Introduction
Ezmove Services LLC (“Ezmove,” “we,” “us,” or “our”) is an authorized retailer for top internet carriers in the United States. Our business operates primarily through inbound call leads generated from our website, ezmove.services, where customers can compare internet carriers in their zip code. All customer interactions, including guidance on carrier plans and order processing, occur via inbound calls to our call center.
Crucially, Ezmove Services LLC does not directly process, store, or transmit any sensitive customer data on its website or directly in its call center beyond what is absolutely necessary for the referral process. Our website does not support online transactions and therefore does not collect, relay, or store customer payment information or other sensitive personal data. Customer orders, including payment processing, are handled within the secure and compliant ecosystems of the internet carriers.
This Data Security, Storage, and Privacy Policy outlines our approach to protecting any data we handle, maintaining a secure operating environment, and respecting privacy, in compliance with U.S. jurisdiction.
Effective Date: June 3, 2025
Data Collection and Usage
Given our business model, our data collection is inherently limited:
- Website Data: The ezmove.services website primarily uses cookies for website functionality and analytics (as detailed in our Cookie Policy). It does not collect or store personal customer data for transactions.
- Call Center Data: When customers call our agents, agents guide them through carrier and plan comparisons. Any information exchanged is for facilitating the customer’s selection of a service and their transition to the carrier’s ecosystem for order finalization. We do not require or intentionally collect sensitive personal data (e.g., SSNs, credit card numbers, health information) directly from customers. If such information is inadvertently shared, we follow strict protocols for immediate handling and redaction from recordings.
- Call Recordings: We record all inbound and permissible outbound calls for quality assurance, training, compliance, and dispute resolution purposes. These recordings are retained for five (5) years. For consent details, see our “Call Recording and Monitoring Consent Policy.”
- Limited Outbound Communication Data: Our policy allows for limited outbound calls only to phone numbers that have initiated an inbound call within the last 30 days. This phone number, used for call-back purposes, is the only direct customer contact data we may retain for a limited period.
We do not sell, rent, or lease any customer information to third parties.
Data Security Principles and Measures
3.1. Foundational Security & Access Control
- Least Privilege: unique user IDs and Role-Based Access Controls (RBAC).
- Regular Access Reviews: management review/sign-off at least annually.
- Segregation of Duties: critical functions are separated.
- Device Hardening Program: documented and management-approved.
- Secure Defaults: default passwords changed/disabled before deployment.
- Session Management: sessions expire after 30 minutes or less of inactivity.
3.2. Network and System Security
- Network Diagram & demarcations reviewed at least annually.
- Logical segregation/isolation between scoped systems and data.
- Anti-Virus/Anti-Malware with quarterly signature updates.
- Web Application Firewall (WAF) to protect web apps.
- Intrusion Detection/Prevention (IDS/IPS) in place.
3.3. Vulnerability Management & Patching
- Quarterly vulnerability scanning of scoped systems.
- Risk-based timelines for remediation.
- Annual validation routines on base images.
3.4. Application Security Program
- Documented program reviewed and approved at least annually.
- SAST/DAST at least quarterly and before production deployments.
- SCA at least quarterly and before releases to manage OSS dependencies/licensing.
3.5. Cryptography and Key Management
- Documented Key Management Program reviewed annually.
- Unique customer keys where applicable; no shared keys.
- Controls to prevent unauthorized key access/duplication; rotation/revocation in place.
3.6. Logging, Monitoring & Incident Response
- 24×7×365 SIEM for logging, monitoring, alerting, and notification.
- Baseline of normal activity established to reduce false positives.
- SIEM configured to comply with relevant standards (updates & retention).
- Incident response plans tested at least annually.
- Asset inventory reviewed at least annually.
3.7. Change Management
- Changes are documented, tested, approved, and communicated prior to production deployment.
Data Storage and Retention
- Limited Direct Data Storage: Ezmove Services LLC does not store customer payment information or sensitive personal data from website transactions.
- Call Recording Retention: Call recordings are securely stored for five (5) years.
- Redaction/Masking: Procedures exist to redact or mask sensitive data inadvertently shared, ensuring it is not retained.
- Secure Storage: Retained data (primarily recordings and limited callback numbers) is stored in secure environments with appropriate access controls and encryption.
Data Privacy and Customer Rights (United States Jurisdiction)
- Transparency: We are transparent about our practices via this policy and our Cookie and TCPA policies.
- Purpose Limitation: Data is used only for legitimate business purposes (e.g., call quality, training, limited follow-ups).
- Data Minimization: We collect the minimum data necessary.
- Security: Robust measures protect the data we do hold.
- No Sale of Data: We do not sell customer/caller data.
- Carrier Responsibility: Customers should review carrier privacy policies for how carriers handle personal/payment data once orders move to their systems.
- Information Requests: Individuals may contact us with questions about any information we might hold related to their interactions with Ezmove.
Third-Party Service Providers (Internet Carriers)
Ezmove Services LLC acts as an authorized retailer, referring customers to internet carriers. We acknowledge that these carriers will collect and process customer personal and payment data. We partner with reputable carriers who are responsible for their own data security and privacy compliance (e.g., PCI DSS and relevant privacy laws).
Policy Violations and Reporting
Any suspected or actual violation of this Data Security, Storage, and Privacy Policy, or any information security concern, should be reported immediately to:
- Email: legal@ezmove.services
- Phone: (855) 504-8305
Policy Review and Updates
This Data Security, Storage, and Privacy Policy will be reviewed annually and updated as necessary to reflect changes in our business operations, technological advancements, and applicable federal and state laws and regulations concerning data security, storage, and privacy in the United States.
Contact Information
Fulfillment Center
2709 Pontiac Lake Rd, Waterford, MI 48328
M–F 8:00 AM – 7:00 PM EST
S–S 10:00 AM – 6:00 PM EST
Corporate Office
885 Gold Hill Rd
Fort Mill, SC 29708
Registered Office
351 Lorraine Rd
Fort Mill, SC 29708
(855) 504-8305concierge@ezmove.services
