Skip to main content

Security Policy

Scope

This policy applies to all websites and digital services operated by Mercantile Entertainment Group, including but not limited to mercantilegroup.ie, cafeenseine.ie, whelanslive.com, opium.ie, nolita.ie, pichet.ie, thegeorge.ie, mercantilehotel.ie, cafe28.ie, and wavtickets.ie.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability affecting any of our services, please report it using our Security Disclosure Form. We request that you do not publicly disclose the vulnerability until we have had reasonable time to investigate and address it.

What We Ask of Researchers

  • Act in good faith and avoid privacy violations, service disruption, or data destruction
  • Do not access or modify data belonging to other users
  • Do not perform testing that degrades the performance or availability of our services
  • Do not demand payment or compensation in exchange for vulnerability details

What You Can Expect From Us

  • Acknowledgement of your report within 3 business days
  • Updates on our progress
  • Credit for your discovery if you wish, once the issue is resolved
  • We will not pursue legal action against researchers who act in good faith in accordance with this policy

Out of Scope

The following are considered out of scope and should not be tested:

  • Social engineering attacks against MEG staff
  • Physical security of our venues
  • Denial of service attacks
  • Spam or email bombing

Preferred Languages

English

Last Updated

July 2026