YNF Deals · Legal
Data Breach Notification Policy
This policy explains how YNF Deals prepares for, responds to, and communicates about security incidents involving personal data. If a breach ever puts your information at risk, we will contain it, investigate it, and notify you by email without undue delay — and we will never use that email to ask for your password. Full payment card numbers are handled exclusively by Stripe and are never stored on our systems.
1. Our commitment
YNF Deals ("we", "us") operates ynfdeals.com and sells through live auctions on TikTok LIVE and TikTok Shop. Protecting the personal data we hold — account details, order history, addresses, support conversations — is part of how we earn your trust, and this policy is our public commitment to handling security incidents responsibly.
If an incident affects personal data, we commit to three things: contain the incident quickly, assess the risk it creates for the people affected, and notify affected individuals and the appropriate authorities without undue delay whenever the law requires it. We follow the New York SHIELD Act as our baseline and the GDPR and UK GDPR where they apply to EU or UK visitors.
Prevention comes first. All pages are served over HTTPS/TLS, our site sits behind Cloudflare's CDN, WAF, and DDoS protection, passwords are stored hashed (never in plain text), staff access is role-based, and we keep regular backups. This policy covers what happens if those defenses are ever breached anyway.
2. What counts as a data breach
A data breach is a security incident that results in the unauthorized access to, or acquisition, disclosure, alteration, loss, or destruction of, personal information in our care. Examples include an attacker gaining access to customer account records, a database of order and shipping details being exposed, or a staff account being compromised and used to view customer data.
Not every security event is a breach. A blocked attack, a phishing email that no one fell for, a vulnerability we fix before anyone exploits it, or an outage with no data exposure are incidents we take seriously and document, but they do not trigger breach notification because no personal data was compromised.
Two boundaries matter to understanding your exposure:
- Payment cards. We never store full card numbers. Payment credentials on ynfdeals.com go directly to Stripe, Inc. (a PCI-DSS Level 1 provider), so a breach of our systems could not expose your full card number.
- TikTok Shop purchases. Checkout and payment for TikTok LIVE auctions are processed entirely by TikTok under TikTok's own terms and security practices. Incidents on TikTok's platform are governed by TikTok's policies, though we will pass on anything relevant we learn that affects our customers.
3. How we respond to an incident
3.1 Contain and investigate
When we detect or are told about a suspected incident, our first priority is stopping it: revoking compromised credentials, isolating affected systems, applying Cloudflare protections, and preserving logs and evidence. We then investigate what happened — which systems and data were involved, whose data, over what period, and the root cause.
3.2 Assess the risk to individuals
We evaluate the likely consequences for the people whose data was involved: the sensitivity of the data, whether it was protected (for example, hashed passwords), whether it was actually acquired or merely exposed, and the realistic risk of misuse such as identity theft or account takeover. This assessment determines who must be notified and how urgently, using the standards of the NY SHIELD Act and, where applicable, the GDPR.
3.3 Notify
Where notification is required — or where we judge it is the right thing to do even if not strictly required — we notify affected customers by email to the address on their account, and we notify regulators on the timelines in Section 4. If email is unavailable or the law requires it, we may also post a notice on ynfdeals.com.
3.4 Document and learn
Every incident, whether or not it becomes a notifiable breach, is recorded in an internal incident log: what happened, what data was involved, what we decided, and why. We keep security and login logs for 12 months in the ordinary course, and incident records for as long as the law and any resulting dispute require. Each incident ends with corrective action so the same weakness is not exploited twice.
4. When and whom we notify
Notification timing depends on who was affected and which law applies. Our operating rule is simple: without undue delay, and never slower than the law allows.
| Who we notify | When | Legal basis |
|---|---|---|
| Affected customers | In the most expedient time possible and without unreasonable delay after we confirm the breach and its scope | NY SHIELD Act; GDPR Article 34 where the breach poses a high risk to EU/UK individuals |
| New York Attorney General, NY Department of State, and NY State Police | At the time New York residents are notified | NY SHIELD Act |
| Consumer reporting agencies | If more than 5,000 New York residents must be notified at one time | NY SHIELD Act |
| EU/UK supervisory authority | Within 72 hours of our becoming aware of the breach, where feasible | GDPR / UK GDPR Article 33 |
| Regulators in other US states | On the timeline each applicable state law sets | State breach-notification laws |
Notification may be delayed only if law enforcement determines that notice would impede a criminal investigation; in that case we notify as soon as law enforcement confirms the delay is no longer needed. Where a breach originates with one of our service providers — Stripe, TikTok / TikTok Shop, Google, Resend, Cloudflare, or a delivery carrier — we coordinate with them, but we remain responsible for notifying our customers about data we control.
5. What a breach notice will contain
A genuine breach notice from us is written in plain English and tells you everything you need to act. It will include:
- What happened — the nature of the incident and, as best we know, when it occurred and when we discovered it.
- What data was involved — the specific categories affected (for example, email addresses and order history) and, just as importantly, what was not affected.
- What we did — the steps we took to contain the incident and prevent recurrence.
- What you should do — practical steps such as changing your password, reviewing recent orders in your account portal, and being alert for phishing emails that reference the incident.
- How to reach us — a way to ask questions, via [email protected] or your account's Support area.
The notice will come by email to the address on your account. It will never require you to click a link to "verify" your identity, and it will never ask you for payment.
6. What we will never do
Attackers often follow real breaches with fake "security alerts" designed to steal credentials. Knowing what we will never do is your best defense:
- We will never ask for your password — not by email, phone, or text. No one at YNF Deals ever needs it; passwords are stored hashed and cannot be read by our staff.
- We will never ask for your full card number. We do not have it, and we will never request it by email.
- We will never ask for a payment or a "verification fee" in connection with a security notice.
- We will never pressure you with countdown deadlines to click a link. If you are unsure about any message, do not click — type ynfdeals.com into your browser yourself, sign in, and check the Support area, or forward the message to [email protected] so we can confirm whether it is genuine.
7. How to report a suspected incident
If you believe your YNF Deals account has been accessed without your permission, you received a suspicious message claiming to be from us, or you have found a security weakness on ynfdeals.com, please tell us right away:
- Email [email protected] with "Security" in the subject line, or
- Open a ticket in the Support area of your account, or
- Call us at +1 516-884-3338.
Include as much detail as you safely can: what you saw, when, the URL or a copy of the suspicious message, and screenshots if available. Please report in good faith — do not access other people's data, attempt to exploit a weakness beyond what is needed to demonstrate it, or disrupt the service. We review security reports promptly, and reports handled this way will not be treated as a violation of our Terms of Service.
8. Contact
Questions about this policy, or about a notice you received, can be directed to:
YNF Deals
585 W Merrick Rd Ste 28 C
Valley Stream, NY 11580, United States
Email: [email protected]
Phone: +1 516-884-3338
This policy is governed by the laws of the State of New York, USA. For how we collect and use personal data generally, see our Privacy Policy; for cookies, see our Cookie Policy.