Legal
Privacy Policy
Effective July 21, 2026. Questions:
Overview
InsuraCards("InsuraCards," "we," "us") provides a private desk product for insurance agencies: carrier contact cards and, where enabled, Ask Becky (shared client knowledge cards). We sell the product as Cloud SaaS (we host multi-tenant workspaces) or OnPrem (you run the software on infrastructure you control). This policy describes how we handle personal and business information for those offerings and related sites (marketing site, Control, deploy portal).
This is a product privacy notice for customers and visitors—not legal advice. Enterprise customers may have a separate order form or data processing terms that control if they conflict with this page.
Cloud SaaS vs OnPrem
- Cloud SaaS — Workspace data (accounts, carrier cards, Ask Becky content, audit events) is hosted by InsuraCards (or our subprocessors) in the United States. We process that data to provide the service.
- OnPrem — You host the application and database. Day-to-day carrier and client content stays in your environment. We may still process limited information you send us outside that install (for example license requests, package downloads, optional license heartbeats, support tickets, or marketing site forms).
Information we collect
- Account data — name, work email, password hash (or SSO identifiers when configured), role, access level, and segment/desk membership for workspace users; similar credentials for platform operators (Control) and deploy-portal accounts.
- Workspace content (SaaS) — carrier cards, contacts, vertical specialists, policy type tags, team notes, and—when used—Ask Becky client cards (producers, insured contacts, subsidiaries, notes). Content is entered by your agency or by people you invite into the workspace.
- Client update invites (when enabled) — magic-link tokens and form submissions so an invited contact can propose updates to client-related fields. Submissions are reviewed by your agency before they become workspace data.
- Security and audit data — login attempts, authentication events, IP addresses, user agent strings, and administrative access logs needed for security monitoring and support.
- Demo and trial signals (SaaS) — device/network IP used to start a demo (to limit abuse), demo credentials metadata, and related lifecycle events.
- Deploy portal (OnPrem product path) — account email, trial or paid license status, package/download activity as needed to deliver install media and licenses.
- Communications and marketing — messages and contact details you send through contact, lead, enterprise, or support forms, and email correspondence with our team.
- OnPrem AI features (customer-configured) — if you enable AI contact-sheet ingest or AI search, prompts and sheet text may be sent to the LLM endpoint you configure (local or third-party). That processing is under your configuration and agreements with that provider; InsuraCards does not sell that content.
How we use information
We use collected information to:
- Provide, secure, and maintain InsuraCards (SaaS workspaces, Control, deploy portal, marketing site)
- Authenticate users and enforce role-based access within your company workspace
- Detect abuse, prevent fraud, and investigate security incidents (including demo trial limits)
- Respond to support, privacy, and enterprise procurement inquiries
- Deliver OnPrem install media, licenses, and related product operations
- Meet legal, regulatory, and contractual obligations
We do not sell your workspace data. We do not use carrier directory or Ask Becky content for advertising.
Cookies and similar technologies
We use a small number of first-party cookies that are necessary for the product to work. We do not use third-party advertising or analytics cookies in the product as shipped.
- Session cookies — signed login sessions for the agency app (
insuracards_session), SaaS Control (insuracards_control_session), OnPrem Deploy Control where applicable, and the public deploy portal (insuracards_deploy_session). These cookies are typically HttpOnly, SameSite=Lax, and Secure when the site is served over HTTPS. - Pricing / post-demo access (SaaS) — a first-party flag (
insuracards_pricing_access) so agency admins can reach plan/invoice steps after a demo ends. It is not used for advertising.
The browser may also store limited data in local storage (for example UI preferences or demo walkthrough progress). That data stays on your device and is not a third-party tracker.
You can clear cookies and site data in your browser. Clearing session cookies signs you out. We show a short cookie notice on first visit so you can acknowledge essential cookies; we do not load third-party advertising trackers.
Data isolation and sharing
Each SaaS agency workspace is scoped to a single company. We do not share your carrier directory or Ask Becky content with other customers. Authorized platform operators may access tenant data only for support, billing, or incident response—masked by default, with documented reason and immutable audit logging where that control is enabled.
We use subprocessors for hosting and email delivery on SaaS (and for email/ops tools we operate). Current categories include cloud infrastructure and transactional email. Ask us if you need a signed subprocessor list for a contract.
Retention and deletion
SaaS workspace data is retained for the life of your subscription or demo period. Demo workspaces are deleted or frozen per product rules when trials end (for example frozen for procurement). Audit and security logs are retained for at least one year unless a longer period is required by law or contract.
Customers may request export or deletion of SaaS workspace data by contacting . OnPrem customers control retention and deletion on systems they host.
Security
We implement technical controls including encryption in transit, password hashing, session hardening, rate limiting, account lockout, and audit logging. Operators can review detailed control docs in Control; security inquiries can go through the contact path on this site. OnPrem customers are responsible for host, network, and backup security of their install.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of personal information. Submit requests to . We will verify your identity before fulfilling requests.
Changes
We may update this policy as our service or legal requirements change. Material updates will be reflected on this page with a revised effective date (currently July 21, 2026).