FCRA vs non-FCRA data
The Fair Credit Reporting Act (FCRA) is the US law that governs how consumer information may be used when it decides something about the consumer. The single most misunderstood point: FCRA is triggered by the purpose of a use, not by the kind of data. The same address-history record can be perfectly legal to use in one workflow and a federal violation in another.
What makes a use FCRA-regulated?
A use falls under the FCRA when information about a consumer is used to determine their eligibility for:
- credit or insurance,
- employment (hiring, promotion, retention),
- housing or tenancy,
- government benefits or licenses,
- or other permissible purposes enumerated in the Act.
When data is used this way, it becomes a "consumer report," the provider must operate as a consumer reporting agency (CRA) — with accuracy obligations, dispute processes, and adverse-action notices — and the user of the data takes on statutory duties of its own. A background check for a job application is the canonical example: FCRA end to end.
What is non-FCRA data use?
Non-FCRA use is everything that informs without deciding eligibility. The recognized categories include:
- Locating people you are legally entitled to contact — skip tracing for collections, process serving, heir search, or reconnecting with your own customers.
- Verifying details you already possess — confirming that a name, date of birth, phone, and address a person gave you are consistent with independent records.
- Fraud awareness and investigation — recognizing synthetic identities, reused phone numbers, or inconsistent applications, provided the outcome is investigation and not an automated eligibility denial.
- Identity resolution and data hygiene — deduplicating customer files, updating stale contact data.
A provider serving these uses is an informational service, not a CRA. That is not a loophole — it is a different legal category with its own obligation: keeping eligibility uses out.
Why "non-FCRA background check" is a contradiction
If a search decides whether someone gets the job, the apartment, or the policy, it is a background check — a consumer report — and it must run through a CRA under FCRA procedures. No disclaimer converts that use into a non-FCRA one; a vendor selling "non-FCRA background checks" for hiring or tenant decisions is describing something that cannot legally exist. The honest framing is the one that matches the purposes above: locating, verifying what you hold, investigating fraud signals.
How CoverFi enforces the line
CoverFi operates strictly on the non-FCRA side and builds the boundary into the product rather than a footer:
- Attestation at two gates. Creating an account and creating each API key both require certifying that the data will not be used for FCRA-regulated eligibility decisions. The attestation is versioned and recorded.
- No eligibility outputs. Results are matches with confidence signals — never scores, grades, or approve/deny recommendations that could be dropped into a decisioning pipeline.
- Contract-level prohibition. The Terms of Service prohibit credit, employment, insurance, housing, and tenancy uses, and prohibit combining CoverFi output into any product that makes those decisions.
- Consumer rights regardless. People in the data can request access or suppression through the privacy request page whether or not they are customers.
Quick self-test for your use case
Ask one question: *does the result of this search change what the person is offered or allowed?* If yes — even partially, even as one input among many — you need an FCRA-compliant CRA, and CoverFi is the wrong tool. If the result only changes what you know or who you can reach — a current address, a consistency signal on details you hold, a fraud-review flag for human investigation — you are in informational territory, which is exactly what CoverFi's records API is built for.
*This page is a plain-language orientation, not legal advice. If your workflow sits near the line, ask a lawyer before you build.*