that exceeds system capacity, we treat external data as untrusted input and perform boundary checks before committing to our systems.
· Cross-site request forgery (CSRF) can occur when an attacker causes a victim's browser to automatically submit a request. This attack is similar to, but different from, a cross-site scripting (XSS) attack. In the case of CSRF, the attacker crafts a malicious request directed at a particular website. If the customer has an active browsing session on that website, the request can be executed to create, read, update, or delete data as the customer themselves. This is equivalent to the attacker logging in with the customer's own credentials to carry out harmful actions within the scope of the customer's authority. To prevent CSRF attacks and protect customer accounts, the system validates CSRF tokens, HTTP referer headers, and CAPTCHA responses.
· Path traversal can occur when query parameters and server paths are not properly sanitized or validated before use in accessing a server-side file system location. An attacker may supply a string with directory navigation operators, possibly escaped (e.g., "../" or "%2E%2E%2F"), to gain unauthorized access to information systems. To prevent this, all customer input is validated and/or escaped after transmission.
· A web shell is a type of remote access trojan (RAT) that exploits a script upload vulnerability to create a command execution environment. An attacker will often use this shell environment through a web browser. This can lead to a series of hazards such as unauthorized information disclosure and tampering. To avoid receiving a web shell, we strictly limit and verify uploaded files. Customers may upload only static files and the system does not trust original filenames. In addition to restricting the upload of malicious code files, the system restricts the execution permissions of related directories.
· Unexpected data disclosure may occur when access logs record sensitive query parameters. To prevent this, the HTTP GET method is not used to transmit sensitive data into the system. When sensitive data must be transmitted into the system, the HTTP POST method is used, and sensitive data placed in the body of the request. The HTTP GET method may be used to transmit non-sensitive data to the system, and to retrieve both sensitive and non-sensitive data from the system.
Customer password security promotes not only the security of customer information on our platform but also the stability of the system as a whole. Some customers may use the same password on multiple platforms; once this password is cracked, the risk of data leakage exists on any other platforms with which it is shared. We mitigate the potential for damage as follows:
· The system assigns an authentication token to customers at login. This token accompanies the customer throughout their session and grants the ability to access assigned functions and data. The system reduces the potential for unauthorized disclosure or tampering by requiring a valid token with requests for privileged functions and data.
· User authentication checks occur with every request. We encourage customers to log out manually when they are finished with the system. As a protection against abandoned sessions, if authentication credentials expire or the authentication process fails, the customer will be required to log in again to minimize the potential for data leakage.
· The AES-GCM encryption algorithm promotes authenticity in the system with authentication codes and authenticated encryption with associated data (AEAD). If system decryption functions note authenticity issues during the decryption process, an exception will be thrown to prevent further processing of corrupted or tampered customer data.
· Customer password length and complexity requirements mitigate the likelihood of brute-force password cracking. We guarantee that customer passwords are not stored in plaintext. Customer passwords are salted and hashed on the frontend with a slow hash operation. Sensitive data, including authentication credentials, will be transmitted to the backend only over a connection encrypted with HTTPS.
· Two-factor verification validates customer ownership of email addresses used for website authentication. When we detect a customer account at risk of misappropriation, the affected customer must correctly supply both their password and a one-time code that the system will send to their email address. CAPTCHA affords an additional layer of protection for this process.
We are continuously strengthening our product security controls to ensure the maximum confidentiality, integrity, and availability of customer accounts and data.
The vast majority of customer operations trigger the creation of audit logs. This provides customers the ability to trace events when necessary. We provide operation logs for each event that include a timestamp, customer ID, the object being operated on, and the contents of the operation. To facilitate unified management, system administrators have the ability to view the operation logs of all customers.
· We record operations performed by customers on their own data. If an operation involves sensitive data, such as password or payment card information, metadata attached to log entries will be encrypted to minimize the potential for data leakage.
· Customer requests for data will be approved or denied based upon credentials and additional security considerations. The results of these decisions will be recorded.
· Multiple customer user accounts may collaborate as a team. In these cases, a team administrator may be designated as an approver for purchase orders placed by other team members. For example, a warehouse manager who wishes to create a purchase order will submit an application to their administrator for approval. The administrator can then choose to deny or approve the application. If the application is approved, the purchase order will be created. The system records these decisions with per-application granularity.
· Potentially risky operations trigger alarms to be handled by dedicated personnel.
· Logs are retained for 180 days.
Developers are subject to sound auditing and log management. We mitigate the potential for developer credential misuse by logging the following events:
· Login and logout timestamps;
· Database and server access attempts;
· Data, file, and network access attempts;
· Changes to customer data, such as deletion or modification of sensitive info;
· Exceptions or other signs of abnormal activity, which may trigger alarms.
Firewalls and network security policies deny or redirect data flow to reduce the efficacy of malicious network-based attacks. Security rules are optimized to establish a proper security perimeter for system components.
Network Access Control (NAC) restricts server access to authorized developers, originating from whitelisted IP addresses, who comply with pertinent security policies.
When network bandwidth becomes saturated it can exhaust server processing capacity, preventing legitimate users from being able to access resources. A distributed denial-of-service (DDoS) is one sort of malicious attack that can produce this result. To address this risk, we:
· Limit the frequency of requests from individual IP addresses;
· Apply load-balancing to shunt traffic toward available servers;
· Disable ICMP on security devices such as firewalls;
· Deny or redirect abnormal traffic with a hardware firewall that mitigates the potential for DDoS with rule-based packet-filtering, deep packet introspection (DPI), and Web Application Firewall (WAF) filtering based on request contents and disposition;
· Apply ISP near-source cleaning and operator traffic suppression to minimize the potential for incidents that could adversely affect service availability to customers;
· Strictly limit, at the application layer, the number of connections and CPU usage time from individual IP addresses;
· Reduce unnecessary dynamic database queries.
A competent patch management process regularly reviews and addresses operating system vulnerabilities. Timely application of patches minimizes the potential for malicious attacks.
Unnecessary service ports are closed as part of the system hardening process.
Audit logs record every server operation. Designated security personnel regularly review these logs and respond immediately when an incident is noted.
To protect customer financial information, we do not store data from payment cards.A third-party vendor, Stripe, acts as our payment processor. Please refer to Stripe for more information on their security policies and procedures.
Developers regularly undergo training to improve security and privacy awareness.The use of external storage media (USB disks, portable hard drives, thumb drives, etc.) is prohibited on company computers.The use of unsecured public cloud applications, including file synchronization tools such as Dropbox and Google Drive, is also prohibited on company computers.
Our customers fulfill orders with the aid of transactional and other data ("Platform Data") synchronized into our system from third-party e-commerce platforms ("Marketplaces"). To ensure the availability of Platform Data when it is needed, we perform regular backups. Each Marketplace imposes its own policies on the use, protection, and retention of Platform Data.
ShipSaving treats Platform Data, and backups thereof, in strict accordance with the requirements of each Marketplace. We do not maintain Platform Data beyond the retention periods mandated by Marketplaces. We do not sell, share, or otherwise disclose customer data in any manner that would violate our agreements with Marketplaces.
· Full database backups occur weekly at 23:59 on Sunday.
· Incremental database backups occur daily at 03:00, 09:00, 15:00, and 21:00.
· The database currently utilizes master-slave synchronization to promote data redundancy. Binary logging on the slave database is enabled for off-site backup.
· Future plans include database read-write separation ("master write, slave read") to promote scalability and high-availability. This master-slave synchronization architecture, with backups in accordance with the original backup scheme, may entail a split into separate databases and additional tables to further improve the ShipSaving recovery time objective (RTO) and recovery point objective (RPO) metrics.
SECURITY INCIDENT RESPONSE PLAN(SIRP)
We maintain a security incident response plan (SIRP) and we review and verify this plan every six months and after any major infrastructure or system change. When our backend engineering managers investigate security incidents, or when automation mechanisms trigger an alarm.
· We identify the type and extent of any associated events.
· We disconnect any relevant systems from the network.
· We gather evidence. System logs may be viewed without shutting down associated servers, which promotes forensic analysis of potential evidence in memory, if required.
· In the event that a breach may affect passwords, we will lock down sensitive information and rotate any relevant passwords.
· The impact of a data breach will be assessed based upon logs and other available evidence. Once a root cause analysis is performed, remedial measures will be taken. These may include, but are not limited to, cryptographic erasure of affected systems, patching of relevant software or operating systems, reconfiguration of firewalls, isolation of subnets, malware scanning, and recalibration of automated alarm thresholds.