Legal

Privacy Policy

Effective date: [PLACEHOLDER: effective date]

1. Scope

This policy applies to personal information we collect (a) from visitors to this website, (b) from consumers whose accounts have been placed with us for collection by our clients, and (c) from client representatives and prospective clients. It does not apply to the practices of our clients, credit bureaus, payment processors, or other third parties, whose own privacy policies govern their handling of your information.

2. Information we collect

Information provided by our clients

When a business places an account with us, it provides information necessary to service that account, which may include your name, contact information, account number, balance and payment history, date of birth, Social Security number or other identifiers, and, for medical accounts, limited information about the services billed. We receive this information as a service provider to the creditor.

Information you provide

We collect information you give us directly — for example, when you email us, submit a form on this website, dispute a debt, make a payment, or set up an arrangement. This may include your name, email address, mailing address, telephone number, account reference number, payment information, and the contents of your communications.

Information from other sources

Where permitted by the Fair Credit Reporting Act and other law, we may obtain information from consumer reporting agencies, public records, and licensed data providers to verify identity and locate current contact information.

Information collected automatically

When you visit this website, our hosting provider's servers automatically record technical information such as your IP address, browser type, device type, pages viewed, and the date and time of your visit. See Cookies and website data below.

3. How we use information

We use personal information to: identify and locate consumers whose accounts have been placed with us; communicate about accounts; verify and respond to disputes; process payments and arrangements; furnish information to consumer reporting agencies where permitted and authorized; report to our clients; comply with legal, regulatory, and licensing obligations; prevent fraud and protect the security of our systems; respond to inquiries; and operate, maintain, and improve this website.

We do not sell personal information, and we do not use consumer account information for marketing purposes.

4. How we share information

We share personal information only as needed to provide our services and as permitted or required by law, including with:

  • Our clients (the creditors who placed your account), to report on account activity and remit payments.
  • Service providers who perform functions on our behalf — such as letter printing and mailing, telephony, payment processing, secure data hosting, and skip-tracing data providers — under contracts that restrict their use of the information.
  • Consumer reporting agencies, where permitted by law and authorized by the client.
  • Regulators, courts, and law enforcement when required by law, subpoena, or licensing obligation.
  • Attorneys representing you, once we are informed of the representation, or independent counsel to whom an account is referred with client authorization.
  • Successors in the event of a merger, acquisition, or sale of assets, subject to this policy.

We do not disclose the existence of a debt to third parties except as permitted by the Fair Debt Collection Practices Act.

5. GLBA privacy notice

Ivy Recovery Group is subject to the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations as a service provider to financial institutions and, in certain activities, as a financial institution itself. Under the GLBA:

  • We collect nonpublic personal information from the sources described in Section 2.
  • We disclose nonpublic personal information only as permitted by the GLBA's exceptions — for example, to service or process an account, to consumer reporting agencies, to protect against fraud, to comply with law, or to service providers under confidentiality agreements. Because we share only under these exceptions, no opt-out right applies to that sharing.
  • We maintain a written information security program designed to meet the GLBA Safeguards Rule, described in Section 7.

If we ever intend to share nonpublic personal information with nonaffiliated third parties outside the GLBA exceptions, we will first provide notice and an opportunity to opt out as the law requires.

6. State privacy rights

Depending on where you live, state law may give you rights regarding your personal information, such as the right to know what information we hold, to request correction or deletion, to opt out of certain sharing, and to not be discriminated against for exercising those rights. Many state privacy laws exempt information governed by the GLBA and the FCRA, which covers most of the information we hold about consumer accounts; where an exemption does not apply, we will honor your rights as the applicable law provides.

To make a request, email support@ivyrecoverygroup.com with "Privacy Request" in the subject line. We will verify your identity before acting on a request and respond within the time required by your state's law. You may designate an authorized agent to make a request on your behalf, subject to verification.

[PLACEHOLDER: add state-specific disclosures required for the states in which you operate — e.g., California (CCPA/CPRA) categories of information and "Notice at Collection," and any other applicable state statutes]

7. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, or disclosure, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication, employee training, vendor oversight, and a written incident-response plan. No system is perfectly secure; if we become aware of a breach affecting your information, we will notify you and the appropriate authorities as required by law. Our Compliance & Security page describes our program in more detail.

8. Retention

We retain personal information for as long as needed to service the account, satisfy our contractual obligations to clients, comply with legal and regulatory record-keeping requirements (which for collection records is generally at least three years after our last collection activity under Regulation F, and longer under some state laws), and resolve disputes. When information is no longer needed, we securely destroy it.

9. Cookies and website data

This website is a static informational site. It does not use advertising cookies or third-party tracking pixels. Our hosting provider records standard server logs for security and performance. Fonts are loaded from Google Fonts, which may receive your IP address when fonts are requested; see Google's privacy policy for details. [PLACEHOLDER: if you add analytics (e.g., Google Analytics) or a payment portal, describe the cookies and data collected here and consider a consent banner where required]

Contact forms on this website send the information you enter to support@ivyrecoverygroup.com by email. The forms include an invisible field used to detect automated spam; no information about legitimate visitors is retained by that mechanism.

10. Children

This website is not directed to children under 13, and we do not knowingly collect personal information from children through it.

11. Changes to this policy

We may update this policy from time to time. The effective date at the top of the page indicates when it was last revised. Material changes will be posted on this page.

12. Contact us

Questions, requests, or concerns about privacy may be sent to support@ivyrecoverygroup.com. Mailing address: [PLACEHOLDER: mailing address if required].