Free shipping above ₹999 Easy returns and secure checkout

Responsible Disclosure

Guidelines for responsibly reporting potential security vulnerabilities.

Security is important to us

We value the work of security researchers and users who help identify potential vulnerabilities. This policy explains how to report a suspected security issue responsibly.

How to report

Send a detailed report to:

Please include:

  • A clear description of the suspected vulnerability.
  • The affected URL, endpoint, feature or application.
  • Steps required to reproduce the issue.
  • Screenshots, requests or logs with sensitive data removed.
  • Potential impact and suggested remediation, where known.
  • Your preferred name and contact information.

Research guidelines

When testing or investigating, do not:

  • Access or modify another customer’s information.
  • Download, retain or disclose personal information.
  • Disrupt website availability or performance.
  • Use denial-of-service, malware or destructive testing.
  • Send spam or automated high-volume traffic.
  • Attempt social engineering against staff or partners.
  • Physically access offices, systems or infrastructure.
  • Demand payment or threaten disclosure.
  • Publicly disclose an issue before reasonable remediation time.

Out-of-scope reports

The following generally do not qualify as security vulnerabilities:

  • Missing security headers without demonstrated impact.
  • Clickjacking on pages without sensitive actions.
  • Self-XSS requiring a user to execute their own code.
  • Rate-limit observations without practical security impact.
  • Version disclosure or generic scanner output.
  • Social-media account impersonation.
  • Issues affecting unsupported or outdated browsers only.

What you can expect

We aim to acknowledge valid reports within a reasonable period, investigate the issue and communicate meaningful status updates where practical.

Submission of a report does not create an employment, agency or contractual relationship and does not guarantee a reward. Any bounty or recognition is entirely discretionary unless a separate written programme states otherwise.

Good-faith research

We do not intend to pursue action against good-faith security research that follows this policy, avoids privacy harm and provides us reasonable time to investigate and remediate.

This statement does not authorise activity prohibited by law or by third-party systems and does not waive rights where research causes harm or exceeds these guidelines.