Privacy Policy · Effective August 14, 2026

What we collect, how we use it, and what we don’t do with it.

Credloom handles some of the most regulated personal data that exists — your credit file. This page spells out, in plain language, what we collect to do the FCRA dispute work you hire us for, what we never do with it, and how to exercise your access and deletion rights.

1. Scope of this policy

This policy applies to Credloom (“we,” “us,” or “our”) and to every customer relationship, website visit, intake submission, signed service agreement, and dispute letter we file on your behalf. It covers information we collect directly from you and information the credit reporting agencies furnish in response to your dispute requests. Other services we link to (a bureau, a bank, an authorized-user tradeline you choose on your own) have their own privacy practices — read theirs too.

2. What we collect

To do credit-repair work on your file under the Fair Credit Reporting Act (FCRA, 15 U.S.C. §1681), we need three things and only three things:

  • Identity and contact information — your legal name, current address, date of birth, Social Security number (only what the bureaus require to pull a file), and an email and phone number we can use to reach you.
  • Your credit reports from all three bureaus — the official Equifax, Experian, and TransUnion files you provide (or that we authorize you to pull). These stay inside your case file.
  • Payment and billing information — to bill you monthly, in arrears, per CROA. We store the minimum needed to bill and refund; card data is tokenized by our payment processor and is never stored on our servers.

We do not collect race, religion, sexual orientation, immigration status, genomic data, biometric identifiers, geolocation history, or any of the other “sensitive” categories you sometimes see in generic SaaS privacy notices.

3. What we do with it

We use your information to perform the service you signed up for and nothing else:

  • Run the FCRA §1681i dispute process on inaccurate, incomplete, or unverifiable items across Equifax, Experian, and TransUnion.
  • Generate, save, and mail dispute letters and bureau response logs to your case file — your audit trail.
  • Bill you monthly, in arrears, after each month of service is delivered (CROA requires this; we never bill before service).
  • Send you a single monthly statement, a single cycle-summary email, and occasional compliance or service notices — never marketing blasts, and never a third-party promotion.

4. What we do not do

Three things we never do with your file — they’re either illegal under CROA and FCRA or they’re the kind of behavior that has put the rest of this industry in front of the FTC:

We do not sell your data. Not to lenders, not to brokers, not to lead generators, not to “affiliate partners.” Selling credit-file data is a prohibited practice under federal credit-repair law.

We do not resell your data. Not in aggregate, not anonymized, not as a “dataset.” Your tradelines are not a commodity.

We do not promise to remove accurate information. FCRA §1681i disputes are grounded in inaccuracy, incompleteness, or unverifiability — not in getting accurate, timely negative items off the report. The bureau decides, not us, and we tell you the same on every cycle.

5. Who we share it with

Only the parties necessary to run the service, and only the minimum each one needs to do its job:

  • Equifax, Experian, and TransUnion — to file FCRA §1681i disputes and to track bureau responses, exactly as you authorize in your signed service agreement.
  • Our payment processor — to bill your monthly subscription and to refund any payment on a CROA cancellation. Cardholder data is tokenized; we do not store full card numbers on our servers.
  • Our hosting and email-infrastructure providers — to run the database that stores your case file and to send you service emails. They are contractually bound to use your data only to provide the service we buy from them.
  • Government authorities — only when we are legally compelled to (a valid subpoena, court order, or statutory investigative demand) or when necessary to detect and prevent fraud.

We do not share your file with attorneys, coaches, or referral partners unless you have signed a separate written authorization naming that specific party.

6. How long we keep it

Case files — signed service agreements, intake forms, every dispute letter, every bureau response, every cancellation notice and refund record — are retained for a minimum of five years from the last dated record on the file. This is consistent with CROA recordkeeping expectations and with the Federal Trade Commission’s enforcement guidance for credit repair organizations. Account-level billing records follow the longer of the standard IRS recordkeeping window or your state’s consumer-record rule. You can request deletion of ancillary communication records (support emails, intake voice notes) at any time; the case file itself stays until the five-year window closes.

7. Your rights

You can exercise the following rights at any time. We respond to every verifiable request within thirty days — often within a few business days, depending on the request type:

  • Access — request a copy of the personal data we hold on you. We will deliver a complete export from your case file.
  • Correction — ask us to fix anything in your account record that is incomplete or inaccurate.
  • Delete ancillary communication records — emails, intake notes, support tickets. (The case file itself follows the five-year retention rule.)
  • Cancel your service — written notice, by email or postal mail, ends the relationship and stops future billing per CROA. Use the /cancel page for the form, or email us directly.

8. Security

Your case file is hosted in a database with encryption at rest and in transit, access is logged, and production credentials rotate on a fixed schedule. Application code is reviewed before deploy. No security posture is perfect — if we ever discover a breach involving your personal information, we will notify you without undue delay and at minimum within the window required by your state’s consumer-protection law.

9. Changes to this policy

If we make a material change to how we handle your data, we will email you at the address on your account, summarize the change in plain language, and update the effective date at the top of this page. The previous version is retained and can be requested on demand.

10. Contact

The fastest way to reach us is email at credloom-2@polsia.app. For any privacy-rights request (access, correction, deletion of ancillary records), include your full name, the email on file, and the specific right you are exercising. We respond within thirty days.

For FCRA-specific questions about the dispute process itself, see the CROA disclosures and the how-it-works page.

Ready to start? The intake walks you through the disclosures and your FCRA rights before anything is signed.