1. Purpose
Oura Marketing takes the security and confidentiality of its website, systems and client information seriously. This page explains how to report a suspected security vulnerability, privacy incident or unauthorized use affecting Oura Marketing.
This process covers Oura Marketing-controlled websites, forms, email domains, systems and applications. It does not authorize testing of Amazon, another client, a service provider or any third-party platform. Suspected issues affecting a third party should be reported through that party’s official security channel.
2. How to report an issue
Email security@ouramarketing.com with the subject line “Security Report”. If that address is unavailable, email info@ouramarketing.com with the same subject line.
Please include, where safely available:
- your name and preferred contact details;
- the affected URL, page, form, account area or system;
- a clear description of the suspected issue and potential impact;
- the date and time you observed it, including time zone;
- steps that allow us to reproduce the issue without exposing additional data;
- limited screenshots, request details or logs that do not contain unnecessary personal data, credentials or client-confidential information; and
- whether you believe the issue is being actively exploited or requires urgent containment.
Do not send passwords, one-time codes, access tokens, payment details, complete advertising reports or large collections of personal data by ordinary email. Tell us that sensitive supporting material exists, and we will determine an appropriate way to receive it.
3. Issues we want to hear about
Examples include:
- unauthorized access to an Oura Marketing-controlled account or administration area;
- exposure of personal information, client-confidential information or Amazon advertising data;
- authentication, authorization or session-management weaknesses;
- exposed credentials, tokens, secrets or private configuration associated with Oura Marketing;
- injection, cross-site scripting or similar vulnerabilities on an Oura Marketing-controlled website;
- a form that sends personal information insecurely or places it in a public URL;
- malicious software, phishing or impersonation using the ouramarketing.com domain or Oura Marketing identity;
- unauthorized campaign changes or advertiser-account access linked to Oura Marketing credentials; and
- any other issue that could materially affect the confidentiality, integrity or availability of Oura Marketing systems or information.
4. Responsible reporting guidelines
To protect users, clients and systems, please:
- act in good faith and stop testing once you have enough information to describe the issue;
- avoid accessing, changing, deleting, downloading or retaining data that is not your own;
- do not attempt to access an Amazon advertiser account, client account or third-party system without express written authorization;
- do not use denial-of-service testing, automated high-volume scanning, spam, social engineering, phishing, malware, physical intrusion or attacks on employees and suppliers;
- do not disrupt services, alter advertising campaigns, place orders, incur advertising spend or affect other users;
- do not publicly disclose the issue before Oura Marketing has had a reasonable opportunity to investigate and address it; and
- comply with applicable law at all times.
5. What you can expect from us
For reports submitted in good faith with sufficient information, we aim to:
- acknowledge receipt within three business days;
- record and triage the report according to apparent severity and impact;
- request additional information only where reasonably necessary;
- investigate with relevant internal personnel and authorized service providers;
- take proportionate containment, remediation and notification measures;
- provide reasonable status updates when appropriate; and
- notify the reporter when the issue is considered resolved or otherwise closed, where doing so is lawful and practical.
These are operational targets, not contractual service-level commitments. Complex issues, third-party dependencies, legal restrictions or incomplete reports may require additional time.
6. Good-faith research
We will not initiate legal action solely because a person reported a vulnerability where that person acted in good faith, complied with this Policy, avoided harm and did not violate applicable law. This statement does not authorize unlawful access and does not protect extortion, threats, data theft, privacy violations, service disruption or conduct outside these guidelines.
7. Recognition and rewards
Oura Marketing does not currently operate a paid bug-bounty programme and does not promise payment, public recognition or other compensation. Do not make disclosure or remediation conditional on payment. We may acknowledge helpful reports at our discretion and only with the reporter’s consent.
8. Privacy and confidentiality of reports
We will use the reporter’s information to evaluate, investigate, communicate about and resolve the reported issue, maintain appropriate security records and comply with legal obligations. We may share limited information with affected clients, authorized service providers, professional advisers, platforms or authorities where reasonably necessary and lawful. For more information, see our Privacy Policy.
9. Suspected personal-data or client-data incidents
If a report may involve personal data, client-confidential information or Amazon advertising data, mark the email as “Urgent — Potential Data Incident”. Do not include unnecessary copies of the affected data. We will assess the incident, take reasonable containment and remediation steps and make notifications to affected parties or competent authorities where required by applicable law or contract.
10. Out-of-scope matters
The following are generally outside this security-reporting process unless they demonstrate a concrete security impact:
- general customer-service, sales, billing or campaign-performance questions;
- missing security headers without a practical exploit or material risk;
- automated scanner output without validation and reproducible evidence;
- issues affecting outdated or unsupported browsers only;
- publicly available information that was intentionally published;
- social-media account disputes not involving Oura-controlled credentials; and
- vulnerabilities in Amazon or another third-party service that do not arise from an Oura Marketing-controlled configuration.
11. Security contact
- Primary: security@ouramarketing.com
- Backup: info@ouramarketing.com
- Oura Marketing