Information Security Policy
Stu Designs LLC d.b.a. Doormat.com / WoodByStu
1. Purpose and Scope
This Information Security Policy ("Policy") establishes the information security framework that Stu Designs LLC d.b.a. Doormat.com / WoodByStu ("the Company," "we," "us," or "our") uses as the baseline for daily operations. Its purpose is to protect the confidentiality, integrity, and availability of the information we handle — including personal information about our customers and buyers, order and transaction data, business records, and credentials — against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
This Policy applies to all systems, applications, networks, servers, endpoints, cloud services, and integrations that store, process, transmit, or otherwise handle Company information or data received from the marketplaces and platforms on which we sell. It applies to all employees, contractors, service providers, and any other personnel who access Company systems or data (collectively, "Personnel").
Where a specific marketplace or platform imposes stricter or additional requirements, those requirements also apply and, to the extent of any conflict, the stricter requirement governs. See Section 16 for marketplace-specific commitments.
2. Roles and Responsibilities
- Information Security Lead — accountable for maintaining this Policy, approving access, reviewing logs and access rights, coordinating incident response, and ensuring the framework is reviewed and updated on schedule. In our organization this responsibility sits with ownership/operations and may be delegated in writing.
- System and Data Owners — responsible for the systems and datasets under their control, including approving access requests and applying the controls in this Policy.
- All Personnel — responsible for complying with this Policy, protecting credentials, using only the access granted to them, and reporting suspected security incidents promptly.
Failure to comply with this Policy may result in revocation of access, disciplinary action, contract termination, or, where applicable, legal action.
3. Information Security Framework
Stu Designs LLC d.b.a. Doormat.com / WoodByStu maintains an established information security framework consisting of the physical, administrative, and technical safeguards described in this Policy. This framework serves as the baseline for daily operations and governs how information is protected throughout its lifecycle.
The framework, together with its supporting policies and guidelines, is reviewed and updated on a regular basis — at least annually, and whenever there is a material change to our systems, data processing activities, vendors, or the requirements of the platforms and laws that apply to us — so that appropriate and current security measures are enforced consistently throughout the organization.
4. Access Control Policy
Stu Designs LLC d.b.a. Doormat.com / WoodByStu maintains this published Access Control Policy and restricts access to systems and personal data based on the principle of least privilege.
4.1 Least Privilege and Need-to-Know
Access to systems and to personal data is granted on a least-privilege, need-to-know basis. Personnel are given only the minimum access required to perform their specific role and no more. Access to personal information (such as buyer name, address, email, phone number, and order details) is restricted to those with a genuine business need.
4.2 Role-Based Access for Employees and Contractors
Access privileges are granted based on specific, defined roles. Employees and contractors receive access according to the role they perform, and access rights are scoped to the systems and data that role requires. Broad or administrative access is limited to a small number of trusted individuals.
4.3 Unique Accounts and Authentication
Each user is assigned a unique account; shared or generic logins are not permitted for access to systems that hold Company or marketplace data. Multi-factor authentication (MFA) is required for administrative and privileged accounts and for marketplace Seller Center / partner accounts wherever the platform supports it. Credential requirements are defined in Section 5.
4.4 Provisioning and Deprovisioning
Access is granted only after approval by the Information Security Lead or the relevant System/Data Owner. When a person changes roles, their access is adjusted to match the new role. When a person leaves the Company or a contract ends, their access and user permissions are revoked promptly — within one business day of separation.
4.5 Access Logging
System access logs are generated and retained. Logins, administrative actions, and access to systems that hold personal data are logged so that access can be monitored, reviewed, and investigated. Log retention and monitoring are described in Section 7.
4.6 Periodic Access Review
User privileges to Company systems are reviewed at least once a year to confirm that each account still requires its access and to remove access that is no longer needed. Privileged, administrative, and PII-access roles are reviewed more frequently (at least quarterly). Any access found to be unnecessary is removed as part of the review.
5. Authentication and Credential Management
- Passwords. Personnel and systems with access to Company or marketplace data must use strong passwords. At minimum, passwords are at least 8 characters and include uppercase letters, lowercase letters, numbers, and special characters. Where a platform requires periodic rotation (for example, Amazon's Data Protection Policy), password-based credentials are rotated at least quarterly. Longer passphrases and MFA are preferred over frequent rotation wherever a platform permits.
- Multi-factor authentication. MFA is enabled on all administrative accounts, marketplace Seller Center / partner accounts, the email account(s) used to recover those accounts, and any system that provides access to personal data, wherever supported.
- Secrets and API credentials. API keys, OAuth tokens, webhook signing secrets, and similar credentials are stored in a secrets manager or equivalent protected store. They are never hardcoded into source files, theme files, or client-side code, never committed to source control, and never exposed in logs or URLs.
- Credential hygiene. Credentials are not reused across platforms, are not shared over insecure channels, and are rotated promptly if compromise is suspected.
6. Encryption
- In transit. All Company and marketplace information is encrypted in transit using current, industry-standard protocols (TLS/HTTPS) whenever it traverses a network or is sent between hosts.
- At rest. Personal data and other sensitive information are encrypted at rest on servers, databases, and storage.
- Backups. Backups that contain personal or sensitive data are encrypted.
- Key management. Encryption keys and secrets are protected, access to them is restricted under this Access Control Policy, and they are rotated where appropriate.
7. Logging and Monitoring
- Access to systems and to personal data is logged, and logs are retained for a period sufficient to support monitoring, investigation, and applicable compliance requirements.
- Logs and systems are monitored for suspicious activity, such as repeated failed logins, unusual access patterns, or abnormal request volumes.
- Account lockout and alerting mechanisms are used to detect and respond to suspicious activity; affected permissions are reviewed and, where warranted, revoked pending investigation.
- Administrative and PII-access events are reviewed as part of the periodic access review in Section 4.6.
8. Network and System Security
- Network protection controls, including firewalls and access control lists, are used to restrict access to authorized users and systems and to deny access from unauthorized sources.
- Systems are kept up to date with security patches, and endpoint protection (anti-malware) is maintained on systems that access Company or marketplace data.
- Systems are hardened by disabling unnecessary services and applying secure configurations.
- Intrusion detection and monitoring are used to identify and respond to unauthorized activity.
9. Data Minimization, Retention, and Disposal
- Minimization. We collect and retain only the personal data needed to operate our business and fulfill orders.
- Retention. Personal data is retained only as long as necessary for the purpose for which it was collected, or as required by law. Where a marketplace imposes a retention limit — for example, Amazon's requirement that order-related personal information generally be retained no longer than 30 days after order fulfillment unless retention is required by law — we honor that limit for data received from that platform.
- Disposal. When personal data is no longer needed, it is securely deleted or de-identified.
- Devices and media. Personal data received from marketplaces is not stored on removable media or personal/unmanaged devices.
10. Data Segregation
- Data received from each marketplace or platform is kept logically segregated from the data of others, and in particular from any platform competitor's data, where required by that platform.
- Test/development data is kept separate from production data; where synthetic or de-identified data can be used for testing, it is preferred.
- We do not aggregate or combine one marketplace's buyer data with another's for purposes outside fulfilling and supporting the specific order, and we do not create cross-marketplace benchmarks from restricted marketplace data.
11. Vendor and Subprocessor Management
- Third parties that process personal data on our behalf (for example, shipping carriers, printers, fulfillment partners, hosting and IT providers, and analytics vendors) are engaged only where they can provide protections consistent with this Policy and applicable law.
- Vendors are granted only the access they need under the Access Control Policy, and their access is reviewed and revoked when no longer required.
- We do not sell, trade, or share marketplace buyer data with third parties for their own independent purposes.
12. Security Awareness and Training
Personnel with access to Company or marketplace data are made aware of this Policy and their responsibilities under it, including safe credential handling, recognizing phishing, and reporting incidents. Awareness is refreshed periodically and when the Policy is materially updated.
13. Vulnerability and Patch Management
- We apply security patches to systems and dependencies in a timely manner.
- We periodically review our systems for vulnerabilities and address identified issues promptly.
- For any code we develop or maintain (including marketplace integrations and automation), we follow secure-development practices such as validating inputs and outputs, verifying webhook signatures, reviewing changes, and scanning dependencies.
14. Incident Response and Breach Notification
- A "security incident" is any actual or suspected unauthorized access to, acquisition, use, disclosure, corruption, or loss of Company or marketplace information, or breach of any environment that holds such information.
- Suspected incidents are reported to the Information Security Lead promptly upon discovery.
- We investigate, contain, and remediate incidents, revoking affected access and preserving relevant logs.
- We provide breach notifications to affected individuals, marketplaces, and authorities as required by applicable law and by the terms of the affected platform, within the timeframes those requirements specify.
15. Physical and Device Security
- Physical access to facilities and devices where personal data is processed is restricted to authorized Personnel.
- Devices that access Company or marketplace data are secured with strong authentication, encryption where available, screen locks, and endpoint protection.
- Lost or stolen devices with access to Company data are reported immediately so that access can be revoked.
16. Marketplace-Specific Compliance
Stu Designs LLC d.b.a. Doormat.com / WoodByStu sells across multiple platforms and commits to complying with each platform's applicable data-protection and security requirements, in addition to this Policy. Where a platform requirement is stricter, the stricter requirement governs. These include, without limitation:
- Amazon — the Selling Partner API Data Protection Policy (DPP) and Acceptable Use Policy (AUP), including least-privilege/need-to-know access, encryption in transit and at rest, credential and password standards, logging, retention limits on order personal information, and compliance certification and recordkeeping on request.
- Walmart — the Marketplace Information Security Addendum, including maintaining a written information security program with physical, technical, and administrative safeguards, access controls, logging, encryption in transit and at rest, monitoring, training, and logical segregation of Walmart information.
- Shopify — the Protected Customer Data requirements (Levels 1 and 2 as applicable), including data minimization, least-privilege API scopes, encryption (including of backups), separation of test and production data, secure secret handling, and an up-to-date privacy policy.
- TikTok Shop — the applicable seller and partner data-security requirements, including maintaining an information security framework, a published access-control policy with least-privilege/need-to-know access, retained access logs, at-least-annual privilege review, encryption, and MFA, and using buyer data only for permitted order-fulfillment purposes.
- Etsy — the Seller Policy and API Terms of Use, including protecting members' personal information, maintaining a compatible privacy policy, and complying with applicable data-protection laws.
Each platform maintains its own privacy and security policies for data on its systems; this Policy governs the systems and data under our control.
17. Compliance, Recordkeeping, and Certification
- We maintain records reasonably required to demonstrate compliance with this Policy and with the marketplace requirements referenced in Section 16.
- Upon a platform's request, we will certify our compliance and cooperate with reasonable assessments to the extent required by our agreements with that platform.
- We complete any annual business-information or high-volume-seller certifications required by the platforms on which we sell.
18. Policy Review and Updates
This Policy is reviewed and updated at least annually and upon any material change to our systems, data flows, vendors, or applicable platform and legal requirements. The "Last Updated" date above reflects the most recent revision. Material updates are communicated to affected Personnel, and continued access to Company systems is conditioned on adherence to the current Policy.
