Privacy Policy

Last Updated: September 15, 2026

I. Who Are We?

CBE Customer Solutions, Inc. (the “Company”), headquartered in Cedar Falls, Iowa, U.S.A., provides accounts receivable management services, business process outsourcing, and contact center solutions for a variety of commercial and consumer market segments.

If you have any questions or comments about this Privacy Policy or our practices, or if you would like to correct, complete, or supplement any of your information we maintain, please contact us:

CBE Customer Solutions, Inc. Attn: Compliance 1309 Technology Parkway Cedar Falls, IA 50613 (866) 206-5283 [email protected]

II. Scope of This Privacy Policy

This Privacy Policy describes the Company’s policies and practices regarding its collection, use, maintenance, and disclosure of personal data, and sets forth your privacy rights. This Privacy Policy applies to the Company’s online information-gathering and dissemination practices for Company web applications including this website (the “Site”), and information collected or received offline, whether directly from you or from other sources.

When you use the Site, you consent to the use of your information in the manner specified in this Privacy Policy. This policy may change periodically as we undertake new personal data practices or adopt new privacy policies. Updates become effective immediately upon posting unless otherwise stated. By your continued use of the Site, you consent to the most recently revised and posted policy.

Use of our Site is strictly limited to persons who are of legal age in the jurisdictions in which they reside and at least eighteen (18) years of age.

III. Third-Party Websites

You may find links to third-party websites on the Site. This Privacy Policy does not apply to any website owned or operated by or on behalf of any other entity. We do not control the content or links on third-party sites and are not responsible for their privacy practices. If you visit other sites, you are subject to those sites’ own privacy policies.

IV. What Personal Information Does the Company Collect, From Where, and Why?

The following describes the categories of personal information the Company may have collected in the preceding 12 months, the sources from which we may have collected it, and the business purposes for which we may have collected it. We do not knowingly solicit, collect, or receive information from or about minors under the age of 18, or from persons residing outside the U.S.A., through the Site or otherwise.

A. Categories of Personal Information

  • Identifiers: Name, address, phone number, email address, Social Security number, and account details.
  • Demographic Information: Age, date of birth, and other demographic data.
  • Commercial Information: Payment history, transaction records, and billing information.
  • Internet or Other Network Activity: IP addresses, cookies, browsing history, and other online interactions with the Site.
  • Professional or Employment-Related Information: Employment status, employer details, and other relevant employment data.
  • Sensitive Information: Legal or court records, bankruptcy filings, or medical-related information for debt servicing, when applicable.
  • Job Applicant Information: Resumes, cover letters, employment history, references, and communications provided as part of the application process.

B. Business Purposes for Processing

  • Authenticating user identity and managing accounts.
  • Facilitating payment processing and collections.
  • Conducting internal analytics for service improvement.
  • Complying with legal or regulatory obligations.
  • Communicating with customers, including resolving disputes or inquiries.
  • Contacting job applicants in connection with potential employment.

C. Information You Provide Directly

You may voluntarily submit Personal Information to us (e.g., name, address, email, telephone number, date of birth, Social Security number, account information, payment information, attorney or court information, bankruptcy information, etc.). That information—whether submitted through the Site, by mail, email, SMS text, telephone, or other channel—is governed by this Privacy Policy.

If you initiate contact with us, we may keep a record of your contact information and correspondence and may use the information you provide to respond, optimize customer service, or manage your account.

For consumer accounts we service: Communications between us are with a debt collector in an attempt to collect a debt. Any information obtained will be used for that purpose.

D. Information From Third Parties

The Company may receive Personal Information from persons acting on your behalf (such as a spouse, power of attorney, attorney, or authorized representative), from our clients (typically creditors and account receivable portfolio owners), from our service providers (such as location services and data scrubbing providers), and from consumer credit reporting bureaus. Information received from credit reporting bureaus is governed by the federal Fair Credit Reporting Act.

E. Information Collected Automatically

The Site automatically collects certain non-personally identifiable information during your visit, including IP addresses, browser type and language, internet service provider, operating system, date/time stamps, user interface interaction data, and browsing history on the Site. We use this information to improve the Site, estimate usage patterns, speed up searches, and improve user experience.

Cookies and Tracking Technologies. We use cookies and may use pixel tags and web beacons to optimize Site functionality and improve your experience. Most browsers allow you to disable or reject cookies by adjusting browser settings.

Do Not Track and Universal Opt-Out Signals. The Company will honor Global Privacy Control (“GPC”) and other legally recognized universal opt-out preference signals transmitted by a user’s browser or device, where required by applicable state law. Where a GPC signal is detected, the Company will treat it as a valid opt-out request for the sale of personal information, sharing for cross-context behavioral advertising, and/or targeted advertising, as applicable under the consumer’s state of residence.

V. What Personal Information Do We Share With Others?

A. We Do Not Sell Personal Information

The Company does not sell your Personal Information to third parties for their own use and does not allow the Company’s service providers to sell or use Personal Information for their own purposes. The Company does not knowingly sell Personal Information of minors under 16 years of age. There have been no sales of non-public Personal Information to third parties for their own use or further disclosure in the past twelve (12) months.

B. Service Providers

We may share your Personal Information with service providers that we contract with to provide a material service, including location service providers, letter and communications vendors, data scrubbers, payment processors, data security providers, and technology support companies. Our service providers are contractually required to implement appropriate security measures, comply with applicable data protection laws, and use your data solely for the authorized business purposes.

C. Clients

We may share your Personal Information with our clients—typically creditors, account receivable portfolio owners, or managers—that engage us as a service provider and direct us to gather or provide Personal Information to fulfill our contractual responsibilities.

D. Credit Reporting Agencies

The Company may provide reports to consumer credit agencies containing Personal Information about the status and current balance of active consumer debt accounts. This information is covered by the federal Fair Credit Reporting Act.

E. At Your Direction

We may share your Personal Information with third parties to whom you or your authorized agents direct us to disclose information in connection with the services we provide.

F. Sale of Company or Assets

In the event of a sale, assignment, liquidation, or transfer of our assets or any portion of our business, we reserve the right to transfer any information we collect to unaffiliated third parties in connection with that event.

G. Law Enforcement and Legal Requests

The Company may disclose Personal Information as required by law enforcement, regulatory entities, or judicial authorities, such as in response to an audit, investigation, or subpoena. We will only disclose information as legally required or necessary to demonstrate compliance with applicable law.

H. Internal Use and Research

The Company reserves the right to use and disclose de-identified, anonymized, or aggregated information for purposes including internal use, analytics, and research.

VI. Data Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, to satisfy our contractual obligations to clients, to comply with our internal policies and procedures, and to comply with applicable law. When personal information is no longer required for these purposes, it is securely deleted or de-identified in accordance with our data retention schedules.

VII. Data Security

The Company is committed to protecting your privacy and takes data security seriously. We maintain physical, electronic, and procedural safeguards designed to protect Personal Information from loss, misuse, unauthorized access, disclosure, alteration, or destruction, implementing industry-standard best practices. Our data security policies and practices are periodically reviewed and modified as necessary and are subject to annual third-party assessments.

VIII. Your Privacy Rights Under State Law

This Section describes the privacy rights available to residents of states that have enacted comprehensive consumer privacy legislation. Your specific rights depend on your state of residence. If you are a resident of one of the states listed below, you may be entitled to exercise the rights described in this Section.

A. States With Comprehensive Privacy Laws

The following table summarizes the states with comprehensive privacy laws currently in effect, the consumer rights they grant, and the applicable enforcement authority. This table is provided for reference and is subject to change as new laws take effect or existing laws are amended.

State (Law)

Effective

Consumer Rights

Enforcer

California (CCPA/CPRA)

Jan 1, 2020 / Jan 1, 2023

Know, Access, Delete, Correct, Opt-Out (Sale/Sharing), Limit Use of Sensitive PI

CPPA / AG

Virginia (VCDPA)

Jan 1, 2023

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Colorado (CPA)

Jul 1, 2023

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Connecticut (CTDPA)

Jul 1, 2023

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Utah (UCPA)

Dec 31, 2023

Access, Delete, Portability, Opt-Out (Sale/Targeted Ads)

AG

Oregon (OCPA)

Jul 1, 2024

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Texas (TDPSA)

Jul 1, 2024

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

Montana (MCDPA)

Oct 1, 2024

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Delaware (DPDPA)

Jan 1, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Iowa (ICDPA)

Jan 1, 2025

Access, Delete, Portability, Opt-Out (Sale/Targeted Ads)

AG

Nebraska (NDPA)

Jan 1, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

New Hampshire (NHPA)

Jan 1, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

New Jersey (NJDPA)

Jan 15, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Tennessee (TIPA)

Jul 1, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

Minnesota (MCDPA)

Jul 31, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling), Appeal

AG

Maryland (MODPA)

Oct 1, 2025

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

Indiana (ICDPA)

Jan 1, 2026

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

Kentucky (KCDPA)

Jan 1, 2026

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

Rhode Island (RIDTPPA)

Jan 1, 2026

Access, Delete, Correct, Portability, Opt-Out (Sale/Targeted Ads/Profiling)

AG

B. Your Rights

Depending on your state of residence, you may have some or all of the following rights with respect to your Personal Information:

  • Right to Know / Right to Access. You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom we have shared it.
  • Right to Delete. You may request that we delete the Personal Information we have collected about you, subject to certain exceptions required by law (for example, where we must retain information to complete a transaction, comply with a legal obligation, or exercise or defend legal claims).
  • Right to Correct. You may request that we correct inaccurate Personal Information we maintain about you.
  • Right to Data Portability. You may request a copy of your Personal Information in a portable, readily usable format.
  • Right to Opt Out of Sale of Personal Information. You may opt out of the sale of your Personal Information to third parties. As stated above, the Company does not currently sell Personal Information.
  • Right to Opt Out of Targeted Advertising. You may opt out of the processing of your Personal Information for purposes of targeted advertising.
  • Right to Opt Out of Profiling. You may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
  • Right to Limit Use of Sensitive Personal Information. Where applicable, you may direct us to limit the use and disclosure of your sensitive Personal Information to purposes necessary to provide the services you have requested.
  • Right to Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights.
  • Right to Appeal. If we deny your privacy rights request, you may appeal that decision. We will provide you with instructions for submitting an appeal in our denial response. If your appeal is also denied, you may have the right to contact your state’s Attorney General to submit a complaint.

C. Sensitive Data

Certain categories of Personal Information may be considered “sensitive” under applicable state law, including Social Security numbers, financial account information, precise geolocation data, health-related information, and certain legal records. Where required by applicable law, the Company will obtain your consent before processing sensitive Personal Information, unless the processing falls within a recognized exception (such as where processing is necessary to perform a contract, comply with a legal obligation, or exercise or defend legal claims).

D. Service Provider Status

Important: The Company acts as a “Service Provider” (or “Processor”) on behalf of its clients, as those terms are defined under applicable state privacy laws. Personal Information that the Company collects, maintains, or processes is at the direction of and within the scope of the Company’s role as a Service Provider, in order to fulfill our contractual responsibilities for the business purposes established in our client contracts. Where we receive a privacy rights request relating to data we process solely as a Service Provider, we may either respond on behalf of the applicable client or inform you that your request should be directed to the client, and, if feasible, provide you with that client’s contact information.

E. Exemptions

Certain Personal Information may be exempt from the requirements of state privacy laws. In particular, information that is subject to the Gramm-Leach-Bliley Act (“GLBA”), the Health Insurance Portability and Accountability Act (“HIPAA”), the Fair Credit Reporting Act (“FCRA”), the Fair Debt Collection Practices Act (“FDCPA”), or other applicable federal law may be partially or fully exempt from state consumer privacy obligations. The availability and scope of these exemptions vary by state; the Company evaluates applicable exemptions on a state-by-state basis when responding to privacy requests.

IX. How to Exercise Your Privacy Rights

A. Submitting a Request

If you are a resident of a state with a comprehensive privacy law and wish to exercise your rights, you may submit a request using any of the following methods:

  • Online: https://paycbegroup.com/CCPA
  • Phone: (866) 206-5283 (toll-free)
  • Email: [email protected]

B. Verification

Before we can respond to your request, we must verify your identity to ensure you are the individual whose Personal Information is the subject of the request (or that you are an authorized agent acting on that individual’s behalf). We may ask you to provide information such as your full name, mailing address, account number, or the last four digits of your Social Security number to verify your identity and locate your records.

To the extent possible, we will use information already in our possession for verification rather than requesting new information. Where heightened verification is required by law (such as for requests to access specific pieces of information), we may require a written declaration under penalty of perjury.

If you authorize another person to act on your behalf, we may require proof of authorization, such as a notarized power of attorney, written authorization verified directly with you, or registration as a designated representative under applicable state law.

C. Response Timelines

We will acknowledge receipt of your request within ten (10) business days and provide a reference number. We will respond to your request within forty-five (45) calendar days of receipt. If additional time is needed, we will notify you of the extension and the reason for it. Under most state laws, we may extend the response period by an additional forty-five (45) days where reasonably necessary.

D. Appeal Process

If we deny your request in whole or in part, our response will explain the basis for the denial and provide instructions for submitting an appeal. We will respond to an appeal within the timeframe required by applicable state law (generally sixty (60) days). If your appeal is denied, we will provide you with information on how to contact your state’s Attorney General to submit a complaint.

E. Fees

We do not charge a fee to process your request unless it is excessive, repetitive, or manifestly unfounded. If a fee is warranted, we will inform you in writing of the reasoning and the estimated cost before completing your request.

X. Children’s Privacy

We do not knowingly collect Personal Information from children under the age of 18 through the Site. We do not knowingly sell or share the Personal Information of consumers under 16 years of age. Where applicable state law imposes additional restrictions on the processing of minors’ Personal Information, we will comply with those requirements.

XI. Data Protection Impact Assessments

Where required by applicable law, the Company conducts Data Protection Impact Assessments (“DPIAs”) for processing activities that present a heightened risk to consumers, including processing of sensitive personal information, processing for purposes of targeted advertising, the sale of personal information, certain profiling activities, and other processing that presents a reasonably foreseeable risk of harm. These assessments evaluate the benefits and risks of the processing activity and identify safeguards to mitigate identified risks.

XII. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting updates on this page and, where appropriate, by direct notification via email. We encourage you to review this policy periodically. The “Last Updated” date at the top of this policy indicates when the most recent revision was made.