Last updated: September 11, 2026

We take the security of this site and of our customers’ data seriously. If you have found a vulnerability, we want to hear about it and we will not take legal action against you for reporting it in good faith.

How to report

Email support@usagazebos.shop with “Security” in the subject line. Please include:

  • A description of the issue and what an attacker could do with it
  • The URL, parameter or page affected
  • Steps to reproduce it, and a proof of concept if you have one
  • Your name or handle, if you would like credit

What we ask of you

  • Give us a reasonable time to fix the issue before you disclose it publicly
  • Do not access, modify or delete data that is not yours
  • Do not run automated scans that degrade the site for customers, and no denial of service testing
  • Do not use social engineering, phishing or physical attacks against our staff or suppliers
  • If you encounter customer data, stop, do not save it, and tell us immediately

What you can expect from us

  • An acknowledgement within two business days
  • An assessment and a planned fix date within ten business days
  • Progress updates until it is resolved
  • Public credit if you want it, once the fix is live

We do not currently run a paid bug bounty. We will say so honestly rather than imply one exists.

Out of scope

Reports generated purely by automated scanners with no demonstrated impact, missing security headers with no exploit path, rate limiting on non-sensitive endpoints, self-XSS, and issues in third-party services we do not control.

If you are a customer with a security concern

If you believe your order or account has been affected, or you have received an email claiming to be from us that looks wrong, forward it to support@usagazebos.shop and do not click anything in it. We will never email you asking for your password or full card number.