This document sets out the security and personal-data protection standards that govern the 3PLicity platform (3plicity.com) and its supporting operations. It is published to inform customers, partners and integration platforms of the controls we maintain.
- Platform
- 3PLicity — operating system for third-party logistics providers (3plicity.com; app.3plicity.com)
- Operated by
- Alset, Inc. (United States)
- Document owner
- Data Protection Officer (see Section 8)
- Version
- 1.0
- Effective date
- August 24, 2026
- Review cadence
- Reviewed at least annually and upon any material change
- Data locations
- United States — Microsoft Azure (Azure App Service, Azure Static Web Apps, Azure SQL Database)
How this document maps to the partner security assessment
Each control area below corresponds to a question in the standard partner data-protection review. Reviewers can navigate directly to the relevant section.
| Assessment topic | Section |
|---|---|
| Published information security policy / program | 1 |
| Network segregation, threat monitoring & prevention | 2 |
| Endpoint anti-virus protection | 3 |
| Security baseline (screen lock, passwords, MFA, clear desk) | 3 |
| Access control policy & least privilege | 4 |
| Data classification & encryption in-transit / at-rest | 5 |
| Incident response policy (roles, reporting channels) | 6 |
| Vulnerability / threat management procedure | 7 |
| Internal personal data protection policy / standard | 8 |
| Data-subject request assistance & end-of-contract deletion | 8 |
| Breach notification process | 6, 8 |
1. Information Security Policy
3PLicity maintains a documented information security program covering the confidentiality, integrity and availability of the data it processes on behalf of merchants, third-party logistics providers (3PLs) and connected sales channels. This policy applies to all personnel, contractors, systems and third-party services involved in operating the platform.
Objectives
- Protect customer and end-user data against unauthorized access, disclosure, alteration and loss.
- Ensure strict logical isolation of data between tenants (per-merchant and per-3PL segregation).
- Maintain a complete, tamper-evident audit trail of actions performed within the platform.
- Meet the security and privacy expectations of our integration partners and applicable data-protection law.
Governance & responsibility
Overall accountability for information security sits with company leadership. Day-to-day ownership of security controls, this policy and the personal-data protection standard (Section 8) is assigned to the Data Protection Officer. All personnel are required to comply with this program as a condition of access to company systems, and to complete security and privacy awareness briefings.
2. Network Security & Threat Management
The platform is hosted entirely on Microsoft Azure. The application runs on Azure App Service, the web frontend is served from Azure Static Web Apps, and data is stored in Azure SQL Database. The network architecture is designed around segregation and least exposure:
- Application and database resources are isolated using Azure networking controls (virtual networks, private endpoints and network security groups); the Azure SQL database is not publicly reachable beyond controlled, authenticated access.
- Network security groups and firewall rules restrict traffic to explicitly required ports, protocols and sources, following a default-deny posture.
- Multi-tenancy is enforced at the application and data layer so that each merchant and 3PL can only access its own data; cross-tenant access is structurally prevented.
- Inbound integrations with sales channels are authenticated and scoped to the minimum permissions required.
- Azure-native monitoring and logging (Azure Monitor) are used to detect anomalous activity, and platform and application logs are retained for investigation.
3. Endpoint Protection & Operational Security Baseline
All company endpoints used to access production systems or customer data must meet a defined security baseline before and during use:
- Anti-virus / endpoint protection: reputable anti-malware / endpoint protection is installed and kept enabled and up to date on all company endpoints.
- Multi-factor authentication (MFA): enforced on all administrative accounts, cloud-provider consoles, source-code repositories and business-critical SaaS.
- Password standards: strong, unique credentials are required; shared credentials are prohibited and a password manager is used to store and generate them.
- Screen locking: automatic screen lock with authentication is enabled on all devices after a short period of inactivity.
- Disk encryption: full-disk encryption is enabled on company endpoints.
- Clear-desk / clear-screen: personnel must not leave sensitive information exposed on screens or in physical form in unattended locations.
- Updates & patching: operating systems and software are kept current with security updates.
4. Access Control & Least Privilege
Access to systems and personal data is granted strictly on a need-to-know basis under the principle of least privilege.
- Access rights are role-based and limited to what each individual requires to perform their function.
- Administrative and production access is restricted to a small number of authorized personnel and protected by MFA.
- Cloud infrastructure access is managed through Microsoft Azure identity and access-management (Azure AD / Entra ID roles) rather than shared administrative credentials.
- Within the platform, per-tenant isolation ensures merchants and 3PLs only see their own records; a full audit trail records who accessed or changed data.
- Access is provisioned when a role begins and promptly revoked on role change or departure; access is reviewed periodically.
5. Data Classification & Encryption
Data handled by 3PLicity is classified to ensure appropriate handling. In broad terms:
- Personal / sensitive data — end-customer order and shipping information (e.g., recipient name, address, contact details) provided by merchants and sales channels. Handled under Section 8.
- Business-confidential data — merchant and 3PL inventory, orders, pricing and operational records.
- Internal / operational data — logs, configuration and system metadata.
- Public data — marketing and documentation intended for publication.
Encryption
- In transit: all data exchanged with the platform and between services is encrypted using TLS 1.2 or higher.
- At rest: data stored in Azure SQL Database is encrypted at rest using Transparent Data Encryption (AES-256).
- Encryption keys are managed by the Microsoft Azure platform.
6. Incident Response
3PLicity maintains an incident response procedure so that security events are detected, contained and resolved quickly, and affected parties are notified.
Roles & responsibilities
- The Data Protection Officer coordinates incident response and is the point of contact for reporting.
- Engineering leads investigation, containment and remediation of technical incidents.
- Leadership approves external communications and any regulatory or partner notifications.
Process
- Report: suspected incidents are reported immediately to the DPO at the address in Section 8.
- Triage & classify: severity is assessed based on scope and the sensitivity of affected data.
- Contain & eradicate: affected systems or credentials are isolated and the root cause removed.
- Notify: where a personal-data breach is confirmed, affected customers, sellers and integration partners are notified without undue delay, together with any regulator where legally required.
- Recover & review: services are restored and a post-incident review captures corrective actions.
7. Vulnerability & Threat Management
We maintain an ongoing process to identify, assess and remediate vulnerabilities across the platform.
- Operating systems, application dependencies and infrastructure are kept patched and updated.
- Software dependencies are monitored for known vulnerabilities and updated on a risk-prioritized basis.
- Infrastructure and application logs and cloud-provider security tooling are used to detect threats.
- Identified vulnerabilities are triaged by severity, with critical issues prioritized for prompt remediation.
- Third-party services and integrations are reviewed for their security posture before adoption.
8. Personal Information Protection Standard
This standard is 3PLicity's internal policy for the protection of personal data. It applies to personal data that merchants, sellers and connected sales channels make available to the platform so that a 3PL can receive, store, fulfil and ship orders. In respect of that data, 3PLicity acts as a processor on behalf of its customers.
Principles
- Personal data is processed lawfully, fairly and only for the purpose of providing the logistics and fulfilment services requested by the customer.
- Only the data necessary to fulfil and ship orders is processed (data minimization).
- Personal data is kept accurate and is protected by the security controls in Sections 1–7.
- This standard is reviewed and updated at least annually and whenever practices or obligations change.
Categories of personal data
Primarily end-customer fulfilment data: recipient name, shipping address, contact details and order contents necessary to pick, pack and ship. 3PLicity does not require or store end-customer payment card data.
Data-subject requests
3PLicity will assist sellers and connected marketplaces (including TikTok Shop) in responding to end-user requests to access, correct, update or delete personal data. Requests are actioned within the platform, and the audit trail records the change.
Retention & end-of-contract deletion
Personal data is retained only for as long as needed to provide the service or as required by law. On termination of the contractual relationship, 3PLicity will delete (or, at the customer's option, return) all customer personal data in its possession within a defined period, subject to any legal retention obligation.
Sub-processors & cross-border transfers
Personal data is stored and processed in the United States on Microsoft Azure (Azure App Service and Azure SQL Database). Microsoft Azure acts as our infrastructure sub-processor and is bound by its own security and data-protection commitments. Any additional sub-processor is subject to equivalent obligations.
Breach notification
If a breach affecting personal data is identified, 3PLicity will notify affected sellers, customers and integration partners without undue delay through the incident process in Section 6, and will notify any regulatory authority where legally required.
Data Protection Officer
Privacy questions, data-subject requests and breach reports can be directed to the Data Protection Officer at contact@alset.com.mx. Our public privacy policy is available at https://3plicity.com/privacy.
This policy is published by 3PLicity and reflects the controls in place at the effective date shown above. It is reviewed at least annually.