REPORT SECURITY ISSUES
Report Security Issues
Arc SportsCards is committed to maintaining the security of our website and protecting our customers. If you discover a security vulnerability or suspicious activity, we appreciate your help in reporting it responsibly.
1. Why Responsible Disclosure Matters
The security of arcsportscards.com and the protection of our customers' personal information, order data, and account details are priorities for Arc SportsCards. Security vulnerabilities, even minor ones, can potentially be exploited by malicious actors to compromise customer data, disrupt services, or damage trust.
We encourage anyone who discovers a potential security issue to report it to us responsibly, so that we can investigate, address the issue, and continue to provide a safe shopping environment for Pokémon trading card collectors and enthusiasts.
Responsible disclosure means reporting the vulnerability directly to Arc SportsCards, allowing us a reasonable opportunity to investigate and resolve the issue before any public disclosure. This approach protects our customers and the broader community.
2. What to Report
We welcome reports about the following types of security concerns:
- Website Vulnerabilities: Issues that could allow unauthorized access to website systems, databases, or customer data.
- Cross-Site Scripting (XSS): Vulnerabilities that could allow injection of malicious scripts into web pages viewed by other users.
- Cross-Site Request Forgery (CSRF): Vulnerabilities that could allow unauthorized commands to be executed on behalf of authenticated users.
- SQL Injection: Vulnerabilities that could allow unauthorized access to or manipulation of database information.
- Authentication or Session Issues: Flaws in login, session management, or authentication mechanisms that could allow unauthorized access to customer accounts.
- Data Exposure: Situations where sensitive customer data (such as personal information, order details, or payment-related information) is unintentionally accessible.
- Phishing or Impersonation: Websites, emails, or communications that impersonate Arc SportsCards or attempt to deceive customers into providing personal information.
- Suspicious Account Activity: If you notice unauthorized transactions, changes, or activity on your Arc SportsCards account.
- Other Security Concerns: Any other issue that could compromise the security, integrity, or availability of arcsportscards.com or its services.
3. What Not to Report Through This Channel
The security reporting channel is intended specifically for security vulnerabilities and suspicious activity. The following types of inquiries should be directed to our regular customer support channels:
- Order status inquiries
- Shipping and tracking questions
- Return and refund requests
- Product questions about Pokémon Booster Boxes, Elite Trainer Boxes, Singles, or other products
- Account management requests (e.g., password resets, address changes)
- General feedback, complaints, or suggestions
- Billing and payment inquiries
For these types of inquiries, please contact our customer service team at contact@arcsportscards.com or call +1 (603) 856-7654 during business hours.
4. How to Report a Security Issue
If you have identified a potential security vulnerability or suspicious activity, please report it by emailing us at:
Please use the subject line: "Security Report" or "Security Vulnerability" so that your report is prioritized appropriately.
Information to Include in Your Report
To help us investigate effectively, please include as much of the following information as possible:
- A clear description of the vulnerability or suspicious activity
- The steps required to reproduce the issue (if applicable)
- The URL(s) or page(s) affected
- The type of vulnerability (e.g., XSS, SQL injection, data exposure)
- Any screenshots, logs, or supporting evidence
- Your assessment of the potential impact or severity
- Your preferred contact information (so we can follow up with you)
5. What NOT to Include in Your Report
- Passwords — Never share your password or the password of any other user.
- Authentication Codes — Do not include two-factor authentication codes, one-time passwords, or security tokens.
- Payment Card Numbers — Never include full credit card numbers, debit card numbers, CVV codes, PINs, or other payment credentials.
- Security Answers — Do not share answers to security questions used to protect your account.
- Private Credentials — Do not include API keys, access tokens, or other private authentication credentials that do not belong to you.
- Other Sensitive Personal Information — Avoid including Social Security numbers, driver's license numbers, or other highly sensitive personal identifiers.
If you need to reference your own account to describe the issue, you may include your email address or order number, but never include passwords or payment information.
6. Responsible Disclosure Expectations
When reporting a security issue to Arc SportsCards, we ask that you:
- Report the issue directly to us via email at contact@arcsportscards.com before disclosing it publicly or to any third party.
- Allow a reasonable time for us to investigate and address the vulnerability before making any public disclosure.
- Do not exploit the vulnerability beyond what is necessary to demonstrate the issue. Do not access, modify, delete, or download data belonging to other customers or Arc SportsCards.
- Do not disrupt our services — Do not perform denial-of-service attacks, social engineering against Arc SportsCards employees, or any action that could negatively impact our website, systems, or customers.
- Act in good faith and in the interest of protecting our customers and our platform.
Arc SportsCards is committed to addressing reported security issues promptly. We will acknowledge receipt of your report and will work to investigate and resolve the issue as quickly as reasonably possible. We value your contribution to the security of our platform and the protection of our Pokémon trading card community.
7. Suspicious Account Activity
If you notice any unauthorized or suspicious activity on your Arc SportsCards account, such as:
- Orders you did not place
- Changes to your account information that you did not make
- Login attempts or notifications you did not initiate
- Emails from Arc SportsCards about actions you did not perform
Please contact us immediately at contact@arcsportscards.com or call +1 (603) 856-7654 during business hours. We recommend changing your password immediately and reviewing your recent account activity.
8. Phishing & Scam Awareness
Arc SportsCards will never send you unsolicited emails, calls, or messages asking for your:
- Password
- Complete credit or debit card number
- CVV or PIN
- Two-factor authentication codes
- Social Security number
- Security question answers
If you receive a communication that appears to be from Arc SportsCards and requests this type of information, it may be a phishing attempt. Do not respond, do not click any suspicious links, and report the communication to us at contact@arcsportscards.com.
9. Our Commitment to Security
Arc SportsCards is committed to maintaining the security and privacy of our website and our customers' information. We implement reasonable technical, administrative, and physical safeguards to protect customer data and maintain the integrity of our e-commerce platform.
We regularly review our security practices and strive to address reported vulnerabilities promptly. While no system is completely immune to security risks, we are dedicated to continuously improving our security posture to protect the Arc SportsCards community.
For more information about how we handle your personal information, please review our Privacy Policy.
10. Contact Information & Business Hours
To report a security issue, suspicious activity, or phishing attempt, or if you have any security-related questions, please contact us:
Our Address
Arc SportsCards
20 Walker St, Concord, NH 03301, United States
Business Hours
- Monday – Friday: 9:00 AM – 9:00 PM
- Saturday: Closed
- Sunday: Closed
This policy is provided for informational and operational purposes and should be reviewed by qualified legal counsel before publication.