Paste into WordPress page titled "Privacy Policy" | Last Updated: July 25, 2026
1. Introduction
Debt Recovery Experts ("DRE," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, share, store, and protect information when you:
- Visit our website at https://debtrecoveryexperts.com (the "Site")
- Create an account or submit a debt recovery claim through our secure portal
- Use our payment portal or client dashboard
- Receive communications from us, including SMS messages
This Privacy Policy applies to clients (businesses and individuals submitting claims), website visitors, and the individuals whose information we receive in the course of debt recovery (debtors). It is incorporated into the DRE Terms of Use.
By using the Site or Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please do not use the Site or Services.
2. Information We Collect
2.1 Information You Provide Directly
Account and Identity Information: - Full name (individual or authorized business representative) - Business name, Employer Identification Number (EIN), and entity type (for business clients) - Email address, phone number, and physical mailing address - Social Security Number (SSN) or Individual Taxpayer Identification Number (ITIN), for tax and IRS compliance on disbursements - Username and password (hashed; DRE never stores or views your plaintext password)
Claim and Financial Information: - Debtor details: legal name, business name, physical address, phone number, email address - Debt details: amount owed, date incurred, nature of the debt, and prior collection history - Supporting documentation: contracts, invoices, account statements, correspondence, payment records, and proof of delivery or completion - Bank account and routing numbers, for ACH disbursement of collected funds via Stripe Connect
Notarization Information (Remote Online Notarization): - Government-issued photo identification (driver's license, passport, or state ID) - Video and audio recording of the online notarization session - Digital signature and timestamp records - Identity verification results from the RON platform
Communications: - Emails, support requests, and messages sent through the client portal - SMS opt-in and opt-out records (see Section 3.5) - Phone call logs and notes, where applicable
2.2 Information Collected Automatically
When you visit the Site or use the portal, we automatically collect:
- Log Data: IP address, browser type and version, operating system, referring URL, pages viewed, and timestamps.
- Device Information: Device type, screen resolution, and browser settings.
- Usage Data: Features accessed, actions taken, session duration, and click patterns.
- Security Signals: Data processed by Cloudflare Turnstile for bot detection (IP address, user agent, device fingerprint), handled per Cloudflare's privacy addendum.
2.3 Information from Third Parties
We may receive information about you from:
- Proof.com (or equivalent RON platform): Identity verification results and notarization confirmations.
- Stripe Connect: Transaction confirmations and payment status. DRE does not store full payment card numbers.
- Public Records and Skip Tracing: Debtor location information from lawful sources, including court records, Secretary of State business registries, and public databases.
- Partner Law Firms: Case status updates for claims referred to litigation (Tier 4).
3. How We Use Information
3.1 Core Service Delivery
We use your information to:
- Process, evaluate, and manage debt recovery claims (including AI-assisted internal review)
- Communicate with clients: claim status updates, document requests, fee disclosures, disbursement confirmations
- Execute Limited Powers of Attorney via Remote Online Notarization
- Conduct debt collection activities on your behalf (demand letters, phone calls, negotiations)
- Process debtor payments and disburse collected funds to your account via Stripe ACH
3.2 Legal and Compliance
We process information as necessary to:
- Comply with the Fair Debt Collection Practices Act (FDCPA), Texas Finance Code Chapter 392, Telephone Consumer Protection Act (TCPA), Fair Credit Reporting Act (FCRA), and all other applicable laws
- Respond to lawful government requests, court orders, and subpoenas
- Establish, exercise, or defend legal claims
- Detect and prevent fraud, abuse, identity theft, or illegal activity
- Maintain records per statutory retention requirements
3.3 Business Operations
We use information for:
- Account management, authentication, and customer support
- Site and Service improvement, including bug fixes, performance optimization, and user experience enhancements
- Aggregated analytics and reporting (anonymized or de-identified where practicable)
- Security monitoring, threat detection, and incident response
- Administrative notices, security alerts, and policy update notifications
3.4 Communications
We may contact you for:
- Service-Related Messages: Claim status updates, fee disclosures, disbursement confirmations, and account alerts. These are necessary for the performance of the Services.
- Support Responses: Answers to your inquiries, requests, and disputes.
- Marketing (Opt-In Only): Promotional emails about DRE Services. You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email.
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
3.5 SMS Communications
DRE may send SMS text messages for claim status updates, document availability notifications, and disbursement alerts. All SMS communications are transactional and informational — we do not send marketing or promotional text messages.
Consent: We obtain your prior express consent before sending SMS messages to your mobile phone. Consent is collected during account registration or claim submission through a clear, standalone checkbox (not pre-ticked) disclosing the types of messages you may receive and the approximate frequency.
Opt-Out: To stop receiving SMS messages at any time, reply STOP to any message. You may also reply UNSUBSCRIBE, CANCEL, or QUIT. SMS opt-out requests are processed immediately upon receipt. You may also opt out through your portal settings, by calling our office, or by emailing our support team.
HELP: Reply HELP to any message for information about the SMS program and DRE contact details.
Rates: Message and data rates may apply. Please check your mobile plan for details.
Carrier Liability: Carriers are not liable for delayed or undelivered messages.
No Mobile Information Sharing: We do not share, sell, rent, or trade your mobile phone number or SMS opt-in consent with any third party for marketing or promotional purposes. Phone numbers are used exclusively to deliver the transactional communications described above.
10DLC Compliance: DRE sends SMS through 10-Digit Long Code (10DLC) messaging in compliance with The Campaign Registry (TCR) standards, the CTIA Messaging Principles and Best Practices, and applicable carrier requirements. All DRE messages are transactional and informational; we do not send marketing or promotional text messages.
For full SMS program terms, see our SMS & 10DLC Compliance notice.
4. How We Share Information
4.1 Service Providers
We share information with third-party service providers only as necessary to deliver the Services, and only under contractual obligations requiring them to protect your data.
| Service Provider | Information Shared | Purpose | Safeguards |
|---|---|---|---|
| Proof.com (RON Platform) | Name, photo ID, video/audio of session, signature | Execute LPOA under Texas notary law | SOC 2 certified; encrypted in transit and at rest |
| LetterStream | Debtor name, address, letter content | Send certified demand letters | Business associate agreement |
| Stripe Connect | Client name, bank account/routing number, disbursement amount | ACH disbursement | PCI DSS Level 1; DRE does not store full banking details |
| Partner Law Firms | Claim documents, debtor information, correspondence history | Litigation and lien filing (Tiers 2.5/4) | Attorney-client privilege where applicable; confidentiality agreements |
| Cloud Hosting / Infrastructure | All stored data | Data storage, hosting, backup | AES-256 at rest; TLS in transit; access controls |
| Analytics Providers | Aggregated, anonymized usage data | Site performance analytics | De-identified; no personally identifiable information |
4.2 Legal and Regulatory Disclosures
We may disclose information if required to:
- Comply with a legal obligation, court order, or governmental request
- Protect and defend DRE's rights, property, or safety, or that of our clients or others
- Investigate, prevent, or take action regarding suspected fraud, illegal activity, or Terms of Use violations
- Enforce the Terms of Use, Acceptable Use Policy, or other agreements
4.3 Business Transfers
If DRE is involved in a merger, acquisition, asset sale, or bankruptcy, client data may be transferred as part of that transaction. You will be notified of any change in ownership or control affecting your personal information.
4.4 With Your Consent
We may share information with other parties when you give us explicit, informed consent to do so.
4.5 What We Do Not Share
- We do not sell, rent, or trade personal information to data brokers, marketers, or third parties for their own purposes.
- We do not use debtor information for unrelated marketing.
- We do not share Social Security Numbers or identification documents beyond what is required for notarization and tax compliance.
5. Data Security
5.1 Technical Safeguards
We implement and maintain industry-standard security measures, including:
- Encryption: TLS 1.3 for all data in transit; AES-256 for data at rest.
- Access Controls: Role-based access with the principle of least privilege; all administrative access requires multi-factor authentication (MFA).
- Network Security: Firewalls, intrusion detection and prevention systems (IDS/IPS), and regular vulnerability scanning.
- Bot and Abuse Protection: Cloudflare Turnstile on all public-facing forms.
- Regular Testing: Periodic vulnerability assessments, penetration testing, and code reviews.
5.2 Administrative Safeguards
- All personnel with access to sensitive data undergo background checks and receive regular training on data privacy, security, and debt collection compliance.
- We maintain a written information security policy and incident response plan.
- Third-party vendors are subject to due diligence and security assessments before engagement.
5.3 Physical Safeguards
Data is hosted in secure facilities with restricted physical access. Any physical documents we receive are stored in locked, access-controlled storage.
5.4 Data Breach Notification
In the event of a security breach that compromises personal information, we will:
- Notify affected individuals without unreasonable delay, in accordance with the Texas breach notification law (Texas Business and Commerce Code § 521.053 — within 60 days).
- Notify the Texas Attorney General if 250 or more Texas residents are affected.
- Provide the nature of the breach, the types of data involved, the steps we have taken, and recommendations for mitigating potential harm.
5.5 No Absolute Guarantee
While we implement robust safeguards, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we continuously review and improve our defenses.
6. Data Retention
6.1 Retention Schedule
We retain personal information only as long as necessary to fulfill the purposes described in this Policy, or as required by law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account information | Account lifetime + 3 years after closure | Business records; dispute resolution |
| Claim documentation and evidence | 5 years after claim closure | Four-year Texas statute of limitations for written contracts, plus buffer |
| Financial and payment records | 7 years | IRS requirements; tax compliance |
| Notarization records (RON) | Per Texas notary law (TX Gov't Code § 406) | Statutory requirement |
| Communications (email, SMS, call logs) | 3 years | Dispute resolution; FDCPA compliance |
| Website analytics (anonymized) | 2 years | Business analysis |
| Server and security logs | 12 months | Security monitoring; forensic investigation |
6.2 Deletion
When the applicable retention period expires, data is securely deleted or irreversibly anonymized using cryptographic erasure, secure overwrite, or physical destruction, as appropriate.
6.3 Active Claims Exception
Data for open, active claims is retained until the claim is closed. The retention clock starts upon claim closure.
6.4 Legal Holds
If a legal hold is placed on data — for example, during litigation or a regulatory investigation — the retention schedule is overridden, and the data is preserved until the hold is released.
6.5 Account Closure
If you close your account, your data is retained per the schedule above. After the retention period, it is securely deleted. You may request earlier deletion subject to the exceptions in Section 7.3.
7. Your Rights and Choices
7.1 Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
| Right | What It Means |
|---|---|
| Access | You may request a copy of the personal data we hold about you. |
| Correction | You may request correction of inaccurate or incomplete data. |
| Deletion | You may request deletion of your personal data, subject to legal and regulatory exceptions. |
| Restriction | You may request limited processing in certain circumstances. |
| Portability | You may request your data in a structured, machine-readable format. |
| Objection | You may object to processing for direct marketing (this is an absolute right). |
| Opt-Out of Sale | DRE does not sell personal data, but we acknowledge this right. |
| SMS Opt-Out | Reply STOP to any SMS, or update preferences in your portal settings. |
7.2 How to Exercise Your Rights
To exercise any of these rights, contact us using the information in Section 12. We will verify your identity before processing your request, which may require you to provide additional information. We respond to verified requests within 45 calendar days, in accordance with the Texas Data Privacy and Security Act.
The first request in any 12-month period is processed at no charge. For excessive or repetitive requests, we may charge a reasonable fee. If we deny a request, we will explain the reason for the denial and inform you of your right to appeal.
7.3 Exceptions to Deletion
We may deny deletion requests if the data is required for:
- Completing an active debt recovery claim.
- Compliance with legal obligations (FDCPA, Texas Finance Code, IRS retention requirements).
- Detecting or preventing fraud, security incidents, or illegal activity.
- Establishing, exercising, or defending legal claims.
- Internal uses that are reasonably aligned with consumer expectations.
7.4 Texas Privacy Rights
Under the Texas Data Privacy and Security Act (effective July 1, 2024), Texas residents have the right to opt out of targeted advertising and profiling. DRE does not engage in targeted advertising or profiling that would trigger these rights. Texas residents may file complaints with the Texas Attorney General's Consumer Protection Division.
7.5 California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) may provide you with additional rights, including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale or sharing of personal information. DRE does not sell or share personal information as defined under California law. We will honor verified CCPA requests where applicable. We do not discriminate against anyone for exercising their privacy rights.
8. Cookies and Tracking Technologies
8.1 Types of Cookies We Use
| Type | Purpose | Duration | Examples |
|---|---|---|---|
| Essential | Site functionality: login sessions, security checks, form submissions | Session to persistent | Authentication tokens, CSRF tokens, Turnstile bot detection |
| Functional | User preferences and portal settings | Up to 1 year | Language preferences, dashboard layout |
| Analytics | Anonymized usage data: page views, load times, errors | Up to 2 years | Google Analytics (with anonymized IP) |
| Marketing | DRE does not use marketing or advertising cookies | N/A | N/A |
8.2 Your Cookie Choices
You can configure your browser to block, delete, or limit cookies. You may opt out of Google Analytics by visiting https://tools.google.com/dlpage/gaoptout. Please note that blocking essential cookies may affect the functionality of the Site and portal.
8.3 Do Not Track
DRE respects Do Not Track (DNT) browser signals where technically feasible. We do not track users across third-party websites for advertising purposes.
9. Children's Privacy
DRE's Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that a child's data has been collected, we will promptly delete it. If you are a parent or guardian and believe your child has provided personal information to us, please contact us immediately.
10. Third-Party Services and Links
Our Site and portal integrate with third-party services — including Proof.com (RON), LetterStream (certified mail), and Stripe Connect (payments). Our Site may also contain links to third-party websites, such as partner law firm sites.
This Privacy Policy does not govern the privacy practices of third parties. We encourage you to review the privacy policies of any third-party service before providing your information.
11. International Data Transfers
DRE is based in the United States and stores all data on servers located in the United States. If you access the Site or Services from outside the United States, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction. By using the Services, you consent to this transfer.
12. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services. Changes will be posted on this page with an updated "Last Updated" date.
For material changes, we will provide notice by email (if we have your email on file) and/or by displaying a prominent notice on the Site. Your continued use of the Services after changes are posted constitutes your acceptance of the updated Privacy Policy. Archived versions of prior policies are available upon request.
13. Contact and Complaints
13.1 Contact DRE
For questions about this Privacy Policy, to exercise your privacy rights, or to report a concern:
Debt Recovery Experts (DRE) [Street Address] [City], TX Email: support@debtrecoveryexperts.com Phone: [Phone] Data Protection Contact: Debt Recovery Experts Compliance Team
13.2 File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with:
Texas Attorney General — Consumer Protection Division P.O. Box 12548 Austin, TX 78711-2548 Phone: (800) 621-0508 Website: https://www.texasattorneygeneral.gov
Federal Trade Commission (FTC) Website: https://reportfraud.ftc.gov For FDCPA or FCRA-related privacy complaints.
⚠️ ATTORNEY REVIEW REQUIRED: This document must be reviewed by a licensed Texas attorney before publication. Key review items: Texas Data Privacy and Security Act applicability and full compliance assessment, CCPA/CPRA applicability determination, data retention periods vs. statutory requirements for debt collectors, SMS consent language for TCPA compliance, and adequacy of international data transfer provisions.
© 2026 Debt Recovery Experts. All rights reserved.