1. Introduction

Everyone Group Buy Inc., operating the website located at www.everyonebuy.hair and developed by the EveryoneBuy team, is committed to protecting the privacy and security of every visitor and client who interacts with our digital platforms. This Privacy Policy explains in clear terms what personal information we gather, why we gather it, how we use it, and the measures we take to safeguard it. By accessing or using our website or services, you acknowledge that you have read and understood the practices described in this document.

Our company, Everyone Group Buy Inc., is a Canadian corporation with its principal place of business at 168 Heintzman Crescent, Vaughan - L6A 4T8, Canada (CA). We operate within the Computer Systems Design and Related Services industry, providing integrated technology consulting, custom software development, cloud infrastructure architecture, and related professional technical services to businesses across North America and internationally.

The EveryoneBuy development team has built this website with privacy-by-design principles in mind. We collect only the minimum amount of data necessary to operate our business effectively and to provide the services you have requested. We do not sell personal data to third parties, and we do not engage in automated profiling that produces legal or similarly significant effects concerning individuals. This policy applies to all information collected through our website, email communications, telephone inquiries, and any other interaction channel where this policy is referenced.

If you disagree with any provision of this Privacy Policy, your remedy is to discontinue use of our website and services. Continued use following any updates to this policy constitutes acceptance of the revised terms. We encourage you to review this page periodically to stay informed about our data handling practices.

2. Information We Collect

We collect several categories of information depending on the nature of your interaction with Everyone Group Buy Inc. The types of data we may gather include but are not limited to the following:

Personal Identification Information: When you fill out a contact form, request a consultation, subscribe to our newsletter, or engage with us through any communication channel, we may collect your full name, email address, telephone number, company name, job title, and physical mailing address. This information is voluntarily provided by you and is used solely for the purpose of responding to your inquiry or delivering the service you have requested.

Technical and Usage Data: Our servers automatically log certain technical information when you visit our website. This includes your Internet Protocol (IP) address, browser type and version, operating system, referring URL, pages viewed, time spent on each page, the date and time of your visit, and other diagnostic data. This information helps us understand how visitors interact with our site and enables us to improve performance and user experience.

Communication Records: We retain copies of email correspondence, contact form submissions, and, where applicable and disclosed, records of telephone conversations. These records help us maintain continuity in client relationships and ensure that we can reference past discussions when providing ongoing services.

Business Relationship Data: For clients with whom we have an active or past service agreement, we maintain records of project specifications, contract details, billing information, payment history, and service delivery documentation. This category of data is governed by both this Privacy Policy and the terms of the specific service agreement between Everyone Group Buy Inc. and the client.

We do not intentionally collect sensitive personal data such as government-issued identification numbers, financial account credentials, health information, biometric data, or information about criminal convictions unless such collection is strictly necessary for the performance of a contract and with your explicit consent.

3. How We Collect Information

Everyone Group Buy Inc. gathers information through multiple lawful channels, each clearly disclosed to you at the point of collection. The primary collection methods we employ are described below:

Direct Collection: This occurs when you voluntarily provide information to us. Examples include completing the contact form on our website, sending an email to serve@everyonebuy.hair, calling our office at +14302394600, registering for a webinar or event, downloading a resource such as a whitepaper or case study, or submitting a request for proposal. In each of these scenarios, you are in control of what information you share, and the purpose of collection is made clear at the time you provide the data.

Automated Collection: As you navigate through our website, certain technical information is collected automatically through cookies, server logs, and similar passive technologies. We use both first-party cookies (set by our domain) and, in limited circumstances, third-party cookies (set by trusted service providers such as analytics platforms). Detailed information about our cookie practices is provided in Section 10 of this policy.

Third-Party Sources: In certain business development contexts, we may receive information about you from third-party sources such as publicly available business directories, professional networking platforms, or data enrichment services used for lead generation. When we receive information from such sources, we take reasonable steps to verify that the data was lawfully collected and that the source has provided appropriate notice to the individuals concerned.

We do not use hidden tracking mechanisms, browser fingerprinting techniques that operate without disclosure, or any other covert data collection method. Our commitment to transparency means that you will always know when and why we are collecting your information.

4. Use of Collected Information

The information we collect serves specific, legitimate business purposes. Everyone Group Buy Inc. uses personal data for the following purposes and no others without first obtaining your consent:

Service Delivery and Client Management: We use your contact details and project-related information to provide the consulting, development, and integration services you have engaged us to perform. This includes communicating project milestones, delivering technical documentation, coordinating with your internal teams, and managing billing and invoicing processes. Without this information, we would be unable to fulfill our contractual obligations to you.

Communication and Support: We use your email address and telephone number to respond to inquiries, provide technical support, send service-related announcements, and share information about updates to our services. These communications are transactional or relationship-based rather than promotional, and you cannot opt out of them while maintaining an active service relationship with us.

Website Improvement and Analytics: Aggregated usage data helps us understand how visitors navigate our website, which pages are most frequently accessed, and where users encounter difficulties. This analysis informs our ongoing efforts to improve site structure, content relevance, and overall user experience. All analytics data is processed in aggregate form and does not identify individual users.

Legal and Regulatory Compliance: We may process your personal information as necessary to comply with applicable laws, regulations, legal processes, or governmental requests. This includes maintaining records required by tax authorities, responding to lawful subpoenas or court orders, and enforcing our contractual rights.

Business Operations: We use aggregated and de-identified data for internal business planning, financial forecasting, capacity management, and strategic decision-making. When data is used for these purposes, it is stripped of all personally identifiable attributes so that it cannot be linked back to any individual.

5. Sharing of Information

Everyone Group Buy Inc. maintains a strict policy regarding the disclosure of personal information. We do not trade, rent, or sell your personal data to any third party for their own marketing or commercial purposes. The limited circumstances under which we may share your information are described below:

Service Providers and Subcontractors: We engage carefully vetted third-party companies and independent contractors to perform certain business functions on our behalf. These include cloud hosting providers, email delivery services, payment processors, customer relationship management platforms, and analytics providers. Each service provider is bound by a written data processing agreement that restricts their use of your information to the specific services they are engaged to perform and requires them to maintain security standards at least as protective as those we apply internally.

Professional Advisors: We may share information with our legal counsel, accountants, auditors, and insurance providers as necessary for the operation of our business and the protection of our legal interests. These professionals are bound by ethical and legal duties of confidentiality that extend to any information we share with them.

Business Transfers: In the event of a merger, acquisition, sale of assets, or other corporate restructuring involving Everyone Group Buy Inc., personal information held by us may be among the assets transferred to the successor entity. In such an event, we will make reasonable efforts to ensure that the recipient agrees to honor the terms of this Privacy Policy.

Legal Obligations: We may disclose personal information when we believe in good faith that disclosure is necessary to comply with a legal obligation, protect and defend our rights or property, prevent or investigate possible wrongdoing in connection with our services, protect the personal safety of users or the public, or protect against legal liability.

We require all third parties with whom we share data to respect the security of your personal information and to treat it in accordance with applicable data protection law. We do not permit our service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes in accordance with our instructions.

6. Data Storage and Security

Everyone Group Buy Inc. takes the security of your personal information seriously and has implemented a comprehensive set of technical, administrative, and physical safeguards designed to protect your data against unauthorized access, alteration, disclosure, or destruction.

Technical Safeguards: We employ industry-standard encryption protocols (TLS 1.3) for all data transmitted between your browser and our servers. Data at rest is encrypted using AES-256 encryption. Our network infrastructure is protected by multiple layers of firewalls, intrusion detection and prevention systems, and continuous security monitoring. Access to production systems is strictly controlled through multi-factor authentication, role-based access controls, and comprehensive audit logging.

Administrative Safeguards: All employees and contractors of Everyone Group Buy Inc. are required to sign confidentiality agreements as a condition of their engagement. Access to personal data is granted on a need-to-know basis only, and our staff receive regular training on data protection best practices and their obligations under applicable privacy laws. We conduct periodic reviews of our data handling practices and security measures to identify and remediate potential vulnerabilities.

Physical Safeguards: Our servers are housed in SOC 2 Type II certified data center facilities with 24/7 on-site security personnel, biometric access controls, video surveillance, and redundant power and environmental systems. Physical access to server hardware is restricted to authorized data center personnel only.

While we implement robust security measures, no method of electronic storage or transmission over the Internet is absolutely secure. We cannot guarantee that your information will never be accessed, disclosed, altered, or destroyed as a result of a breach of our security measures. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable legal requirements as described in Section 15 of this policy.

7. Data Retention Policies

We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are determined based on the following criteria:

Active Client Relationships: For clients with whom we maintain an ongoing business relationship, we retain all relevant personal and project data for the duration of the relationship. Following project completion, core client records including contact information, contract documents, and financial records are retained for a period of seven years to comply with Canadian tax and commercial record-keeping requirements under the Income Tax Act and applicable provincial legislation.

Inquiry and Prospect Data: Personal information collected from individuals who have inquired about our services but have not entered into a client relationship is retained for a maximum of twenty-four months from the date of last contact, after which it is securely deleted or anonymized unless the individual has requested earlier deletion.

Website Analytics Data: Server logs and analytics data are retained in identifiable form for a maximum of twenty-six months. After this period, the data is either deleted or aggregated to a level where individual identification is no longer possible.

Legal Hold Exceptions: In certain circumstances, we may be required to retain information beyond our standard retention periods due to pending or anticipated litigation, regulatory investigation, or audit requirements. When a legal hold is in effect, we preserve all relevant data until the hold is formally lifted by our legal counsel.

Upon expiration of the applicable retention period, we either securely delete the data using industry-standard data destruction methods or irreversibly anonymize it so that it can no longer be associated with any identifiable individual.

8. Your Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding the personal information we hold about you. Everyone Group Buy Inc. is committed to honoring these rights to the fullest extent required by applicable law. The rights described in this section may be subject to certain limitations and exceptions as provided by law.

Right of Access: You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data along with information about how it is being used. We will provide this information in a commonly used electronic format within the timeframe prescribed by applicable law, typically thirty calendar days from the date of verified request.

Right to Rectification: If you believe that the personal information we hold about you is inaccurate or incomplete, you have the right to request that it be corrected. We will act on such requests promptly and will notify any third parties to whom we have disclosed the relevant information of the correction, where feasible.

Right to Erasure: In certain circumstances, you may request that we delete your personal information. This right is not absolute and may be limited where we have a compelling legitimate interest or legal obligation to retain the data. Common examples where erasure may be denied include ongoing contractual relationships, tax record-keeping requirements, and the establishment or defense of legal claims.

Right to Restrict Processing: You may request that we limit the processing of your personal information in specific situations, such as when you contest the accuracy of the data or object to our processing activities. During the period that processing is restricted, we will store your data but will not otherwise process it without your consent or for legal claims.

Right to Data Portability: Where processing is based on consent or contractual necessity and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another controller where technically feasible.

Right to Object: You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis. Upon receiving a valid objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To exercise any of the rights described above, please contact us using the details provided in Section 18. We may need to verify your identity before processing your request, which may require you to provide additional information.

9. Privacy for Children

Our website and services are not directed to individuals under the age of eighteen, and we do not knowingly collect personal information from children. If you are a parent or guardian and you become aware that a child under the age of eighteen has provided us with personal information without your consent, please contact us immediately using the information provided in the Contact Information section below.

Upon receiving notice that a child under eighteen has submitted personal data to us, we will take prompt steps to remove such information from our records and terminate any associated accounts. We will also take reasonable measures to prevent the child from resubmitting their information.

We do not have actual knowledge that we sell or share the personal information of consumers under sixteen years of age. Our business model does not involve monetizing user data, and we have no financial incentive to collect or retain information about minors. If our practices change in this regard, we will update this policy and implement appropriate age verification mechanisms before making any such changes effective.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors originate. This section explains what cookies are, which types we use, and how you can control them.

A cookie is a small text file that a website places on your device when you visit. Cookies serve various functions: they can remember your preferences, keep you logged in, and help website operators understand how visitors interact with their pages. Cookies may be session-based (deleted when you close your browser) or persistent (remaining on your device for a set period or until manually deleted).

Essential Cookies: These cookies are necessary for the basic functionality of our website. They enable core features such as page navigation, secure form submission, and access to protected areas. The website cannot function properly without these cookies, and they do not require your consent under most privacy regulations.

Analytics Cookies: We use analytics cookies to collect information about how visitors use our website, including which pages are most popular, how long visitors spend on each page, and what links they click. We use this aggregated data to improve site structure and content. Our analytics platform is configured to anonymize IP addresses before storage, and we do not combine analytics data with personally identifiable information from other sources.

Managing Your Cookie Preferences: Most web browsers allow you to control cookies through their settings. You can typically configure your browser to block all cookies, accept only first-party cookies, or delete cookies when you close your browser. Please note that blocking essential cookies may impair the functionality of certain parts of our website. For detailed instructions on managing cookies in your specific browser, consult the help documentation provided by your browser vendor.

11. Third-Party Services

Our website may include links to third-party websites, plug-ins, services, or applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. When you leave our website, we encourage you to read the privacy policy of every website you visit.

We may use third-party services for specific business functions, including but not limited to website hosting, email delivery, analytics, customer relationship management, and payment processing. Each of these service providers has been evaluated for their data protection practices, and we have contractual agreements in place that govern their handling of any personal data we share with them. A list of the categories of third-party service providers we currently engage is available upon request by contacting our privacy team.

We do not use advertising networks, demand-side platforms, or data brokers that track users across websites for behavioral advertising purposes. Our website does not serve third-party advertisements, and we do not participate in programmatic advertising exchanges. If this practice changes in the future, we will update this policy and provide appropriate notice mechanisms before implementing any advertising-related tracking.

12. International Data Transfers

Everyone Group Buy Inc. is headquartered in Canada, and our primary data storage and processing infrastructure is located in Canadian data centers. However, certain service providers we engage may process data in facilities located in the United States or other jurisdictions. When personal information is transferred across international borders, we take appropriate safeguards to ensure that the data receives an equivalent level of protection as it would in Canada.

For transfers to service providers in jurisdictions that have not been recognized as providing an adequate level of data protection by Canadian authorities, we rely on contractual mechanisms such as Standard Contractual Clauses, data processing agreements with enhanced security obligations, and supplementary technical measures including end-to-end encryption where feasible. We conduct transfer impact assessments to evaluate the legal framework of the destination country and implement additional safeguards where the assessment identifies residual risks.

By using our website and providing your personal information to us, you acknowledge that your data may be transferred to and processed in countries outside your country of residence. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

13. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or business operations. When we make material changes, we will update the Last Updated date at the top of this page and, where required by law, provide additional notice such as a prominent banner on our website or a direct email notification to affected individuals.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after any modification to this policy constitutes your acceptance of the revised terms. If you disagree with the updated policy, you must discontinue use of our website and services and may request deletion of your personal data as described in Section 8.

We maintain a version history of this Privacy Policy for our internal records. Upon request, we can provide information about previous versions of this policy and the dates on which material changes were made, subject to reasonable limitations on the historical period covered.

14. Do Not Track Signals

Do Not Track (DNT) is a privacy preference that users can set in certain web browsers. When enabled, the browser sends a signal to websites requesting that the user not be tracked. Currently, there is no universally accepted standard for how websites should respond to DNT signals, and regulatory guidance on this topic continues to evolve.

At Everyone Group Buy Inc., we respect your privacy regardless of technical signal protocols. As described throughout this policy, we do not engage in cross-site tracking, behavioral advertising, or the sale of personal data to third parties. Our data collection practices are already consistent with the objectives that DNT signals seek to promote. Because of the lack of a standardized interpretation of DNT signals, we do not currently alter our data collection and use practices in response to DNT browser settings. We will continue to monitor developments in DNT technology and standards and will update our practices as appropriate when a clear consensus emerges.

15. Data Breach Notification

In the unfortunate event of a data breach involving personal information under our control, Everyone Group Buy Inc. will follow a documented incident response procedure designed to contain the breach, assess the scope and impact, and notify affected individuals and regulatory authorities as required by applicable law.

Under Canadian federal privacy legislation, specifically the Personal Information Protection and Electronic Documents Act (PIPEDA), organizations are required to report breaches of security safeguards involving personal information that pose a real risk of significant harm to the affected individuals. We will notify the Office of the Privacy Commissioner of Canada and any affected individuals as soon as feasible after determining that a breach has occurred and meets the statutory reporting threshold.

Our notification to affected individuals will include a description of the breach, the types of personal information involved, the steps we have taken to contain and remediate the breach, recommendations for protective measures the individual can take, and contact information for our privacy team. We maintain cyber liability insurance coverage and have engaged external incident response consultants who can be activated immediately in the event of a significant breach.

16. State-Specific Disclosures

While Everyone Group Buy Inc. is a Canadian company, we recognize that certain regulations in the United States and other jurisdictions may apply to our processing of personal data from residents of those jurisdictions. This section provides supplemental disclosures required by specific state privacy laws.

California Residents: Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have rights including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. Everyone Group Buy Inc. does not sell or share personal information as those terms are defined under the CCPA. We do not use or disclose sensitive personal information for purposes other than those specified in the CCPA regulations.

United Kingdom and European Economic Area Residents: If you are located in the UK or EEA, you may have additional rights under the UK GDPR and EU GDPR, respectively, including the rights described in Section 8 of this policy. Our legal basis for processing your personal data will depend on the specific context, and may include the performance of a contract, compliance with a legal obligation, our legitimate business interests (provided these do not override your fundamental rights and freedoms), or your explicit consent.

Residents of other jurisdictions with comprehensive privacy legislation may also have specific rights. Please contact us using the details in Section 18, and we will address your inquiry in accordance with the applicable legal framework.

17. Governing Law and Jurisdiction

This Privacy Policy and all matters relating to the collection, use, and disclosure of personal information by Everyone Group Buy Inc. shall be governed by and construed in accordance with the laws of the Province of Ontario, Canada, and the federal laws of Canada applicable therein, without giving effect to any choice of law or conflict of law principles.

Any dispute arising out of or relating to this Privacy Policy or our data handling practices shall be subject to the exclusive jurisdiction of the courts of the Province of Ontario. You agree to submit to the personal jurisdiction of such courts for the purpose of resolving any such dispute.

If you are a resident of a jurisdiction with data protection laws that provide greater protections than those described in this policy, we will comply with those laws to the extent they apply to our processing of your personal data. Nothing in this policy is intended to limit any rights you may have that cannot be waived by contract under applicable law.

18. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, we encourage you to contact us through any of the following channels. Our privacy team is dedicated to responding promptly and thoroughly to all inquiries.

Email: serve@everyonebuy.hair

Phone: +1 (430) 239-4600

Postal Address:
Everyone Group Buy Inc.
168 Heintzman Crescent
Vaughan, ON L6A 4T8
Canada (CA)

Website: https://www.everyonebuy.hair

We aim to acknowledge all privacy-related inquiries within five business days and to provide a substantive response within thirty calendar days. If additional time is needed to address your request, we will inform you of the extension and the reasons for the delay. If you are not satisfied with our response, you may have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Ontario, or the data protection authority in your jurisdiction of residence.