Report Security Issues
SECURITY VULNERABILITY DISCLOSURE POLICY
Last updated: September 12, 2026
Vape & Toys Store takes the security of our website and customers seriously.
If you believe you have discovered a security vulnerability affecting vapetoysstore.co.uk, please report it to us promptly at contact@vapetoysstore.co.uk.
We will review legitimate reports and make reasonable efforts to resolve confirmed security issues as quickly as possible. Before submitting a report, please read this policy carefully, including our responsible disclosure principles, eligibility requirements, reward guidelines and exclusions.
1. RESPONSIBLE DISCLOSURE PRINCIPLES
If you comply with this policy when investigating and reporting a potential security vulnerability, Vape & Toys Store will not initiate legal action against you in connection with your good-faith security research.
We ask that you:
-
Give us a reasonable amount of time to investigate and resolve the reported issue before disclosing it publicly or sharing it with another person.
-
Do not access, modify, download or delete data belonging to another person without their explicit permission.
-
Make a good-faith effort to avoid privacy violations, loss of data, service disruption or degradation of our systems.
-
Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate and confirm its existence.
-
Do not use a vulnerability for financial gain, data extraction, unauthorised access or any other harmful purpose.
-
Do not use automated tools that generate excessive traffic or affect the availability or performance of our website.
-
Comply with all applicable laws and regulations.
2. HOW TO SUBMIT A REPORT
Please send your vulnerability report to:
Use the subject line:
Security Vulnerability Report – vapetoysstore.co.uk
Your report should include:
-
A clear description of the vulnerability
-
The affected page, URL, feature or system
-
Detailed steps needed to reproduce the issue
-
Screenshots, videos or proof-of-concept code, where appropriate
-
The potential security or privacy impact
-
Any suggested solution or mitigation
-
Your name and preferred contact details
Please do not contact individual employees or publish the vulnerability before we have had a reasonable opportunity to investigate and resolve it.
3. ELIGIBILITY REQUIREMENTS
To be considered for recognition or a possible reward, you must:
-
Follow all responsible disclosure principles in this policy.
-
Be the first person to submit a valid and previously unknown vulnerability.
-
Provide a detailed report containing sufficient information for us to reproduce and verify the issue.
-
Avoid accessing unnecessary customer, employee or business information.
-
Immediately disclose any accidental access to personal data, account information, system configurations or other confidential information.
-
Give us a reasonable opportunity to investigate and resolve the issue before making any public disclosure.
Vape & Toys Store will determine whether a reported issue is a valid security vulnerability and assess its severity at its sole discretion.
4. BOUNTY PROGRAM
We may recognise and reward security researchers who help us protect our website, customers and services.
The payment of a monetary reward is not guaranteed. All rewards are discretionary and may depend on:
-
The severity and impact of the vulnerability
-
The likelihood and ease of exploitation
-
The number of affected users
-
The quality and completeness of the report
-
Whether the issue was previously known or reported
-
The researcher’s compliance with this policy
We aim to review and respond to legitimate reports as soon as reasonably possible. Response and resolution times may vary depending on the complexity, severity and impact of the reported issue.
We reserve the right to publish information about resolved reports. We will not identify the researcher without their permission unless required by law.
5. REWARD GUIDELINES
The following amounts are maximum discretionary rewards and are not guaranteed.
Critical-Severity Vulnerabilities — Up to £200
Vulnerabilities that may enable a complete system compromise, remote code execution, administrative access or significant financial theft.
Examples include:
-
Remote code execution
-
Remote command or shell execution
-
Privilege escalation from an unprivileged user to an administrator
-
SQL injection exposing sensitive customer or business data
-
Authentication bypass providing full access to customer or administrator accounts
High-Severity Vulnerabilities — Up to £100
Vulnerabilities that significantly affect the security of the website, its users or its supporting systems.
Examples include:
-
Authentication or authorisation bypass
-
Stored cross-site scripting affecting another user
-
Exposure of sensitive business or customer information
-
Local file inclusion
-
Insecure handling of authentication cookies or session tokens
-
Unauthorised access to another customer’s account
Medium-Severity Vulnerabilities — Up to £50
Vulnerabilities that may affect multiple users and require limited user interaction to exploit.
Examples include:
-
Significant business logic flaws
-
Insecure direct object references
-
Cross-site request forgery involving a sensitive action
-
Improper access controls with a limited impact
Low-Severity Vulnerabilities
Low-severity reports may be acknowledged but will not normally qualify for a monetary reward.
Examples include:
-
Open redirects
-
Reflected cross-site scripting requiring significant user interaction
-
Low-sensitivity information disclosure
-
Issues requiring unlikely or complex prerequisites
6. DUPLICATE AND RELATED REPORTS
If we receive duplicate reports, only the first complete report that we can reproduce will normally be eligible for a reward.
Multiple vulnerabilities resulting from the same underlying issue will generally be treated as one report and may receive one reward.
Reports describing the same issue across multiple pages or endpoints may also be treated as a single vulnerability.
7. OUT-OF-SCOPE REPORTS
The following issues are generally not eligible for a reward unless they demonstrate a clear and significant security impact:
-
Missing security headers without a demonstrated vulnerability
-
Automated scanner reports without manual verification
-
Spam, phishing or social-engineering attempts
-
Denial-of-service or distributed denial-of-service testing
-
Physical attacks against our premises, employees or equipment
-
Self-XSS
-
Clickjacking on pages without sensitive actions
-
Rate-limit issues without a meaningful security impact
-
Username or email enumeration without a demonstrated risk
-
Reports relating only to outdated software versions without proof of exploitability
-
Issues affecting third-party services outside our control
-
Publicly available information
-
Cosmetic errors, spelling mistakes or general website bugs
-
Vulnerabilities requiring access to a stolen device or compromised account
-
Reports based solely on theoretical risk
Do not carry out denial-of-service testing, send spam, use social engineering, install malware or attempt to physically access our premises or equipment.
8. PRIVACY AND DATA PROTECTION
You must stop testing immediately if you encounter personal data, payment information, confidential business information or credentials belonging to another person.
Do not copy, download, retain, disclose or share such information. Notify us immediately and include only the minimum information necessary to identify the issue.
Any accidentally obtained information must be securely deleted after we confirm that it is no longer required for the investigation.
9. SAFE HARBOUR
Security research conducted in good faith and in accordance with this policy will be considered authorised by Vape & Toys Store.
This safe-harbour statement does not authorise activity that violates applicable law, causes harm, disrupts our services or affects systems and services operated by third parties.
If you are uncertain whether a particular action is permitted, contact us before proceeding.
10. CONTACT INFORMATION
Please submit security vulnerability reports to:
Vape & Toys Store
25 County Road
Liverpool
L4 3QA
United Kingdom
Email: contact@vapetoysstore.co.uk
Telephone: +44 7473 996139
Website: https://vapetoysstore.co.u