Security & Data Protection Policy

Last Updated: September 2026

Domain: envirobiotics.store

At ENVIROBIOTICS®, protecting your personal information and ensuring a safe browsing and shopping environment is a fundamental priority. This Security Policy outlines how we safeguard our web infrastructure, protect your payment transactions, and handle your data across all language options on our website (envirobiotics.store).

1. Website Infrastructure & Transmission Security

HTTPS & SSL Encryption

All communication between your web browser and envirobiotics.store is protected using industry-standard 256-bit TLS/SSL (Transport Layer Security) encryption. This ensures that any data you submit—including contact details, account credentials, and shipping addresses—remains private and safe from interception.

Single-Domain Integrity & Flexible Language Selection

Our entire platform operates under a single, unified domain (envirobiotics.store). We offer complete freedom of navigation across our supported site languages:

  • Traditional Chinese (Hong Kong): /zh_hk/
  • Traditional Chinese (Taiwan): /zh_tw/
  • Japanese: /ja/
  • Korean: /ko/
  • Thai: /th/

We do not use automatic IP tracking, location-based enforcement, or regional subdomains to restrict or redirect your connection. Regardless of your physical location or shipping destination, you are free to browse and complete transactions in whichever language you prefer. Your session remains secure, predictable, and directly connected to our official primary server.

2. Payment Gateway & Financial Security

Your financial safety is strictly protected. ENVIROBIOTICS® does not store, process, or transmit credit card details or payment account credentials on our servers.

Stripe Payment Infrastructure

All online payments are processed exclusively through Stripe, our sole authorized payment gateway provider. Stripe is certified as a PCI-DSS Level 1 Service Provider—the highest, most stringent level of security certification available in the global payments industry.

Transaction Security & Digital Wallets

When you complete a purchase using major payment cards or supported digital wallets (such as Apple Pay or Google Pay):

  • All payment data is handled directly within Stripe’s PCI-compliant environment using encrypted API endpoints.
  • End-to-end encryption ensures that card numbers, CVVs, and sensitive payment tokens are never exposed to, accessible by, or stored on ENVIROBIOTICS® servers.
  • Transactions utilize advanced risk-evaluation algorithms and 3D Secure (3DS) authentication protocols to protect against fraud.

3. Account & Session Protection

To protect customer accounts and administrative tools, we maintain the following security standards:

  • Secure Cookies: All authentication, shopping cart, and language-preference cookies are assigned strict security flags (Secure, HttpOnly, and SameSite=Lax). This prevents unauthorized third-party scripts from accessing your session data.
  • Modern Authentication: Our platform supports modern passwordless security standards and secure passkey endpoints to reduce the risk of credential theft and unauthorized account access.
  • Rate Limiting: Automated systems monitor login forms and checkout pages to block automated bot attacks and brute-force attempts.

4. Web Application Firewall & Threat Monitoring

We employ continuous, server-level protection to guard against cyber threats:

  • Firewall Filtering: A global Web Application Firewall (WAF) inspects incoming traffic to prevent malicious code injection, Cross-Site Scripting (XSS), and Distributed Denial of Service (DDoS) attacks.
  • System Updates: Our platform core, security modules, and integration tools are regularly patched and updated to eliminate vulnerabilities.
  • System Discovery & Crawlers: Automated checks are conducted solely to verify security endpoints, search engine indexing, and payment gateway health.

5. Third-Party Data Handling & Privacy

We treat your personal data with strict confidentiality:

  • No Selling of Data: We never sell, rent, or trade your personal or business information to third parties.
  • Essential Service Providers: Information is shared strictly with trusted operational partners required to complete your order (specifically, Stripe for payment processing and our regional logistics/courier partners for delivery).

6. Vulnerability Disclosure & Contact

We welcome feedback from security researchers and customers to help us maintain a safe platform.

If you suspect a security vulnerability or have concerns regarding your account security, please contact our technical team immediately:

  • Email: security(at)ebt-asia.com
  • General Inquiries: info(at)ebt-asia.com

Please include a detailed description of the issue, steps to reproduce it, and any relevant details so our technical team can address it promptly.


Secret Link