About alletronic
Privacy & Security - How we keep you safe
1. Your information is protected.
Ensuring your privacy and protecting your information is our highest priority. Bottom line: we do not and will not sell, rent or lease your personal information or purchasing history to any Third Parties for marketing purposes for any reason.
2. allEtronic provides bank-level data security for the information we store.
- allEtronic uses 128-bit SSL encryption to ensure that all communications between your browser and our Web site are secure.
- We store information and purchasing history in a secure facility protected by 24/7 security guards and biometric scanners.
- All allEtronic employees pass financial and criminal background checks as a condition of employment.
- allEtronic.com has received the Trustwave security seal and is tested daily by McAfee
- allEtronic's privacy protection standards are certified by TRUSTe.
3. allEtronic does not know your credit card numbers.
When you link your credit or debit cards to your allEtronic account, we only request and store the first 6 and last 4 digits of your card numbers, the expiration data, and your last name. Since we're missing 6 digits of your card number(s), it is impossible for your card to be charged by us, or anyone else. We only ask you to link your credit and debit cards so we can identify your allEtronic account. Using cards you already carry in your wallet, you're able to receive digital receipts, conduct paperless returns, link and redeem coupons through your account, and participate in loyalty programs without another wallet/purse card or key chain card.
By tracking your personal shopping habits and the products you purchase, our complex algorithms are able to predict the types of products and services that you are most likely to buy. In other words, the more we know about how and where you shop, the more discounts we can offer. And the more discounts you take advantage of, the more money you're saving.
4. Our systems are subject to Trustwave vulnerability scans.
allEtronic's systems are scanned for vulnerabilities once a month by a company called Trustwave. Trustwave is the leading provider of on-demand data security and payment card industry compliance management solutions to businesses and organizations throughout the world. They have helped more than 30,000 organizations, ranging from Fortune 500 businesses and large financial institutions to small and medium-sized retailers manage compliance and secure their network infrastructure, data communications and critical information assets.
Trustwave is one of the few companies throughout the world certified by credit card brands (Visa®, MasterCard®, American Express® and Discover®) to perform a full range of solutions from compliance validation to incident response to point-of-sale security:
- Qualified Security Assessor (QSA)
- Authorized Scanning Vendor (ASV)
- Qualified Incident Response Assessor (QIRA)
- Qualified Payment Application Security Company (QPASC)
Trustwave has relationships with organizations and associations that affect how business is transacted. Their management team serves as board and committee members for various associations, including the Electronic Transactions Association (ETA), Merchant Risk Council (MRC), International Association of Financial Crimes Investigators (IAFCI), InfraGard and Open Web Application Security Project (OWASP).
Trustwave specializes in helping organizations discover and understand their security vulnerabilities before hackers can exploit them. Trustwave scans are designed to detect more than 5,000 known network, operating system and application vulnerabilities - including the SANS Top 20 -- and are executed without any impact on our systems.
Bottom Line: If our systems pass their tests, and they do every single month, your partial payment card information is protected.
5. Our systems are PCI Compliant.
The vulnerability scans performed by Trustwave determine the continued certification and compliancy of our system. Our systems consistently pass their vulnerability scans every single month.
6. PCI Compliance wasn't required
When we originally hired Trustwave as our consultants while developing allEtronic, they said we didn't need monthly vulnerability scans. They said this because we only request and store the first 6 and last 4 digits of a card number, the expiration date, and the last name of the cardholder. We did it anyway because we knew it would be important to you and to the retailers that offer our service. We did it to make sure you feel comfortable about providing partial credit card information.
To learn more about the Card Association Security Standards & Programs
- Visa Payment Application Best Practices
- Visa Cardholder Information Security Program