BACKBONEAI SOLUTIONSLIVE · SCAN2STOCK
  • Home
  • Tools
  • Roadmap
  • About
  • Contact
Sign inContact us
01Home02Tools03Roadmap04About05ContactSign in →
BACKBONEAI SOLUTIONS

The backbone to any business. Nine integrated products across four categories. Built in public, shipping in public.

Operations

  • Backbone IMSLive
  • Scan2StockLive
  • Backbone POS
  • Backbone Mechanic

Finance & Growth

  • Accounting AI
  • Backbone Social
  • Backbone Farming

Intelligence

  • Backbone Intelligence
  • HobbyAI

Company

  • Tools
  • Roadmap
  • About
  • Contact
  • Sign in
© 2026 Backbone Solutions · Horizon Digital Marketing LLC · Milwaukee, WI
backbonesolutions.ai · Set in Geist
PrivacySecurityTerms
Trust

Security & Privacy Program

Version 1.0 · Adopted October 3, 2026

Backbone Solutions is a venture of Horizon Digital Marketing LLC. This policy sets the security and privacy requirements for the people, systems, suppliers, and integrations that handle Backbone business and customer data. The owner adopted this program on October 3, 2026. It is a statement of our program requirements, not an independent audit or certification. Our Privacy Policy explains the information we collect, its purposes, retention, and your choices.

1. Responsibility and review

Our founder, Murad Dahche, owns this program and is responsible for access approvals, incident coordination, privacy requests, and follow-up on identified risks. Policies must be reviewed at least annually and whenever a material change to the service, its providers, or its data use requires a change. Exceptions must have a documented owner, reason, safeguards, and review date. We do not claim ISO 27001, ISO 27701, or SOC 2 certification.

2. Data classification and handling

  • Public: information approved for publication, such as product information and this policy.
  • Internal: working documents and operational records intended for authorized personnel.
  • Confidential: merchant records, customer personal data, nonpublic financial information, and support cases. Access must be limited to an authorized business purpose.
  • Restricted: passwords, access tokens, private keys, and other authentication secrets. These must remain in approved secret storage and must not appear in source code, public documents, or ordinary logs.

Customer data must be collected only as needed for the authorized service. Personal data and secrets must be excluded from routine diagnostics wherever possible. Payment card details are handled through our payment providers; Backbone personnel must not collect them through email or support tickets.

3. Access control

Access must follow least privilege: each person or service receives only the access needed for its work. Merchant access is scoped by business membership and role, with database row-level security and server-side authorization protecting tenant boundaries. Privileged service credentials must stay server-side; a database service credential must never be exposed to a customer browser.

Administrative accounts must use individual identities and multi-factor authentication where supported. Access must be reviewed at least quarterly and after role changes, and removed promptly when no longer needed. Production access and sensitive changes must leave an audit record. Any suspected credential exposure requires investigation and revocation or rotation of the affected credential.

4. Systems, endpoints, and encryption

Backbone uses managed application and database services. Internet connections carrying confidential data must use HTTPS/TLS, and confidential stored data and backups must use provider-supported encryption at rest. Production settings, access restrictions, backup locations, and provider security responsibilities must be checked before an integration is enabled and when they change. Tenant separation does not replace network access controls or monitoring.

Devices used to administer Backbone must have supported software, current security updates, enabled malware protection, full-disk encryption, an enabled firewall, and password-protected screen locking. Confidential information must be kept out of unattended screens, unsecured storage, and shared accounts. Security-relevant logs and provider alerts must be reviewed and escalated when they indicate unauthorized access or abuse.

5. Development and vulnerability management

Changes must be reviewed and tested before release, including authorization and tenant isolation when affected. Production database changes require an approved migration and a controlled application process. Secrets must stay out of code and test fixtures; synthetic data should be used for development and testing.

Dependency findings, vulnerability reports, and provider security notices must be assessed for severity and exposure, assigned an owner, and tracked to resolution. Suspected active exploitation requires immediate incident triage. Remediation must include a check that the fix works and does not weaken related controls.

6. Incident response and notification

Report a suspected incident or vulnerability to security@backbonesolutions.ai with “Security” in the subject. Include enough detail to investigate, but do not email passwords, access tokens, payment details, or a copy of customer data. We will arrange an appropriate channel if sensitive evidence is needed.

The incident lead must record the report, assess scope and urgency, contain unauthorized access, preserve necessary evidence, and coordinate recovery. The investigation must identify affected systems and data, required notifications, corrective actions, and an owner for each follow-up. A post-incident review must capture lessons and verify remediation.

We will notify affected merchants and, where their data is involved, TikTok Shop or other relevant partners without undue delay and within the applicable contractual and legal deadlines. Notifications must communicate the known impact, actions taken, recommended steps, and a contact for updates. Initial notices must not be delayed solely because every fact is not yet known. Required regulator and individual notices are assessed as part of the response.

7. Privacy requests and data lifecycle

We process merchants’ customer data to provide the services they authorize. New uses and providers must be reviewed for purpose, necessary permissions, personal-data exposure, location, retention, and contractual obligations before use. TikTok Shop data must not be used for advertising profiles or AI model training. We have not appointed a formal Data Protection Officer; the program owner coordinates privacy matters.

Merchants, TikTok Shop, and individuals can request access, correction, export, or deletion through support@backbonesolutions.ai with “Privacy” in the subject. We must verify the requester’s authority, locate the relevant records, involve the merchant when it is the controller, and record the response. We respond within 30 days, or sooner when required by law or platform terms, and explain any restriction or legally permitted extension.

Disconnecting TikTok Shop removes stored authorization tokens and stops future synchronization; it does not by itself erase historical orders. At the end of the relationship, or on an authorized erasure request, our offboarding process must remove or sanitize TikTok customer data from active records and raw integration payloads within 30 days, or sooner when required. Minimum accounting and provenance records without customer contact details, such as ledger references and receipt identifiers, and a pseudonymous shop marker may remain for reconciliation and to prevent erased data from being imported again. These records must remain restricted and be reviewed for continued necessity; pseudonymous data is not treated as anonymous. Backups are isolated from ordinary use and allowed to expire on the hosting provider's backup schedule; if restored, pending deletions must be reapplied before returning the data to use. Security logs are kept only as long as needed for security and operations, with customer payloads and unnecessary personal identifiers excluded or removed.

A legal retention requirement may delay deletion of specific records only for the necessary purpose and period. Such records must be isolated, access restricted, and the requester informed of the reason and retention period unless the law prohibits notice. See our retention policy for the full scope.

8. Providers and assurance

Providers must be reviewed for the data they handle, access, security commitments, processing locations, retention, and incident reporting. Their certifications do not certify Backbone. Our Privacy Policy lists providers and optional integrations. We do not promise that all processing occurs in a single country; location details must be confirmed for the relevant service. Customers can contact support for security questions or available assurance information.