Reporting a vulnerability or a suspected breach
If you have found a security problem with this site, or you believe buyer data has been exposed, write to us. You do not need an account and you do not need to be a customer.
What to include
What you found and where: a URL or a route is enough to start.
How to reproduce it, if you can.
Whether you believe any buyer data was actually accessible.
Please do not access, download, or alter data belonging to anyone else while testing. Report it and stop.
Machine-readable contact: /.well-known/security.txt (RFC 9116). Our internal breach-response procedure is in force. The commitments it enforces — 24-hour acknowledgment, notice to affected individuals within 30 days, and notice to the Florida Attorney General at 500 or more Florida residents — are set out in Privacy Policy section 9.