SimpleCheck/Legal & Compliance
FCRA Compliant - Industry Leading Standards

Legal & Compliance

SimpleCheck doesn't just meet the legal bar - we built the bar. Every soft pull is consent-based, FCRA compliant, and leaves zero impact on the prospect's credit score.

๐Ÿ›ก
FCRA
Fully Compliant
Soft pull framework built to exceed FCRA requirements
โœ…
100%
Consent-Based
Every single pull requires explicit written consumer opt-in
0๏ธ
Zero
Credit Score Impact
Soft inquiries never appear on the consumer's credit report
๐Ÿ”
IP
Captured at Consent
CredibleCapture records a timestamped digital consent record on every pull
SimpleCheck's Compliance Commitment

We are at the forefront of legal compliance in the soft pull services industry. Our unwavering commitment to exceeding regulatory requirements is fundamental to how we operate - ensuring that every business using SimpleCheck and every consumer whose data is accessed can do so with full confidence in the legal integrity of the platform.

1

Compliance Overview

Active
๐Ÿ“‹
FCRA

Fair Credit Reporting Act - the primary federal law governing how consumer credit data is collected, shared, and used.

๐Ÿ”’
Data Security

End-to-end encryption, access controls, and audit logging built to the same standards you'd expect from a regulated financial institution.

โœ
Consumer Consent

CredibleCapture records explicit, time-stamped, IP-verified consent before any data is accessed - on every single pull.

2

FCRA - Fair Credit Reporting Act

Compliant
โš–
Important Client Responsibility

FCRA compliance is a shared obligation. SimpleCheck provides the consent framework and soft pull infrastructure. You, as the business using SimpleCheck, are responsible for using the data only within the permitted scope described here and in your Terms of Service. Using SimpleCheck data for employment, housing, or credit decisions without additional FCRA consent and adverse action procedures is a violation of your agreement with SimpleCheck and may expose you to independent regulatory liability.

3

Soft Pull Technology

Zero Credit Impact
Soft Pull (SimpleCheck)
No credit score impact
Not visible to other creditors
Consent-based and FCRA compliant
Used for pre-qualification signaling
Consumer can decline without consequence
Hard Pull (NOT SimpleCheck)
Can lower credit score 5-10 points
Visible to all future creditors for 2 years
Requires different consent framework
Used for formal credit applications
May trigger FCRA adverse action rules
5

HIPAA - Why It Doesn't Apply

๐Ÿฅ
Healthcare Vertical Clients

SimpleCheck is used by dental practices, med spas, cosmetic surgery centers, and fertility clinics to pre-qualify patients on financial capacity - not to access or process health information. Your HIPAA obligations remain separate and are not affected by your use of SimpleCheck. If you have specific questions about how SimpleCheck integrates with your compliance framework, contact our team at support@simplecheck.com.

6

Data Security Standards

Enterprise Grade
๐Ÿ”’
End-to-End Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). No unencrypted consumer data exists anywhere in our systems.

๐Ÿ‘ค
Access Controls

Role-based access controls ensure that only authorized personnel can access consumer data, and only for the purposes defined in our data governance framework.

๐Ÿ“‹
Audit Logging

Every data access event is logged with timestamp, user identity, and action taken. These logs are immutable and retained for compliance review.

๐Ÿ”
Proactive Compliance Audits

Our compliance protocols are continuously evaluated against the latest legal standards. We adapt to regulatory changes before they become enforcement actions.

๐Ÿ”
CredibleCapture Integrity

Consent records created by CredibleCapture are cryptographically signed and cannot be modified retroactively - ensuring tamper-proof proof of consent.

๐Ÿ›ก
Vendor Security

All third-party data partners and sub-processors are vetted for security compliance before integration and reviewed on an ongoing basis.

7

Record-Keeping & Audit Trail

Retention Schedule
Consumer financial data signals
90 days (active)
Purged from active systems
Consent records (CredibleCapture)
24 months minimum
FCRA audit compliance
Billing and payment records
7 years
Standard business/tax requirements
Audit logs
24 months
Security and compliance review
8

Client Compliance Obligations

โœ…
The Short Version

SimpleCheck handles the infrastructure. You handle your forms. Specifically: put the consent language on every form that triggers a pull. Use the data for sales pre-qualification only. Don't share it. Tell us immediately if anyone asks about it officially.

9

Consumer Rights

10

Contact Compliance Team

General Compliance
Mon-Fri, 9am-6pm ET
Mailing Address
SimpleCheck LLC
254 Chapman Rd, Ste 208
Newark, Delaware 19702
Consumer Data Requests
Response within 5 business days
Deletion within 30 days
Fully Compliant - FCRA, Soft Pull Only

Comfortable with how we operate?

500+ businesses trust SimpleCheck. Every pull is consent-based, FCRA compliant, and leaves zero credit score impact. Your leads never know it happened.

Soft pull only - zero credit impact
Consent captured on every pull
Up in under 15 minutes