Lun-Vie 9:30a-6:30p
    Legal Document

    Privacy Policy

    MESA & CO CONSULTING LLC DBA MESA GROUP CONSULTING

    Effective Date: [TBD — date of publication]
    Last Updated: [TBD — date of publication]

    Table of Contents

    1
    INTRODUCTION

    Welcome to Mesa Group Consulting. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how MESA & CO CONSULTING LLC, doing business as Mesa Group Consulting ("Mesa Group," "we," "us," or "our"), collects, uses, shares, and protects your information when you:

    • Visit our website at www.mesafinanciera.com
    • Use our services (credit repair, business funding, credit monitoring, DIY training, financial consulting, life insurance referrals)
    • Communicate with us via email, phone, SMS, or other channels
    • Create an account or client portal access
    • Submit forms or inquiries through our website

    By using our website or services, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our website or services.

    Important Legal Compliance:

    Mesa Group Consulting complies with applicable federal and state privacy and consumer protection laws, including:

    • • Gramm-Leach-Bliley Act (GLBA)
    • • Fair Credit Reporting Act (FCRA)
    • • Credit Repair Organizations Act (CROA)
    • • Telemarketing Sales Rule (TSR)
    • • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
    • • Telephone Consumer Protection Act (TCPA)
    • • CAN-SPAM Act
    • • State-specific privacy laws (see Section 14)

    Anti-Phishing Notice:

    We will never ask you to provide sensitive personal information (such as your Social Security Number or password) by email. DO NOT RESPOND to any email that appears to be from us requesting such information. If you receive a suspicious communication, contact us immediately at compliance@mesagroupconsulting.com or 661-310-3040.

    2
    INFORMATION WE COLLECT

    2.1 Information You Provide Directly

    We collect information that you voluntarily provide to us, including:

    Personal Identification Information:

    • • Full legal name
    • • Date of birth
    • • Social Security Number (for credit services only)
    • • Government-issued ID (driver's license, passport)
    • • Email address
    • • Phone number (mobile and landline)
    • • Mailing address and physical address

    Financial Information:

    • • Income and employment details (for debt-to-income ratio calculations and action plans)
    • • Bank account information (for payment processing)
    • • Credit card information (processed securely through third-party payment processors)
    • • Business financial information (for business funding services)
    • • Credit report information (obtained with your authorization)

    Account Information:

    • • Username and password for client portal access
    • • Security questions and answers
    • • Communication preferences
    • • Service preferences and selections

    Communications:

    • • Messages sent through our website contact forms
    • • Email correspondence
    • • Phone call recordings (with notice and consent)
    • • SMS text messages
    • • Support tickets and inquiries
    • • Client portal messages

    Service-Specific Information:

    • • Credit disputes and dispute documentation
    • • Creditor communications and correspondence
    • • Business funding applications and supporting documents
    • • Financial goals and objectives
    • • DIY training progress and materials accessed
    • • Life insurance application information (where applicable)

    2.2 Information We Collect Automatically

    When you visit our website or use our services, we automatically collect:

    Device and Usage Information:

    • IP address
    • Browser type and version
    • Operating system
    • Device type (desktop, mobile, tablet)
    • Unique device identifiers
    • Pages visited and time spent on pages
    • Referring website/source
    • Click-through data
    • Date and time stamps

    Cookies and Tracking Technologies:

    • Session cookies and persistent cookies
    • Web beacons and pixel tags
    • Click-Through URLs (used in email communications to measure interest and engagement)
    • Google Analytics data
    • Facebook Pixel data
    • Retargeting and advertising cookies
    • GoHighLevel (GHL) tracking

    For more details, see our Cookie Policy and Section 5 below.

    2.3 Information from Third Parties

    We may receive information about you from:

    Credit Bureaus:

    • • Experian, Equifax, and TransUnion credit reports (with your written authorization)
    • • Credit monitoring updates and alerts
    • • Credit score information

    Service Partners:

    • • SmartCredit (credit monitoring services)
    • • Novae (business funding and debt relief for business and personal)
    • • SuperMoney (financial product comparisons)
    • • Ava Finance, CreditStrong, Self (credit building platforms)
    • • RentReporters, Rental Kharma, BoomPay, Experian Boost (credit building and rent reporting)
    • • PolicyGenius (life insurance comparison platform)
    • • Various life insurance carriers (for life insurance applications)
    • • Trust & Will (estate planning document platform)
    • • Various lenders (through SuperMoney and other lending networks)

    Business Information Providers:

    • • Business credit bureaus (Dun & Bradstreet, Experian Business)
    • • Public business records and filings
    • • Business verification services

    Marketing and Analytics Providers:

    • • Social media platforms (Facebook, Instagram, TikTok, YouTube, X/Twitter, LinkedIn)
    • • Email marketing platforms
    • • Advertising networks

    3
    HOW WE USE YOUR INFORMATION

    3.1 Providing Services

    • Processing your enrollment and service agreements
    • Conducting credit report analysis and identifying disputed items
    • Preparing and submitting dispute letters to credit bureaus and creditors
    • Facilitating business funding applications and connecting you with lending partners
    • Providing credit monitoring services through SmartCredit
    • Delivering DIY credit repair training materials and resources
    • Offering financial consulting and personalized action plans
    • Connecting you with life insurance carriers
    • Calculating debt-to-income ratios and creating financial strategies
    • Managing your client portal account and access
    • Processing payments and billing
    • Providing customer support and responding to inquiries

    3.2 Communication and Marketing

    • Sending service-related notifications and updates
    • Providing progress reports and credit monitoring alerts
    • Sending promotional emails about our services, features, and offers
    • Sending SMS messages (consistent with Section 7)
    • Conducting customer surveys and feedback requests
    • Sending newsletters and educational content
    • Following up on abandoned forms or incomplete applications

    3.3 Website Optimization and Analytics

    • Analyzing website traffic and user behavior
    • Understanding how visitors interact with our website
    • Improving website functionality and user experience
    • Testing new features and content
    • Identifying technical issues and bugs
    • Optimizing marketing campaigns and advertising performance

    3.4 Legal and Compliance Purposes

    • Complying with CROA, FCRA, GLBA, CCPA, TCPA, TSR, and other applicable laws
    • Responding to legal requests, court orders, and subpoenas
    • Protecting against fraud, unauthorized access, and illegal activity
    • Enforcing our Terms & Conditions and service agreements
    • Defending legal claims and litigation
    • Conducting internal audits and compliance reviews

    3.5 Business Operations

    • Processing transactions and payments
    • Managing client relationships and accounts
    • Training staff and quality assurance
    • Conducting research and development
    • Evaluating and improving our services
    • Business planning and strategic decision-making

    4
    HOW WE SHARE YOUR INFORMATION

    Mesa Group Consulting does not sell your personal information to third parties. We may share your information in the following circumstances:

    4.1 Service Partners (As Needed)

    We share information with trusted service partners only when necessary to provide services you have requested.

    Credit Repair Services:

    • • In-house fulfillment (not outsourced to third parties).

    Credit Monitoring:

    • SmartCredit: Client information for 3-bureau credit monitoring services (name, DOB, SSN, address)

    Business Funding:

    • Novae: Business and personal information for funding applications and debt relief services (business details, financial info, owner information)

    Financial Product Comparisons:

    • SuperMoney: Basic information for product recommendations and comparisons

    Credit Building Platforms:

    • Ava Finance, CreditStrong, Self: Information necessary to enroll clients in credit-building products

    Rent Reporting Services:

    • RentReporters, Rental Kharma, BoomPay, Experian Boost: Information necessary to report rental and utility payments to credit bureaus

    Life Insurance Referrals:

    • PolicyGenius: Information necessary to compare life insurance options
    • Various life insurance carriers: Application information necessary to obtain quotes and underwrite policies

    Estate Planning:

    • Trust & Will: Information necessary to create estate planning documents

    Lending Network:

    • Various lenders (through SuperMoney and other lending networks): Information necessary for loan applications and pre-qualification

    Important: Not every client's information is shared with all partners. Sharing only occurs when you enroll in specific services that require partner fulfillment.

    4.2 Credit Bureaus and Creditors

    With your written authorization, we share information with:

    • Experian, Equifax, and TransUnion (for credit report disputes and investigations)
    • Creditors, collection agencies, and data furnishers (for dispute resolution)
    • Business credit bureaus (for business credit services)

    4.3 Payment Processors

    We use secure third-party payment processors to handle credit card, debit card, and ACH transactions. Your payment information is transmitted directly to these processors and is not stored on our servers.

    4.4 Technology and Service Providers

    We share information with technology providers that help us operate our business:

    • GoHighLevel (GHL): CRM, email marketing, SMS marketing, automation, client portal hosting, call recording storage
    • Skool: Educational content platform, community access, course delivery
    • Google Analytics: Website analytics and performance tracking
    • Facebook/Meta: Advertising, retargeting, and social media marketing
    • Web hosting providers: Secure website hosting and storage
    • Cloud storage providers: Secure document storage, backup, and call recording storage/transcription
    • Email service providers: Transactional and marketing email delivery

    4.5 Legal and Regulatory Requirements

    We may disclose your information when required by law or to:

    • Comply with legal processes (subpoenas, court orders, regulatory requests)
    • Enforce our Terms & Conditions and service agreements
    • Protect the rights, property, or safety of Mesa Group, our clients, or others
    • Prevent fraud, security threats, or illegal activity
    • Cooperate with law enforcement or government agencies

    4.6 Business Transfers

    In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity or successor organization. You will be notified of any such change via email and/or prominent notice on our website.

    4.7 With Your Consent

    We may share your information with third parties when you provide explicit consent or direct us to do so.

    Important Note: We do not sell, rent, or lease your personal information to third-party marketers, data brokers, or advertisers. See also our Do Not Sell or Share My Personal Information page.

    5
    COOKIES AND TRACKING TECHNOLOGIES

    Mesa Group Consulting uses cookies, web beacons, pixels, and similar tracking technologies to enhance your experience and analyze website performance.

    5.1 Types of Cookies We Use

    Essential Cookies:

    Required for basic website functionality, security, and session management. These cannot be disabled.

    Analytics Cookies:

    Google Analytics and other analytics tools track website traffic, user behavior, page views, and performance metrics.

    Marketing Cookies:

    Facebook Pixel, Instagram ads, TikTok Pixel, YouTube ads, X (Twitter) ads, LinkedIn Insight Tag, Google Ads cookies, and other advertising/retargeting cookies track conversions, ad performance, and enable personalized advertising.

    Functional Cookies:

    Store preferences, language settings, and personalization options to improve your experience.

    Third-Party Cookies:

    Cookies set by third-party services like GoHighLevel, Google, Facebook, and other platforms we use.

    5.2 Cookie Consent

    When you first visit our website, you will be presented with a cookie consent notice allowing you to accept, reject, or customize your cookie preferences. Essential cookies will load by default, while non-essential cookies (analytics, marketing, functional) will only load with your consent. You can change your preferences at any time through the cookie settings link in our website footer.

    5.3 Managing Cookies

    You can also control cookies through your browser settings:

    • Block All Cookies: May prevent website functionality
    • Delete Cookies: Removes existing cookies from your device
    • Third-Party Cookies: Can be blocked separately in most browsers

    To opt out of interest-based advertising:

    For more details, see our dedicated Cookie Policy.

    6
    EMAIL MARKETING

    We use GoHighLevel (GHL) and other email platforms to send:

    • Promotional emails about our services and offerings
    • Educational content and newsletters
    • Service updates and announcements
    • Special offers and discounts

    Opt-Out: Every marketing email includes an unsubscribe link. You can also email compliance@mesagroupconsulting.com to opt out.

    CAN-SPAM Compliance:

    We comply with the CAN-SPAM Act by:

    • • Including accurate sender information
    • • Providing clear subject lines
    • • Honoring opt-out requests within 10 business days
    • • Including our physical address in emails

    7
    SMS / TEXT MESSAGING

    Mesa Group Consulting separates SMS communications into two categories: service-related SMS and marketing SMS. Each is governed by different consent requirements.

    7.1 Service-Related SMS (Required for Account Security and Service Delivery)

    We may send service-related SMS messages for purposes including:

    • Identity verification and multi-factor authentication (MFA)
    • One-time passwords (OTP) for account access
    • Account security alerts (login from new device, password reset)
    • Appointment reminders and scheduled call confirmations
    • Critical service notifications (document requests, dispute results, time-sensitive updates)
    • Credit monitoring alerts (if enrolled)

    These messages are necessary to provide and secure the services you have requested. By providing your mobile number when enrolling in our services, you consent to receive service-related SMS messages. Your mobile number is not shared with third parties for SMS marketing purposes.

    Message and data rates may apply. Reply STOP to opt out of service-related SMS, though doing so may impair certain account security and service features.

    7.2 Marketing SMS (Requires Separate Express Written Consent)

    We send marketing SMS messages only with your explicit, separate opt-in consent in compliance with the Telephone Consumer Protection Act (TCPA).

    What We Send:

    • Promotional offers and discounts
    • New service announcements
    • Educational content and tips
    • Re-engagement messages

    TCPA Compliance:

    • • We obtain express written consent before sending marketing texts
    • • We provide clear opt-in disclosures explaining what messages you will receive
    • • We honor opt-out requests immediately
    • • We maintain do-not-contact lists

    Opt-Out: Reply "STOP" to any marketing text to unsubscribe immediately. You may continue to receive service-related (transactional) messages related to your active services.

    Message Frequency: Varies by service and enrollment. Marketing messages may be sent up to 4 times per month.

    Standard Rates Apply: Message and data rates may apply based on your mobile carrier plan.

    For more details, see our dedicated TCPA Consent Policy.

    8
    DATA SECURITY

    Mesa Group Consulting takes data security seriously and implements industry-standard measures to protect your information.

    8.1 Security Measures

    • Encryption: SSL/TLS encryption for data transmission
    • Secure Storage: Encrypted databases and secure cloud storage
    • Access Controls: Role-based access restrictions and multi-factor authentication
    • Firewalls: Network security and intrusion detection systems
    • Regular Security Audits: Vulnerability assessments and penetration testing
    • Employee Training: Ongoing security awareness and privacy training
    • Secure Payment Processing: PCI-DSS compliant payment processors

    8.2 Limitations

    While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for all activities under your account.

    Because email and instant messaging are not recognized as secure communications, we request that you not send sensitive personal information to us by email or instant messaging. If you need to transmit sensitive information, contact us at 661-310-3040 to arrange a secure method.

    8.3 Data Breach Notification

    In the event of a data breach that compromises your personal information, we will notify you in accordance with applicable laws, including California's data breach notification requirements (Cal. Civ. Code § 1798.82) and any other applicable state breach notification statutes.

    9
    DATA RETENTION

    Mesa Group Consulting retains your information for as long as necessary to:

    • Provide services and fulfill our contractual obligations
    • Comply with legal and regulatory requirements
    • Resolve disputes and enforce agreements
    • Prevent fraud and maintain security

    Retention Periods:

    • Active Clients: Information retained for the duration of the service relationship
    • Inactive Clients: Information retained for seven (7) years after termination, which exceeds the five (5) year minimum required by the Telemarketing Sales Rule (TSR), to satisfy legal, tax, and recordkeeping obligations
    • Credit Reports: Retained as required by FCRA and CROA
    • Financial Records: Retained for seven (7) years (IRS requirements)
    • Marketing Data: Retained until you opt out or request deletion

    After retention periods expire, we securely delete or anonymize your information. We may retain residual copies in backup systems for a limited time for disaster recovery purposes.

    10
    YOUR PRIVACY RIGHTS

    10.1 General Rights

    Subject to applicable law, you have the right to:

    • Access: Request a copy of the personal information we hold about you
    • Correction: Request correction of inaccurate or incomplete information
    • Deletion: Request deletion of your information (subject to legal retention requirements)
    • Opt-Out: Unsubscribe from marketing emails and SMS messages
    • Withdraw Consent: Withdraw consent for data processing where consent is the legal basis

    Important — GLBA Pre-Emption:

    Mesa Group Consulting is subject to the Gramm-Leach-Bliley Act (GLBA), which governs how financial institutions handle nonpublic personal information. Where GLBA applies, its definitions and obligations may pre-empt or modify rights provided under state privacy laws (such as CCPA). Some information may be exempt from deletion or other rights requests due to GLBA, FCRA, or other applicable financial services laws.

    10.2 California Residents

    California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). For full details on your California-specific rights — including the right to know, right to delete, right to correct, right to opt out of sale/sharing, and right to limit use of sensitive personal information — please review our California Privacy Rights page on our website.

    10.3 Other State Privacy Rights

    Residents of other states may have rights under their state's privacy laws. See Section 14 for state-specific notices.

    10.4 Exercising Your Rights

    To exercise your privacy rights, contact us:

    We will respond to your request within thirty (30) days, or within forty-five (45) days where required by applicable law (such as CCPA). If we need additional time, we will notify you within the initial response period and may extend the response period by up to forty-five (45) additional days.

    We may require verification of your identity before processing requests. Verification may include matching information you provide against our records, requesting government identification, or using knowledge-based authentication.

    10.5 Non-Discrimination

    You will not be discriminated against for exercising your privacy rights. We will not:

    • Deny you services (except where the requested action, such as deletion, makes service provision impossible)
    • Charge different prices or rates for services
    • Provide a different level or quality of service
    • Suggest that you may receive a different price or quality of service

    If you exercise your right to delete your information, please understand that we may not be able to continue providing services that depend on that information.

    11
    AUTHORIZED AGENTS

    You may designate an authorized agent to submit privacy requests on your behalf.

    To authorize an agent, the agent must provide:

    • Written authorization signed by you (notarized authorization is preferred and may be required for certain requests)
    • A copy of the agent's government-issued identification
    • Sufficient information about you to allow us to verify your identity

    Submission methods:

    • Email: compliance@mesagroupconsulting.com (with required documents attached)
    • Mail: Mesa Group Consulting, Attn: Compliance Department — Authorized Agent Request

      5001 California Ave, Suite 219

      Bakersfield, CA 93309

    We may contact you directly to verify the agent's authority before processing the request. We reserve the right to deny requests where we cannot reasonably verify the agent's authority or your identity.

    12
    CHILDREN'S PRIVACY

    Mesa Group Consulting does not knowingly collect, use, or disclose personal information from individuals under the age of eighteen (18). Our services are intended for adults only and require legal capacity to enter into binding contracts.

    If we become aware that we have collected information from a person under 18 without verifiable parental consent, we will delete that information promptly. If you believe we have collected information from a minor, please contact us at compliance@mesagroupconsulting.com.

    13
    THIRD-PARTY LINKS

    Our website may contain links to third-party websites, services, or resources. Mesa Group Consulting is not responsible for the privacy practices, content, or security of these third-party sites.

    Third-Party Services We Link To:

    • SmartCredit (credit monitoring)
    • Lending partners (business funding)
    • Life insurance carriers
    • Social media platforms (Facebook, Instagram, TikTok, YouTube, X/Twitter, LinkedIn)
    • Educational resources and tools

    We encourage you to review the privacy policies of any third-party sites you visit. Your interactions with these third parties are governed by their own privacy policies and terms of service.

    14
    STATE PRIVACY NOTICES

    This section provides notices required for residents of specific states. Where state-specific rights conflict with applicable federal law (including GLBA, FCRA, or CROA), the federal law governs.

    14.1 California Residents

    California residents have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

    • Right to know what personal information is collected, used, shared, or sold
    • Right to delete personal information held by a business
    • Right to correct inaccurate personal information
    • Right to opt out of the sale or sharing of personal information
    • Right to limit use and disclosure of sensitive personal information
    • Right to non-discrimination for exercising privacy rights

    For full details, please see our California Privacy Rights page on our website.

    Complaint Assistance:

    California residents may contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N-112, Sacramento, CA 95834, or by telephone at (916) 445-1254 or (800) 952-5210.

    14.2 Nevada Residents

    Under Nevada Revised Statutes Chapter 603A, Nevada residents have the right to opt out of the sale of certain personal information. Mesa Group Consulting does not sell personal information as defined under Nevada law. To submit any opt-out or privacy request, contact us at compliance@mesagroupconsulting.com or 661-310-3040.

    Bureau of Consumer Protection:

    Nevada law also requires us to provide the following contact information for the Bureau of Consumer Protection:

    Bureau of Consumer Protection

    Office of the Nevada Attorney General

    555 E. Washington St., Suite 3900

    Las Vegas, NV 89101

    Phone: (702) 486-3132

    Email: aginfo@ag.nv.gov

    14.3 Colorado Residents

    Under the Colorado Privacy Act (CPA), Colorado residents have the right to:

    • Access personal data
    • Correct inaccuracies
    • Delete personal data
    • Obtain personal data in a portable format
    • Opt out of targeted advertising, sale of personal data, and certain profiling

    To exercise these rights, contact compliance@mesagroupconsulting.com.

    14.4 Virginia Residents

    Under the Virginia Consumer Data Protection Act (VCDPA), Virginia residents have similar rights to those listed for Colorado residents above, including access, correction, deletion, portability, and opt-out rights. To exercise these rights, contact compliance@mesagroupconsulting.com.

    14.5 Connecticut Residents

    Under the Connecticut Data Privacy Act (CTDPA), Connecticut residents have the right to access, correct, delete, port, and opt out of the sale of personal data and targeted advertising. To exercise these rights, contact compliance@mesagroupconsulting.com.

    14.6 Utah Residents

    Under the Utah Consumer Privacy Act (UCPA), Utah residents have the right to access, delete, port, and opt out of the sale of personal data and targeted advertising. To exercise these rights, contact compliance@mesagroupconsulting.com.

    14.7 Texas Residents

    Under the Texas Data Privacy and Security Act (TDPSA), Texas residents have the right to access, correct, delete, port, and opt out of the sale of personal data, targeted advertising, and certain profiling. To exercise these rights, contact compliance@mesagroupconsulting.com.

    14.8 Other States

    Residents of other states with comprehensive privacy laws (including but not limited to Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, and Tennessee) may have rights similar to those described above. To exercise any state-law privacy right, contact compliance@mesagroupconsulting.com.

    14.9 GLBA Pre-Emption Notice

    Mesa Group Consulting is a financial services provider subject to the Gramm-Leach-Bliley Act (GLBA). The GLBA includes definitions for "nonpublic personal information" and "personally identifiable financial information" that may pre-empt state privacy law definitions for matters involving services provided by Mesa Group Consulting, our service providers, or our agents. Where GLBA applies, its provisions govern.

    15
    CHANGES TO THIS PRIVACY POLICY

    Mesa Group Consulting reserves the right to modify this Privacy Policy at any time. When we make material changes, we will:

    • Update the "Last Updated" date at the top of this policy
    • Post the revised policy on our website
    • Notify you via email (if you have provided an email address)
    • Provide prominent notice on our website

    Your continued use of our services after changes become effective constitutes acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically.

    16
    CONTACT US

    If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

    MESA GROUP CONSULTING

    Mailing Address

    5001 California Ave, Suite 219

    Bakersfield, CA 93309

    Privacy / Compliance Email

    compliance@mesagroupconsulting.com

    Compliance Department:

    For all privacy-related questions, requests, or complaints:

    Data Protection Inquiries:

    For privacy-related inquiries, including access, correction, or deletion requests, contact our Compliance Department at compliance@mesagroupconsulting.com. The Compliance Department serves as the point of contact for all data protection matters.

    Hours of Operation:

    Monday – Friday: 9:30 AM – 6:30 PM Pacific Time

    Saturday: 10:30 AM – 2:30 PM Pacific Time

    Sunday: Closed

    ACKNOWLEDGMENT

    By using our website or services, you acknowledge that you have read, understood, and agree to this Privacy Policy.

    © 2026 Mesa Group Consulting. All Rights Reserved.