Data Breach Notification Policy | Eazy Phones

Your data.
Our responsibility.
Explained in plain language.

This policy explains, in specific and practical terms, how Eazy Phones protects the personal information you share with us when you buy a smartphone, tablet, smart watch, or audio accessory, and exactly what we do — and who we tell — if that information is ever compromised.

Last updated: July 18, 2026
Effective: July 18, 2026
Purpose & Scope

Why This Policy Exists

Eazy Phones is a registered Canadian retailer of new, factory-sealed smartphones, tablets, smart watches, and audio accessories, operating a single storefront at eazyphones.com and shipping exclusively to Canada and the United States. Running that storefront means we collect personal information — names, delivery addresses, email addresses, phone numbers, and order history — in order to process, ship, and support the orders you place with us. This policy sets out how we safeguard that information, how we detect and respond if it is ever accessed without authorization, and how and when we notify the people and regulators the law requires us to notify. It applies to every customer account, guest checkout, and support interaction on eazyphones.com, and it works alongside our Privacy Policy and Terms of Service rather than replacing them.

Applies to eazyphones.com customers in Canada & the United States Covers account, order, and support data Read together with our Privacy Policy
Definitions

What We Mean by a "Data Breach"

For the purposes of this policy, a data breach is any incident where personal information we hold — or that a service provider holds on our behalf — is lost, stolen, accessed, disclosed, altered, or destroyed without authorization. Because we run a single WordPress and WooCommerce storefront rather than multiple systems, the categories of information that could be affected are limited and specific to how our store actually operates:

Account & Contact Data

Name, email, delivery address, and phone number entered at checkout or in a My Account profile

Payment Metadata

Transaction records and order totals — we never store full card numbers; those are processed directly by PayPal and our payment gateway

Order & Shipping Records

What you purchased, tracking numbers, and delivery status shared with DHL Express and FedEx for fulfillment

Support Correspondence

Emails, WhatsApp messages, and contact-form submissions sent to our Ontario support desk

A breach can be malicious (a criminal accessing our systems or a supplier's systems), accidental (a misconfigured setting exposing data that should have been restricted), or the result of human error (information sent to the wrong recipient). All three trigger the same assessment process described below.

Prevention & Safeguards

How We Protect Your Information Every Day

Preventing a breach matters more than reacting to one well, so our safeguards are built into how the store operates day to day, not treated as a separate project.

Encrypted checkout

Every checkout page runs over TLS/SSL encryption, and card payments are handled directly by PayPal and our PCI-DSS-compliant payment gateway. We never see or store your full card number, expiry date, or CVV on our own servers.

Restricted staff access

Only the Ontario-based team members who genuinely need order data to fulfil, ship, or support your purchase can see it. Access is individually logged and revoked immediately when a role changes.

Maintained platform

Our WordPress and WooCommerce storefront, plugins, and hosting environment are kept on current, patched versions, with firewall and malware-scanning protection active around the clock.

Strong password enforcement

Customer accounts require a minimum password strength, and internal admin logins are protected by unique credentials and multi-factor authentication where the platform supports it.

Ongoing monitoring

Login attempts, checkout traffic, and admin activity on our storefront are monitored for the kind of unusual patterns — repeated failed logins, bulk data exports, irregular hours — that often signal a compromise before it escalates.

Vetted service providers

We only work with shipping carriers, payment processors, and hosting providers that maintain their own recognized security and data-protection standards, as described in the third-party section below.

Detection, Containment & Assessment

What Happens the Moment We Suspect a Breach

If our monitoring tools, a payment processor, a shipping carrier, our hosting provider, or a customer alerts us to a possible incident, we follow the same disciplined sequence every time, regardless of how the alert reached us.

STEP 01 — IDENTIFY

Confirm and record the incident

We verify whether unauthorized access, disclosure, or loss actually occurred, and log the date, time, and source of the alert the moment it is received.

STEP 02 — CONTAIN

Stop the exposure

We immediately revoke compromised credentials, isolate the affected system or account, and close the specific vulnerability that allowed the access, working with our hosting provider where needed.

STEP 03 — ASSESS

Scope the impact

We determine exactly which categories of data and which individuals were affected, and evaluate whether the breach creates a real risk of significant harm — financial loss, identity theft, or reputational harm — to those individuals.

STEP 04 — NOTIFY

Tell the people and regulators the law requires

Based on the assessment above, we notify affected customers, the Office of the Privacy Commissioner of Canada, and any applicable U.S. state authority, following the thresholds and timelines set out below.

STEP 05 — REMEDIATE

Close the gap and record the lesson

We fix the underlying cause, review related systems for the same weakness, and keep a written record of the incident and our response, as Canadian law requires us to do.

Canadian Legal Framework

The Notification Rules We Follow in Canada

Eazy Phones is registered and headquartered in Vaughan, Ontario, so our notification obligations start with federal Canadian privacy law and are layered with Ontario consumer-protection standards.

PIPEDA breach obligations

Under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and its Breach of Security Safeguards Regulations, we must report to the Office of the Privacy Commissioner of Canada (OPC) and notify affected individuals wherever a breach creates a real risk of significant harm — meaning a reasonable likelihood of financial loss, identity theft, damage to reputation, or other serious harm to the individual.

Notification timing

Where that threshold is met, we notify affected individuals and the OPC as soon as feasible after we determine the breach has occurred — we do not wait for an investigation to fully conclude before warning the people affected.

Mandatory record-keeping

PIPEDA requires us to keep a written record of every breach of security safeguards involving personal information under our control — not only the ones that meet the notification threshold — for a minimum of 24 months, and to provide that record to the OPC on request.

Ontario consumer standards

Alongside PIPEDA, we operate in line with the Ontario Consumer Protection Act, 2002, which reinforces our obligation to deal with customers honestly and to disclose material information — including a breach affecting their order or account — rather than concealing it.

United States Legal Framework

The Notification Rules We Follow for U.S. Customers

The United States has no single federal breach-notification law. Instead, each of the fifty states, plus Washington D.C., has its own statute setting out when and how a business must notify residents affected by a breach. Because we ship to customers across the United States, we treat every state's law as potentially applicable and follow the strictest standard that applies to the specific customers affected by any given incident.

"Without unreasonable delay" standard

Most U.S. state statutes require notification to affected residents without unreasonable delay, and several set a firm outer limit — commonly 30 to 60 days from discovery of the breach — once the scope of the incident is known.

State Attorney General reporting

A number of states additionally require notice to the state Attorney General or a designated state agency once the number of affected residents in that state crosses a defined threshold, which we track and comply with on a state-by-state basis.

FTC fair-practices standard

As a business handling U.S. consumer data, we are also subject to Section 5 of the FTC Act, which prohibits unfair or deceptive practices — including misrepresenting how we protect data or delaying notification in a way that harms consumers.

What triggers notice

State laws generally require notice when unencrypted personal information — typically a name combined with a Social Security number, driver's licence number, or financial account number — is acquired without authorization. As explained above, we do not store card numbers, which meaningfully limits this exposure for our customers.

Why we describe this generally rather than state by state

Because state breach laws are numerous and change over time, and because the specific obligations that apply depend on which residents are affected and what data is involved, we assess the exact requirements at the time of any actual incident rather than fixing a single rule here. Whichever standard applies, we will never notify later, or disclose less, than the law of the affected customer's state requires.

Customer Notification

How and When We Will Notify You

If a breach affecting your personal information meets the legal threshold described above, we will contact you directly rather than relying only on a public notice.

Primary channelEmail, sent to the address on file for your Eazy Phones account or order
Backup channelPhone call or a prominent notice on eazyphones.com if we cannot reach you by email within a reasonable time
TimingAs soon as feasible after we confirm the breach and its scope — we do not delay notice to finish an internal investigation first
LanguagePlain English, describing exactly what happened and what you should do — never vague or legalistic

What a Notification From Us Will Always Include

  • A description of what happened, in plain terms, and the date or date range we believe it occurred
  • The specific categories of your personal information involved — for example, name and shipping address, but not payment card data, if that is the case
  • The steps we have already taken to contain the incident and prevent it from recurring
  • Practical steps you can take to protect yourself, such as changing your account password or watching for unusual activity
  • A direct way to reach us with questions, using the contact details at the bottom of this page
  • Confirmation of whether we have notified the Office of the Privacy Commissioner of Canada or a relevant U.S. state authority
Third-Party Service Providers

Shared Responsibility With Our Service Providers

We do not run every system your data touches. Payment processing, delivery, and hosting are each handled by specialist providers who maintain their own security programs and their own breach-notification obligations to us.

Payment processing

PayPal and our payment gateway process and store card data under their own PCI-DSS-certified security programs. If a breach occurs on their side, they are contractually required to inform us, and we will pass that information on to you under this policy.

Shipping carriers

DHL Express and FedEx receive only the shipping details needed to deliver your order — name, address, and phone number — and each maintains its own data-security and breach-response program as a global logistics provider.

Website hosting & platform

Our WordPress and WooCommerce hosting environment is maintained with active security monitoring and regular backups, and our hosting provider notifies us immediately of any confirmed intrusion affecting our environment.

Whichever provider is involved, Eazy Phones — not the provider — is responsible for deciding whether the incident meets a notification threshold and for contacting you directly. We do not leave that decision, or that conversation, to a third party.

Remediation

What We Do After a Breach Is Contained

Notification is not the end of our response. Depending on the nature and scale of a confirmed breach, we take further steps proportionate to the risk to affected customers.

Forced password resets

If account credentials were exposed, we invalidate the affected passwords and prompt an immediate reset before the account can be used again.

Guidance on next steps

Where the exposed data creates a risk of identity theft or fraud, we tell affected customers specifically what to watch for and, where appropriate, point them toward relevant credit-monitoring or fraud-alert resources in their country.

Systemic review

We review every related system, plugin, and provider connection for the same weakness that allowed the incident, not just the single point that was breached.

Documented follow-through

Every incident, whether or not it met the notification threshold, is logged with its cause, scope, and resolution, and kept on file for at least 24 months in line with PIPEDA record-keeping requirements.

Your Rights

What You Can Do, Any Time

Whether or not a breach has occurred, you always have the right to ask us what personal information we hold about you, to request a correction, or to ask us to close your account and delete your data, subject to any records we are legally required to keep — such as order records for tax and warranty purposes. If you believe your information has been misused, you may also file a complaint with the Office of the Privacy Commissioner of Canada, or with your state Attorney General's office if you are a U.S. resident. Full detail on these rights is set out in our Privacy Policy.

Report a Suspected Incident

If You Suspect Something Is Wrong, Tell Us First

If you notice unusual activity on your Eazy Phones account, receive a suspicious message claiming to be from us, or have any reason to believe your information may have been exposed, contact our Ontario support desk immediately using the details below. We investigate every report the same day it is received during business hours.

Business hours Mon–Fri, 9:00 AM–5:00 PM EST (Toronto)
WhatsApp Live chat on the website during business hours
Registered address 4140 Steeles Ave W, Unit 4, Vaughan, ON L4L 4V3, Canada

Eazy Phones — Business Identification Number (BIN) 1001503255 — will never ask you to confirm a full card number, password, or one-time verification code by email, phone, or WhatsApp. If you receive such a request claiming to be from us, do not respond, and report it to support@eazyphones.com right away.