Security Controls Statement

At WeedPlugs.com, we maintain administrative, technical, and operational safeguards designed to protect customer information, secure e-commerce transactions, and reduce overall security risk. Our security model is built around a hosted e-commerce infrastructure, third-party validated payment processing, and controlled use of integrated service providers.


 

1. PAYMENT SECURITY AND PCI SCOPE

  • WeedPlugs.com does not store, process, or directly handle full payment card information on its servers. 
  • All payment transactions are processed through third-party, PCI DSS-compliant payment providers integrated within our Shopify-based checkout environment. Payment data is securely transmitted directly from the customer to the payment processor through encrypted channels.
  • Because payment data is handled externally by PCI-validated providers, WeedPlugs.com operates under a reduced PCI scope consistent with hosted e-commerce checkout models. At no point does WeedPlugs.com retain full cardholder data.

 

2. PLATFORM SECURITY (SHOPIFY INFRASTRUCTURE)


WeedPlugs.com is built on Shopify, a leading e-commerce platform that maintains its own
security controls, infrastructure protections, and PCI DSS compliance.

Shopify provides:

● Secure hosting and infrastructure management
● TLS-encrypted connections across storefront and checkout
● Continuous platform monitoring and patching
● Segregation of payment processing from merchant-controlled systems

This architecture ensures that sensitive payment operations are isolated from the
WeedPlugs.com application layer.

 


 

3. ENCRYPTION AND DATA TRANSMISSION

  • All data transmitted between users, the website, and integrated services is encrypted using industry-standard TLS protocols.
  • Sensitive transactional data is transmitted securely to payment processors and is not stored in raw form within WeedPlugs.com systems. Where applicable, third-party providers utilize tokenization or equivalent mechanisms to reduce exposure of sensitive data.

 


 

4. ACCESS CONTROL AND ACCOUNT SECURITY

Administrative access to WeedPlugs.com systems is restricted based on role and business necessity.

Controls include:

  • Unique user accounts for administrative access
  • Role-based permissions limiting access to sensitive functions
  • Multi-factor authentication (MFA) where supported
  • Controlled access to Shopify admin, payment dashboards, and third-party tools

Access is reviewed and adjusted as roles change.


5. THIRD-PARTY SERVICE PROVIDERS

WeedPlugs.com integrates a limited set of third-party services to support operations, fraud
prevention, and customer experience, including:

  • Payment processors (PCI DSS-compliant providers)
  • Fraud prevention tools (e.g., NoFraud)
  • Package protection services (e.g., Route)
  • Age verification systems (e.g., Age Checker)

These providers are selected based on their ability to support secure operations and are
expected to maintain their own security controls and c ompliance obligations.

WeedPlugs.com does not grant third-party services access beyond what is necessary for their defined function.


6. FRAUD PREVENTION AND RISK MONITORING

WeedPlugs.com utilizes third-party fraud detection and risk management tools to monitor
transactions and reduce unauthorized activity.

These systems analyze transaction patterns and provide risk scoring to support secure order processing decisions.


7. VULNERABILITY MANAGEMENT AND PLATFORM MAINTENANCE

Because WeedPlugs.com operates on a managed platform (Shopify), core infrastructure
patching and security updates are handled by the platform provider.

At the application level, WeedPlugs.com:

  • Limits use of third-party integrations
  • Reviews and manages installed applications
  • Removes unused or unnecessary tools
  • Monitors for operational or security issues

8. DATA MINIMIZATION AND HANDLING

WeedPlugs.com collects only the information necessary to fulfill orders, provide customer
support, and meet legal or regulatory requirements.

Customer data is:

  • Stored within secured platform environments
  • Accessed only by authorized personnel
  • Retained only as long as operationally necessary

WeedPlugs.com does not store full payment card information.


 

9. INCIDENT RESPONSE AND OPERATIONAL CONTINUITY

WeedPlugs.com maintains procedures for identifying, escalating, and responding to
security-related events.

In the event of a suspected issue, actions may include:

  • Investigation and containment
  • Coordination with platform providers or service vendors
  • Customer communication where required

Operational dependencies on Shopify and third-party providers include their own security and recovery processes.


 

10. CONTINUOUS REVIEW

Security practices are periodically reviewed and adjusted based on:

  • Changes in infrastructure or vendors
  • Evolving risk factors
  • Industry standards and best practices

CONCLUSION

WeedPlugs.com utilizes a layered security approach built on a secure hosted platform,
third-party PCI-compliant payment processing, controlled access, and limited, purpose-driven integrations.

By avoiding direct handling of payment card data and leveraging established infrastructure
providers, WeedPlugs.com reduces exposure while maintaining secure and reliable transaction processing.