AMAMREFIE CUSTOMER ACCOUNT

Data Loss Prevention Strategy

How Amamrefie minimizes, protects, monitors, retains, and recovers information.

Effective date: August 3, 2026

Owner: Peter Nuako / Amamrefie

Review frequency: Quarterly and after material security changes or incidents

1. Objective

This strategy reduces the risk that merchant or customer information is lost, disclosed, altered, copied, or retained beyond its intended purpose. It applies to Amamrefie Customer Portal & Loyalty source code, Shopify integrations, Google Cloud services, development devices, support processes, and authorized operators.

2. Data Minimization

3. Environment Separation

4. Access Control

5. Encryption and Secret Handling

6. Logging and Detection

7. Prevention Controls

8. Incident Response

When suspected data loss or unauthorized disclosure is identified:

1. Stop the affected deployment or revoke access when needed to contain the event.

2. Rotate affected Shopify, database, Google Cloud, and automation credentials.

3. Preserve relevant sanitized logs and record the incident timeline without copying unnecessary personal data.

4. Determine affected stores, data categories, individuals, systems, and time period.

5. Remove unauthorized copies, correct access controls, and validate the fix.

6. Notify affected merchants without undue delay after confirming a breach and provide information needed for legally required notifications.

7. Document the cause, response, and preventive actions, then review this strategy.

9. Recovery and Availability

10. Customer Rights and Deletion

11. Reviews and Evidence

Quarterly reviews confirm:

Evidence may include dated access-review results, deployment records, webhook tests, credential-rotation records, restore-test records, and incident reports. Evidence must not include secret values or unnecessary personal data.