How to report a security issue. No public bounty. A person reads the mailbox.
Where to write
Email legal@theplacetoshoplocal.com with the subject “Vulnerability”. Include the URL, what you did, what you saw, and a screenshot or request/response if you have it. Do not send a working exploit against a merchant, and do not pull anyone else’s data to prove the point.
What is in scope
theplacetoshoplocal.com and the forms on it. Processor, bank, and card-network systems are not ours — report those to them.
What we ask
Give us a reasonable chance to fix it before you publish. We will write back. We will not pay a bounty and we will not sign a researcher NDA as a default. Good-faith research that follows this page is welcome; everything in Acceptable Use still applies.