A week is no time whatsoever.
Lots of people routinely publish vulnerabilities; anecdotally, if you do it the same way everyone else does, I think your risk is probably minimal.
Some thoughts:
* Have a calendar and stick to it. If it's 90 days from acknowledged contact, don't publish anything for 90 days.
* Be careful about upselling services (my advice: simply don't do it). If you're effectively breaking someone's terms of services by testing (spoiler: you probably are) and you "ask" for a service contract in return for doing something favorable (ie, not doing something unfavorable) with the results of that testing, you're being coercive. Doing something unlawful to coerce someone into giving you something of value is extortion. Don't extort people.
* Be extremely careful testing other people's sites. The short answer to "is it lawful to test someone's site" is, "probably not". If they've posted a bug bounty or a list of thank-yous to researchers, you can reasonably infer that they're allowing remote testing --- but if your testing crashes their site or compromises user data, all bets are off.
* Do not under any circumstances post actual user information, sanitized or otherwise.
* Do not post exploit code, or information that makes exploitation trivial. If the world doesn't believe you about the severity of your finding, get better at gauging severity, or become a better writer.
If it were me, I'd probably sketch out a policy as follows:
* A calendar and set of escalations for confirmation of a finding --- first contact in order to find a safe way to relay the finding, escalating to public (Twitter) requests for someone to relay the finding to (maybe 2-3 business days later), escalating to simply sending the finding to public support addresses (maybe a week later). With no acknowledgement of a finding after, like, a month, I might escalate to posting the name of the company and a SHA2 hash of the finding, repeatedly confirming the finding every other week or so, and then maybe a month later more details on what the finding enables (the "Phone numbers. Names. Location." thing you wrote here, I would not write for a long time.)
* Once the finding is confirmed, a simple schedule for public announcement. Maybe 30-90 days, depending, on generating a patch, and then N days after than for an announcement on my blog or whatever. If we're doing a coordinated announcement where you send a bulletin that credits me and agrees with my assessment of the finding, maybe I'll give you an extra 30 days after the patch if you want it. If I'm the only one who announces, maybe I'm announcing 5 days after the patch. Things like that.
The important things are:
1. Write a policy and stick to it.
2. Get the vulnerability confirmed before you announce it.
3. Negotiate with the vendor to minimize harm.
Again: be especially careful when you're testing someone's servers. The law is generally pretty supportive of testing software you personally install, but not at all supportive of you testing software on other people's machines.