Privacy Policy — CredFin, Inc.
Legal & Compliance

CredFin, Inc.
Privacy Policy

How we collect, use, protect, and honor your rights regarding your personal information — including our SMS/Text Messaging and A2P 10DLC compliance disclosures.
Last Updated: May 2026 Effective: May 2026 Governing Law: State of Florida & applicable federal law Applies To: credfin.ai and all CredFin services
Data Controller / Business Identity
Legal Name
CredFin, Inc. (Delaware corporation)
Website
credfin.ai
Address
1395 Brickell Ave, Ste 800, Miami, FL 33131
Phone
(949) 828-4020
Privacy Contact
[email protected]
Legal Contact
[email protected]
SECTION 1 Scope and Who We Are

This Privacy Policy describes how CredFin, Inc. ("CredFin," "we," "us," or "our") collects, uses, discloses, and protects information about you when you:

  • Visit or use our website at credfin.ai or any CredFin subdomain (including workshop.credfin.ai, app.credfin.ai, invest.credfin.ai, and others)
  • Enroll in or use any CredFin program or service (Empire Accelerator™, Empire Credibility Builder™, Capital Qualified™ + Lender Match™ System, or any other product)
  • Attend or register for a CredFin workshop, webinar, or consultation
  • Contact us by phone, email, SMS/text, live chat, or online form
  • Interact with our call center team, coaching staff, or agents
  • Provide your mobile number or other contact information to receive communications from CredFin

By using our services or submitting information to us, you acknowledge that you have read and understood this Privacy Policy. This Policy is incorporated by reference into our Client Service Agreement.

This Policy applies primarily to business and commercial information you provide as a business owner or authorized representative. To the extent we collect personal information about you as an individual, this Policy governs that data as well.
SECTION 2 Information We Collect
2.1   Information You Provide Directly
CategoryExamplesWhen Collected
Identity & ContactFull name, email address, phone number(s) including mobile, mailing address, job titleForms, enrollment, workshop registration
Business InformationBusiness name, EIN/tax ID, entity type, state of formation, date formed, industry, annual revenue, number of employeesEnrollment, funding applications, consultations
Financial InformationMonthly revenue, existing debt obligations, funding goals, self-reported credit score ranges (we do not collect full bank account numbers)Fundability assessments, coaching sessions
Business Credit ProfileD&B DUNS number, Equifax Business file data, Experian Business credit data, PAYDEX scores, trade line informationPlatform use, fundability analysis (with your authorization)
Payment InformationCredit/debit card details, billing address — processed by PCI-compliant third-party processor. CredFin does not store full card numbers.Enrollment checkout
SMS / Mobile ConsentMobile phone number, opt-in confirmation, opt-out requests, STOP/HELP responsesWeb forms, workshop registration, enrollment
CommunicationsCall recordings, voicemails, email correspondence, SMS/text messages, chat transcripts, coaching session notesOngoing interactions with our team
2.2   Information Collected Automatically
  • Device & Browser Data: IP address, browser type and version, operating system, device identifiers, screen resolution
  • Usage Data: Pages viewed, time on page, click paths, referring URLs, session duration, platform features accessed
  • Location Data: Approximate geographic location inferred from IP address
  • Cookies & Tracking Technologies: See Section 5 for full details
  • Call Metadata: Call date/time, duration, caller ID (see Section 7)
2.3   Information From Third Parties
  • Business Credit Bureaus: Dun & Bradstreet, Equifax Business, and Experian Business — accessed with your authorization
  • Lead Data Partners: RetargetIQ and similar providers may supply contact and business profile data for outreach permitted by law
  • CRM Platforms: GoHighLevel (our CRM and dialing platform) may provide contact or behavioral data
  • Payment Processors: Transaction confirmation and payment status data
  • Public Records: Business registry data, Secretary of State filings, and similar public sources
SECTION 3 How We Use Your Information
PurposeDescriptionLegal Basis
Service DeliveryProviding coaching, fundability assessments, lender matching, platform access, and all contracted servicesContract performance
Account ManagementCreating and maintaining your account, processing payments, sending receipts and service communicationsContract performance
Fundability AnalysisAnalyzing business credit data from D&B, Equifax Business, and Experian Business to generate reports and recommendationsContract; legitimate interest
Lender MatchingUsing your business profile to identify and introduce you to appropriate lendersContract; consent
SMS & Phone CommunicationsSending appointment reminders, workshop confirmations, follow-ups, program updates, and promotional texts (with consent — see Section 6)Consent; legitimate interest
Marketing & OutreachPromotional offers, newsletters, and information about new services. You may opt out at any time.Consent; legitimate interest
Call Center OperationsRecording and reviewing calls for QA, compliance, training, and dispute resolution (see Section 7)Legitimate interest; legal obligation
Legal & ComplianceComplying with legal obligations, responding to lawful requests, enforcing our agreementsLegal obligation; legitimate interest
Security & Fraud PreventionDetecting and preventing fraud, unauthorized access, and security incidentsLegitimate interest; legal obligation
Analytics & ImprovementUnderstanding service usage to improve features and user experienceLegitimate interest
SECTION 4 How We Share Your Information
We do not sell your personal information. CredFin does not sell, rent, or lease your personal information — including your mobile phone number — to third parties for their own marketing or commercial use.
4.1   Service Providers

We engage trusted third-party vendors who are contractually prohibited from using your data for their own purposes:

  • CRM & Marketing: GoHighLevel (CRM, email, SMS delivery, power dialing)
  • Payment Processing: PCI DSS-compliant third-party processor(s)
  • Business Credit Data: Dun & Bradstreet, Equifax Business, Experian Business
  • Lead Data: RetargetIQ and similar compliant lead providers
  • Communications: VoIP/dialing providers, email delivery services
  • Cloud Hosting: Hosting and data storage providers
  • Analytics: Website analytics platforms (e.g., Google Analytics)
4.2   Lender Network

With your explicit consent, we may share your business profile with lenders in our network as part of the Lender Match™ service. Each lender has its own privacy policy governing their use of your information. We do not share your data with lenders for purposes other than evaluating your eligibility for financing.

4.3   Legal Requirements

We may disclose information when required by law, subpoena, or court order; to enforce our agreements; or to protect the rights, property, or safety of CredFin, our clients, or others.

4.4   Business Transfers

In the event of a merger, acquisition, or sale of substantially all assets, your information may be transferred to the successor entity. We will notify you of any material change in how your information is used, where required by law.

4.5   SMS / Phone Number Sharing Policy
We will never share, sell, or provide your mobile phone number to any third party for their own SMS marketing campaigns or outbound calling programs. Phone numbers collected for SMS opt-in are used solely by CredFin, Inc. for the messaging purposes described in Section 6.
SECTION 5 Cookies and Tracking Technologies
TypePurposeCan Opt Out?
Strictly NecessaryRequired for the website and platform to function (authentication, security, session management)No — required
FunctionalRemember your preferences, language settings, and prior interactionsYes
Analytics / PerformanceMeasure website traffic and usage patterns (e.g., Google Analytics)Yes
Marketing / RetargetingTrack behavior to show relevant ads and measure campaign effectiveness (e.g., Facebook Pixel, Google Ads)Yes

Manage cookie preferences through your browser settings, our cookie consent banner, or by emailing [email protected]. Our website does not currently alter its data collection practices in response to browser Do Not Track (DNT) signals, as no universal standard exists.

Web Beacons: Our emails may contain small image files ("web beacons") that allow us to track open rates and engagement. You can disable this by setting your email client to block remote images.

SECTION 6 SMS / Text Messaging & A2P 10DLC Compliance

CredFin, Inc. sends SMS and MMS text messages through registered A2P 10DLC messaging campaigns in full compliance with the Telephone Consumer Protection Act (TCPA, 47 U.S.C. § 227), FCC regulations, CTIA Messaging Principles and Best Practices, and all applicable A2P 10DLC carrier requirements.

6.1   How We Obtain Your Consent

We obtain express written consent before sending any marketing or promotional SMS messages. Consent is collected when you:

  • Check an SMS opt-in box on a CredFin web form, workshop registration page, or enrollment checkout
  • Provide your mobile number and agree to receive text communications from CredFin during a call center interaction
  • Complete an online form at credfin.ai or any CredFin subdomain that includes an SMS consent disclosure
Consent to receive SMS messages is never required as a condition of purchasing any CredFin product or service. You may opt out at any time without affecting your access to services you have purchased.
6.2   Types of Messages We Send
Message TypeDescription / Examples
Appointment RemindersReminders for upcoming workshop sessions, coaching calls, and consultations
Workshop ConfirmationsRegistration confirmations and access details for free and VIP workshops
Program UpdatesNotifications about your Capital Qualified™ status, platform activity, and program milestones
Follow-Up CommunicationsPost-call or post-workshop follow-up messages from our team
Promotional MessagesInformation about new CredFin services, offers, and educational content (marketing only with prior consent)
Transactional AlertsPayment confirmations, account notices, and service-related updates
6.3   Key SMS Disclosures
Required A2P / CTIA Disclosures
Message Frequency
Varies
Typically 2–8 messages per month depending on your program stage and activity.
Rates
Msg & data rates may apply
Standard carrier message and data rates may apply depending on your mobile plan.
Opt Out
Reply STOP
Reply STOP to any CredFin text message to opt out. You will receive one final confirmation and no further messages.
Get Help
Reply HELP
Reply HELP for support information, or email [email protected] or call (949) 828-4020.

Phone Number Privacy: CredFin will never sell, share, or disclose your mobile phone number to any third party for their own marketing or SMS outreach purposes.

6.4   How to Opt Out of SMS

You may opt out of SMS communications from CredFin at any time using any of the following methods:

  • Reply STOP to any text message from CredFin — you will receive one confirmation message and no further texts will be sent
  • Email [email protected] with your name and mobile number and the subject line "SMS Opt-Out"
  • Call (949) 828-4020 and ask to be removed from our SMS list

After opting out, you may re-subscribe at any time by texting START to the same number or by completing a new opt-in form.

6.5   A2P 10DLC Registration

CredFin's SMS campaigns are registered with the major U.S. wireless carriers through the A2P 10DLC system administered by The Campaign Registry (TCR). This registration includes disclosure of our brand identity, message types, and opt-in/opt-out procedures to carriers and their aggregators. Our messaging complies with all applicable carrier codes of conduct and CTIA short code and 10DLC guidelines.

6.6   Supported Carriers

CredFin's SMS program is available on all major U.S. wireless carriers, including AT&T, Verizon, T-Mobile, and others. Carrier support may vary. We are not liable for delayed or undelivered messages due to carrier transmission failures.

SECTION 7 Call Center Operations and Call Recording
7.1   Call Recording Notice

CredFin operates a call center and may record telephone calls for quality assurance, compliance, agent training, dispute resolution, and service improvement. By calling us or accepting a call from us, you consent to call recording. Where state law requires two-party consent (including Florida, California, and other two-party consent states), we provide notice at the start of each call. Recordings are stored securely and accessed only by authorized personnel.

7.2   Outbound Calling

CredFin may contact you by telephone using an automated dialing system or pre-recorded messages for service-related and marketing purposes. By providing your phone number on a CredFin web form or during enrollment, you expressly consent to such calls. You may revoke consent at any time by saying "remove me" during any call, emailing [email protected], or replying STOP to any text message.

7.3   National Do Not Call Registry

CredFin maintains an internal Do Not Call list and honors the National Do Not Call Registry. To be added to our internal Do Not Call list, contact us at [email protected] or (949) 828-4020.

SECTION 8 Financial and Business Credit Data
8.1   Business Credit Bureau Data

With your authorization, we access your business credit profile from Dun & Bradstreet, Equifax Business, and Experian Business. This data includes your business credit scores, payment history, trade lines, and public records associated with your business entity. We use this data solely to deliver our Capital Qualified™ Fix and Lender Match™ services. We do not access your personal consumer credit report without separate explicit written consent.

8.2   Gramm-Leach-Bliley Act (GLBA)

To the extent CredFin collects nonpublic personal financial information in connection with financial advisory activities, we operate in compliance with applicable provisions of the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and the FTC Safeguards Rule (16 C.F.R. Part 314). We maintain a written information security program to protect the security, confidentiality, and integrity of client financial information.

8.3   Payment Card Data

All payment card transactions are processed by a PCI DSS-compliant third-party processor. CredFin does not store, transmit, or have access to your full credit card number, CVV, or card expiration date after a transaction is processed.

SECTION 9 AI Platform and Automated Processing
  • What It Does: The CredFin AI Funding Platform analyzes your business credit data, entity structure, and financial profile to generate fundability scores, identify improvement areas, and suggest lender matches.
  • Human Oversight: All material recommendations involve human review by CredFin's expert team. The Platform is a decision-support tool — it does not make final determinations about your funding eligibility without human review.
  • No Adverse Action Based on AI Alone: CredFin does not take adverse action based solely on automated processing without human review.
  • Right to Explanation: You may request a plain-language explanation of any fundability score or recommendation by contacting your assigned coach or emailing [email protected].
  • AI Training: Your data is never shared with AI model providers for training purposes without separate explicit consent.
SECTION 10 Data Security

CredFin implements reasonable and appropriate technical, administrative, and physical safeguards including:

  • Encryption of data in transit using TLS/SSL
  • Encryption of sensitive data at rest
  • Access controls limiting data access to authorized personnel
  • Multi-factor authentication for systems containing client data
  • Regular security assessments and vendor due diligence
  • Written Information Security Program (WISP) maintained in compliance with the FTC Safeguards Rule
Important: No method of internet transmission or electronic storage is 100% secure. If you believe your account has been compromised, contact us immediately at [email protected] or (949) 828-4020. In the event of a data breach, CredFin will notify you as required by Florida's Information Protection Act (§ 501.171, Fla. Stat.) and applicable federal law.
SECTION 11 Data Retention
Data CategoryRetention Period
Active client account dataDuration of Service Period plus 7 years
Payment and transaction records7 years from transaction date (tax and accounting requirements)
Call recordings3 years from recording date, unless required longer for disputes
Email and SMS communications3 years from last interaction
SMS opt-in / opt-out records5 years (TCPA compliance requirement)
Business credit data (bureau reports)Duration of program plus 2 years
Lead and prospect data (non-enrollees)2 years from last contact, or until opt-out
Website analytics / cookiesUp to 2 years (varies by cookie type)
Legal dispute / compliance records7 years or as required by law

After the applicable retention period, we securely delete or anonymize your information, subject to our legal obligations to retain certain records.

SECTION 12 Children's Privacy (COPPA)

CredFin's services are intended exclusively for business owners and authorized representatives who are 18 years of age or older. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected such information, we will promptly delete it. Contact us at [email protected] if you believe a child has provided us personal information.

CredFin complies with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.) and the FTC's COPPA Rule (16 C.F.R. Part 312).

SECTION 13 California Residents — CCPA / CPRA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights:

Right to KnowRequest the categories and specific pieces of personal information we've collected, the sources, our purposes, and third parties we share with.
Right to DeleteRequest deletion of personal information we hold, subject to exceptions (legal obligations, fraud prevention, etc.).
Right to CorrectRequest correction of inaccurate personal information we maintain about you.
Right to Opt Out of SaleWe do not sell your personal information or share it for cross-context behavioral advertising.
Right to Limit Sensitive DataRequest that we limit use of sensitive personal information to purposes necessary to provide services.
Right to Non-DiscriminationWe will never deny services, charge different prices, or provide lesser quality for exercising these rights.

Submit a California Privacy Request by emailing [email protected] with subject line "California Privacy Request" or calling (949) 828-4020. We respond within 45 days and process up to two requests per 12-month period at no charge. Identity verification may be required.

SECTION 14 Other U.S. State Privacy Rights

Residents of the following states have rights under their respective state privacy laws. CredFin honors these rights for qualifying residents where applicable:

StateLawKey Rights
VirginiaCDPAAccess, correction, deletion, portability, opt-out of sale/targeted advertising, appeal
ColoradoColorado Privacy ActAccess, correction, deletion, portability, opt-out, appeal
ConnecticutCTDPAAccess, correction, deletion, portability, opt-out, appeal
TexasTDPSAAccess, correction, deletion, portability, opt-out
NevadaSB 220 / SB 260Opt-out of sale of covered information
FloridaFlorida Information Protection ActData breach notification rights; security safeguards

To exercise rights under any applicable state law, contact [email protected] and include your state of residence. We will respond within the timeframe required by your state's law.

Many of these laws include business-to-business (B2B) exemptions. Because much of CredFin's data collection occurs in the context of providing services to businesses, some data may fall outside individual consumer rights under these laws. We will evaluate each request on its merits and notify you if an exemption applies.
SECTION 15 International Users

CredFin, Inc. is headquartered in the United States and our services are designed for U.S.-based businesses. If you access our services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our services, you acknowledge and consent to this transfer for the purposes described in this Policy.

SECTION 16 Third-Party Links and Services

Our website and platform may contain links to third-party websites, tools, or services (including lender websites, educational resources, and partner tools). This Privacy Policy does not apply to any third-party websites. We encourage you to review the privacy policies of any third-party site before providing your information. CredFin is not responsible for the privacy practices or content of third-party sites.

When you are introduced to a lender through our Lender Match™ service and visit that lender's website, you are interacting directly with that third party under their own privacy policy.

SECTION 17 Changes to This Privacy Policy

CredFin reserves the right to update or modify this Privacy Policy at any time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy
  • Post a notice on our website homepage for at least 30 days
  • Send an email notification to active clients at the email address on file

Your continued use of our services after the effective date of any update constitutes acceptance of the revised Policy. If you do not agree to the revised Policy, you may terminate your service relationship per the terms of your Client Service Agreement.

SECTION 18 Contact Us — Privacy Requests and Questions

For any privacy-related questions, requests, or complaints, contact us using the information below. We are committed to acknowledging your request within 10 business days and resolving it within the timeframe required by applicable law.

Privacy & Data Rights Contact
Reach our Privacy team directly for data requests, SMS opt-out assistance, or any compliance question.
Email — Privacy [email protected]
Email — Legal [email protected]
SMS Opt-Out Reply STOP to any CredFin text
Mailing Address CredFin, Inc. — Privacy
1395 Brickell Ave, Ste 800
Miami, FL 33131
Website credfin.ai