1. Our approach
Fullstack Connections, Inc operates Parcel Watch. We use application access controls and infrastructure security features to protect the service and information entrusted to it. Security is an ongoing process, and no system is guaranteed to be free of vulnerabilities or interruptions.
This policy describes our approach and vulnerability-reporting process. It is not a security certification, an independent audit report, a service-level agreement, or a guarantee that a planned feature or control has been implemented. We do not claim SOC 2 or ISO 27001 certification for Parcel Watch.
2. Access and data handling
Where private account workspaces are available, the application uses authenticated accounts and account-scoped permissions, including database row-level access policies. Public lookup features are designed to show public-source property information rather than private workspace records. Administrative service credentials must remain on trusted server infrastructure.
Hosted connections use HTTPS. We rely on our infrastructure providers for underlying hosting, database, and storage security features. Access to workspace data is also affected by the members and integrations your organization authorizes. Avoid uploading unnecessary sensitive information or government portal passwords.
Security fixes, dependency updates, and operational investigations are part of maintaining the service. We assess reported issues based on likely impact and exposure. We do not promise a fixed remediation time, uninterrupted monitoring, a particular backup recovery objective, or lossless recovery under this policy.
3. How you can help protect your account
Use a unique password or trusted sign-in provider, enable available multifactor authentication, protect recovery methods, and review workspace membership. Sign out on shared devices and remove access that is no longer needed. Do not send us passwords, session cookies, access tokens, private keys, or full payment-card details.
Email-monitoring unsubscribe links contain a private token that lets the holder manage that subscription. Do not share those links publicly. Report suspected account or subscription compromise promptly to legal@fullstackconnections.com. Include your account email and a description of the issue, but no secrets. If an account or provider offers session revocation or credential rotation, use those controls when appropriate.
4. Reporting a vulnerability
Send reports privately to legal@fullstackconnections.com with the subject “Security report — Parcel Watch.” Include the affected URL or component, clear reproduction steps, expected and actual behavior, likely impact, and a minimal proof of concept using your own test data. Redact personal information and secrets from screenshots and logs.
An initial report should contain only the information needed to understand and reproduce the issue. Ask us for a suitable transfer method before sending sensitive evidence. We will review reports and coordinate follow-up where possible. Do not assume a report has been received or resolved until we respond; this policy does not promise a particular response deadline.
5. Responsible research and scope
Research under this policy is limited to Parcel Watch application surfaces operated by us, using your own accounts and data or accounts for which you have explicit permission. Cloudflare, Supabase, government portals, payment and email providers, and other third-party systems are outside this authorization. Ask us before testing if ownership or scope is unclear.
Use the minimum activity needed to demonstrate an issue. Do not perform denial-of-service, load testing, credential stuffing, phishing, social engineering, persistence, malware delivery, destructive changes, or bulk extraction. Do not access, change, retain, or share another person’s information. If you unexpectedly encounter it, stop immediately, preserve only a minimal redacted description, and report the issue.
Allow us a reasonable opportunity to investigate and remediate before publicly disclosing technical details. We welcome coordinated disclosure. We do not offer a guaranteed bounty or other payment.
7. Incidents and policy updates
If we identify a security incident, we will investigate, take appropriate containment and remediation steps, and notify affected people or authorities as required by applicable law. We may also provide relevant service updates. We will avoid disclosing details that would create additional risk.
We will post material changes to this policy with an updated effective date. Security questions and reports should be directed to Fullstack Connections, Inc at legal@fullstackconnections.com.
Questions or requests?
Contact Fullstack Connections, Inc about legal, privacy, or security matters.
legal@fullstackconnections.com