What does this security notice cover?
The notice concerns use of True Blue Auctions’ website, registration and related communications. Different technology providers may control separate accounts and bidding or payment services. Their security information and account-recovery rules should also be reviewed.
The existing policy commits to reasonable and appropriate protection while recognizing the limitations of internet transmission. This page is not a certification that every connected website or system is free of vulnerabilities.
How should account credentials be protected?
Keep login details and bidder credentials confidential, use credentials only for the purpose authorized, and do not permit another person to bid through them without the authority allowed by the auction terms. The source terms assign responsibility for account activity and require prompt reporting of unauthorized use.
Use a unique password for each service, do not reuse a compromised password, and use stronger authentication if the relevant provider offers it. A suggestion to use an available feature is not a statement that every True Blue Auctions system currently provides it.
When should a password be changed?
Change a password promptly when you believe it has been exposed, reused on a compromised service or used without authorization. The older policy’s advice to change passwords periodically is replaced here with practical exposure-based guidance rather than an assertion that arbitrary frequent changes solve account risk.
Contact the actual account provider for its recovery procedure. True Blue Auctions’ website administrator cannot necessarily reset a password held by a separate bidding service.
How do you recognize the correct website or bidding service?
Check the complete web address before entering information and reach an auction’s registration service through the official auction information. A familiar logo or sender name can be copied. Do not assume that an unrelated look-alike domain is genuine.
The old notice identified only the main website address. Because auction services can link to a separate provider, verify the specific event’s destination rather than assuming every legitimate registration must occur on one host.
What does a secure connection establish?
HTTPS helps protect a connection in transit, but it does not prove the identity or honesty of a sender, the safety of every server, the absence of malware or the validity of an invoice. Verify a request and its destination as well as the connection.
Do not send passwords, complete card details or confidential identity documents in a normal email reply or chat message simply because the request looks official.
How should phishing and unexpected requests be handled?
The existing notice warns about official-looking emails directing recipients to imitation sites or seeking account, identity, bank or card information. Be cautious with unexpected attachments, password requests and payment instructions, and independently contact True Blue Auctions when uncertain.
Ordinary auction inquiries can legitimately request some contact or property information. The source’s broad “never requests personal information by email” statement therefore requires precise operational confirmation rather than repetition as an absolute guarantee.
How can you check a questionable invoice or payment instruction?
The existing policy asks anyone who doubts an invoice bearing the True Blue Auctions name or another payment request to contact Client Services for confirmation. Use contact details you obtained independently, not just the reply address or number in the questionable message.
Verify a proposed change in payment instructions before acting. Neither a familiar thread nor an urgent deadline proves a new bank destination is correct. An inquiry about suspected fraud does not itself resolve contractual deadlines; promptly contact the relevant auction staff.
What should you do about lost or compromised bidder credentials?
Report lost, misplaced, stolen or misused bidder credentials to auction staff immediately and identify the affected auction and account without sending the password. The inspected event terms allocate responsibility for bids made before notice and contain additional bidder-number provisions.
Read the actual event agreement. The Security page does not silently cancel accepted bids, change contractual liability or determine who made a disputed bid.
What should users do on shared devices?
End the account session when finished and use the provider’s logout function. Avoid leaving credentials or transaction documents accessible on shared equipment. Use appropriate controls on the device and review whether the browser has saved account information.
The precise location of a logout control depends on the service; the old instruction that it is always at the top right of the main website is not assumed to match every current provider.
What access, maintenance and technical safeguards are actually in place?
PUBLICATION HOLD — owner/counsel confirmation required. The legacy notice asserts encrypted login/password/credit information, a secure database with limited staff access, regular professional testing and patches applied immediately on release. The privacy policy also lists firewalls, scanning, backup/recovery planning, staff training and audits. These statements must be checked against current host and business evidence before any is represented as an operating control.
The commitment to reasonable protection is different from claiming a particular certification, implementation or test result. Do not infer that rebuilding pages cures a compromised hosting account.
How are payment security and third-party responsibilities described?
Payment instructions and the relevant provider’s own information should explain the channel through which payment data is supplied. Verify the actual processor and record custody instead of treating a payment logo, active plugin or encrypted web connection as proof of certification.
PUBLICATION HOLD — owner/counsel confirmation required. Confirm what payment data True Blue Auctions and each provider receive and retain, what access is available, and which specific security representations are supported. No PCI, SOC 2, ISO, “bank-grade,” “military-grade” or 100%-secure claim is made by this draft.
How should uploaded documents and private information be handled?
Before sending a document or photograph, consider whether it contains unnecessary account details, identification data, third-party private information or embedded location metadata. Ask which secure submission method is appropriate when sensitive information is needed.
Material supplied for public auction marketing is different from a private identity or payment record. The actual transaction and privacy terms determine its intended use; this page does not invent a new permission to publish private information.
How are security incidents and notifications addressed?
The original privacy policy states that, where True Blue Auctions believes personal data has been compromised, it will notify the affected user. That commitment is preserved for review alongside applicable breach-notification requirements. An incident assessment must distinguish website defacement or injected links from evidence concerning particular personal information.
PUBLICATION HOLD — owner/counsel confirmation required. Confirm incident escalation, preservation, assessment, contact and notification procedures with the host and counsel. Do not silently reduce the existing notification promise to a narrower threshold, or claim an incident has been resolved or a notice sent when it has not.
How can you report a vulnerability or suspicious activity?
Email info@TrueBlueAuctions.com or call 844-243-2255. Provide the affected URL, a description and the time observed without including passwords, full card data, other customers’ documents or exploit payloads in ordinary email. Explain that the matter concerns security.
This contact channel is not authorization to access another account, bypass controls, disrupt an auction, extract records or conduct intrusive testing. No reward program, testing safe harbor or fixed response time is promised.
What security limitations and related policies should you read?
Internet and computer-network security cannot be guaranteed. The existing agreement and privacy notice contain limitations concerning technical errors and third-party acts, but their enforceability and any mandatory rights require review. No statement here eliminates obligations that cannot lawfully be waived.
Read the [tba_legal_link slug="privacy-policy"]Privacy Policy[/tba_legal_link], [tba_legal_link slug="cookie-policy"]Cookie Policy[/tba_legal_link] and [tba_legal_link slug="terms-and-conditions"]Terms & Conditions[/tba_legal_link]. The Last Updated date indicates the notice revision; it is not a date of penetration testing, certification or host security clearance.
