1. Scope and responsible company
This Policy applies to the Credit Polaris website, free credit tools, accounts, customer portal, communications, and paid program.
It does not govern a third party's independent service. A third party's own privacy notice may also apply when you interact with that service.
2. Information we collect
- Identity and contact data, such as name, email, phone number, mailing address, and account identifiers.
- Credit information, including reports, scores, bureau metadata, tradelines, inquiries, public-record information, dispute selections, and uploaded files.
- Identity-verification data when reasonably required, which may include date of birth, partial or full Social Security number, government ID, or proof of address.
- Program records, including agreements, consent and disclosure versions, dispute letters, mail status, results, cancellation records, refund requests, and customer-support communications.
- Payment metadata, such as an opaque payment-method reference, card brand, last four digits, billing events, invoices, and refunds. Hosted payment fields keep full card numbers from touching our servers or database.
- Device, network, and usage data, such as IP address, browser/device details, timestamps, pages and features used, security events, cookies, and similar technologies.
- Concierge and automation data, including chat content, uploaded context, actions requested, feedback, and the operational records needed to review or fulfill those interactions.
3. Sources of information
Information may come directly from you, from an authorized credit-report connection or upload, from activity in the services, from staff acting on your requests, and from contracted providers that support payment, mail, identity, communications, hosting, security, or analytics.
4. Credit-report access and authorization
Before a report is pulled or analyzed, we request explicit authorization identifying the person, purpose, consent text, version, and time. Uploading a report authorizes processing for the purpose described at upload; it does not by itself enroll you in paid service or authorize us to mail disputes.
We do not access a consumer report without a permissible purpose.
5. How we use information
- Provide, personalize, and support education, analysis, account, portal, and paid-program services you request.
- Authenticate users, verify authorization, prevent fraud and abuse, and protect systems and consumers.
- Prepare, review, send, and track authorized dispute correspondence for paid customers.
- Process billing, cancellations, refund requests, receipts, and account history.
- Communicate service messages and, where lawfully permitted, marketing messages with available choices.
- Operate, debug, measure, and improve the services using data minimized for the task.
- Comply with law, enforce agreements, respond to valid process, and establish or defend legal claims.
6. Payments
When payment information is provided, it is collected through hosted payment fields and tokenization so Credit Polaris does not receive or store full card numbers. We retain limited display metadata and transaction records needed for billing, refunds, disputes, accounting, and legal obligations.
A payment processor's own privacy notice may apply. Whether and when a vaulted payment method can be deleted depends on the processor, active obligations, fraud controls, and applicable retention duties.
7. When information is disclosed
We disclose information only as reasonably needed for the purposes described here, including to contracted providers; bureaus, furnishers, and mail recipients involved in authorized dispute work; professional advisers; authorities responding to valid legal process; and parties to a legitimate business transaction subject to appropriate safeguards.
Provider categories may include credit data, identity verification, payment, physical mail, email, hosting, storage, security, error monitoring, analytics, and customer-support tooling.
We do not currently sell personal information or use it for cross-context behavioral advertising or targeted advertising. If that practice changes, we will update this Policy and provide the choices required by law before the change applies.
8. Financial privacy notice (Gramm-Leach-Bliley Act)
As a company that provides consumer financial services, we handle nonpublic personal information (NPI) about you. This notice describes the categories of NPI we collect, how we protect and share it, and the choices available to you under the federal Gramm-Leach-Bliley Act (GLBA) and related state financial-privacy law. It supplements, and does not replace, the other sections of this Policy.
The categories of nonpublic personal information we collect can include:
- Application and identity information, such as name, contact details, date of birth, and government identifiers you provide for verification.
- Consumer-report and credit information obtained with your authorization, including scores, tradelines, inquiries, and public-record data.
- Transaction and account information, such as program enrollment, billing events, service history, and communications with us.
- Payment information limited to tokenized references and display metadata, not full card numbers.
- Information about your use of the services, such as device, network, and activity records tied to your account.
9. How we share nonpublic personal information
We share nonpublic personal information only as permitted by law and only as needed to deliver the services you request. We do not sell your personal information, and we do not share it for cross-context behavioral advertising or targeted advertising.
Federal law lets consumers limit some kinds of financial-information sharing, such as sharing with affiliates for their own marketing or sharing with nonaffiliated third parties outside permitted exceptions. We do not share your nonpublic personal information for those purposes, so no opt-out is required today. If we ever propose to share your nonpublic personal information in a way that would trigger a GLBA opt-out right, we will give you notice and a reasonable way to opt out before that sharing begins.
We disclose nonpublic personal information to the following categories of recipients, in each case only for the purpose described:
- Contracted service providers that support credit data, identity verification, payments, physical mail, email, hosting, storage, security, error monitoring, analytics, and customer support, under contracts that limit their use of the information.
- Credit bureaus, furnishers, and mail recipients involved in authorized dispute work for paid customers.
- Government authorities, courts, or others when responding to valid legal process or to establish, exercise, or defend legal claims.
- Parties to a legitimate business transaction, such as a merger or asset transfer, subject to appropriate confidentiality safeguards and this Policy.
- Professional advisers, such as auditors, accountants, and lawyers, who are bound by duties of confidentiality.
10. Cookies, analytics, and communications
We use essential cookies for security and account functions. We do not currently enable nonessential analytics or advertising trackers on the public website. If we enable analytics or error-monitoring tools, we will update this Policy and provide any choices required by law.
Service messages may be necessary to administer an account. Marketing email provides the choices required by law. We respond to browser or device signals when required by applicable law and supported by our systems.
11. Retention and deletion
We keep each information class only as long as reasonably needed for the stated purpose, security, contracts, legal duties, dispute history, accounting, or legal claims. Contracts, disclosures, mail proof, billing records, credit-report data, ID images, uploads, communications, and analytics may require different schedules.
We minimize sensitive files when they are no longer needed. A valid legal hold or nonwaivable recordkeeping duty may delay deletion.
Account and portal history remain available indefinitely after program cancellation, with no paid-period expiration. A privacy request is separate from canceling paid service, and some records may be retained where required for legal, security, accounting, or dispute purposes.
12. Security
We use reasonable administrative, technical, and physical safeguards appropriate to the information and services involved. No security system can guarantee absolute protection.
13. Data-breach notification
If we discover a security incident that compromises the security, confidentiality, or integrity of personal information we hold about you, we will investigate promptly, take reasonable steps to contain and remediate it, and notify affected individuals and the appropriate regulators or authorities where required by applicable law.
Notification will be provided without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the incident and restore the reasonable integrity of the affected systems. Where a law sets specific content, method, or timing for a breach notice, our notice will follow those requirements.
14. Your choices and requests
Depending on your relationship and state, you may have rights to access, correct, delete, or obtain a portable copy of information; learn about disclosures; opt out of certain advertising uses; limit certain sensitive-data uses; or appeal a denied request. Applicable rights and exceptions vary.
Customers with portal access may submit requests through the portal concierge. We do not currently publish a staffed public privacy-request email address, phone number, or mailing address; when a dedicated privacy-request channel opens, it will appear on our contact page. Separately, public consumer-report intake and paid enrollment are not yet available, so the personal information we hold today is limited; that status is independent of, and does not affect how we handle, a privacy request you submit. We may verify identity and authority before responding and will handle requests within the time required by applicable law.
15. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA and CPRA), gives you specific rights, subject to verification and legal exceptions. Some information we handle is regulated by the federal Fair Credit Reporting Act or the Gramm-Leach-Bliley Act and may be exempt from these rights; the rights below apply to personal information that is not exempt.
When you use the services, the categories of personal information we collect are described in the section on information we collect, and they can include identifiers, financial and credit information, commercial and transaction information, internet and device activity, and, where you provide it, sensitive personal information such as government identifiers and account credentials. Because public consumer-report intake and paid enrollment are not yet open, the personal information actually collected in the preceding 12 months has been limited to categories such as contact and account identifiers and internet and device activity; we have not collected consumer credit reports, Social Security numbers, or government identifiers from consumers through the public experience. We disclose the categories we collect to service providers and the other recipients described in this Policy for the business purposes stated here.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA and CPRA. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit that use.
You may exercise the rights below as described in the section on your choices and requests. We will verify your identity, or an authorized agent's authority, before responding, and we will not discriminate against you for exercising a privacy right.
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
- Right to delete personal information we collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information we maintain about you.
- Right to opt out of the sale or sharing of personal information, if we ever engage in those activities.
- Right to limit the use and disclosure of sensitive personal information to permitted purposes.
- Right to be free from discrimination or retaliation for exercising your privacy rights.
- Right to use an authorized agent to submit a request on your behalf, with proof of authorization.
16. Other U.S. state privacy rights
If you are a resident of a state with a comprehensive consumer-privacy law, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of others, you may have similar rights with respect to personal information that is not otherwise exempt, for example information governed by the Fair Credit Reporting Act or the Gramm-Leach-Bliley Act.
Available rights, exceptions, and response times vary by state. You may exercise these rights as described in the section on your choices and requests, and we will respond within the period your state's law requires.
- Right to confirm whether we process your personal information and to access it.
- Right to correct inaccuracies in your personal information.
- Right to delete personal information you provided or that we obtained about you.
- Right to obtain a portable copy of personal information you provided to us.
- Right to opt out of the sale of personal information, targeted advertising, and certain profiling. We do not sell personal information or use it for targeted advertising.
- Right to appeal a decision on your request. If we deny a request, you may appeal, and we will respond to your appeal within the time your state's law allows.
17. State and financial-privacy notices
Additional state-specific privacy or credit-services notices may apply based on where a service is offered and the information involved.
This general Policy does not replace a separate notice required by applicable financial-privacy or consumer-reporting law.
18. Children
The services are for adults age 18 or older and are not directed to children. We do not knowingly request a child's consumer report or personal information through the public experience. If we learn that a child submitted information, we will take appropriate steps consistent with applicable law.
19. Changes and contact
We may update this Policy as our services and practices change. Material changes will be identified through the website or another appropriate notice, and information will not be used under a materially different promise without the process required by law.
Customers with portal access may submit privacy questions through the portal concierge. No staffed public privacy-request email address, phone number, or mailing address is currently published; when one opens, it will appear on our contact page. Public consumer-report intake and paid enrollment are also not yet available; that status is independent of any privacy-request channel.