Responsible Disclosure
Last updated: June 17, 2026
We take the security of our website and our customers' information seriously. If you believe you have found a security vulnerability, we appreciate your help in disclosing it to us responsibly.
How to report
Please email info@spinny.ca with the subject line "Security" and include:
- A description of the issue and where you found it.
- Steps to reproduce it.
- Any supporting details, such as screenshots, that help us understand the impact.
Please do
- Give us a reasonable amount of time to investigate and fix the issue before disclosing it publicly.
- Make a good-faith effort to avoid privacy violations, data loss, and service disruption.
- Only interact with accounts you own or have permission to test.
Please do not
- Access, modify, or delete data that does not belong to you.
- Run automated scans that degrade or disrupt our services.
- Use social engineering, phishing, or physical attacks against our staff or facilities.
Our commitment
If you report an issue in good faith and follow this policy, we will acknowledge your report, work to confirm and fix valid issues promptly, and we will not pursue legal action against you for your research. We are a small local business and do not currently operate a paid bug-bounty program, but we are grateful for responsible reports.
Report a security issue
Email: info@spinny.ca (subject: "Security")