Security Policy
1. Purpose
This Security Policy explains the measures used by PrintWare Tech to protect customer information, order information, payment-related data, account credentials, business records, and website systems from unauthorized access, misuse, loss, alteration, disclosure, or destruction.
This policy applies to our website, online store, administrative systems, employees, contractors, vendors, service providers, and any third-party tools used to operate the e-store.
2. Scope
This policy applies to all information collected, processed, transmitted, or stored through our business operations, including:
-
Customer names, addresses, phone numbers, and email addresses
-
Order details and shipping information
-
Customer account information
-
Payment-related information
-
Website activity and transaction records
-
Communications through email, website forms, WhatsApp, SMS, social media, or other customer service channels
-
Internal business records and administrative access credentials
3. General Security Commitment
We take reasonable administrative, technical, and physical safeguards to protect customer and business information. These safeguards are designed to reduce the risk of unauthorized access, accidental loss, misuse, fraud, data breaches, and service disruption.
No internet-based system is completely secure. However, we aim to use appropriate security practices, reputable service providers, access controls, encryption, monitoring, and staff procedures to help protect customer information.
4. Customer Account Security
Where customer accounts are available on our website, we use reasonable measures to protect account access.
Customers are responsible for:
-
Creating strong passwords
-
Keeping login details confidential
-
Not sharing account credentials with others
-
Logging out after using shared or public devices
-
Notifying us promptly if they believe their account has been accessed without authorization
-
We may reset passwords, suspend accounts, or restrict access where suspicious activity is detected.
5. Administrative Access Controls
Access to website administration, order systems, customer records, payment dashboards, email platforms, and business tools must be limited to authorized personnel only. Administrative security controls should include:
-
Unique login credentials for each authorized user
-
Strong passwords
-
Multi-factor authentication where available
-
Limited access based on job duties
-
Prompt removal of access when a staff member, contractor, or vendor no longer requires it
-
Restricted access to payment, customer, and order-management systems
-
Periodic review of user permissions
-
Shared admin accounts should be avoided unless technically unavoidable.
6. Password and Login Security
All staff, contractors, and authorized users must use secure login practices, including:
-
Strong passwords that are not easy to guess
-
Different passwords for different business systems
-
No password sharing by email, text message, WhatsApp, or social media
-
Password manager use where appropriate
-
Immediate password changes if compromise is suspected
-
Multi-factor authentication for critical systems where available
-
Default passwords must be changed before any system, platform, plugin, device, or service is used.
7. Payment Security
We use third-party payment processors and payment gateways to process online payments. We do not intentionally store full credit card or debit card numbers, CVV codes, PINs, or full magnetic stripe/chip data on our own servers, website files, email accounts, spreadsheets, or customer service systems.
Payment processors are responsible for securely handling payment authorization and card processing through their own systems. Customers should review the privacy and security practices of the payment processor used at checkout.
Our business will take reasonable steps to:
-
Use reputable payment processors
-
Avoid collecting card details manually unless absolutely necessary
-
Avoid storing full card numbers or CVV codes
-
Restrict access to payment dashboards
-
Review suspicious transactions
-
Follow applicable payment processor rules
-
Cooperate with chargeback, fraud, or payment-security investigations where required
8. Transmission of Card Details
Customers should enter card details only through the secure checkout page or approved payment processor interface provided on our website.
We do not encourage customers to send card details by email, WhatsApp, SMS/text message, Instagram or Facebook direct message, website contact forms, live chat, voice notes, screenshots, unsecured documents, or any other informal messaging channel.
If a customer sends card details through an unsecured or unapproved channel, we will not use those details to process payment through that channel. The message should be deleted or redacted where reasonably possible, and the customer should be directed to use the approved secure payment method.
Where cardholder data is transmitted over open or public networks, it should be protected using strong cryptography and secure transmission protocols, consistent with PCI DSS principles for protecting cardholder data in transmission.
Our business should not request or record:
-
Full card number, except through an approved secure payment gateway
-
CVV or card security code
-
PIN or online banking password
-
Full card images
-
Full payment screenshots showing complete card details
-
Where telephone payment collection is ever used, it must only be done through an approved secure process that prevents storage of sensitive authentication data and limits staff exposure to full card details.
9. Email and Communication Security
Customer communications may occur through email, phone, WhatsApp, SMS, website forms, or social media channels. Staff must not request sensitive payment data, passwords, PINs, banking passwords, or unnecessary identification documents through unsecured communication channels.
Business email accounts should be protected using:
-
Strong passwords
-
Multi-factor authentication where available
-
Limited user access
-
Suspicious-link awareness
-
Caution with attachments
-
Prompt reporting of suspected phishing or account compromise
-
Customers should be cautious when receiving payment links, account requests, or unusual instructions. If in doubt, customers should contact us directly using the official contact details listed on our website.
10. Customer Data Handling
Customer information should only be collected and used for legitimate business purposes, such as:
-
Processing orders
-
Delivering products
-
Communicating with customers
-
Handling returns or complaints
-
Preventing fraud
-
Maintaining business records
-
Complying with legal, tax, or regulatory obligations
-
Customer data should not be accessed, copied, exported, shared, or disclosed unless required for authorized business purposes.
11. Data Storage and Retention
Customer and business records should be stored securely and retained only as long as reasonably necessary for business, legal, accounting, tax, customer-service, fraud-prevention, or regulatory purposes. Data should be deleted, anonymized, archived, or securely destroyed when no longer required.
Sensitive data should not be stored in unnecessary locations, including:
-
Personal devices
-
Personal email accounts
-
Unprotected spreadsheets
-
Public cloud folders
-
WhatsApp chats
-
Social media inboxes
-
Printed notes left unsecured
12. Third-Party Vendors and Service Providers
We may use third-party vendors to support business operations, including payment processors, website hosting providers, e-commerce platforms, delivery and courier providers, email marketing platforms, customer service tools, analytics providers, fraud-prevention tools, and accounting or invoicing systems.
Before using a vendor, we should consider whether the vendor has appropriate privacy, security, and data-handling practices. Vendors should only receive the information necessary to perform their services.
13. Order, Delivery, and Fulfillment Security
Order and delivery information should be handled carefully to avoid misuse or unauthorized disclosure. Staff and delivery partners should only receive the customer information needed to complete delivery, such as customer name, delivery address, contact number, order reference, and delivery instructions.
Customer payment details should not be shared with delivery personnel unless absolutely necessary and authorized.
14. Fraud Prevention
We may review orders for fraud risk, unusual activity, inconsistent customer details, suspicious payment activity, chargeback patterns, or unauthorized account use. We reserve the right to:
-
Request additional verification
-
Delay order processing
-
Cancel suspicious orders
-
Refuse shipment or delivery
-
Report suspected fraud to payment processors, banks, law enforcement, or relevant authorities where appropriate
15. Staff and Contractor Responsibilities
All staff, contractors, and authorized representatives must:
-
Protect customer information
-
Use business systems only for authorized purposes
-
Keep passwords confidential
-
Avoid downloading unnecessary customer data
-
Avoid discussing customer information in public areas
-
Report suspected security incidents promptly
-
Follow payment-security procedures
-
Avoid collecting card details through unsecured channels
-
Use approved business communication tools where possible
-
Violation of this policy may result in removal of access, termination of engagement, or other corrective action.
16. Physical Security
Where customer records, devices, receipts, packages, or business documents are handled at a physical location, reasonable safeguards should be used, including:
-
Restricted access to staff-only areas
-
Secure storage of printed records
-
Proper disposal of documents containing personal information
-
Locking devices when unattended
-
Keeping delivery paperwork and customer details away from public view
-
Limiting access to stockrooms, order-processing areas, and administrative workstations
17. Device Security
Business devices used to access customer, payment, or order information should be protected by:
-
Passwords, PINs, or biometric locks
-
Updated operating systems
-
Antivirus or endpoint protection where appropriate
-
Screen locks
-
Secure Wi-Fi connections
-
Avoidance of public or unsecured Wi-Fi for administrative access
-
Remote wipe capability where available
-
Prompt reporting of lost or stolen devices
-
Personal devices should not be used for business administration unless approved and properly secured.
18. Backup and Recovery
Important business data should be backed up where appropriate to protect against accidental deletion, system failure, ransomware, or other disruption. Backup practices may include:
-
Regular backups of website data where supported
-
Secure storage of accounting and order records
-
Restricted access to backup files
-
Periodic checks to confirm backups are working
-
A recovery plan for critical systems
19. Incident Response
A security incident may include unauthorized access to customer information, lost or stolen devices, compromised email or admin accounts, malware or ransomware, payment fraud, accidental disclosure of customer data, suspicious website activity, or unauthorized changes to website or payment settings.
If an incident occurs, we will take reasonable steps to:
-
Identify and contain the issue
-
Secure affected accounts, systems, or data
-
Investigate what happened
-
Determine what information may have been affected
-
Notify relevant service providers, payment processors, banks, or authorities where required
-
Notify affected customers where appropriate or legally required
-
Reset credentials and strengthen controls
-
Document the incident and corrective actions taken
20. Breach Notification
If we determine that a data breach has occurred, we will assess the nature and scope of the breach, the type of information involved, the risk of harm, and any legal or contractual notification obligations. Where required, we may notify affected customers, payment processors, banks or acquiring institutions, website or hosting providers, law enforcement, regulatory authorities, and other relevant parties.
Notifications will be made in accordance with applicable law, contractual obligations, and reasonable business practices.
21. Data Minimization
We will aim to collect only the information reasonably necessary to provide products, process orders, deliver goods, communicate with customers, prevent fraud, and comply with applicable obligations. Unnecessary collection of sensitive personal data should be avoided.
22. Use of WhatsApp, SMS, Social Media, and Messaging Channels
Where we communicate with customers through WhatsApp, SMS, Instagram, Facebook, or similar tools, those channels are used for general customer service, order updates, product inquiries, delivery coordination, and marketing where permitted.
Customers should not send sensitive payment details, passwords, identification numbers, banking information, or other highly sensitive information through these channels. These third-party messaging platforms are operated by outside providers and may be subject to their own privacy and security practices.
23. Security Reviews
We may periodically review our security practices, including admin access, payment settings, website apps and plugins, vendor access, password practices, customer data storage, fraud patterns, staff compliance with payment- security rules, and backup and recovery readiness.
​
Security procedures should be updated when systems, vendors, laws, payment requirements, or business operations change.
24. Customer Responsibilities
Customers also play a role in protecting their information. Customers should:
-
Use strong passwords
-
Avoid sharing login credentials
-
Use secure internet connections
-
Review order confirmations carefully
-
Notify us promptly of unauthorized account activity
-
Avoid sending card details through email, WhatsApp, SMS, or social media
-
Confirm they are using our official website before entering payment information
25. Policy Updates
We may update this Security Policy from time to time to reflect changes in our business operations, website systems, payment methods, security practices, or legal requirements. Updates will be posted on our website with a revised effective date.
26. Contact Us
If you have questions about this Security Policy, wish to report a security concern, or believe your information may
have been accessed without authorization, please contact us:
PrintWare Online Jamica Limited
8 Haining Road, Kingston 5, Jamaica W.I.
