HomePrivacy Statement

Privacy Statement

Last updated: March 2026

1. Introduction

Credit Technologies, Inc. ("CTI," "we," "us," or "our") is committed to protecting the privacy and security of personal information. This Privacy Statement explains how we collect, use, disclose, and safeguard your information when you visit our website at credittechnologies.com (the "Site"), use our credit reporting services, or interact with our AI assistant, Jarvis. CTI is an FCRA-regulated consumer reporting agency subject to the Fair Credit Reporting Act, the Fair and Accurate Credit Transactions Act, the Gramm-Leach-Bliley Act, and applicable state privacy laws.

2. Information We Collect

Information You Provide Directly: When you register for membership, request a demo, fill out a contact form, or otherwise interact with our Site, we may collect your name, email address, phone number, company name, job title, and NMLS number. Account and Service Data: When you use CTI's credit reporting platform, we collect login activity, service usage records, report request history, and billing information. Automatically Collected Information: When you visit our Site, we automatically collect certain technical information including your IP address, browser type, operating system, referring URL, pages visited, and time spent on pages. AI Assistant (Jarvis) Data: When you interact with Jarvis, we collect conversation content, timestamps, and usage patterns. You should not share sensitive personal information, consumer credit data, or account credentials through the Jarvis chat interface.

3. How We Use Your Information

We use the information we collect to: process and manage your CTI membership; provide credit reporting and related services; respond to inquiries and support requests; send relevant product information, service updates, and industry news; improve our website, services, and AI assistant; comply with legal and regulatory obligations; detect and prevent fraud and unauthorized access; and fulfill our contractual obligations to you.

4. Consumer Credit Report Information (FCRA)

As an FCRA-regulated consumer reporting agency, CTI handles consumer credit report data with the highest level of care and in strict accordance with the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.), the Fair and Accurate Credit Transactions Act (FACTA), and all applicable federal and state regulations.

Consumer credit information is: accessed and disclosed only to authorized parties who have certified a permissible purpose under FCRA Section 604; never used for marketing purposes; never sold to third parties; protected by industry-standard administrative, technical, and physical safeguards; retained only for the period required by applicable law and contractual obligations; and subject to consumer dispute rights as provided by the FCRA.

Consumers who believe their credit report information has been accessed improperly may contact CTI directly or file a complaint with the Consumer Financial Protection Bureau (CFPB).

5. Financial Privacy (GLBA)

As a financial institution subject to the Gramm-Leach-Bliley Act (GLBA), CTI maintains a comprehensive information security program to protect the security, confidentiality, and integrity of nonpublic personal information (NPI). We do not share NPI with nonaffiliated third parties except as permitted or required by law, to process transactions you request, or to service your account. You have the right to opt out of certain information-sharing practices. To exercise this right, contact us at 800.445.4922 or info@credittechnologies.com.

6. Cookies and Tracking Technologies

Our Site uses cookies and similar tracking technologies. Essential Cookies are required for the Site to function properly and cannot be disabled. Analytics Cookies help us understand how visitors interact with our Site by collecting aggregate, anonymized usage data. Functional Cookies remember your preferences and settings. You can control cookie preferences through your browser settings. Disabling certain cookies may affect Site functionality. We do not use cookies for behavioral advertising or sell cookie data to third parties.

7. Data Security

CTI implements industry-standard security measures to protect personal information, including: encryption of data in transit (TLS/SSL) and at rest; access controls and authentication requirements; regular security assessments and vulnerability testing; employee training on data protection and privacy; incident response procedures; and physical security controls at our facilities. While we employ commercially reasonable security measures, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

8. Third-Party Service Providers

We may share personal information with third-party service providers who assist us in operating our business, including: credit bureaus (Equifax, Experian, TransUnion) for credit data retrieval and reporting; cloud hosting and infrastructure providers for data storage and processing; payment processors for billing and subscription management; analytics providers for website performance monitoring; and LOS integration partners for seamless data delivery. These providers are contractually obligated to protect your information and may only use it for the purposes for which it was disclosed.

9. AI Assistant (Jarvis) Disclosure

Jarvis is an AI-powered assistant that provides general information about CTI's products and services. Jarvis conversations are processed using artificial intelligence technology, stored and may be reviewed by CTI staff to improve response quality and accuracy, retained for a period of up to 90 days for quality assurance purposes, not used to make credit decisions or for any FCRA-regulated purpose, and subject to the same data protection standards as other CTI data. Jarvis is not a licensed financial advisor, attorney, or credit counselor. Responses should not be relied upon as professional advice.

10. Data Retention

We retain personal information for the following periods: membership account data is retained for the duration of your membership plus seven years as required by financial recordkeeping regulations; credit report access logs are retained per FCRA requirements (typically five years); website analytics data is retained in aggregate form for up to three years; AI assistant conversation data is retained for up to 90 days; and marketing communication records are retained until you opt out or for three years, whichever is shorter. After the applicable retention period, data is securely deleted or anonymized.

11. Your Privacy Rights

All Users: You have the right to access, correct, or delete your personal information held by CTI. You may opt out of marketing communications at any time. You may request information about what personal data we hold about you.

California Residents (CCPA/CPRA): If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including: the right to know what personal information we collect and how it is used; the right to delete personal information we hold about you; the right to opt out of the sale or sharing of personal information (CTI does not sell personal information); the right to non-discrimination for exercising your privacy rights; and the right to correct inaccurate personal information. To exercise these rights, contact us at info@credittechnologies.com or 800.445.4922. We will respond to verified requests within 45 days.

12. Children's Privacy

Our Site and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will promptly delete that information.

13. Data Breach Notification

In the event of a data breach involving personal information, CTI will: promptly investigate and contain the breach; notify affected individuals as required by applicable state and federal law; notify relevant regulatory authorities as required; and take steps to prevent future incidents. Notification timelines comply with the breach notification laws of each applicable state, with most states requiring notification within 30 to 60 days of discovery.

14. Do Not Track Signals

Our Site does not currently respond to Do Not Track (DNT) signals from web browsers. However, you can control tracking through your browser cookie settings as described in Section 6 above.

15. Changes to This Statement

We may update this Privacy Statement from time to time to reflect changes in our practices, legal requirements, or industry standards. Material changes will be posted on this page with an updated revision date. We encourage you to review this Statement periodically. Your continued use of the Site after any changes constitutes acceptance of the updated Statement.

16. Contact Information

For privacy-related questions, data access requests, or to exercise your privacy rights, contact Credit Technologies, Inc.

Credit Technologies, Inc. — Attn: Privacy Officer — 51147 Pontiac Trail, Wixom, MI 48393 — Phone: 800.445.4922 — Email: info@credittechnologies.com