Security Policy

Last updated: 12 July 2026

Welcome to Eaglecart.

This Security Policy explains the measures Eaglecart takes to protect its platform, infrastructure, merchant accounts, customer data and business information.

Security is a core component of the Eaglecart platform, and we work continuously to maintain a secure and reliable environment for all users.


1. Introduction

Eaglecart is a UAE-based business management platform providing ecommerce websites, online stores, Point of Sale (POS), Warehouse Management Systems (WMS), workshop management software, inventory management, customer management, quotations, invoicing, reporting, AI features and related business services.

We are committed to implementing security practices designed to protect information, maintain platform availability and support the trust our merchants place in us.


2. Security Standards and Practices

Eaglecart follows recognised industry security practices in the design, development and operation of the Services, including encryption, access control, least-privilege principles, secure development practices, monitoring and incident response.

We review our security controls on an ongoing basis and improve them as the platform, the threat landscape and applicable requirements change.


3. Security Architecture

Eaglecart is designed with security as a structural principle rather than an added feature.

  • Security controls are applied at the infrastructure, network, application and account layers
  • Systems are separated so that a failure or compromise in one area is contained
  • Access to production systems is restricted, authenticated and logged
  • Sensitive operations are subject to additional controls
  • Security requirements are considered when new features are designed, not only after release

4. Platform and Infrastructure Security

Cloud infrastructure

Eaglecart is hosted using trusted cloud infrastructure providers selected to support the security, availability and reliability of the Services.

Network security

  • Web application firewall
  • Distributed denial-of-service protection
  • Traffic monitoring
  • Threat detection systems
  • Network segmentation

Encryption

  • Data in transit is encrypted using TLS
  • Data at rest is protected using industry-standard encryption

Access control

  • Role-based access control
  • Least-privilege access principles
  • Authentication controls
  • Audit logging

5. Infrastructure Monitoring

Eaglecart monitors its infrastructure to protect the availability, integrity and security of the Services.

  • System availability and performance monitoring
  • Error and anomaly detection
  • Traffic and load monitoring
  • Alerting on suspicious or abnormal activity
  • Investigation of events that may indicate a security issue

Monitoring is designed to identify problems early and to support rapid investigation and response.


6. Application Security

Eaglecart applies security practices throughout the software development lifecycle.

  • Secure software development lifecycle — security is considered at design, build, review and release stages
  • Code reviews — changes are reviewed before they reach production
  • Dependency management — third-party libraries and components are tracked and updated
  • Patch management — security patches are applied to systems and dependencies on an ongoing basis
  • Vulnerability assessments — systems are assessed to identify and remediate weaknesses
  • Security testing — the platform is tested for common application security risks

7. API Security

Access to Eaglecart APIs requires authentication. API keys, tokens and credentials are account credentials and must be protected accordingly.

  • APIs require authentication and authorisation
  • API activity may be logged and monitored
  • Rate limits and fair-use controls may be applied to protect stability and availability
  • Access may be restricted, suspended or revoked where misuse, abuse or a security risk is identified

You are responsible for protecting your API keys and for all activity carried out using them. If you believe a key has been exposed, revoke it and contact [email protected] immediately.


8. Merchant Data Isolation

Eaglecart maintains logical separation between merchant accounts.

Each merchant's data is scoped to that merchant's account, and access controls are designed to prevent one merchant from accessing another merchant's data.

Access to merchant data by Eaglecart personnel is restricted, controlled and limited to what is necessary to operate the Services, provide support, meet a legal obligation or investigate a security incident.


9. Data Protection

Eaglecart implements measures designed to protect:

  • Merchant information
  • Customer information
  • Order records
  • Inventory data
  • Workshop records
  • Financial records
  • Business content

How personal data is collected, used, shared and retained is set out in the Eaglecart Privacy Policy.


10. Payment Security

Payment processing is handled by independent third-party payment providers. Eaglecart currently supports Stripe for card payments.

Eaglecart does not store full payment card numbers or card security codes on its servers.

Payment information is processed according to the security standards and practices of the payment provider. Merchants remain responsible for complying with the requirements of their payment providers.


11. Account Security

Users are responsible for maintaining the confidentiality of their account credentials.

Recommended practices include:

  • Strong, unique passwords
  • Multi-factor authentication where available
  • Secure devices
  • Regular password updates

Passwords are never stored in plain text.


12. Account Recovery

Where you lose access to your account, recovery requires verification of your identity and of your control over the registered account.

Eaglecart will never ask you for your password. We will not disclose credentials, reset access or transfer account ownership on the basis of an unverified request.

Keep the email address and contact details on your account current. If we cannot verify you, we may be unable to restore access.


13. Staff and Access Management

Merchants are responsible for managing access permissions for employees, contractors, administrators, POS users, workshop users and warehouse users.

Users should only be granted the minimum access necessary for their role, and access should be removed promptly when it is no longer needed.


14. Monitoring and Logging

We maintain monitoring and logging systems designed to:

  • Detect unauthorised access
  • Identify suspicious activity
  • Investigate security incidents
  • Support compliance and legal requirements

Logs may be retained for security, operational and legal purposes.


15. Backups and Disaster Recovery

Eaglecart performs routine backups to support disaster recovery, business continuity, system restoration and operational resilience.

Backup procedures are reviewed and tested periodically.

Backups are maintained for service continuity and are not a substitute for your own records. You remain responsible for exporting and maintaining independent copies of important business data.


16. Business Continuity

Eaglecart maintains procedures designed to keep the Services available and to restore them where they are disrupted.

  • Redundancy and resilience in core infrastructure
  • Backup and restoration procedures
  • Incident escalation and response processes
  • Communication of significant service disruptions

Service status information is published so that merchants can check the current availability of the Services.


17. Incident Response

Eaglecart maintains incident response procedures designed to address security incidents, unauthorised access attempts, service disruptions and data exposure risks.

Security incidents are investigated, contained and managed according to internal procedures. Where an incident is confirmed, we take steps to limit its impact, remediate the cause and prevent recurrence.

Eaglecart will notify affected merchants and competent authorities where required by applicable law.

You should report any suspected security incident to [email protected] without delay.


18. Responsible Disclosure

If you believe you have found a security vulnerability in Eaglecart, report it to [email protected] with enough detail for us to reproduce and verify the issue.

Where you report in good faith and comply with the conditions below, Eaglecart will not pursue legal action against you in respect of that research:

  • Do not access, modify, delete or extract data belonging to any other person
  • Do not degrade, disrupt or interrupt the Services for other users
  • Do not conduct denial-of-service, spam, phishing or social-engineering attacks
  • Do not test physical security or attempt to access Eaglecart premises
  • Give us a reasonable opportunity to investigate and remediate before disclosing the issue publicly

We will acknowledge reports we receive and will act on validated findings.

Eaglecart does not currently operate a paid bug bounty programme, and reporting a vulnerability does not entitle you to a reward.


19. Merchant Security Responsibilities

Security is a shared responsibility. Merchants should:

  • Use strong, unique passwords
  • Enable multi-factor authentication where available
  • Remove access for former employees and contractors immediately
  • Review staff permissions regularly and apply least privilege
  • Secure POS devices, including physical access and screen locks
  • Secure warehouse and workshop devices
  • Protect API keys and treat them as credentials
  • Keep devices, browsers and operating systems updated
  • Train staff to recognise phishing and social-engineering attempts
  • Review account activity and investigate anything unexpected

Most account compromises begin outside the platform, with a weak password, a shared login or a phishing email. These controls are the ones that matter most.


20. Prohibited Security Activities

Except where you are reporting a vulnerability in accordance with section 18, users must not:

  • Share account credentials
  • Attempt unauthorised access
  • Circumvent security controls
  • Distribute malware
  • Conduct unauthorised security testing
  • Interfere with platform operations
  • Probe, scan or test the vulnerability of any system without authorisation

Such activities may result in suspension or termination of the account, and may be reported to the competent authorities.


21. Third-Party Providers

Eaglecart relies on third-party providers to operate the Services, including cloud infrastructure providers, payment providers, communication providers, analytics providers and delivery partners.

We consider security when selecting and integrating third-party providers. However, third-party services operate under their own security practices and policies, and Eaglecart does not control their systems.

Merchants who connect third-party applications or integrations to their Eaglecart account are responsible for the access they grant and for the security practices of those third parties.


22. Government and Legal Requests

Eaglecart may disclose information where required to do so by applicable law, regulation, court order or a valid request from a competent authority.

We may also disclose information where we reasonably believe it is necessary to investigate fraud, protect the safety of any person, protect the security of the platform, or enforce our agreements.


23. Security Limitations

No system is completely secure.

Eaglecart works continuously to protect the platform, but no method of transmission, processing or storage can guarantee absolute security, and no provider can eliminate risk entirely.

Eaglecart cannot protect against risks outside its control, including:

  • Compromised merchant devices, browsers or networks
  • Passwords that are weak, reused or shared
  • Credentials disclosed through phishing or social engineering
  • Access granted by a merchant to a third party
  • Actions taken by a merchant's own staff or contractors

The security of your account depends on both our controls and yours.


24. Changes to This Security Policy

We may update this Security Policy from time to time to reflect new security requirements, technology updates, regulatory changes or operational improvements.

Updated versions will be published on our website and may be communicated by email or platform notification.

Continued use of the Services after updates become effective constitutes acceptance of the revised Security Policy.


25. Contact Information

For security questions, incident reporting, vulnerability reports or security concerns, contact:

Eaglecart FZC
Sharjah Research, Technology and Innovation Park (SRTIP)
Sharjah, United Arab Emirates

Website: eaglecart.com
Email: [email protected]