EZMOVE SERVICES LLC · POLICIES

Payment Card Industry Data Security Standard (PCI DSS) Policy

Ezmove Services LLC maintains a reduced PCI scope (no card handling) while aligning to applicable PCI DSS controls that protect the broader payment ecosystem.

Contact EZMove

Introduction

Ezmove Services LLC (“Ezmove,” “we,” “us,” or “our”) operates the website ezmove.services. We are an authorized retailer for top internet carriers in the United States of America. Our website serves as a platform for customers to compare internet carriers in their zip code. The primary call to action promoted on our website is an inbound phone call to our Ezmove call center agents.

Crucially, Ezmove Services LLC does not directly process, store, or transmit any credit card data. All customer orders, including credit card processing, are handled entirely within the secure systems and ecosystem of the respective internet carriers. This policy outlines our commitment to PCI DSS compliance, acknowledging our role in facilitating customer interaction that leads to payment processing by a third party (the internet carrier).

Effective Date: June 3, 2025 · Annual Certification: January of each year

Scope of this Policy

This PCI DSS Policy applies to all personnel, systems, and environments within Ezmove Services LLC that could potentially impact the security of cardholder data, even if we do not directly handle it. This includes:

  • Call center environment: Agents do not collect credit card information; they guide customers to the carrier’s ecosystem for order processing. We ensure our environment does not inadvertently expose or compromise cardholder data.
  • Website (ezmove.services): While the site itself does not support transactions, we ensure its security does not create vulnerabilities that could indirectly affect the payment process once a customer transitions to a carrier’s system.
  • Any Ezmove systems or processes that interact with or could potentially impact the security of a carrier’s payment processing environment.

PCI DSS Compliance Posture

Ezmove Services LLC maintains an annual PCI DSS certification, obtained every January. Our compliance is based on the understanding that we are a referral-based business where payment processing is entirely offloaded to the internet carrier’s secure environment. Therefore, our PCI DSS scope is significantly reduced but still requires adherence to relevant controls to protect the broader payment ecosystem.

Employee Training and Awareness

  • This PCI DSS Policy and its implications for their roles.
  • The strict prohibition against handling, storing, or transmitting credit card data.
  • Recognizing and reporting potential security incidents or suspicious activities.
  • The importance of directing customers to the carrier’s secure payment ecosystem.

Incident Response Plan

Ezmove Services LLC maintains an incident response plan to address any suspected or actual security incidents that could potentially impact the security of our systems or indirectly affect cardholder data, even if we do not directly handle it. This plan includes procedures for:

  • Detection and analysis of incidents.
  • Containment, eradication, and recovery.
  • Post-incident review.
  • Communication with relevant parties, including our acquiring bank and the payment brands, if deemed necessary based on the nature and scope of the incident.

4.1. Minimizing PCI DSS Scope

  • No Direct Payment Processing: Ezmove agents never ask for, collect, store, or transmit credit card numbers, CVV codes, expiration dates, or any other sensitive authentication data.
  • Referral to Carrier Ecosystem: Customers are directed to the internet carrier’s official and PCI-compliant systems for all transaction processing.
  • No Cardholder Data Storage: Since we do not process payments, we do not store cardholder data (e.g., PAN or sensitive authentication data).

4.2. Adherence to Relevant PCI DSS Requirements

Req 1 — Network Security Controls

  • Firewalls and routers segment internal network from the internet.
  • Restrict inbound/outbound traffic to business-necessary flows only.
  • Document and review firewall configurations.

Req 2 — Secure Configurations

  • No vendor defaults; strong, unique passwords.
  • Secure configurations for components touching call-center/web workflows.

Req 4 — Strong Cryptography in Transit (as applicable)

  • TLS 1.2+ for website and any public-network transmissions, even if not directly involving CHD.

Req 5 — Malware Protection

  • Endpoint AV/AM on call-center workstations/servers; kept current; logs retained.

Req 6 — Secure Systems & Applications

  • Patch management to keep systems/applications up-to-date.
  • Prompt remediation of security vulnerabilities.

Req 7 — Restrict Access by Need-to-Know

  • Strict access controls; grant only necessary privileges.

Req 8 — Identify Users & Authenticate Access

  • Unique IDs for all users; strong authentication for system access.

Req 9 — Restrict Physical Access

  • Controlled access to call center, server rooms, and sensitive areas; protect media/devices.

Req 10 — Log & Monitor Access

  • Comprehensive logging for systems/network resources; regular review for anomalies.

Req 11 — Test Security Systems & Processes

  • Regular vulnerability scans; penetration testing as required; test IR processes.

Req 12 — Policies & Programs

  • Maintain an information security policy (reviewed/updated annually).
  • Formal security awareness program; defined roles and responsibilities.

Managing Third-Party Service Providers (Carriers)

While carriers are responsible for their own PCI DSS compliance, Ezmove Services LLC partners only with reputable internet carriers that demonstrate their commitment to security and compliance. We verify their PCI DSS posture as part of our relationship management.

Annual Certification

Ezmove Services LLC undergoes an annual PCI DSS assessment and obtains certification every January. We maintain our SAQ and AOC to demonstrate compliance.

Jurisdiction

This PCI DSS Policy is drafted in accordance with the Payment Card Industry Data Security Standard (PCI DSS) and is applicable under the jurisdiction of the United States of America. We comply with all relevant federal and state laws that may indirectly impact security practices related to cardholder data.

Contact Information

Fulfillment Center

2709 Pontiac Lake Rd, Waterford, MI 48328

M–F 8:00 AM – 7:00 PM EST

S–S 10:00 AM – 6:00 PM EST

Corporate Office

885 Gold Hill Rd

Fort Mill, SC 29708

Registered Office

351 Lorraine Rd

Fort Mill, SC 29708

(855) 504-8305concierge@ezmove.services
EZMOVE SERVICES

Let’s talk about what you need.

Call us with your location and preferred timing to discuss availability and a personalized quote.

(855) 504-8305