Security ยท Privacy ยท Trust

Security & Compliance

Your data security matters to us. Jerome's Digital Shop is committed to protecting your information through enterprise-grade security practices aligned with internationally recognized standards.

๐Ÿ”’
ISO 27001
Information Security Management
โœ“
SOC 2
Trust Services Criteria
โ™ฅ
HIPAA
Health Information Privacy

01 โ€” Security & Compliance Overview

Jerome's Digital Shop (jeromesdigitalshop.com) is an e-commerce platform offering premium digital products including ebooks, educational guides, trading resources, and professional development materials. We are founded by a Registered Nurse (RN-BSN) and Pharmacy Technician with deep understanding of data protection in both healthcare and digital commerce.

Our security practices are aligned with three internationally recognized frameworks:

Our Commitment

Compliance is not a destination โ€” it's a continuous process. We regularly review and update our security controls, conduct risk assessments, and invest in protecting your data at every stage of its lifecycle.

02 โ€” What Data We Collect

We collect only the minimum data necessary to provide our services and fulfill your orders:

Data TypeExamplesPurpose
Account Information Name, email address Order fulfillment, digital product delivery, account management
Transaction Data Purchase history, order IDs Order processing, customer support, refund handling
Payment Information Processed by third-party gateway (we never store card numbers) Payment processing via PCI-compliant provider
Device & Usage Data Browser type, IP address, pages visited Site optimization, security monitoring, analytics
Communication Data Support emails, contact form submissions Customer service, responding to inquiries
Payment Security

We never store your credit card numbers, CVV codes, or full payment credentials on our servers. All payment processing is handled by PCI DSS-compliant payment gateways (e.g., Stripe, PayPal) that maintain the highest levels of payment security certification.

03 โ€” How We Use Your Data

Your data is used strictly for the following purposes:

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

04 โ€” How We Protect Your Data

We implement multiple layers of security controls aligned with ISO 27001, SOC 2, and HIPAA requirements:

Encryption

Infrastructure Security

Monitoring & Logging

05 โ€” Access Control & Authentication

Access to systems containing customer data is strictly controlled:

06 โ€” Data Classification & Handling

All data is classified into four tiers with corresponding handling requirements:

LevelDescriptionProtection
Restricted Protected Health Information (PHI), SSNs, clinical data AES-256 + TLS, MFA required, access logged, 6-year retention
Confidential Customer PII (names, emails, purchase history), financial records Encrypted storage, role-based access, 7-year retention
Internal Operational documents, internal procedures Standard access controls, internal-only distribution
Public Published content, website copy, marketing materials Integrity controls to prevent unauthorized modification

Data Lifecycle

Data is managed through its complete lifecycle:

07 โ€” HIPAA Notice of Privacy Practices

Given our founder's healthcare background (RN-BSN, Pharmacy Technician) and our healthcare-adjacent digital products, we maintain HIPAA-aligned practices to protect any health-related information that may be collected through our platform.

Administrative Safeguards

Physical Safeguards

Technical Safeguards

Minimum Necessary Standard

We access, use, and disclose only the minimum amount of Protected Health Information necessary to accomplish the intended purpose. This applies to internal use, disclosures to business associates, and requests for PHI from external parties.

08 โ€” Third-Party Services & Business Associate Agreements

We carefully select third-party service providers and require appropriate safeguards:

Service TypeSafeguards
Web Hosting HIPAA-eligible hosting with Business Associate Agreement (BAA) where applicable. Data encrypted at rest and in transit.
Payment Processing PCI DSS Level 1 compliant gateway. We never receive or store raw card data. BAA in place where payment metadata intersects health data.
Email Services TLS-encrypted transport. PHI is never included in marketing emails. HIPAA-compliant email solutions used for any health-related correspondence.
Analytics Privacy-first analytics that do not track PHI. No analytics scripts on pages that collect health information.
Cloud Storage Encrypted with BAA in place for any storage containing PHI or Restricted data.

All business associates are contractually required to:

09 โ€” Incident Response & Breach Notification

We maintain a documented Incident Response Plan with defined severity levels and response procedures:

SeverityDefinitionResponse Time
SEV-1 (Critical)Active breach involving Restricted/PHI data or system-wide compromiseWithin 1 hour
SEV-2 (High)Confirmed unauthorized access to Confidential data or major service disruptionWithin 4 hours
SEV-3 (Medium)Suspected incident with limited scopeWithin 24 hours
SEV-4 (Low)Minor event, no data exposure confirmedWithin 72 hours

HIPAA Breach Notification

In the event of a breach involving Protected Health Information, we comply with federal notification requirements under 45 CFR ยงยง 164.404โ€“408:

All notification content includes: description of the breach, types of information involved, steps you should take, our investigation and mitigation actions, and contact information for questions.

10 โ€” Your Rights

You have the following rights regarding your personal data and any Protected Health Information:

To exercise any of these rights, please contact us using the information below.

11 โ€” Contact Us

Privacy & Security Inquiries

For questions about this policy, data access requests, or to report a security concern:

Jerome's Digital Shop, LLC
Email: privacy@jeromesdigitalshop.com
Website: jeromesdigitalshop.com

We aim to respond to all privacy and security inquiries within 5 business days.

Last Updated: July 2026 ยท Version 1.0