Skip to content
tltradelines.ai

Legal

Privacy Policy

How we collect, use, share, and protect personal information.

Version
1
Effective date
July 2, 2026
Entity
Learning Machines LLC d/b/a Tradelines.AI
Source-of-record
framework/legal/privacy-policy-v1-2026-06-29.md

Learning Machines LLC d/b/a Tradelines.AI (“we,” “us,” “our”) provides credit services that require us to handle some of the most sensitive information a person has. This policy describes what we collect, why, how we protect it, with whom we share it, and your rights. It applies to the tradelines.ai website and all interactions with our team.

1. Information We Collect

You provide directly: your name, mailing address, email address, and telephone number; identity-verification information including date of birth, Social Security number, and government-issued identification; your tradeline selection and order details; your uploaded wire confirmation or sending-bank receipt (which may include your sending bank’s name and account information); and the content of your communications with us, including with our site assistant.

Collected automatically: IP address, browser and device information, pages viewed, and referring URLs; session cookies required for the Site to function, and limited preference and analytics cookies you can control through your browser.

From third parties: confirmation from the issuing bank that your authorized-user enrollment posted; confirmation from our business banking institution that your wire transfer has been received; and your signed agreement and signature audit certificate from our electronic-signature provider.

2. Why We Collect It

We collect and use this information only to: perform the service you purchased (registering you as an authorized user); verify your identity and prevent fraud; process wire payments and any refunds as described in your Consumer Agreement; communicate with you about your order; send you tips and offers by email, and by text if you asked for them; meet our legal obligations, including contract, disclosure, and recordkeeping requirements under the Texas Credit Services Organization Act, and tax law; and improve our services using only aggregated, de-identified data. We will not use your information for a materially different purpose without first giving you notice and any opt-out the law requires.

3. With Whom We Share It

We share your information only as needed to perform the service or as the law requires:

  • The issuing bank for the card on which you are enrolled: your name, date of birth, address, and Social Security number, solely to register you as an authorized user. The bank’s own privacy policy governs its use.
  • The cardholder whose account you are added to: your name, address, date of birth, and Social Security number, because that person is the one who submits the authorized-user request to the bank. Your Social Security number is disclosed to that cardholder when it is needed to complete the request with the bank; that access requires multi-factor authentication and every access is logged. No part of your Social Security number — not even the last four digits — and no date of birth is shown to any cardholder before your three-business-day cancellation period has expired, and no authorized-user request is submitted to any issuing bank before then.
  • Our business banking institution: information needed to identify your incoming wire transfer and to issue refunds, including the originating account information shown on your uploaded receipt and your mailing address on file.
  • Our electronic-signature provider: your agreement and acknowledgment records.
  • Our infrastructure providers (database and hosting): encrypted operational data, under contractual data-protection obligations.
  • Government authorities when required by law, regulation, or valid legal process, or to protect our legal rights.
  • A successor entity in a sale, merger, or change of control, subject to this policy’s protections continuing.

We do not sell your personal information, and we do not share it with anyone for third-party marketing. We do not share mobile phone numbers or text-message consent with any third party for marketing. We may use or share aggregated, de-identified information that cannot identify you.

4. How We Protect It

We maintain an information security program designed to meet the Gramm-Leach-Bliley Act Safeguards Rule (16 C.F.R. Part 314). Current measures include:

  • Field-level encryption of your Social Security number and date of birth, in addition to full-database encryption at rest; encryption keys are stored separately from the database.
  • Secure file storage for uploaded receipts: wire confirmations and other documents you upload are stored in encrypted object storage, accessed only through short-lived signed links, and never embedded directly in our application logs. Any bank account or routing information present on an uploaded receipt is protected at the file level by this storage layer; we do not extract or separately store those numbers.
  • Encryption in transit over TLS for all communication between your device and our servers and between our servers and our service providers.
  • Least-privilege access controls: your sensitive information is accessible only to personnel whose role requires it, and our operations role cannot access Social Security numbers at all.
  • Multi-factor authentication required for every administrative account with access to customer information.
  • Access auditing: every read and write of sensitive fields — including each time a Social Security number is accessed or an uploaded wire receipt is opened — is recorded in an append-only audit log.

No security program eliminates all risk. Section 7 describes what we will do if a breach occurs.

5. Retention and Disposal

We retain: signed agreements and cancellation records for at least 5 years after the customer relationship closes; transaction records as tax law requires, typically 7 years; and communications consent records for the duration of consent plus 5 years. When information is no longer required, we delete or irreversibly anonymize it using secure disposal procedures.

6. Your Rights and Choices

Access and correction: request a copy of your information, or correction of inaccurate information, at privacy@tradelines.ai. We verify identity before honoring any request.

Deletion: request deletion at the same address. Deletion is subject to the retention obligations in Section 5; we will tell you what must be retained and why, and delete the rest.

GLBA sharing opt-out: federal law gives you the right to opt out of certain sharing with non-affiliated third parties for marketing. We do not engage in that sharing, so there is nothing to opt out of; if that ever changes, we will provide the required notice and opt-out first.

Texas residents: you have the breach-notification rights described in Section 7, under Tex. Bus. & Com. Code § 521.053.

7. Breach Notification Commitment

If a security incident affects your sensitive personal information (your name combined with your Social Security number, government-ID number, or financial account identifier), we will: notify you without unreasonable delay and no later than 60 days after determining a breach occurred; notify the Texas Attorney General within 30 days if 250 or more Texas residents are affected; notify the nationwide consumer reporting agencies if 10,000 or more individuals are affected at one time; and give you the information you need to protect yourself, including what data was involved and the protective steps available to you. Our internal incident-response procedures are maintained as part of our information security program.

8. Children

Our services are for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact privacy@tradelines.ai and we will delete it.

9. United States Only

Our services are intended for U.S. residents in the states where we operate (see tradelines.ai/availability). Information is processed in the United States under U.S. law.

10. Changes to This Policy

Material changes will be communicated to you by email at least 30 days before they take effect. The current version, with its effective date, is always available on the Site.

11. Contact

Email: privacy@tradelines.ai
Mail: Learning Machines LLC, Attn: Privacy, 2267 Trawood Dr, Suite A-2, El Paso, TX 79935