Scope
This policy applies to all websites and digital services operated by Mercantile Entertainment Group, including but not limited to mercantilegroup.ie, cafeenseine.ie, whelanslive.com, opium.ie, nolita.ie, pichet.ie, thegeorge.ie, mercantilehotel.ie, cafe28.ie, and wavtickets.ie.
Reporting a Vulnerability
If you believe you have discovered a security vulnerability affecting any of our services, please report it using our Security Disclosure Form. We request that you do not publicly disclose the vulnerability until we have had reasonable time to investigate and address it.
What We Ask of Researchers
- Act in good faith and avoid privacy violations, service disruption, or data destruction
- Do not access or modify data belonging to other users
- Do not perform testing that degrades the performance or availability of our services
- Do not demand payment or compensation in exchange for vulnerability details
What You Can Expect From Us
- Acknowledgement of your report within 3 business days
- Updates on our progress
- Credit for your discovery if you wish, once the issue is resolved
- We will not pursue legal action against researchers who act in good faith in accordance with this policy
Out of Scope
The following are considered out of scope and should not be tested:
- Social engineering attacks against MEG staff
- Physical security of our venues
- Denial of service attacks
- Spam or email bombing
Preferred Languages
English
Last Updated
July 2026