Skip to content

Trust

Information Security & Data Protection Policy

Version 1.0 | Effective date: August 24, 2026

This document sets out the security and personal-data protection standards that govern the 3PLicity platform (3plicity.com) and its supporting operations. It is published to inform customers, partners and integration platforms of the controls we maintain.

Platform
3PLicity — operating system for third-party logistics providers (3plicity.com; app.3plicity.com)
Operated by
Alset, Inc. (United States)
Document owner
Data Protection Officer (see Section 8)
Version
1.0
Effective date
August 24, 2026
Review cadence
Reviewed at least annually and upon any material change
Data locations
United States — Microsoft Azure (Azure App Service, Azure Static Web Apps, Azure SQL Database)

How this document maps to the partner security assessment

Each control area below corresponds to a question in the standard partner data-protection review. Reviewers can navigate directly to the relevant section.

Assessment topicSection
Published information security policy / program1
Network segregation, threat monitoring & prevention2
Endpoint anti-virus protection3
Security baseline (screen lock, passwords, MFA, clear desk)3
Access control policy & least privilege4
Data classification & encryption in-transit / at-rest5
Incident response policy (roles, reporting channels)6
Vulnerability / threat management procedure7
Internal personal data protection policy / standard8
Data-subject request assistance & end-of-contract deletion8
Breach notification process6, 8

1. Information Security Policy

3PLicity maintains a documented information security program covering the confidentiality, integrity and availability of the data it processes on behalf of merchants, third-party logistics providers (3PLs) and connected sales channels. This policy applies to all personnel, contractors, systems and third-party services involved in operating the platform.

Objectives

  • Protect customer and end-user data against unauthorized access, disclosure, alteration and loss.
  • Ensure strict logical isolation of data between tenants (per-merchant and per-3PL segregation).
  • Maintain a complete, tamper-evident audit trail of actions performed within the platform.
  • Meet the security and privacy expectations of our integration partners and applicable data-protection law.

Governance & responsibility

Overall accountability for information security sits with company leadership. Day-to-day ownership of security controls, this policy and the personal-data protection standard (Section 8) is assigned to the Data Protection Officer. All personnel are required to comply with this program as a condition of access to company systems, and to complete security and privacy awareness briefings.

2. Network Security & Threat Management

The platform is hosted entirely on Microsoft Azure. The application runs on Azure App Service, the web frontend is served from Azure Static Web Apps, and data is stored in Azure SQL Database. The network architecture is designed around segregation and least exposure:

  • Application and database resources are isolated using Azure networking controls (virtual networks, private endpoints and network security groups); the Azure SQL database is not publicly reachable beyond controlled, authenticated access.
  • Network security groups and firewall rules restrict traffic to explicitly required ports, protocols and sources, following a default-deny posture.
  • Multi-tenancy is enforced at the application and data layer so that each merchant and 3PL can only access its own data; cross-tenant access is structurally prevented.
  • Inbound integrations with sales channels are authenticated and scoped to the minimum permissions required.
  • Azure-native monitoring and logging (Azure Monitor) are used to detect anomalous activity, and platform and application logs are retained for investigation.

3. Endpoint Protection & Operational Security Baseline

All company endpoints used to access production systems or customer data must meet a defined security baseline before and during use:

  • Anti-virus / endpoint protection: reputable anti-malware / endpoint protection is installed and kept enabled and up to date on all company endpoints.
  • Multi-factor authentication (MFA): enforced on all administrative accounts, cloud-provider consoles, source-code repositories and business-critical SaaS.
  • Password standards: strong, unique credentials are required; shared credentials are prohibited and a password manager is used to store and generate them.
  • Screen locking: automatic screen lock with authentication is enabled on all devices after a short period of inactivity.
  • Disk encryption: full-disk encryption is enabled on company endpoints.
  • Clear-desk / clear-screen: personnel must not leave sensitive information exposed on screens or in physical form in unattended locations.
  • Updates & patching: operating systems and software are kept current with security updates.

4. Access Control & Least Privilege

Access to systems and personal data is granted strictly on a need-to-know basis under the principle of least privilege.

  • Access rights are role-based and limited to what each individual requires to perform their function.
  • Administrative and production access is restricted to a small number of authorized personnel and protected by MFA.
  • Cloud infrastructure access is managed through Microsoft Azure identity and access-management (Azure AD / Entra ID roles) rather than shared administrative credentials.
  • Within the platform, per-tenant isolation ensures merchants and 3PLs only see their own records; a full audit trail records who accessed or changed data.
  • Access is provisioned when a role begins and promptly revoked on role change or departure; access is reviewed periodically.

5. Data Classification & Encryption

Data handled by 3PLicity is classified to ensure appropriate handling. In broad terms:

  • Personal / sensitive data — end-customer order and shipping information (e.g., recipient name, address, contact details) provided by merchants and sales channels. Handled under Section 8.
  • Business-confidential data — merchant and 3PL inventory, orders, pricing and operational records.
  • Internal / operational data — logs, configuration and system metadata.
  • Public data — marketing and documentation intended for publication.

Encryption

  • In transit: all data exchanged with the platform and between services is encrypted using TLS 1.2 or higher.
  • At rest: data stored in Azure SQL Database is encrypted at rest using Transparent Data Encryption (AES-256).
  • Encryption keys are managed by the Microsoft Azure platform.

6. Incident Response

3PLicity maintains an incident response procedure so that security events are detected, contained and resolved quickly, and affected parties are notified.

Roles & responsibilities

  • The Data Protection Officer coordinates incident response and is the point of contact for reporting.
  • Engineering leads investigation, containment and remediation of technical incidents.
  • Leadership approves external communications and any regulatory or partner notifications.

Process

  • Report: suspected incidents are reported immediately to the DPO at the address in Section 8.
  • Triage & classify: severity is assessed based on scope and the sensitivity of affected data.
  • Contain & eradicate: affected systems or credentials are isolated and the root cause removed.
  • Notify: where a personal-data breach is confirmed, affected customers, sellers and integration partners are notified without undue delay, together with any regulator where legally required.
  • Recover & review: services are restored and a post-incident review captures corrective actions.

7. Vulnerability & Threat Management

We maintain an ongoing process to identify, assess and remediate vulnerabilities across the platform.

  • Operating systems, application dependencies and infrastructure are kept patched and updated.
  • Software dependencies are monitored for known vulnerabilities and updated on a risk-prioritized basis.
  • Infrastructure and application logs and cloud-provider security tooling are used to detect threats.
  • Identified vulnerabilities are triaged by severity, with critical issues prioritized for prompt remediation.
  • Third-party services and integrations are reviewed for their security posture before adoption.

8. Personal Information Protection Standard

This standard is 3PLicity's internal policy for the protection of personal data. It applies to personal data that merchants, sellers and connected sales channels make available to the platform so that a 3PL can receive, store, fulfil and ship orders. In respect of that data, 3PLicity acts as a processor on behalf of its customers.

Principles

  • Personal data is processed lawfully, fairly and only for the purpose of providing the logistics and fulfilment services requested by the customer.
  • Only the data necessary to fulfil and ship orders is processed (data minimization).
  • Personal data is kept accurate and is protected by the security controls in Sections 1–7.
  • This standard is reviewed and updated at least annually and whenever practices or obligations change.

Categories of personal data

Primarily end-customer fulfilment data: recipient name, shipping address, contact details and order contents necessary to pick, pack and ship. 3PLicity does not require or store end-customer payment card data.

Data-subject requests

3PLicity will assist sellers and connected marketplaces (including TikTok Shop) in responding to end-user requests to access, correct, update or delete personal data. Requests are actioned within the platform, and the audit trail records the change.

Retention & end-of-contract deletion

Personal data is retained only for as long as needed to provide the service or as required by law. On termination of the contractual relationship, 3PLicity will delete (or, at the customer's option, return) all customer personal data in its possession within a defined period, subject to any legal retention obligation.

Sub-processors & cross-border transfers

Personal data is stored and processed in the United States on Microsoft Azure (Azure App Service and Azure SQL Database). Microsoft Azure acts as our infrastructure sub-processor and is bound by its own security and data-protection commitments. Any additional sub-processor is subject to equivalent obligations.

Breach notification

If a breach affecting personal data is identified, 3PLicity will notify affected sellers, customers and integration partners without undue delay through the incident process in Section 6, and will notify any regulatory authority where legally required.

Data Protection Officer

Privacy questions, data-subject requests and breach reports can be directed to the Data Protection Officer at contact@alset.com.mx. Our public privacy policy is available at https://3plicity.com/privacy.

This policy is published by 3PLicity and reflects the controls in place at the effective date shown above. It is reviewed at least annually.