Privacy Policy
Effective date: August 16, 2026
Company: Credit Letter MVP LLC ("Credit Letter MVP," "we," "us," or "our")
Business mailing and customer-notice address: 5781 S New York Ave, Cudahy, WI 53110
1. Scope
This Policy describes how we collect, use, disclose, retain, and protect personal information when you use our website, account, report-analysis, document-preparation, support, payment, and optional mailing features.
2. Information we collect
- Account and profile information: name, username, email, password hash, mailing address, phone number when provided, and account preferences.
- Reports and extracted information: reports you upload and structured information extracted from them, which may include names, addresses, employers, account details, inquiries, balances, dates, status, and other report content.
- Documents and instructions: facts, reasons, selected accounts, recipient details, generated letters, signatures, identity documents, proof of address, statements, reports, and other attachments you choose to provide.
- Transactions: order amount, status, timestamps, consent records, and payment or mailing provider reference numbers. Stripe processes full payment-card details; we do not store the full card number.
- Support and assistant content: questions, messages, feedback, temporary support-access authorization, and records needed to respond or investigate a problem.
- Technical and security data: IP address, browser and device information, session identifiers, request and error logs, authentication events, and security or fraud signals.
- First-party usage and campaign data: random session identifiers, page names, referring hostnames, campaign labels included in links (such as source, medium, campaign, and post identifier), and milestones such as signup, report queued, analysis completed, checkout started, and purchase completed. The analytics record does not contain report contents, account numbers, letter text, full referring URLs, IP addresses, or browser fingerprints.
3. How we use information
- create and secure accounts and authenticate users;
- extract, organize, and display information from submitted reports;
- prepare, save, display, download, print, sign, and mail the documents you request;
- process orders, record consent, provide receipts, and reconcile provider transactions;
- answer support questions, troubleshoot errors, and prevent fraud or abuse;
- understand which outreach links bring visitors to the service and measure the signup, analysis, and purchase funnel;
- operate, test, monitor, and improve reliability, accessibility, and security; and
- comply with law, enforce our terms, and establish or defend legal claims.
4. Service providers and disclosures
We disclose information only as reasonably necessary for the service or another purpose described here. Providers may include:
- OpenAI or other configured AI providers to interpret submitted report text, prepare requested content, or support the assistant;
- Stripe to process payments and help prevent fraud;
- Lob when you authorize printing and mailing, including the final letter, address, signature, and selected attachments;
- Postmark or another configured email provider to deliver account and transactional emails;
- Namecheap Private Email or another mailbox provider to receive and host messages sent to our company email address;
- Twilio, when owner text alerts are enabled, to deliver privacy-minimized operational notices that an account was created or a payment was confirmed. These alerts exclude report contents, account numbers, letters, uploaded documents, addresses, and customer contact details;
- Photon, operated by komoot and using OpenStreetMap data, to return optional address suggestions as you type. Partial address text is sent only when you use that suggestion feature; manual entry and browser autofill remain available; and
- Railway and other infrastructure providers to host, store, secure, and operate the application.
We may also disclose information to professional advisers, law enforcement, regulators, courts, or other parties when reasonably necessary to comply with law, protect people or the service, investigate misconduct, or complete a merger, financing, reorganization, or sale subject to appropriate protections.
We do not sell personal information for money or share it for cross-context behavioral advertising. We do not use submitted reports or identity documents for advertising.
5. Retention
- Source report files: retained in encrypted form only while an analysis job is pending and deleted after processing finishes or fails.
- Structured analysis: available for up to 72 hours unless you delete it sooner, then removed from persistent and in-memory analysis storage.
- Saved letters, signatures, and saved attachments: retained in your account until you delete the applicable item or account.
- Temporary mailing-checkout uploads: deleted after mailing completes or the temporary upload session is cleared. A document deliberately saved to a letter remains until deletion.
- Transaction, consent, security, and provider records: retained as reasonably necessary for accounting, fraud prevention, dispute handling, audits, legal obligations, and enforcement. Where possible after account deletion, these records are minimized or disconnected from active profile information.
- First-party usage analytics: retained as reasonably necessary to measure product performance and outreach. Analytics rows linked to your user ID are deleted when your account is deleted; unlinked traffic records may remain without active profile information.
- Support correspondence: retained in our company mailbox and sent-mail records as reasonably necessary to answer requests, document service activity, prevent abuse, and resolve disputes.
Backups, provider systems, legal holds, and postal processing may delay final deletion. A mailing already submitted cannot be recalled from Lob or the postal system through account deletion.
6. Support access
If account-level inspection is needed to solve a support issue, we may ask you to grant time-limited support access. We record the authorization, staff access, time, and stated reason. We may access information without that permission only when reasonably necessary for security, fraud prevention, legal compliance, emergency protection, or service integrity.
7. Cookies and sessions
We use first-party cookies and similar local storage for login sessions, security, preferences, checkout continuity, core application operation, and first-party traffic measurement. Campaign tracking uses only allowlisted labels from our links and the referring website's hostname; it does not use an advertising network or cross-site behavioral profile. Blocking required cookies may prevent parts of the service from functioning. We honor browser Do Not Track and Global Privacy Control signals by disabling this traffic and funnel tracking for that browser session.
8. Security
We use measures designed to protect information, including encrypted transport, encrypted sensitive-file storage, access controls, password hashing, session protections, audit records, and deletion routines. No method of storage or transmission is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Contact us promptly if you suspect an incident involving your account.
9. Your choices and privacy requests
You can update profile information and delete certain analyses, letters, attachments, and signatures from the service. You may request account deletion through the Profile page. You may also email us to request access, correction, deletion, or a portable copy of information, or to object to or restrict certain processing where applicable.
We may verify your identity and authority before acting. We may deny or limit a request when permitted by law, including to preserve transaction, security, legal-claim, or fraud-prevention records. If applicable law provides an appeal right, reply to our decision with "Privacy Appeal" in the subject line. You may use an authorized agent where permitted, subject to verification.
10. State and regional rights
Depending on where you live, you may have additional privacy rights. These can include rights to know, access, correct, delete, or obtain a copy of personal information and to receive information about disclosures. We will honor applicable rights and will not unlawfully discriminate against you for exercising them.
11. Age restriction
The service is intended only for adults age 18 or older. We do not knowingly collect personal information from children. If you believe a child submitted information, contact us so we can investigate and delete it where appropriate.
12. United States processing
The service is operated for United States users. Information may be processed in the United States and other locations where our providers operate, subject to the safeguards and legal requirements applicable to those providers.
13. Changes
We may update this Policy as the service or law changes. We will post the new effective date and provide additional notice for material changes when required. If consent is legally required for a new use, we will request it before that use.
14. Contact
Email contact@creditlettermvp.com or write to Credit Letter MVP LLC, 5781 S New York Ave, Cudahy, WI 53110, with privacy questions or requests.