Security Policy

Effective date: 19 July 2026

Platform protection

  • Supported browsers connect over HTTPS/TLS.
  • Administrative areas require authentication and are restricted to authorised users.
  • WordPress, WooCommerce, plugins, themes and server software are maintained to address known issues.
  • Backups, logs and monitoring support recovery and investigation.
  • Access to customer and order records is limited to staff and providers who need it for their role.
  • Public requests are separated from the database through the container and network design.

Checkout and payment

When card or online payment is enabled, the provider identified during checkout handles sensitive payment credentials. Barrier Shop does not intend to store complete card numbers or security codes in the WordPress database. Payment providers maintain their own compliance and security programmes.

What customers should do

  • Create a strong password that is not reused elsewhere.
  • Keep credentials private and sign out on shared equipment.
  • Install browser and operating-system updates.
  • Report unfamiliar orders, account changes or reset messages promptly.
  • Verify an unexpected bank-detail change through the telephone number published on this site rather than contact details contained only in the message.

Reporting a concern

Email sales@heightbarriers.co.uk with “Security report” in the subject. Include the affected URL, what happened, when it was observed and safe contact information. Do not send a password, full payment credentials or unrelated personal information.

Do not access another person’s information, impair the service, use destructive tests, run high-volume automated scans or disclose a suspected issue publicly before a reasonable investigation period. This page does not authorise activity which would otherwise be unlawful and no paid bug-bounty programme is offered.

Response and related information

Reported events are assessed and proportionate containment, recovery, evidence preservation and notification steps are taken. Affected individuals and regulators are notified where law requires it. Personal-information practices are described in the Privacy Policy, with purchase provisions in the Terms & Conditions.