Security Statement
Last Updated: July 29, 2026
MARSTEN is operated by ZENTARA BRANDS LIMITED (“MARSTEN,” “we,” “us,” or “our”).
This Security Statement describes the measures and practices used to support the security of:
- [marstenhome.com]
- Our online store
- Customer information
- Customer accounts
- Transactions
- Order and delivery records
- Returns and refunds
- Related business systems
We use reasonable administrative, technical, and organizational safeguards intended to protect information against unauthorized access, acquisition, disclosure, alteration, misuse, loss, destruction, or other unlawful processing.
No website, network, device, application, storage system, payment platform, or method of electronic transmission can be guaranteed to be completely secure.
This statement describes our general security approach. It does not guarantee that:
- A security incident will never occur
- Every attempted attack will be detected
- Every fraudulent transaction will be identified
- Every website interruption will be prevented
- Information will never be accessed or disclosed unlawfully
Nothing in this statement excludes or limits any security obligation, consumer right, remedy, or liability that cannot lawfully be excluded or limited.
1. Our Security Approach
We seek to maintain safeguards reasonably appropriate to:
- The nature of our ecommerce operations
- The categories of information we process
- The sensitivity of that information
- The purposes for which the information is used
- The systems and service providers involved
- Reasonably foreseeable threats affecting online retailers
- Applicable legal, regulatory, and contractual requirements
Our security practices may be reviewed and adjusted as our:
- Website
- Products
- Business operations
- Service providers
- Applications
- Technologies
- Threat environment
- Legal obligations
change over time.
We may implement security improvements without publicly describing every technical control, configuration, monitoring method, or response procedure where disclosure could reduce the effectiveness of the safeguard.
2. Secure Website Connections
The MARSTEN online store is hosted through Shopify and uses HTTPS connections protected by Transport Layer Security, commonly referred to as TLS.
TLS is designed to encrypt information transmitted between a visitor’s browser and the website while that information is in transit.
A secure connection is generally indicated by:
- A website address beginning with https://
- A padlock or similar security indicator displayed by the browser
A padlock indicates that the connection is encrypted. It does not independently guarantee that every website, message, link, product, or person is legitimate.
Do not submit information if:
- Your browser displays a certificate warning
- The website address is misspelled or unfamiliar
- The connection is identified as insecure
- You were directed to the page through a suspicious message
- The website appears materially different from [marstenhome.com]
If you are uncertain, close the page and access MARSTEN directly by entering our official domain into your browser.
3. Shopify Platform Security
Shopify provides the principal ecommerce platform used to host and operate the MARSTEN online store.
Shopify’s platform may support functions such as:
- Secure storefront connections
- Shopping-cart functionality
- Checkout
- Administrative authentication
- Customer accounts
- Payment-related processing
- Fraud analysis
- Access permissions
- Platform monitoring
- Security updates
- Compliance reporting
Shopify’s safeguards supplement but do not replace MARSTEN’s responsibility to protect its own:
- Administrative accounts
- Email accounts
- Domain account
- Connected applications
- Pixels and scripts
- Staff and contractor access
- Business devices
- Customer-support processes
- Payment and fulfillment workflows
Information about Shopify’s own security and compliance practices is available through [Shopify Security] and [Shopify Compliance Reports].
4. Payment Security
Payments are processed through Shopify and the authorized payment providers displayed during checkout.
Depending on the payment method selected, processing may involve:
- Shopify
- An authorized payment processor
- A bank or card issuer
- A card network
- A digital-wallet provider
- A payment-authentication provider
- A fraud-prevention or transaction-verification provider
These providers operate their own:
- Encryption
- Authentication
- Fraud-prevention
- Monitoring
- Security
- Compliance
controls.
MARSTEN does not directly receive or store complete payment-card numbers or card security codes through its ordinary business systems.
We may receive limited payment-related information, such as:
- Payment status
- Payment-method type
- Card brand
- The final digits of a payment card
- Billing address
- Transaction identifiers
- Authentication results
- Fraud-screening results
- Refund or payment-dispute information
This information may be used to:
- Process and verify an order
- Provide customer support
- Issue refunds
- Reconcile transactions
- Investigate fraud
- Respond to payment disputes
- Maintain required business records
Payment-related practices are further described in our [Payment Policy] and [Privacy Policy].
5. Payment Card Industry Standards
The Payment Card Industry Data Security Standard, commonly referred to as PCI DSS, establishes requirements intended to protect payment-account information.
Shopify publishes compliance documentation relating to its assessment under PCI DSS.
Using Shopify and authorized payment providers reduces the amount of payment information handled directly through MARSTEN’s ordinary systems. It does not eliminate every security responsibility associated with operating an ecommerce business.
MARSTEN will not ask you to send any of the following through email, telephone, voicemail, chat, or our contact form:
- A complete payment-card number
- A card security code
- An online-banking password
- A digital-wallet password
- A bank-issued authentication code
- A customer-account password
Card security codes must not be retained after payment authorization.
6. Administrative, Technical, and Organizational Safeguards
Depending on the system, provider, information, and risk involved, our safeguards may include:
- Encrypted website connections
- Password-protected accounts
- Multi-factor authentication where supported
- Unique administrative accounts
- Role-based or restricted permissions
- Access limited according to business need
- Secure payment processing
- Fraud-screening tools
- Transaction-review procedures
- Account and security notifications
- Software and application updates
- Review of connected applications and permissions
- Removal of unnecessary access
- Data-retention controls
- Service-provider review
- Backup and recovery features provided by applicable platforms
- Investigation and response procedures for suspected incidents
The precise controls available may differ among:
- Shopify
- Payment providers
- Email systems
- Domain providers
- Customer-support systems
- Fulfillment providers
- Shipping providers
- Analytics and advertising platforms
- Other connected applications
We do not represent that every possible security control is used in every system or circumstance.
7. Access Controls
Access to customer and business information is intended to be limited to persons and service providers who reasonably require that access for an authorized purpose.
Authorized purposes may include:
- Processing and fulfilling orders
- Providing customer support
- Processing returns and refunds
- Managing payments
- Investigating fraud or account misuse
- Maintaining the website
- Providing accounting, tax, insurance, or legal services
- Complying with legal obligations
- Establishing, exercising, or defending legal claims
Access may be limited through:
- Individual user accounts
- Authentication controls
- Role permissions
- Administrative restrictions
- Business-need limitations
- Removal of access when no longer required
Employees, contractors, and service providers are not authorized to access customer information for personal, unauthorized, deceptive, or unlawful purposes.
Where appropriate, access may be suspended or removed if security, confidentiality, or acceptable-use requirements are not followed.
8. Administrative Account Security
We seek to protect the accounts used to manage MARSTEN through safeguards appropriate to the applicable platform.
These safeguards may include:
- Strong and unique passwords
- Multi-factor authentication
- Restricted staff permissions
- Periodic review of account access
- Prompt removal of unnecessary access
- Monitoring of relevant security notifications
- Separation of permissions where practical
- Review of suspicious sign-in or account activity
The security of connected accounts is important because unauthorized access to one service may create risks for other connected systems.
Connected accounts may include:
- Shopify
- Business email
- Domain and DNS management
- Payment providers
- Advertising platforms
- Analytics platforms
- Fulfillment systems
- Customer-support services
- Social-media accounts
9. Fraud Prevention and Transaction Security
We may use automated systems and manual review to identify transactions or activity that may be:
- Fraudulent
- Unauthorized
- Abusive
- Deceptive
- Technically suspicious
- Inconsistent with ordinary customer activity
Information considered during a security or fraud review may include:
- Billing and shipping addresses
- Address-verification results
- Payment-authentication results
- Card security-check results
- IP address
- Device or browser information
- Email address
- Telephone number
- Order value
- Order history
- Payment attempts
- Transaction velocity
- Delivery information
- Customer communications
- Previous refunds, disputes, or chargebacks
- Risk indicators provided by Shopify or payment providers
Where an order presents an elevated risk, we may:
- Hold the order for review
- Request limited verification
- Contact the customer
- Delay fulfillment
- Decline the transaction
- Cancel and refund the order
- Restrict further payment attempts
- Restrict future transactions
- Provide relevant records to a payment provider or appropriate authority
These measures are intended to protect customers, payment-account holders, MARSTEN, and payment-system participants.
Additional terms are available in our [Payment Policy] and [Terms of Service].
10. Order and Identity Verification
In limited circumstances, we may request information reasonably necessary to verify:
- The purchaser’s name
- Billing or delivery information
- The email address or telephone number associated with the order
- An address discrepancy
- Payment authorization
- The legitimacy of the transaction
Where stronger verification is reasonably required, we will seek to:
- Limit the amount of information requested
- Explain the reason for the request
- Use information reasonably connected with the transaction
- Avoid collecting unnecessary sensitive information
Failure to complete a reasonable verification request may result in:
- Processing delay
- Temporary order hold
- Order cancellation
- Refund to the original payment method
- Restriction of further transactions
Do not send identification documents unless MARSTEN specifically requests limited documentation and provides instructions for submitting it.
Personal information used for verification is handled as described in our [Privacy Policy].
11. Applications, Themes, Pixels, and Integrations
MARSTEN may use Shopify themes, applications, pixels, scripts, integrations, and other third-party software.
Before or during use, we may consider factors such as:
- The provider’s reputation
- The operational need for the service
- The permissions requested
- The type of information accessed
- The service’s privacy and security information
- Whether access remains necessary
- Whether a less intrusive alternative is available
Where appropriate, we may:
- Limit unnecessary applications or scripts
- Review requested permissions
- Remove unused integrations
- Apply available updates
- Investigate unexpected website changes
- Review security or account alerts
- Replace a provider whose access or risk is no longer appropriate
No application-review process can guarantee that third-party software is free from vulnerabilities or will never experience a security incident.
Third-party applications remain responsible for their own independent systems, personnel, security practices, and legal obligations.
12. Service Providers
MARSTEN relies on third-party providers for services that may include:
- Ecommerce hosting
- Payment processing
- Fraud prevention
- Order fulfillment
- Shipping and delivery
- Returns processing
- Customer support
- Analytics
- Advertising
- Product reviews
- Cloud storage
- Accounting
- Legal, insurance, and professional services
Where reasonably appropriate, we seek to:
- Use established providers
- Limit access to information relevant to the service
- Review available privacy and security information
- Remove access when the service is no longer required
MARSTEN does not directly control every provider’s:
- Infrastructure
- Networks
- Employees
- Security tools
- Monitoring
- Software
- Independent business decisions
A provider may experience an interruption, vulnerability, or security incident despite reasonable precautions.
Information about disclosures to service providers is available in our [Privacy Policy].
13. Data Minimization and Retention
We seek to collect and retain personal information only where reasonably connected to legitimate purposes, including:
- Order fulfillment
- Payment processing
- Customer support
- Returns and refunds
- Fraud prevention
- Security
- Accounting and taxation
- Legal compliance
- Payment-dispute handling
- Establishment or defense of legal claims
- Marketing where permitted
Retention periods vary according to:
- The type of information
- The purpose for which it was collected
- The sensitivity of the information
- Transaction and chargeback periods
- Fraud-prevention requirements
- Accounting and tax obligations
- Contractual requirements
- Legal limitation periods
- Pending or anticipated disputes
When information is no longer reasonably required, it may be:
- Deleted
- Anonymized
- Aggregated
- Securely restricted
- Disposed of through the applicable provider’s available procedures
Additional retention information is available in our [Privacy Policy].
14. Customer-Account Security
Where customer-account functionality is available, you are responsible for protecting your login credentials and controlling access to your account.
You should:
- Use a strong and unique password
- Avoid reusing passwords from another website
- Keep passwords and authentication codes private
- Keep your email account secure
- Sign out when using a shared device
- Review unexpected account or order activity
- Notify us promptly if you believe your account has been compromised
MARSTEN will not ask you to disclose your customer-account password through email or telephone.
Activity completed through a properly authenticated account may be treated as authorized unless we receive credible information indicating that the account or related credentials were compromised.
If you believe your account has been accessed without authorization, contact us immediately at [contact@marstenhome.com].
15. Customer Devices and Networks
The security of your own:
- Device
- Browser
- Email account
- Internet connection
- Passwords
- Digital wallet
- Payment account
can affect the security of your interaction with MARSTEN.
You should:
- Keep your operating system and browser updated
- Use trusted device-security protections
- Avoid entering sensitive information on public or untrusted devices
- Avoid unsecured public Wi-Fi for sensitive transactions
- Use unique passwords
- Enable multi-factor authentication on your email and payment accounts where available
- Review website addresses before entering credentials
- Avoid suspicious links and attachments
- Lock devices containing order or account information
- Contact your bank promptly regarding suspected unauthorized payment activity
Except where applicable law provides otherwise, MARSTEN is not responsible for an incident originating solely from a compromised customer-controlled device, email account, network, payment account, or credential outside our control.
16. Phishing, Impersonation, and Suspicious Communications
Fraudsters may attempt to impersonate:
- MARSTEN
- Shopify
- A payment provider
- A bank
- A shipping carrier
- A customer-support representative
- Another business involved with an order
Be cautious of messages that:
- Demand urgent payment using an unusual method
- Request passwords or security codes
- Ask for complete payment-card details through email
- Contain unexpected attachments
- Use a misspelled or unfamiliar domain
- Request payment through gift cards or cryptocurrency
- Ask for remote access to your device
- Threaten immediate account closure unless credentials are provided
- Direct you to an unfamiliar login page
- Claim that you must pay a fee to receive a refund
MARSTEN will not ask you to send:
- Your online-banking password
- Your customer-account password
- A bank-issued one-time authentication code
- A complete payment-card number by email
- A card security code
- A cryptocurrency payment
- A gift-card payment
When uncertain:
- Do not select the link or use the telephone number contained in the suspicious message.
- Visit [marstenhome.com] directly.
- Contact us using the details published on our official website.
Please report suspected impersonation, fraudulent websites, fake support accounts, or phishing messages to [contact@marstenhome.com].
17. Monitoring, Logs, and Security Records
Shopify and other service providers may maintain logs and security records relating to:
- Authentication
- Account access
- Website requests
- Transactions
- Device or browser activity
- Fraud indicators
- Application activity
- Website errors
- Security events
MARSTEN may review information made available through these systems where reasonably necessary to:
- Detect suspicious activity
- Investigate an order
- Respond to an account concern
- Prevent fraud
- Diagnose technical problems
- Enforce store policies
- Respond to a payment dispute
- Establish, exercise, or defend legal claims
- Comply with law
We do not represent that every system, transaction, or customer action is continuously monitored in real time.
Security and fraud records may be preserved for the periods described in our [Privacy Policy].
18. Security-Incident Response
If we become aware of a suspected security incident affecting systems or information under our control, our response may include:
- Assessing the nature and scope of the incident
- Restricting or removing affected access
- Securing affected accounts
- Preserving relevant evidence and records
- Working with Shopify or another provider
- Investigating the systems and information involved
- Addressing identified vulnerabilities
- Resetting credentials where appropriate
- Consulting cybersecurity, legal, insurance, or law-enforcement professionals
- Providing notices where required by applicable law
- Taking reasonable steps to reduce the risk of recurrence
The response will depend on:
- The nature of the incident
- The affected system
- The information involved
- The likelihood and severity of harm
- The providers involved
- Available evidence
- Applicable legal requirements
Not every:
- Technical error
- Attempted attack
- Suspicious message
- Unsuccessful login
- Website interruption
- Provider outage
constitutes a legally reportable personal-information breach.
Where a security incident creates a legally recognized notification obligation, we will provide required notices to affected individuals or authorities in the manner and within the period required by applicable law.
19. Security Limitations
Despite reasonable safeguards, security risks may arise from:
- Human error
- Credential theft
- Phishing
- Malware
- Software vulnerabilities
- Third-party incidents
- Unauthorized application access
- Internet-routing problems
- Customer-device compromise
- Social engineering
- Provider outages
- Sophisticated criminal activity
- Events outside our reasonable control
Accordingly, we cannot guarantee that:
- The website will always be available.
- Every attempted attack will be detected.
- Every vulnerability will be prevented.
- Every security event will be identified immediately.
- Transmitted or stored information will never be accessed unlawfully.
- A third-party provider will never experience an incident.
- Every fraudulent transaction will be identified before fulfillment.
- Every security concern can be resolved without interruption.
This limitation does not exclude any duty or liability that cannot lawfully be excluded.
20. Reporting a Security Concern
Report a suspected security issue affecting MARSTEN promptly.
Examples include:
- An unexpected customer-account login
- An order you did not place
- A suspected phishing message impersonating MARSTEN
- An apparent exposure of customer information
- An unexpected checkout redirect
- A suspicious MARSTEN webpage or domain
- An unauthorized account-information change
- A fraudulent website or support profile using the MARSTEN name
- A security-related website or application error
Contact:
Email: [contact@marstenhome.com]
Suggested subject line: Security Concern – MARSTEN
For an urgent matter, use:
Suggested subject line: Urgent Security Concern – MARSTEN
Please include, where available:
- Your full name and contact information
- A description of the concern
- The affected webpage or URL
- The date and approximate time observed
- Relevant screenshots or error messages
- The browser and device involved
- Any steps already taken
- Whether customer, account, or payment information may be involved
- The applicable order number, if relevant
Do not include:
- Passwords
- Authentication codes
- Card security codes
- Complete payment-card numbers
- Banking credentials
- Malicious executable files
- Unnecessary personal information concerning another person
Ordinary customer-support response periods are not guaranteed incident-response or remediation periods. Security reports may require technical investigation and coordination with third-party providers.
21. Vulnerability Reports
Security researchers may report a suspected vulnerability using the contact details above.
A useful report should include:
- The affected URL or feature
- The type of vulnerability
- Clear steps to reproduce the issue
- The potential impact
- Supporting screenshots or technical details
- Suggested remediation, if available
Submitting a vulnerability report does not create:
- A bug-bounty arrangement
- A contract
- An entitlement to payment
- A promise of public recognition
- Permission to access customer information
- Permission to disrupt the website
- Permission to test Shopify or another third-party system
- Permission to violate applicable law
MARSTEN does not operate a public bug-bounty program unless expressly announced in writing.
Without prior written authorization, you must not:
- Access or attempt to access another person’s account
- Obtain or attempt to obtain customer information
- Use stolen, guessed, or exposed credentials
- Conduct denial-of-service testing
- Disrupt checkout or website availability
- Deploy malware
- Send spam
- Alter, delete, corrupt, or download data
- Conduct social-engineering attacks
- Impersonate a customer, employee, contractor, or service provider
- Test Shopify or another provider beyond authorization granted by that provider
- Publicly disclose an unremediated vulnerability in a manner that creates avoidable risk
- Demand payment as a condition of withholding harmful disclosure
Ordinary good-faith reporting does not authorize intrusive, destructive, deceptive, or unlawful testing.
Do not submit reports that are knowingly false, misleading, extortionate, abusive, or intended to disrupt operations.
22. Privacy and Security
Information collected or generated for security purposes may be used to:
- Investigate incidents
- Prevent fraud
- Protect customers and systems
- Respond to reports
- Enforce policies
- Comply with legal obligations
- Establish, exercise, or defend legal claims
Our broader personal-information practices are described in:
- [Privacy Policy]
- [Cookie Policy]
- [California Consumer Privacy Act (CCPA/CPRA) Policy]
- [Do Not Sell or Share My Personal Information]
- [Terms of Service]
23. Changes to This Security Statement
We may update this Security Statement to reflect changes to:
- Security practices
- Website functionality
- Shopify services
- Payment providers
- Applications and integrations
- Business operations
- Applicable law
- Recognized security risks
- Incident-response procedures
The current version will be published on this page with a revised “Last Updated” date.
We may implement security changes without publicly describing every technical detail, particularly where disclosure could create or increase a security risk.
24. Contact Information
Store Name: MARSTEN
Legal Company Name: ZENTARA BRANDS LIMITED
Company Number: 78899970
Security and Customer-Support Inquiries
Email: [contact@marstenhome.com]
Phone: [+1 (512) 631-9468]
Contact Form: [Contact Us]
Suggested subject line: Security Concern – MARSTEN
Customer Service Hours
Monday–Friday: 9:00 a.m.–6:00 p.m. Eastern Time
Saturday–Sunday: Closed
Our customer-support team generally responds to ordinary inquiries within 24–48 hours on business days.
Security reports, suspected incidents, and vulnerability reports may require additional time for investigation. The ordinary customer-service response period is not a guaranteed incident-response or remediation timeframe.
Registered Company Address
ZENTARA BRANDS LIMITED
Unit 2A, 17/F, Glenealy Tower
No. 1 Glenealy, Central
Hong Kong
The registered company address is not a retail store, customer-service location, technical-support center, or authorized return facility.