# Responsible Disclosure | ShopBack Discover

Canonical URL: https://discover.shopback.com/responsible-disclosure
HTML page: https://discover.shopback.com/responsible-disclosure
Last updated: 2026-09-23
This file is the Markdown twin of the HTML page above, generated from the same sources. Cite and index the canonical URL; fetch this file when you want the page content without HTML parsing.

How to report a suspected security vulnerability affecting ShopBack Discover, what to include, and how to test without harming readers or services.

If you find a security vulnerability in the public ShopBack Discover site, report it privately with enough detail for the team to reproduce and investigate the issue.

## What belongs in a report.

Report security issues that could affect the confidentiality, integrity, or availability of Discover pages, feeds, Markdown twins, or supporting public endpoints. Examples include cross-site scripting, broken access controls, unintended data exposure, or a way to alter content outside the normal publishing process.

A suspected issue in a ShopBack account, app, payment flow, or merchant site should be reported through that service’s official support or security channel instead. Include the affected product when the issue crosses a service boundary.

- The affected URL, endpoint, or page surface.
- A concise description of the impact and the steps needed to reproduce it.
- Request and response details, screenshots, or a minimal proof of concept when safe to share.
- Your preferred contact method and whether the issue is time-sensitive.

## How to report.

Send a private report through the contact route on the ShopBack corporate site and identify it as a Discover security report. Do not publish the vulnerability, exploit code, or reader data before the team has had a reasonable opportunity to investigate and coordinate a fix.


## Safe testing rules.

Test only accounts, content, and systems you own or have explicit permission to use. Keep tests low volume, avoid automated scanning that could affect availability, and stop as soon as you have enough evidence to explain the issue.

Do not access, change, download, or retain another person’s data. Do not send messages, alter published content, create accounts in someone else’s name, or use a vulnerability to move money or gain access to a ShopBack or merchant account.


## What happens after a report.

The team reviews the report, validates the scope and impact, and may ask for clarification or a safe reproduction. Fixes and public acknowledgements are handled case by case. Please do not assume that a report creates a contract, guarantees a reward, or authorizes testing outside the described scope.


## Editorial and privacy concerns.

For a factual correction or editorial complaint, use the contact route described on the Trust & Safety page. For questions about browsing data, read the Privacy Policy. Keeping these routes separate helps a security report reach the people who can respond to it.


## Related pages

- Trust & Safety: https://discover.shopback.com/trust-and-safety
- Privacy Policy: https://discover.shopback.com/privacy-policy
- Editorial policy: https://discover.shopback.com/editorial-policy

## Official references

- ShopBack corporate site: https://corporate.shopback.com
- ShopBack US: https://www.shopback.com
