Privacy Policy
Last updated: July 21, 2026
1. Scope and our role
LeadToPolicy is a hosted CRM and quote-funnel platform for life-insurance agents and agencies. This Privacy Policy explains how we handle personal information through the LeadToPolicy service and our static marketing site.
Our customers control the personal information of the leads and clients they place in the service. For that information, the customer is the data controller and LeadToPolicy processes the information on the customer's behalf to provide the service. We also collect limited information directly from our customers to manage their accounts and operate LeadToPolicy.
2. Information processed for customers
The information we process on a customer's behalf depends on the modules the customer uses and what the customer or its leads and clients submit. It can include:
- Contact details.
- Answers submitted through quote requests, including date of birth, health information, and coverage information that a lead chooses to provide.
- Call recordings and transcripts.
- SMS and email message content.
- Appointment and booking details.
- Browsing and page-visit data on the customer's own quote forms.
We process this information to provide the customer's selected features, which may include an embeddable quote funnel and lead dashboard; contacts, pipeline, appointments, booking, email follow-ups, and a secure client portal; business phone and SMS; and AI-assisted call transcription, summaries, follow-up drafts, and lead intelligence.
3. Information LeadToPolicy collects directly
We collect customer account information such as name, email address, and login credentials. Passwords are stored in hashed form. We also collect billing and subscription status; service usage metrics such as call minutes, message counts, and transcription minutes used for billing; server logs; and messages sent to [email protected].
We use this information to provide and administer customer accounts, authenticate users, measure billable service usage, operate the service, and respond to emails.
4. Cookies and tracking
LeadToPolicy app instances use session-authentication cookies to keep signed-in users authenticated. The LeadToPolicy marketing site is static. We do not use advertising trackers or third-party analytics, and we do not sell or share personal information for advertising.
5. Isolated customer instances
Each customer runs on an isolated instance with a separate application container and separate database. This keeps one customer's application and database separate from those of other customers.
6. Service providers and infrastructure
We use the following providers to operate LeadToPolicy:
- Hetzner for hosting in its United States data center in Ashburn, Virginia.
- Cloudflare for DNS, CDN and proxy services, and R2 backup storage. Cloudflare provides provider-managed encryption at rest for R2 storage.
- Amazon Web Services Simple Email Service for transactional email delivery.
- Telnyx as the voice and SMS carrier for customers on phone tiers.
For AI features, the customer supplies an API key for the customer's own AI provider account, such as an OpenAI account. Relevant data is sent using that customer-supplied key. LeadToPolicy does not send customer data to AI providers under LeadToPolicy's own keys.
7. Security and backups
LeadToPolicy uses TLS on all public endpoints. Automated backups are stored in Cloudflare R2, with provider-managed encryption at rest. No method of storage or transmission can eliminate every risk, but these measures are used to protect information handled through the service.
If we become aware of a personal information breach affecting customer data, we will notify affected customers without undue delay.
8. Retention, cancellation, and export
Customer data is retained while the subscription is active. After cancellation, customer data is retained for 30 days and then deleted. Customers can export their data at any time, including while an account is suspended and during the 30-day post-cancellation window. Phone numbers are portable out.
If an account is suspended for non-payment, embedded forms display a graceful unavailable notice and the CRM becomes read-only. The customer's data remains available for export and is never withheld.
9. Privacy choices and requests
If you are a lead or client whose information is held by a LeadToPolicy customer, direct access, deletion, correction, or other privacy requests to the agent or agency that collected your information. That customer is the controller and is responsible for responding. LeadToPolicy will assist the customer with requests involving information we process on its behalf.
Residents of U.S. states that provide privacy rights may request access, deletion, or correction through the applicable agent or agency. For personal information LeadToPolicy collects directly as customer-account information, email your request to [email protected].
10. Children
LeadToPolicy is not directed to people under 18.
11. Contact
Questions or requests about this policy or our handling of customer-account information may be sent to [email protected].
Use of the service is also governed by our Terms of Service.
← Back to LeadToPolicy