Effective July 29, 2026
Privacy Policy
Credit Orchard is a Michai Media project operated by Midwest Auto & Commerce LLC. This policy explains the information used to provide the service and the controls available to you.
Information we collect
We collect account identity supplied through Sign in with ChatGPT; contact and SMS-consent preferences; the case facts you confirm; supporting evidence files you deliberately add; customer-authorized credit-report information received from an approved provider; agreements and provider status; submission confirmations; support requests; and payment, delivery, and audit identifiers. During the temporary AnnualCreditReport.com bridge, you may deliberately upload up to three saved report files to private Credit Orchard storage. The browser extracts selectable text from those files and sends it only to the authenticated report endpoint. Credit Orchard stores a versioned account-level analysis, field provenance, rule identifiers, and evidence-led findings so the review can be reopened and audited. Do not enter a full Social Security number, bureau password, security answer, or full account number into ordinary Credit Orchard forms.
How information is used
Information is used to authenticate you, organize your case, prepare customer-approved correspondence, operate official online and mail routes, send consented transactional alerts, process post-performance payments, provide support, prevent abuse, and maintain required records.
Service providers
Credit Orchard uses Sites and Cloudflare for hosting, private storage, and versioned signed-agreement records; Stripe for hosted identity and payments; Lob for customer-authorized mail; and Telnyx for consented transactional SMS. If you choose optional monitoring or direct report access, the active credit-data provider is identified before enrollment and presents its own price, authorization, privacy, cancellation, and retention terms. Each provider processes only the information needed for its approved role.
Sharing
We do not sell customer credit-case data. Information is shared with a provider only when necessary for a customer-requested service and authorized access, with government or legal authorities when required, or in a business transaction subject to appropriate protections. Monitoring enrollment and funding inquiries are separate and require their own authorization.
Retention and deletion
Active case information is retained while the service is being provided. Closed-case evidence, customer-uploaded reports and their review summaries, and Credit Orchard-held provider report snapshots are scheduled for removal after two years unless a shorter request is legally permitted or a longer period is required for fraud prevention, dispute resolution, tax, payment, or regulatory records. Customers can download or remove individual uploaded reports and evidence files from the workspace, and can export or delete workspace data from Account & privacy. When workspace data is deleted, the completed signed disclosure record is separated from the customer workspace and retained for two years after signing as required; it is then eligible for removal. Deleting Credit Orchard data does not cancel a separate monitoring subscription. Provider-held monitoring, mailing, identity, and payment records may remain under the provider's terms or legally required period.
Security
We use signed-in access, per-customer record checks, private storage, file limits and type validation, signed webhook verification, minimal provider data, audit events, and transport security. No system is risk-free; report suspected unauthorized access immediately.
Your choices
You may disable SMS, cancel a service case, export your workspace data, delete workspace data, and request correction or assistance. SMS consent is optional and is not a condition of purchase. Reply STOP to opt out or HELP for help.
Contact
Email privacy@creditorchard.com or use the support form. Mail: Credit Orchard, 3407 S Jefferson Ave, St. Louis, MO 63118.