Your data.
Our responsibility.
Explained in plain language.
This policy explains, in specific and practical terms, how Eazy Phones protects the personal information you share with us when you buy a smartphone, tablet, smart watch, or audio accessory, and exactly what we do — and who we tell — if that information is ever compromised.
Why This Policy Exists
Eazy Phones is a registered Canadian retailer of new, factory-sealed smartphones, tablets, smart watches, and audio accessories, operating a single storefront at eazyphones.com and shipping exclusively to Canada and the United States. Running that storefront means we collect personal information — names, delivery addresses, email addresses, phone numbers, and order history — in order to process, ship, and support the orders you place with us. This policy sets out how we safeguard that information, how we detect and respond if it is ever accessed without authorization, and how and when we notify the people and regulators the law requires us to notify. It applies to every customer account, guest checkout, and support interaction on eazyphones.com, and it works alongside our Privacy Policy and Terms of Service rather than replacing them.
What We Mean by a "Data Breach"
For the purposes of this policy, a data breach is any incident where personal information we hold — or that a service provider holds on our behalf — is lost, stolen, accessed, disclosed, altered, or destroyed without authorization. Because we run a single WordPress and WooCommerce storefront rather than multiple systems, the categories of information that could be affected are limited and specific to how our store actually operates:
Account & Contact Data
Name, email, delivery address, and phone number entered at checkout or in a My Account profilePayment Metadata
Transaction records and order totals — we never store full card numbers; those are processed directly by PayPal and our payment gatewayOrder & Shipping Records
What you purchased, tracking numbers, and delivery status shared with DHL Express and FedEx for fulfillmentSupport Correspondence
Emails, WhatsApp messages, and contact-form submissions sent to our Ontario support deskA breach can be malicious (a criminal accessing our systems or a supplier's systems), accidental (a misconfigured setting exposing data that should have been restricted), or the result of human error (information sent to the wrong recipient). All three trigger the same assessment process described below.
How We Protect Your Information Every Day
Preventing a breach matters more than reacting to one well, so our safeguards are built into how the store operates day to day, not treated as a separate project.
Encrypted checkout
Every checkout page runs over TLS/SSL encryption, and card payments are handled directly by PayPal and our PCI-DSS-compliant payment gateway. We never see or store your full card number, expiry date, or CVV on our own servers.
Restricted staff access
Only the Ontario-based team members who genuinely need order data to fulfil, ship, or support your purchase can see it. Access is individually logged and revoked immediately when a role changes.
Maintained platform
Our WordPress and WooCommerce storefront, plugins, and hosting environment are kept on current, patched versions, with firewall and malware-scanning protection active around the clock.
Strong password enforcement
Customer accounts require a minimum password strength, and internal admin logins are protected by unique credentials and multi-factor authentication where the platform supports it.
Ongoing monitoring
Login attempts, checkout traffic, and admin activity on our storefront are monitored for the kind of unusual patterns — repeated failed logins, bulk data exports, irregular hours — that often signal a compromise before it escalates.
Vetted service providers
We only work with shipping carriers, payment processors, and hosting providers that maintain their own recognized security and data-protection standards, as described in the third-party section below.
What Happens the Moment We Suspect a Breach
If our monitoring tools, a payment processor, a shipping carrier, our hosting provider, or a customer alerts us to a possible incident, we follow the same disciplined sequence every time, regardless of how the alert reached us.
Confirm and record the incident
We verify whether unauthorized access, disclosure, or loss actually occurred, and log the date, time, and source of the alert the moment it is received.
Stop the exposure
We immediately revoke compromised credentials, isolate the affected system or account, and close the specific vulnerability that allowed the access, working with our hosting provider where needed.
Scope the impact
We determine exactly which categories of data and which individuals were affected, and evaluate whether the breach creates a real risk of significant harm — financial loss, identity theft, or reputational harm — to those individuals.
Tell the people and regulators the law requires
Based on the assessment above, we notify affected customers, the Office of the Privacy Commissioner of Canada, and any applicable U.S. state authority, following the thresholds and timelines set out below.
Close the gap and record the lesson
We fix the underlying cause, review related systems for the same weakness, and keep a written record of the incident and our response, as Canadian law requires us to do.
The Notification Rules We Follow in Canada
Eazy Phones is registered and headquartered in Vaughan, Ontario, so our notification obligations start with federal Canadian privacy law and are layered with Ontario consumer-protection standards.
PIPEDA breach obligations
Under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and its Breach of Security Safeguards Regulations, we must report to the Office of the Privacy Commissioner of Canada (OPC) and notify affected individuals wherever a breach creates a real risk of significant harm — meaning a reasonable likelihood of financial loss, identity theft, damage to reputation, or other serious harm to the individual.
Notification timing
Where that threshold is met, we notify affected individuals and the OPC as soon as feasible after we determine the breach has occurred — we do not wait for an investigation to fully conclude before warning the people affected.
Mandatory record-keeping
PIPEDA requires us to keep a written record of every breach of security safeguards involving personal information under our control — not only the ones that meet the notification threshold — for a minimum of 24 months, and to provide that record to the OPC on request.
Ontario consumer standards
Alongside PIPEDA, we operate in line with the Ontario Consumer Protection Act, 2002, which reinforces our obligation to deal with customers honestly and to disclose material information — including a breach affecting their order or account — rather than concealing it.
The Notification Rules We Follow for U.S. Customers
The United States has no single federal breach-notification law. Instead, each of the fifty states, plus Washington D.C., has its own statute setting out when and how a business must notify residents affected by a breach. Because we ship to customers across the United States, we treat every state's law as potentially applicable and follow the strictest standard that applies to the specific customers affected by any given incident.
"Without unreasonable delay" standard
Most U.S. state statutes require notification to affected residents without unreasonable delay, and several set a firm outer limit — commonly 30 to 60 days from discovery of the breach — once the scope of the incident is known.
State Attorney General reporting
A number of states additionally require notice to the state Attorney General or a designated state agency once the number of affected residents in that state crosses a defined threshold, which we track and comply with on a state-by-state basis.
FTC fair-practices standard
As a business handling U.S. consumer data, we are also subject to Section 5 of the FTC Act, which prohibits unfair or deceptive practices — including misrepresenting how we protect data or delaying notification in a way that harms consumers.
What triggers notice
State laws generally require notice when unencrypted personal information — typically a name combined with a Social Security number, driver's licence number, or financial account number — is acquired without authorization. As explained above, we do not store card numbers, which meaningfully limits this exposure for our customers.
Why we describe this generally rather than state by state
Because state breach laws are numerous and change over time, and because the specific obligations that apply depend on which residents are affected and what data is involved, we assess the exact requirements at the time of any actual incident rather than fixing a single rule here. Whichever standard applies, we will never notify later, or disclose less, than the law of the affected customer's state requires.
How and When We Will Notify You
If a breach affecting your personal information meets the legal threshold described above, we will contact you directly rather than relying only on a public notice.
| Primary channel | Email, sent to the address on file for your Eazy Phones account or order |
|---|---|
| Backup channel | Phone call or a prominent notice on eazyphones.com if we cannot reach you by email within a reasonable time |
| Timing | As soon as feasible after we confirm the breach and its scope — we do not delay notice to finish an internal investigation first |
| Language | Plain English, describing exactly what happened and what you should do — never vague or legalistic |
What a Notification From Us Will Always Include
- A description of what happened, in plain terms, and the date or date range we believe it occurred
- The specific categories of your personal information involved — for example, name and shipping address, but not payment card data, if that is the case
- The steps we have already taken to contain the incident and prevent it from recurring
- Practical steps you can take to protect yourself, such as changing your account password or watching for unusual activity
- A direct way to reach us with questions, using the contact details at the bottom of this page
- Confirmation of whether we have notified the Office of the Privacy Commissioner of Canada or a relevant U.S. state authority
Shared Responsibility With Our Service Providers
We do not run every system your data touches. Payment processing, delivery, and hosting are each handled by specialist providers who maintain their own security programs and their own breach-notification obligations to us.
Payment processing
PayPal and our payment gateway process and store card data under their own PCI-DSS-certified security programs. If a breach occurs on their side, they are contractually required to inform us, and we will pass that information on to you under this policy.
Shipping carriers
DHL Express and FedEx receive only the shipping details needed to deliver your order — name, address, and phone number — and each maintains its own data-security and breach-response program as a global logistics provider.
Website hosting & platform
Our WordPress and WooCommerce hosting environment is maintained with active security monitoring and regular backups, and our hosting provider notifies us immediately of any confirmed intrusion affecting our environment.
Whichever provider is involved, Eazy Phones — not the provider — is responsible for deciding whether the incident meets a notification threshold and for contacting you directly. We do not leave that decision, or that conversation, to a third party.
What We Do After a Breach Is Contained
Notification is not the end of our response. Depending on the nature and scale of a confirmed breach, we take further steps proportionate to the risk to affected customers.
Forced password resets
If account credentials were exposed, we invalidate the affected passwords and prompt an immediate reset before the account can be used again.
Guidance on next steps
Where the exposed data creates a risk of identity theft or fraud, we tell affected customers specifically what to watch for and, where appropriate, point them toward relevant credit-monitoring or fraud-alert resources in their country.
Systemic review
We review every related system, plugin, and provider connection for the same weakness that allowed the incident, not just the single point that was breached.
Documented follow-through
Every incident, whether or not it met the notification threshold, is logged with its cause, scope, and resolution, and kept on file for at least 24 months in line with PIPEDA record-keeping requirements.
What You Can Do, Any Time
Whether or not a breach has occurred, you always have the right to ask us what personal information we hold about you, to request a correction, or to ask us to close your account and delete your data, subject to any records we are legally required to keep — such as order records for tax and warranty purposes. If you believe your information has been misused, you may also file a complaint with the Office of the Privacy Commissioner of Canada, or with your state Attorney General's office if you are a U.S. resident. Full detail on these rights is set out in our Privacy Policy.
If You Suspect Something Is Wrong, Tell Us First
If you notice unusual activity on your Eazy Phones account, receive a suspicious message claiming to be from us, or have any reason to believe your information may have been exposed, contact our Ontario support desk immediately using the details below. We investigate every report the same day it is received during business hours.
Eazy Phones — Business Identification Number (BIN) 1001503255 — will never ask you to confirm a full card number, password, or one-time verification code by email, phone, or WhatsApp. If you receive such a request claiming to be from us, do not respond, and report it to support@eazyphones.com right away.













