Privacy Policy

Last updated: July 4, 2026

This policy explains how PastDue collects and uses information when agencies, debt buyers, servicers, and their authorized users access our collection operations platform.

Information we collect

We collect account information you provide when you create or administer a PastDue workspace, including names, business contact details, login credentials, tenant settings, and billing or support information.

Customers may upload or enter portfolio, debtor, account, payment, contact, document, and activity data into the service. That customer data is controlled by the agency or organization that provided it, and PastDue processes it to provide the service.

We also collect usage, device, log, and security data such as IP address, browser information, pages visited, timestamps, authentication events, and error reports.

How we use information

We use information to provide, secure, maintain, and improve PastDue; create and manage workspaces; authenticate users; process imports; route tenant traffic; deliver transactional emails; provide support; and troubleshoot service issues.

We may use aggregated or de-identified information to understand product performance and improve features. We do not use debtor account data to advertise to consumers.

Customer responsibilities

PastDue is a business tool for collection operations. Customers are responsible for having the rights and notices required to upload, process, contact, or otherwise use debtor and account information in PastDue.

Customers are also responsible for configuring their teams, roles, workflows, scripts, consent records, and compliance procedures for their own legal obligations.

How we share information

We share information with service providers that help us host, secure, operate, store, email, monitor, and support PastDue. These providers may process information only as needed to provide services to us.

We may disclose information if required by law, to protect PastDue, our customers, consumers, or others, to investigate misuse, or in connection with a merger, financing, acquisition, or sale of assets.

We do not sell personal information.

Security and retention

We use administrative, technical, and organizational safeguards designed to protect information in PastDue. No system is perfectly secure, and customers should use strong passwords, role-based access, and careful import practices.

We retain customer data for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and maintain backups or audit records. Customers may request deletion or export according to their agreement and applicable law.

Your choices

Workspace users can update certain profile and company information in the product or by contacting their workspace administrator. Customers may ask us for help accessing, exporting, correcting, or deleting data where supported by the service.

Transactional emails, such as password reset, invite, and verification messages, are required to operate the service and may not include an unsubscribe option.

Children and consumers

PastDue is not directed to children and is not intended for personal, family, or household use by consumers. Consumer-facing balance lookup features, if enabled by a customer, are provided on behalf of that customer.

Changes and contact

We may update this policy as PastDue changes. If changes are material, we will provide notice through the service, by email, or by updating this page.

Questions about this policy can be sent to privacy@pastdue.app.