Access Control Policy

Last Updated: July 2026

This Access Control Policy establishes the standards used by WEB3 TREK, INC., operator of TrekO.ai, to control access to company systems, customer information, seller accounts, marketplace integrations, cloud infrastructure, payment systems, and confidential business data.

1. Purpose

The purpose of this policy is to ensure that only authorized individuals have access to systems, applications, customer information, seller information, and technical resources required to perform approved business functions.

2. Scope

This policy applies to all employees, contractors, administrators, service providers, cloud platforms, APIs, databases, and systems operated or managed by WEB3 TREK, INC. in support of TrekO.ai, including:

3. Access Principles

WEB3 TREK, INC. follows the principles of least privilege and business need-to-know. Access is granted only to the minimum resources necessary to perform approved business responsibilities.

4. User Authentication

Users accessing company systems or supported applications must authenticate using approved methods.

5. Administrative Access

Administrative access is limited to authorized personnel responsible for maintaining TrekO.ai infrastructure, integrations, and marketplace services.

Administrative privileges are granted only when necessary and are removed promptly when no longer required.

6. Customer and Seller Data Access

Customer and seller information may only be accessed when necessary to provide requested services, investigate operational issues, maintain security, or comply with applicable legal obligations.

7. Credential Protection

API keys, OAuth tokens, access credentials, encryption secrets, and service accounts are protected using secure storage mechanisms.

8. Third-Party Access

Third-party integrations are limited to approved providers that support TrekO.ai business operations.

Access to customer marketplace accounts requires explicit customer authorization through secure authentication mechanisms such as OAuth.

9. Monitoring and Logging

Authentication attempts, administrative actions, API requests, payment events, and security events may be logged to support:

10. Access Reviews

Administrative permissions, service accounts, and privileged access are reviewed periodically to ensure permissions remain appropriate.

Unnecessary accounts and permissions are removed as soon as practical.

11. Account Termination

Access privileges are revoked promptly when personnel separate from the organization, responsibilities change, or access is no longer required.

Inactive accounts may be disabled or removed in accordance with company security procedures.

12. Policy Review

This Access Control Policy is reviewed at least once every six (6) months and updated whenever significant operational, technical, security, or regulatory changes occur.

13. Compliance

WEB3 TREK, INC. maintains access control practices designed to support industry security standards and marketplace security requirements, including those established by the Amazon Selling Partner API, payment providers, cloud service providers, and other approved marketplace integrations.

14. Contact

Questions regarding this Access Control Policy may be directed to:

WEB3 TREK, INC.
Email: support@treko.ai
Website: https://treko.ai