Report a vulnerability
If you find a security problem in RetailIntel, we want to hear about it, and we will work with you to fix it.
Last updated
How to report
Email a security report with the affected address, steps to reproduce, and the impact you see. Please do not include other people's personal data. We acknowledge reports within 3 working days, keep you updated, and credit you when the fix ships if you would like. We do not run a paid bounty programme.
Scope and rules
- In scope: retailintel.in and its subdomains, the RetailIntel API and our emails.
- Out of scope: denial-of-service, spam, social engineering, physical attacks, and findings in third-party services we use (report those to the vendor).
- Only test against your own account. Do not access, change or delete data that is not yours; stop and tell us if you do by accident.
- Give us reasonable time to fix the issue before you disclose it publicly.
Safe harbour
If you follow this policy in good faith, we will not take legal action against you or ask others to, and we will treat your research as authorised under our Terms.