Fix My Reports Privacy Policy
Effective July 2026 · Last reviewed July 2026
Fix My Reports (fixmyreports.com and the client portal) is built around a simple idea: your credit file is yours, and the tools you use to work on it shouldn't come with strings attached. This policy explains exactly what we collect while you use the platform, why we collect it, who ever sees it, and how you stay in control of it.
- Account and identity details. When you sign up, we collect your name, phone number, email, mailing address, date of birth, and the last four digits of your Social Security number. This is the minimum needed to generate dispute letters that a bureau or furnisher will actually accept — letters have to identify who's disputing, or they get rejected outright.
- Your credit report data. Once you link a SmartCredit / ConsumerDirect account, we pull your three-bureau report, scores, and tradeline details so the software can flag what's worth disputing and track what changes round to round. We never see or store your SmartCredit password — the connection works by looking your account up through their partner API, not by holding your login.
- Documents you upload. Government ID and proof-of-address files you provide to support your disputes.
- Basic usage data. Device and browser information needed to keep the portal secure and working correctly — nothing tied to advertising profiles.
- Cookies. Used to keep you signed in and recognize returning visitors. They're not linked to any personal profile beyond your own session.
We are not in the business of selling data, and we don't hand your information to marketers. Full stop. The only parties who ever see your information are:
- The credit bureaus and furnishers named on a letter you personally sign and send — that's the entire point of the platform, and it only happens when you choose to send it.
- SmartCredit/ConsumerDirect, solely to authenticate you and retrieve your report data.
- Authorize.Net, solely to process your subscription payment.
- Law enforcement or courts, only if we're legally compelled to respond.
If you follow a link to a third-party site or partner offer from within our platform, that party's own privacy practices govern what happens there — we'd encourage you to check before sharing anything further.
Sensitive information is encrypted in transit (look for "https" — it's always there on this site). Inside our systems, your records are isolated per-account with row-level security at the database layer, uploaded documents live in a private storage bucket scoped to your account only, and staff access is role-based and limited to what someone actually needs to do their job.
You can, at any time, by emailing info@fixmyreports.com:
- Ask what data we hold about you
- Correct anything that's wrong
- Request deletion, subject to what we're legally required to retain (e.g. billing records)
- Opt out of any non-essential communications
- Raise a concern about how your data is being used
We respond to these requests within 30 days.
If this policy changes, the update goes up on this page with a new effective date. We don't make retroactive changes that weaken protections already promised to you without giving notice.
Questions or concerns about this policy: info@fixmyreports.com
This section applies specifically to California residents and uses the defined terms established by the California Consumer Privacy Act (CCPA), as amended by the CPRA.
Categories of personal information collected in the past 12 months
- Identifiers (name, address, email, phone)
- Protected classification characteristics (age)
- Commercial information (services requested)
- Internet/network activity on our site
- Geolocation inferred from IP address
- Inferences drawn from the above
This does not include publicly available government records, de-identified/aggregated data, or information already covered by sector-specific laws like FCRA, GLBA, or the Driver's Privacy Protection Act.
Where it comes from
Directly from you (forms, uploads), indirectly through your use of the site, and from partners you explicitly connect (like your credit monitoring account).
Why we use it
To operate the software and generate your dispute letters, to support you when you reach out, and to comply with legal obligations. We won't repurpose it for something materially different without telling you first.
Sales
We have not sold personal information in the preceding 12 months, and we don't intend to.
Your CCPA rights
- Know/Access — request the categories and specific pieces of personal information we've collected, our purpose for collecting it, and who it's been shared with.
- Delete — request deletion of what we've collected, with standard exceptions (completing a transaction you requested, security/fraud prevention, legal compliance, debugging, free speech rights, internal uses consistent with your relationship with us).
- Opt-out of sale — moot in practice since we don't sell data, but you may still submit a request.
To exercise any of these, email info@fixmyreports.com. We verify identity using information you've previously given us — two matching data points for a "know categories" request, three plus a signed declaration for a "know specific pieces" or "delete" request. If we can't verify you, a deletion request is treated as an opt-out request instead.
Timing
We aim to respond within 45 days (up to 90 with notice) for access/deletion requests, and within 15 days for opt-out requests. Portable data is provided electronically in a usable format.
Non-discrimination
Exercising any of these rights never results in different pricing, different service quality, or denial of service.
Shine the Light (Civil Code §1798.83)
California residents may separately request information about disclosures made for direct marketing purposes by emailing info@fixmyreports.com.
We may update this California notice from time to time; changes are posted here with an updated effective date.
See also our Terms of Use.