Security
Your personal information and payment data are protected every step of the way. Learn how we keep your account safe, your rights as a consumer, and how to report a security concern.
Account Protection
Password hashing with bcrypt. Suspicious login alerts by email. Session tokens expire automatically. No shared credentials across platforms.
Personal Data Rights
You can download, correct, or delete your personal data at any time from Account → Privacy. We comply with CCPA and applicable consumer privacy laws.
Safe Shopping Guarantee
Every purchase is protected against unauthorized charges. If you spot a transaction you don't recognize, contact us and we'll investigate within 24 hours.
Payment Security
PCI-DSS Level 1
Our payment processors are PCI-DSS Level 1 certified. Market Express never stores raw card numbers.
3D Secure 2.0
Supported on all card transactions. Provides an additional layer of authentication for high-risk purchases.
Tokenization
Payment methods are stored as secure tokens with our payment processors — never on Market Express servers.
Fraud Detection
Transactions are screened for fraud by our payment processor. Unusual activity triggers manual review before fulfillment.
BuyersClub members are covered by our Safe Shopping Guarantee. If an unauthorized charge appears on your account, contact Fulfillment Support and we will investigate within 24 hours.
Your Privacy Rights
As a BuyersClub member you have the following rights over your personal data under CCPA and applicable consumer privacy laws:
Right to Know
Request a copy of the personal data we hold about you.
Right to Delete
Ask us to delete your account and associated personal data.
Right to Correct
Update inaccurate information in your account at any time.
Right to Opt Out
Opt out of data sharing for targeted advertising.
Exercise these rights via Account → Privacy or email privacy@marketexpres.us.
Keeping Your Account Safe
- ✓Use a strong, unique password and a password manager
- ✓Never share your login credentials with anyone
- ✓Check your order history regularly for unrecognized purchases
- ✓Log out of shared or public devices after shopping
- ✓Contact us immediately if you receive a suspicious email claiming to be Market Express
Responsible Disclosure
We welcome reports from security researchers who discover vulnerabilities in our platform. Please follow these guidelines to ensure a coordinated and responsible disclosure process.
In Scope
- ✓marketexpress.us and all subdomains (www, business, buyersclub, government, dobusiness, marketing, vendors, admin, api, auth, status)
- ✓Market Express iOS and Android mobile applications
- ✓Market Express APIs (authenticated and unauthenticated endpoints)
- ✓Authentication and authorization systems
- ✓Payment processing and checkout flows
- ✓Vendor portal and admin panel
Out of Scope
- ✗Third-party services (Stripe, PayPal, FedEx, USPS, FusionAuth)
- ✗Social engineering or phishing attacks against Market Express staff
- ✗Denial of service (DoS/DDoS) attacks
- ✗Automated scanning without prior written approval
- ✗Physical security of data centers or offices
- ✗Issues already reported by another researcher
Safe Harbor
If you make a good-faith effort to comply with this policy during your security research, we commit to the following:
- ✓We will not pursue civil or criminal action against researchers who follow these guidelines
- ✓We will acknowledge receipt within 2 business days
- ✓We will keep you informed of our progress toward resolution
- ✓We will credit you in our acknowledgements (unless you prefer anonymity)
Report a Vulnerability
Email our security team with a description of the issue, steps to reproduce, and potential impact. Please do not publicly disclose until we have had a chance to address it.
security@marketexpres.us
PGP key available on request
Response within 2 business days · Mon–Fri 8am–6pm PT
What to Include in Your Report
- •Description of the vulnerability and its potential impact
- •URL, endpoint, or component affected
- •Step-by-step instructions to reproduce
- •Screenshots, logs, or proof-of-concept (no live exploit code)
- •Your name / handle for acknowledgement (optional)