Legal
Privacy
Two parts. What this demonstration website does, which is very little, and what a real practice of this kind would have to do, which is a great deal more.
Part one — this website
This is a demonstration site. Uptick Credit is not a real business. No form on this site transmits anything: the contact form, the file review form and the simulator all run entirely in your browser and nothing is sent to a server.
There is no analytics, no tag manager, no pixel, no advertising network, no session recording and no cookie of any kind. Three things are stored locally on your own device, and only your browser can read them:
uptick.customizer.v1— the colour, typography and identity settings you choose in the brand customizer, so they survive navigation.uptick.diy.v1— which steps of the do-it-yourself guide you have ticked off.- Nothing else. Clearing site data removes both, and neither is ever transmitted.
The only external requests the site makes are for its own fonts and images, served from the same origin. Nothing is loaded from a third-party CDN, so no third party learns that you visited.
Part two — what a real practice would do
The rest of this page describes how a credit repair organisation operating under this model would handle information. It is written as the real policy would be, because a demonstration of a regulated business that skipped its privacy policy would be demonstrating the wrong thing.
What would be collected
- Identity information — name, address, date of birth and the last four digits of a Social Security number, which is what a bureau requires to identify a file on a dispute.
- Credit file information — the reports you provide or authorise us to pull, and the correspondence generated by disputes.
- Contact information — email, phone, and the notes of conversations we have with you.
- Billing information — held by a PCI-compliant payment processor, never on our systems, and never charged before services are performed.
What would never be collected
- Your online banking credentials. A company that asks for them is asking for the wrong thing.
- A full Social Security number by email or through an unencrypted form.
- Information about anyone other than you, unless you hold a power of attorney for them and have shown it to us.
How it would be used
Only to perform the services you have contracted for: reading your file, preparing and filing disputes, corresponding with bureaus and furnishers on your behalf, and giving you the results. Nothing else.
Who it would be shared with
- The consumer reporting agencies and furnishers named in your disputes, and only the information needed for that dispute.
- A payment processor, for billing after work has been performed.
- Nobody else. Your information would not be sold, rented, licensed, traded, or shared with a marketing affiliate. There is no lead-generation arrangement, and there never would be.
How long it would be kept
For the duration of the engagement and for five years afterwards, which is what the Credit Repair Organizations Act requires for contract records. You could request deletion of anything beyond that at any time.
Your rights over it
- Ask what we hold about you, and get a copy.
- Correct anything that is wrong.
- Withdraw consent and have us stop, at any time, without owing anything for work not performed.
- Request deletion of anything not subject to a legal retention requirement.
Statutes this would sit under
The Gramm-Leach-Bliley Act and its Safeguards Rule, which govern how a financial institution protects customer information; the Fair Credit Reporting Act, which governs the permissible purposes for which a credit report may be obtained; and the Credit Repair Organizations Act, which governs the contract and the record retention. Florida’s own breach-notification requirements would apply on top.
Contact
On a live site, privacy questions would go to hello@uptickcredit.com or to the office at 401 E Jackson St, Suite 2340, Tampa, FL 33602. Because this is a demonstration, nobody is there.