Information Security Policy
Company Name: Evallyshop
Address: 670 River St, Hyde Park, MA 02136, United States
Email: customer@evallyshop.com
Phone: +1-(857)-837-0165
Effective Date: [Add Date]
Review Cycle: Annual or as required
1. Purpose
The purpose of this Information Security Policy is to protect Evallyshop’s information assets, customer data, payment information, and business systems from unauthorized access, misuse, disclosure, alteration, or destruction.
This policy establishes security principles and responsibilities applicable to all employees, contractors, and authorized third parties.
Evallyshop is owned and operated by AllRoundFix LLC, a company focused on offering reliable products, honest pricing, and a secure shopping environment for customers.
2. Scope
This policy applies to:
- All Evallyshop employees and contractors
- All information systems, networks, devices, and applications
- All customer, payment, operational, and business data
- All physical and electronic media used by Evallyshop
3. Information Security Commitment
Evallyshop is committed to:
- Protecting customer privacy and confidential business information
- Maintaining secure systems for processing payments and orders
- Complying with applicable data protection and payment security standards
- Reducing the risk of data breaches and security incidents
4. Employee Responsibilities
All personnel must:
- Handle information according to its sensitivity and classification
- Use company systems responsibly and for legitimate business purposes
- Protect login credentials and never share passwords
- Lock workstations when unattended
- Avoid installing unauthorized software or hardware
- Report suspected security incidents immediately
Evallyshop reserves the right to monitor and audit company systems to ensure compliance with this policy.
5. Acceptable Use of Systems
Employees must not:
- Use company systems for illegal, abusive, or inappropriate activities
- Access data beyond their authorized job role
- Bypass security controls or safeguards
- Transmit sensitive data through unsecured channels
Limited personal use is permitted provided it does not interfere with business operations or security.
6. Data Classification
Evallyshop classifies data into the following categories:
a) Confidential Data
Includes customer information, payment-related data, credentials, and internal business records.
b) Internal Use Data
Operational data intended for internal business use only.
c) Public Data
Information approved for public distribution.
All data must be handled according to its classification.
7. Payment & Cardholder Data Protection
Evallyshop does not store sensitive cardholder authentication data such as:
- Full card numbers (PAN)
- CVV/CVC codes
- PIN or magnetic stripe data
Payment processing is handled through secure, compliant third-party payment processors.
If any payment-related data is displayed, it must be masked and limited to authorized personnel only.
8. Access Control
- Access to systems is granted based on job role and business need
- Unique user IDs are assigned to each authorized user
- Access rights are reviewed periodically
- Accounts are disabled immediately upon termination of employment
Passwords must be strong, unique, and changed regularly.
9. Network & System Security
Evallyshop implements reasonable safeguards including:
- Firewalls and secure network configurations
- Antivirus and malware protection
- Regular system updates and security patches
- Monitoring for suspicious activity
Security vulnerabilities are addressed promptly based on risk level.
10. Physical Security
- Access to areas containing sensitive information is restricted
- Visitors must be escorted in secure areas
- Devices and systems are protected from tampering
- Paper records containing sensitive data are securely stored
11. Data Transmission & Encryption
Sensitive information must not be transmitted using unsecured methods such as plain email or messaging platforms.
When data transmission is required, secure and encrypted channels must be used.
12. Data Retention & Disposal
Evallyshop retains data only for as long as necessary for business or legal purposes.
When no longer required:
- Paper records are securely shredded or destroyed
- Electronic data is permanently deleted or securely wiped
- Storage media is rendered unrecoverable before disposal
13. Third-Party Service Providers
Third-party vendors with access to Evallyshop systems or data must:
- Follow reasonable security standards
- Use data only for authorized purposes
- Protect customer and business information
- Notify Evallyshop of any security incidents
Vendor access is reviewed periodically.
14. Security Awareness & Training
- Employees receive periodic security awareness training
- This policy is reviewed regularly
- Personnel must acknowledge and comply with security requirements
15. Incident Response
All suspected or confirmed security incidents must be reported immediately to management.
Evallyshop will:
- Investigate incidents promptly
- Contain and mitigate risks
- Notify affected parties when required by law
- Review controls to prevent recurrence
16. Policy Review & Updates
This Information Security Policy is reviewed at least annually and updated as necessary to address new risks, technologies, or legal requirements.
17. Compliance
Failure to comply with this policy may result in disciplinary action, including termination of employment or contractual relationships.
18. Contact Information
For questions or concerns related to information security, contact:
Evallyshop
📧 customer@evallyshop.com
Phone: +1-(857)-837-0165
📍 670 River St, Hyde Park, MA 02136, United States


