Eco-Friendly Solutions for Every Bite!

Security & Responsible Disclosure

Last updated: 9 July 2026

1. Our Commitment to Security

At Easy Supply LTD (trading as Easy Supply), the security of your personal data and payment information is a top priority. We take a proactive approach to protecting our website, systems and customers, and we continually review our safeguards in line with recognised industry standards and UK data protection law.

This page explains how we protect your information, how you can help keep your account secure, and how security researchers can report a vulnerability to us responsibly.

2. How We Protect Your Data & Payments

We use a layered set of technical and organisational measures to keep your information safe, including:

  • Encryption in transit — all traffic to and from our website is encrypted using TLS/HTTPS, so data exchanged between your browser and our servers is protected.
  • Password protection — account passwords are stored using strong one-way hashing; we never store them in plain text.
  • Secure payment processing — card payments are handled by PCI-DSS compliant payment providers such as WorldPay. We do not store your full card details on our own servers.
  • Network & application protection — we use Cloudflare and other safeguards to help mitigate malicious traffic, and apply security updates to our systems.
  • Access controls — access to personal data is restricted to authorised staff on a need-to-know basis.

For full details of how we collect, use and protect personal data, please see our Privacy Policy.

3. Your Role in Staying Secure

Security is a shared responsibility. You can help protect your account by:

  • Choosing a strong, unique password and not reusing it on other websites.
  • Keeping your login details confidential and never sharing them with anyone.
  • Being alert to phishing — fraudulent emails, texts or calls that try to trick you into revealing personal or payment information.
  • Keeping your device, browser and antivirus software up to date.

We will never ask you for your full card number, CVV or account password by email or over the phone. If you receive a message claiming to be from us and asking for these details, do not respond, and please report it to us at [email protected].

4. Reporting a Vulnerability (Responsible Disclosure)

We welcome reports from security researchers and members of the public who identify potential vulnerabilities in our website or systems. If you believe you have found a security issue, please report it responsibly to [email protected] with the subject line "Security Disclosure".

To help us investigate quickly, please include:

  • A clear description of the vulnerability and the potential impact.
  • The steps required to reproduce it (URLs, parameters, screenshots or a proof of concept).
  • Any tools or techniques used, and your contact details so we can follow up.

Please give us a reasonable opportunity to investigate and remediate the issue before disclosing it publicly, and do not access, modify or delete any data that does not belong to you.

5. Our Commitment to Researchers (Safe Harbour)

If you make a good-faith effort to comply with this policy during your research, we commit to:

  • Acknowledging your report promptly, typically within five working days.
  • Working with you to understand and resolve the issue in a timely manner.
  • Not pursuing legal action against researchers who act in good faith and within the scope of this policy (safe harbour).

We consider activities conducted consistently with this policy to be authorised conduct, and we will not treat good-faith security research as a breach of our terms.

6. What is Out of Scope

To protect our customers and services, the following activities are not permitted and fall outside this policy:

  • Any testing that harms, degrades or disrupts our data, systems or service, including denial-of-service (DoS/DDoS) attacks.
  • Accessing, downloading, modifying or deleting data that does not belong to you.
  • Social engineering of our staff, customers or contractors (for example, phishing or pretexting).
  • Physical attacks against our premises or equipment.
  • Automated scanning that generates excessive traffic.

Findings from third-party services we rely on may need to be reported to those providers directly.

7. Recognition

We are grateful to the security community for helping keep our customers safe. While we do not currently operate a paid bug bounty programme, we are happy to acknowledge researchers who responsibly disclose valid, previously unreported vulnerabilities, where they wish to be credited.

8. Changes to This Policy

We may update this Security & Responsible Disclosure policy from time to time to reflect changes to our systems, practices or legal obligations. The date at the top of this page shows when it was last revised.

9. Contact

For any security-related questions or to report a vulnerability, please contact us:

  • Email: [email protected]
  • Telephone: +44 7956 786011
  • Address: Registered Office: Flat 200 Edinburgh House, Edinburgh Gate, Harlow, CM20 2TJ, United Kingdom — Trading/Warehouse: Unit 6 Marshall Paving, Cattlegate Road, Enfield, EN2 9ED, United Kingdom
WhatsApp

Easy Supply

Easy Supply AI Assistant

Online

Assistant responses may be inaccurate.