Last Updated: July 2026
This Incident Response Policy describes how WEB3 TREK, INC., operator of TrekO.ai, prepares for, detects, responds to, documents, and resolves information security incidents affecting company systems, customer information, marketplace integrations, payment processing, and third-party services.
The purpose of this policy is to ensure that security incidents are identified, contained, investigated, documented, and resolved promptly while protecting customer information, marketplace data, seller information, payment data, digital assets, and company systems.
This policy applies to all systems, infrastructure, cloud services, employees, contractors, administrators, and third-party integrations operated by WEB3 TREK, INC. in support of TrekO.ai, including but not limited to:
The Incident Response Coordinator is responsible for directing incident investigations, coordinating remediation efforts, documenting findings, and communicating with affected users, marketplace partners, and service providers when required.
Current Incident Response Coordinator:
A security incident includes any event that may compromise the confidentiality, integrity, or availability of TrekO.ai systems or customer information, including:
Potential incidents are identified through monitoring, logging, administrator reports, customer reports, cloud provider alerts, payment processor alerts, or third-party marketplace notifications.
Affected credentials, API keys, OAuth tokens, payment credentials, or infrastructure components may be disabled, rotated, isolated, or temporarily suspended to prevent additional exposure.
The Incident Response Coordinator reviews logs, audit records, system activity, and available forensic information to determine:
Systems are restored only after the incident has been contained, verified, and appropriate security measures have been implemented.
Every confirmed incident is documented, reviewed, and used to improve security controls, infrastructure, and operational procedures.
If WEB3 TREK, INC. determines that an incident involves Amazon Information or Amazon Selling Partner API data, Amazon will be notified at security@amazon.com within twenty-four (24) hours of confirmation of the incident, in accordance with Amazon's Selling Partner API Data Protection Policy.
If WEB3 TREK, INC. identifies or reasonably suspects a security incident involving information obtained from or processed on behalf of TikTok Shop, another marketplace partner, or a seller, the Incident Response Coordinator will evaluate the incident and provide notification to the affected marketplace partner or seller when required by applicable law, contractual requirements, marketplace policies, or security requirements.
Notifications will be made through the applicable marketplace's designated security, support, or incident-reporting channel and will be provided within any notification timeframe required by that marketplace or applicable law.
Where appropriate, notification may include:
WEB3 TREK, INC. will cooperate with TikTok Shop, affected sellers, marketplace partners, service providers, and appropriate authorities as reasonably required to investigate, contain, remediate, and document a security incident.
Each incident record includes:
This Incident Response Policy is reviewed at least once every six (6) months and updated whenever significant infrastructure, marketplace integrations, security controls, or regulatory requirements change.
Incident documentation is treated as confidential company information, and access is restricted to authorized personnel with a legitimate business need.
Questions regarding this Incident Response Policy may be directed to:
WEB3 TREK, INC.
Email:
support@treko.ai
Website:
https://treko.ai