YNF Deals · Legal
Information Security Policy
This policy explains how YNF Deals protects your information — from the moment you load a page to the moment your order leaves our warehouse. The most important thing to know: your payment card details never touch our systems. They go directly to Stripe, a PCI-DSS Level 1 certified processor, and we keep the personal data we do hold to a minimum, behind layered defenses.
1. Our approach
YNF Deals is a small business, and we secure it like one — honestly and deliberately. We do not claim to run the security operation of a global bank. Instead, we follow a principle called defense in depth: several independent layers of protection, so that no single failure exposes your information.
In practice, that means three things. First, we hand the highest-risk data — your payment credentials — to a specialist (Stripe) rather than handling it ourselves. Second, we put specialist infrastructure (Cloudflare) between the public internet and our servers. Third, we collect and keep only the personal data we actually need, for only as long as we need it, on the theory that the safest data is data we never stored.
This document describes what we actually do today. Where a protection has limits, we say so. How we collect and use personal data is covered separately in our Privacy Policy; the cookies we set are listed in our Cookie Policy.
2. Encryption in transit
Every page on ynfdeals.com is served over HTTPS using TLS 1.2 or higher. There are no unencrypted pages: your browsing, your account, your bag, and your checkout are all encrypted between your device and our infrastructure.
We also send the HTTP Strict Transport Security (HSTS) header, which instructs your browser to refuse any unencrypted connection to our site — even if you type the address without "https" or click an old link. This protects you against downgrade attacks on untrusted networks such as public Wi-Fi.
3. Your account
3.1 Passwords
Passwords are stored only as one-way cryptographic hashes — never in plain text. We cannot read your password, our staff cannot read your password, and it cannot be emailed back to you. If it is ever lost, the only path is to reset it.
3.2 One-time email codes
Signing up requires a one-time verification code sent to your email address, which confirms you control that inbox before an account is created. These codes are short-lived and single-use. You can also sign in with Google (OAuth), in which case Google verifies your identity and we never see a password at all.
3.3 Sessions
Your signed-in session is maintained by a first-party session cookie scoped to ynfdeals.com. Sessions expire, and signing out of the customer portal at /my ends your session immediately. If you believe someone else has accessed your account, change your password and contact us at [email protected].
4. Payments
All website payments are processed by Stripe, Inc., which is certified at PCI-DSS Level 1 — the most stringent level of the payment card industry's security standard. When you enter card details at checkout, they are transmitted directly to Stripe. Our servers receive a payment confirmation and reference, never your full card number, and we do not store full card numbers anywhere, ever.
The same applies to the other payment methods we accept — ACH Direct Debit, Klarna, Amazon Pay, Apple Pay, Google Pay, Samsung Pay, Link, and PayPal: the credentials stay with the payment provider, not with us.
Purchases made through TikTok Shop (including our live auctions) are processed entirely by TikTok's own checkout, under TikTok's terms and security practices; we never receive your payment credentials from those purchases either.
5. Infrastructure and access
5.1 Network protection
All traffic to ynfdeals.com passes through Cloudflare, which provides our CDN, a web application firewall (WAF) that filters common attack patterns such as injection attempts, and DDoS protection that absorbs traffic floods before they reach our servers.
5.2 Staff access
Staff access to our systems is role-based and least-privilege: each team member can reach only the data their job requires. A warehouse operator packing your order does not have access to customer financial records; support staff see what they need to resolve your ticket and no more.
5.3 Audit logs
Administrative and security-relevant actions in our systems are logged. Consent records — your acceptance of our terms and policies — are stored in a tamper-evident, hash-chained audit log: each record is cryptographically linked to the one before it, so any attempt to alter or delete a past record breaks the chain and is immediately detectable. This protects both of us: your consent history cannot be quietly rewritten, by anyone.
5.4 Backups
We maintain regular backups of our systems so that a hardware failure, ransomware event, or operational mistake does not result in the loss of your orders, account, or support history.
6. Monitoring and updates
Security is maintenance, not a one-time setup. On an ongoing basis we:
- apply security patches to our platform and operating systems as they are released;
- update software dependencies to pick up fixes for published vulnerabilities;
- review security and access logs for signs of unauthorized activity.
Security and login logs are retained for 12 months, which gives us a meaningful window to investigate suspicious activity while limiting how long access data is kept. The full retention schedule for all data categories is in our Privacy Policy; the security-relevant entries are:
| Record type | Retention period | Why |
|---|---|---|
| Security and login logs | 12 months | Investigating unauthorized access and abuse |
| Packing QA videos | 90 days, unless needed for an active dispute | Quality assurance and fraud evidence |
| Consent records (hash-chained log) | Retained indefinitely | Legal evidence of agreement; tamper-evident by design |
7. Fraud prevention
Fraud raises costs for every honest customer, so we run a small set of targeted controls:
- Device recognition. We set a first-party cookie (ynf_fp) that helps us recognize a returning device. It is used only for fraud prevention and to record proof of legal consent — never for advertising. It is described in full in our Cookie Policy.
- Automated order screening. Orders are screened for fraud signals, partly by automated systems. If an automated decision goes against you — for example, an order is held or cancelled — you can ask for a human review by contacting [email protected], and a person will look at it.
- Packing video evidence. The packing of orders is video-recorded. If a package arrives with an item missing or a dispute arises about what was shipped, we can review exactly what went into your box. These recordings are kept for 90 days unless needed for an active dispute.
We reserve the right to cancel suspicious orders, verify identity, limit quantities, and refuse or block accounts involved in fraud, as set out in our Terms of Service.
8. Your part
The strongest account protection is a partnership. Here is what we ask of you:
- Use a strong, unique password. Do not reuse a password from another site — most account takeovers start with a password leaked somewhere else. A password manager makes this easy.
- Never share your one-time codes. Verification codes sent to your email are for you alone. No one from YNF Deals will ever ask you to read a code back over the phone, by email, or in a chat or DM. Anyone who asks is not us.
- Watch for phishing. We will never ask for your password by email. If a message claiming to be from us asks for your password, a verification code, or full payment details, do not respond — go directly to ynfdeals.com by typing the address, and forward the message to [email protected] so we can warn other customers.
- Sign out on shared devices. If you use a public or shared computer, sign out of /my when you are done.
9. Reporting a vulnerability
If you discover a security vulnerability in ynfdeals.com or our systems, we want to hear from you, and we want the report to be safe for you to make. Email the details to [email protected] with "Security" in the subject line, including what you found, where, and how to reproduce it.
Our commitments to you:
- We will acknowledge your report within 5 business days.
- We will keep you informed of our progress toward a fix where practical.
- We will not pursue legal action against research conducted in good faith.
Good faith, for this purpose, means: you make a reasonable effort to avoid privacy violations, data destruction, and service disruption; you do not access, modify, or download data belonging to others beyond what is minimally necessary to demonstrate the issue; and you give us a reasonable opportunity to fix the problem before disclosing it publicly.
10. If a breach occurs
No security program eliminates risk entirely, and we plan for that honestly. If a security incident affects your personal data, we will investigate, contain it, and notify affected customers and regulators as required by applicable law. Our procedures for handling a data breach — including how and when we notify you — are set out in our Data Breach Response Policy.
11. Contact
Questions about this policy, or a security concern that is not a vulnerability report, can be directed to:
YNF Deals
585 W Merrick Rd Ste 28 C
Valley Stream, NY 11580, United States
Email: [email protected]
Phone: +1 516-884-3338
For order issues, use the Support area of your account at /my/support.