Effective date: June 2026
Company: GLOBAL BROTHER S.L.
Website: [https://www.globalbrother.es]
Security contact: [security@globalbrother.es]
1. Purpose
GLOBAL BROTHER S.L. is committed to protecting the confidentiality, integrity, and availability of the systems, data, applications, and services we operate.
This Security Policy describes the organizational and technical controls we use to protect business data, seller data, customer data, marketplace data, and API data, including data processed through TikTok Shop integrations.
2. Scope
This policy applies to:
3. Security Governance
Global Brother maintains internal security practices designed to protect systems and data from unauthorized access, disclosure, misuse, loss, alteration, or destruction.
Security responsibilities are assigned internally, and access to systems and data is granted only where necessary for legitimate business purposes.
4. Access Control
We apply access control measures based on the principle of least privilege.
Access to systems, databases, APIs, cloud services, and business tools is limited to authorized personnel who require access for their role.
We use authentication controls, role-based access permissions, password requirements, and account management procedures. Access rights are reviewed periodically and removed when no longer required.
5. Authentication
Where supported, we use multi-factor authentication for administrative accounts, cloud services, developer accounts, and other sensitive systems.
Credentials, API keys, tokens, and secrets must be stored securely and must not be shared through insecure channels.
6. Encryption
We use encryption to protect data in transit and, where applicable, data at rest.
Data transmitted through websites, APIs, and integrations is protected using HTTPS/TLS. Sensitive credentials, tokens, secrets, and authentication data are stored using secure mechanisms appropriate to the system.
7. API Security
For API-based services, including TikTok Shop integrations, we apply controls designed to protect API credentials, tokens, and seller data.
These controls may include:
We only request API permissions necessary to provide the approved service.
8. Data Segregation
Where our systems process data for multiple sellers, clients, or shops, we logically separate data by account, seller, shop, or business relationship.
Access to seller-specific data is restricted to authorized users and systems.
9. Logging and Monitoring
We maintain logs for security, troubleshooting, audit, and service reliability purposes.
Logs may include authentication events, API requests, system events, errors, and administrative actions.
Logs are protected against unauthorized access and retained only as long as necessary for security, audit, operational, and compliance purposes.
10. Vulnerability Management
We use reasonable vulnerability management practices to identify, assess, and remediate security weaknesses.
These practices may include:
11. Secure Development
We follow secure development practices for applications, APIs, and integrations.
These practices include limiting access to production systems, using secure coding practices, protecting credentials, validating input, reviewing changes before deployment, and separating development and production environments where appropriate.
12. Vendor and Third-Party Security
We use third-party service providers for hosting, infrastructure, communication, analytics, support, logistics, and other business functions.
We select vendors that provide appropriate security and privacy protections and require them to process data only for authorized purposes.
13. Incident Response
Global Brother maintains procedures to identify, investigate, respond to, and mitigate security incidents.
In the event of a confirmed security incident, we will take appropriate steps to contain the issue, assess the impact, restore secure operations, notify affected parties where required, and comply with applicable legal and contractual notification obligations.
Security incidents can be reported to:
[security@globalbrother.es]
14. Data Backup and Recovery
We use backup and recovery practices designed to support service continuity and data availability.
Backups, where applicable, are protected from unauthorized access and retained according to operational and legal requirements.
15. Data Retention and Secure Deletion
Data is retained only for as long as necessary for business, legal, security, audit, and contractual purposes.
When data is no longer required, we delete, anonymize, or securely archive it according to applicable retention and deletion procedures.
16. Employee and Contractor Responsibilities
Employees and contractors with access to company systems or data are expected to follow internal security practices, protect credentials, report suspicious activity, avoid unauthorized data sharing, and use company systems responsibly.
17. Security Reviews and Improvements
We periodically review and improve our security practices based on operational needs, technology changes, platform requirements, regulatory requirements, and identified risks.
18. Contact
For security questions, vulnerability reports, or security-related requests, contact:
GLOBAL BROTHER S.L.
Avda. del Doctor Arce 14, Madrid 28002, Spain
Email: [security@globalbrother.es]
©2026 All Rights Reserved
Global Brother