At Eco Outdoor Garden Centre, we are committed to maintaining the security, privacy, and reliability of our systems and your data. We value the contributions of ethical security researchers and the broader technology community in helping us identify and address any potential vulnerabilities.
If you’ve discovered a security issue related to Eco Outdoor systems, services, or infrastructure, we encourage you to report it to us responsibly under the terms of this Responsible Disclosure Policy.
1. Our Commitment
If you comply with this policy in good faith, Eco Outdoor commits to:
Acknowledging your report promptly
Validating and assessing the submission in a timely and respectful manner
Working together with you (where appropriate) to address valid concerns
Not taking legal action against you for reporting vulnerabilities responsibly
Issuing a token of appreciation or public acknowledgement (if applicable), subject to eligibility
2. How to Report a Security Vulnerability
Please send any suspected vulnerability details to our security contact at:
Any relevant screenshots, logs or supporting materials
Your contact details (optional if you wish to remain anonymous, but preferred for follow-up)
We encourage you to encrypt sensitive data using a secure channel, which can be arranged upon request.
3. Guidelines for Responsible Reporting
To ensure a collaborative and positive interaction, please:
Report the issue directly and promptly to us before disclosing it publicly
Do not exploit the vulnerability or access personal data, accounts, or systems beyond what is necessary to demonstrate the issue
Avoid privacy violations, degradation of services, or use of malware
Refrain from publicly disclosing any details until we’ve had a reasonable opportunity to investigate and, if necessary, implement mitigation steps
4. Non-Qualifying Submissions
While we appreciate all efforts, certain types of submissions do not qualify under this Policy. These may include, but are not limited to:
Publicly disclosed or known issues (e.g. CVEs)
Informational messages, stack traces, or default error pages
Clickjacking without sensitive user interaction
Issues on pages without meaningful impact or functionality (e.g. robots.txt, favicon access)
Spam or brute force vulnerabilities (unless novel or bypassing security layers)
5. Scope of This Policy
This policy covers security vulnerabilities or privacy issues that may affect:
Our website or web applications
APIs, backend systems or integrations
Data protection mechanisms involving customers or business operations
Any environment under Eco Outdoor’s direct control
It does not authorise attempts to gain access to third-party platforms linked to Eco Outdoor which are not within our operational purview.
6. Legal Protection for Good-Faith Reports
Eco Outdoor will not pursue legal action against anyone who:
Acts in good faith to discover and report a vulnerability
Follows the principles laid out in this policy
Does not exploit the issue or act maliciously
We reserve legal rights in matters involving bad-faith activity, fraud, disruption, unauthorised data access, or damage to our systems or reputation.
7. Acknowledgement of Contributions
Where appropriate, and only with your permission, Eco Outdoor may offer:
A certificate of appreciation for valid, qualifying submissions
Recognition on a dedicated Security Hall of Thanks page
Future collaboration opportunities with our digital and security teams
While we currently do not offer a formal bounty reward programme, this may evolve with future policy updates.
8. Policy Evolution
As technology and security practices evolve, so will our Responsible Disclosure Policy. We reserve the right to update and clarify scope or requirements without prior notice; the most current version will be available on our website.
Thank you for helping us maintain the trust and safety of the Eco Outdoor Garden Centre platform.
We appreciate your commitment to responsible disclosure and the security of our customers.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.