Breach Notification Policy

Last updated: July 26, 2026

1. Our Commitment

Shortsale Genie™ (a product of The Collective Software Group LLC) takes the confidentiality and integrity of your data seriously. We handle sensitive financial information covered by the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule and state data-breach notification statutes in all 50 U.S. states. This policy explains what we do if a security incident occurs.

2. What We Consider a Breach

A reportable breach is any confirmed unauthorized acquisition of, or access to, unencrypted personal information — including names combined with SSNs, financial account numbers, driver's license numbers, tax return data, bank statements, or hardship documentation stored in your file.

3. Detection & Investigation

4. Notification Timelines

When a breach is confirmed and your data is affected, we will notify you as follows:

5. What Notice Will Contain

6. Regulator Cooperation

We cooperate fully with the FTC, state attorneys general, and (where applicable) the CFPB. We do not delay individual notice for law-enforcement investigations except upon written request from a qualifying agency, as permitted by 15 U.S.C. § 6805 and state law.

7. Reporting a Suspected Incident

If you believe your account has been compromised or you have observed suspicious activity, report it immediately to security@shortsalegenie.com. Include your account email and a description of what you observed. We acknowledge reports within 24 hours.

8. Statutory References

This policy is designed to satisfy the FTC Safeguards Rule (16 CFR Part 314), the GLBA incident-notification interpretive rule, and applicable state breach-notification statutes including but not limited to Cal. Civ. Code § 1798.82, N.Y. Gen. Bus. Law § 899-aa, Tex. Bus. & Com. Code § 521.053, and Fla. Stat. § 501.171. Where a specific state law imposes stricter timelines or content requirements, that law controls.

Questions? See our Security page or contact legal@shortsalegenie.com.