Privacy Policy & Security Measures
The Winning Team, Inc. is committed to protecting the privacy and security of our clients and partners
Our Security Commitments
Multi-Factor Authentication
Encrypted Data Storage
Access Monitoring
Regular Security Audits
Employee Training
Breach Notification
Privacy Policy
Section 1 of 5
Data Collection
We only collect personal data (such as names, shipping addresses, and contact information) necessary to provide our services.
Use of Data
Personal data is used strictly for business operations, order fulfillment, and communication. We do not sell, rent, or lease client lists to third parties.
California Consumer Privacy Act (CCPA)
As a California corporation, we comply with the CCPA. Residents have the right to request access to their data, request deletion, and opt-out of data sharing.
Data Erasure
We maintain the technical capability to permanently erase or destroy personal data upon verified request, subject to legal record-keeping requirements.
Information Security Management Program (ISMP)
Section 2 of 5
Access Control
We enforce a strict "least-privilege" access model. Only employees who require data to perform their job duties have access.
Authentication
All user accounts are secured with a strong password policy and Multi-Factor Authentication (MFA/2FA) where available.
Internal Audits
We conduct annual internal security audits to review our systems, access logs, and physical security measures at our Valencia facility.
Data Security & Technical Measures
Section 3 of 5
Encryption
Data is encrypted at rest and in transit using industry-standard protocols.
Unauthorized Access
We utilize firewalls, secure VPNs, and managed endpoint security to ensure systems housing data are protected from unauthorized personnel.
Employee Responsibility
All personnel are trained on their responsibility to protect client data and must sign confidentiality agreements as a condition of employment.
Business Continuity & Disaster Recovery
Section 4 of 5
Cloud Redundancy
Critical business data is backed up to secure, geographically redundant cloud environments.
Recovery
In the event our Valencia office is inaccessible, our team is equipped to resume operations remotely within 24 hours, ensuring no loss of data or service.
Data Breach Response Plan
Section 5 of 5
Identification
Our team will immediately investigate to determine the source and scope of the incident.
Containment
We will take immediate steps to secure systems and prevent further unauthorized access.
Notification
We will notify affected clients and partners within 48 hours of a confirmed breach involving their data.
Reporting
We will provide a full report on the incident and the measures taken to prevent future occurrences.
Committed to Your Security
We understand that your data is critical to your business. That's why we've implemented comprehensive security measures and maintain strict compliance with privacy regulations including the California Consumer Privacy Act (CCPA). Your trust is our top priority.
Last Updated: January 2026 • Questions? Contact us at 661.295.1428