Information Security Policy

Organization: Integra3D

Website: https://integra3d.recolor.com.br/

Document owner: Sole developer / system administrator

Version: 1.0

Effective date: June 2026

Review cycle: Annual, or after a significant security event

1. Purpose

This Information Security Policy establishes the security principles, responsibilities, and controls applied to Integra3D, a web application that helps sellers manage marketplace listings and orders across Mercado Livre, Shopee, and TikTok Shop.

The policy supports the protection of customer data, marketplace credentials, and business information in line with Brazilian Lei Geral de Proteção de Dados (LGPD) and partner security requirements, including TikTok Shop API compliance.

2. Scope

This policy applies to:

This policy does not cover infrastructure operated solely by third-party marketplaces (TikTok, Mercado Livre, Shopee).

3. Organizational Context

Integra3D is developed and operated by a single independent software developer based in Brazil.

4. Security Objectives

Integra3D aims to:

  1. Protect the confidentiality, integrity, and availability of customer and marketplace data
  2. Prevent unauthorized access to systems and credentials
  3. Detect and respond to security incidents in a timely manner
  4. Apply the principle of least privilege across development and production environments
  5. Comply with applicable Brazilian data protection law (LGPD)

5. Information Classification

ClassificationExamplesHandling
PublicMarketing pages, public API documentationMay be shared openly
InternalApplication source code, deployment scriptsAccess limited to the developer
ConfidentialCustomer account data, order information, product draftsEncrypted in transit; access restricted; deleted when the business relationship ends
RestrictedMarketplace OAuth tokens, API secrets, encryption keys, database credentialsEncrypted at rest (marketplace tokens); stored in environment configuration on the server; not logged in plain text

6. Technical Security Controls

6.1 Network and Transport Security

6.2 Application Security

6.3 Infrastructure Security

6.4 Development Environment Security

6.5 Local Automation (Optional)

Where a local RPA bridge is used for TikTok Shop workflows, it runs on the user’s machine, communicates over localhost, and does not replace server-side credential storage or HTTPS protections for the web application.

7. Data Handling

8. Third-Party Services

Integra3D integrates with external marketplace APIs. Data shared with these platforms is limited to what is necessary for listing management, order synchronization, and authorized API operations. Each marketplace maintains its own security and privacy terms.

9. Roles and Responsibilities

RoleResponsibility
Developer / AdministratorImplements controls, monitors systems, responds to incidents, reviews this policy
CustomersProtect account passwords, authorize marketplace connections, report suspected misuse

There is no dedicated Data Protection Officer (DPO). Privacy and security inquiries are handled directly by the operator (see Privacy Policy).

10. Policy Compliance

Violations of this policy may result in suspension of customer accounts, revocation of marketplace tokens, or permanent deletion of data.

11. Related Documents

12. Document Control

VersionDateAuthorChanges
1.0June 2026Integra3DInitial release

Contact: https://integra3d.recolor.com.br/caio_fekete@hotmail.com