Privacy Policy
Effective .
Controller / business: H Holdings Group LLC, a State of Wyoming limited liability company, operating the InsureLeads brand.
Registered address: 30 N Gould St, STE R, Sheridan, WY 82801, United States
Privacy contact: [email protected] (subject line: “Privacy”)
The short version you should not miss: we generate consumer insurance enquiries and deliver them to licensed insurance agents who pay for them. Under California and several other state privacy laws, that is a “sale” of personal information. Section 7 explains it, and section 10 tells you how to opt out.
This policy describes what we collect, why, who we give it to, how long we keep it, and what you can require us to do. Where we cannot state something precisely, we say so rather than filling the gap with standard language.
1. Scope and the three groups of people covered
This policy covers getinsureleads.com, app.getinsureleads.com, the campaign landing pages we operate, and our related services. Three different groups of people appear in this document, and the rules differ for each:
- Business visitors and customers— agents, agencies and companies who browse the site or buy from us. We do not sell your information.
- Account and CRM users — people who log into our application.
- Consumers— individuals who submitted an insurance enquiry through one of our campaigns. Your information is the product we deliver to a licensed agent, which is a sale. Sections 4, 7, 10 and 11 are written for you.
Where you upload your own contacts into the CRM, we handle that data on your behalf as a service provider under your instructions, not for our own purposes. Your own privacy policy governs those individuals, not this one.
2. Site visitors and business customers
The quote and contact forms on this site collect your name, email address, phone number, and optionally company name and a free-text message, together with the answers you select in the form — whether you are an agent or an agency, whether you want leads or done-for-you services, which insurance verticals and lead format interest you, your target weekly volume, and the states you sell in.
Submitting the form also sends whatever marketing attribution your browser has stored: UTM parameters, a Google Ads gclid or Meta fbclidif you arrived from an ad, the page you landed on, your referring site, and the time it was captured. That attribution is held in your browser’s local storage under the key il_attribution. Clearing your browser storage removes it.
A submission is written to our PostgreSQL database, which is the record of your enquiry. It is then emailed to our team through Resend, our email provider. If a CRM webhook is configured, a copy is also posted to that CRM. If the database write fails, the form returns an error rather than reporting success — we do not silently drop an enquiry.
If you become a customer we also hold your billing contact details, transaction history, licence and appointment information you give us, order configuration, support correspondence, and the records needed for tax and accounting.
3. Account and CRM users
Logging into the application creates a session cookie. We hold your name, email, role, organisation membership, authentication data, invitation records, and application activity needed to operate and secure the service. If you connect a calendar, a scheduling link or your own telephony account, we hold the credentials or tokens required for that connection and the resulting activity records — call logs, message logs and appointment records.
4. Consumers who requested an insurance quote
Separately from this site’s business forms, we generate consumer insurance enquiries on campaign landing pages and deliver them to the licensed agent who purchased that campaign. For those enquiries we collect, depending on the product:
- identity and contact details — name, phone number, email address, postal address or ZIP code, state;
- the answers you gave — age or date of birth, coverage type and amount sought, beneficiary or household context, and for some final-expense products, health and medication questions used to determine which tier of policy you may qualify for;
- consent artefacts recorded at the moment of submission — a TrustedForm or Jornaya certificate, the exact consent language displayed to you, the timestamp, the source URL and the IP address;
- for live transfers, call metadata and, where recording applies, the call recording.
We may also receive enquiries from publishers and lead partners who collected them under their own consent, and we may verify or supplement a record using validation vendors (for example, checking whether a phone number is live, or whether it appears on a Do Not Call or litigator list).
Full detail on how these leads are generated and verified is on how we source leads.
5. Information collected automatically
- Google Analytics 4— loaded only when a measurement ID is configured for this site. When active it records page views, scroll depth, outbound and contact-link clicks, and form-start / form-submit events.
- Vercel Analytics and Vercel Speed Insights— page-level traffic and performance measurement from our hosting provider. Speed Insights runs in production only.
- Calendly— the scheduling widget loads from Calendly only after you click to book a call. If you book, Calendly receives what you enter there under its own privacy policy.
- Server and security logs— IP address, user agent, request path and timestamp, kept for security, abuse prevention and debugging.
We do not run advertising retargeting pixels on this site. If that changes, this section changes with it.
6. How we use information
- to operate, deliver and support the services, and to process orders and payments;
- to generate consumer insurance enquiries and deliver them to the licensed agent who purchased them — this is the core purpose for consumer data;
- to verify and validate records, deduplicate, and screen against Do Not Call and litigator lists before delivery;
- to respond to enquiries, provide customer support, and send service and transactional messages;
- to send business marketing to agents and agencies, subject to opt-out;
- to detect, investigate and prevent fraud, abuse and security incidents;
- to measure and improve site and campaign performance;
- to keep records required for tax, accounting, audit and legal-defence purposes, including evidence of consent; and
- to comply with law and to establish, exercise or defend legal claims.
We do not use consumer insurance-enquiry data to train our own machine-learning models, and we require our buyers not to do so either.
7. Selling and sharing — read this one
Business contacts.We do not sell, rent or share the contact details you give us on this site’s business enquiry forms.
Consumer insurance enquiries. These are different, and they are the product. When you submit an insurance quote request through one of our campaigns, you are asking to be contacted by a licensed agent, and we deliver your record to the agent or agency who purchased that campaign, in exchange for payment. Under the California Consumer Privacy Act and comparable laws in other states, that transfer is a “sale” of personal information, and may also be a “share”.We state that plainly rather than describing it as “connecting you with a partner”.
- Real-time exclusive leads and live transfers are delivered to a single buyer.
- Aged leads are labelled as aged and may have been delivered to buyers previously.
- Buyers are contractually restricted to using your information to market and sell insurance they are licensed to sell, and are prohibited from reselling it.
- We do not sell the personal information of anyone we know to be under 16.
Once your information is delivered to a buyer, that buyer becomes independently responsible for it under its own privacy policy. Deleting your record from our systems does not automatically delete it from a buyer’s systems — we will tell you who received it so you can ask them directly, and we will pass on a suppression request.
8. Who we disclose information to
- Purchasing agents and agencies— consumer enquiry data, as described in section 7.
- Hosting and infrastructure— Vercel (hosting, analytics, speed insights) and our managed PostgreSQL database provider.
- Email delivery — Resend.
- Payments— Stripe. Card data is tokenised by Stripe; we do not store full card numbers on our servers.
- Consent certification— TrustedForm and Jornaya, which record and store the certificate evidencing your submission.
- Verification and compliance vendors— phone validation, Do Not Call and litigator-list screening.
- Scheduling and calendars— Calendly, and Google or Microsoft calendar services where a user connects them.
- Telephony— where a customer connects their own Twilio account, call and message data flows through that customer’s own provider account.
- AI model providers— OpenAI and Anthropic, used by the CRM assistant to draft messages and summarise records. Content sent for drafting may include contact and lead details.
- Analytics — Google Analytics 4, when configured.
- Professional advisers— accountants, auditors and lawyers, under duties of confidentiality.
- Legal and safety— where required by law, subpoena or regulator, or to protect rights, safety, or to investigate fraud or abuse.
- Corporate transactions— a buyer or successor in a merger, acquisition, financing or sale of assets, subject to this policy.
Service providers are permitted to use the information only to perform services for us. This list names the categories and the providers in use as at the effective date; it may change as vendors change, and this page is updated when it does.
9. Categories table (CCPA disclosure)
Categories of personal information collected in the 12 months before the effective date, and what happens to each.
| Category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Name, postal address, email, phone, IP address, account ID | Yes — consumer enquiry data only. Never for business contacts. |
| Customer records | Billing contact, transaction and payment records, licence details | No |
| Protected classifications | Age or date of birth, and where the product requires it, gender | Yes — consumer enquiry data only |
| Commercial information | Coverage sought, products purchased, order history | Yes — consumer enquiry data only |
| Internet activity | Pages viewed, referrer, UTM and click IDs, form interactions | No |
| Geolocation | State, ZIP code, city inferred from IP | Yes — consumer enquiry data only |
| Audio | Call recordings on live transfers, where recording applies | Yes — consumer enquiry data only |
| Inferences | Likely product fit, eligibility tier for final-expense products | Yes — consumer enquiry data only |
| Sensitive personal information | Health and medication answers on pre-vetted final-expense enquiries | Disclosed to the purchasing agent to perform the service you requested. See section 15. |
Sources: directly from you; from your browser and device; from publishers and lead partners; and from verification vendors. Business purposes for collection are listed in section 6. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under the CCPA regulations.
10. Your privacy rights and how to use them
Depending on where you live, you may have the right to:
- Know and access what personal information we hold, its sources, the purposes, and the categories of recipients;
- Delete the personal information we hold about you;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of your personal information, and of targeted advertising;
- Limit the use of sensitive personal information;
- Data portability;
- Non-discrimination for exercising any of these rights. We will not deny you service, charge a different price or provide a lesser quality of service because you exercised a privacy right; and
- Appeal a refusal, where your state provides that right.
How to make a request. Email [email protected]with “Privacy Request” in the subject line. Tell us which right you are exercising and include the email address or phone number you submitted, so we can find your record. You may use an authorised agent; we will ask for proof of their authority and may still verify your identity directly.
Verification. We verify a request by matching the details you give us against the record we hold. We ask only for what is necessary, and we do not use verification information for any other purpose. If we cannot verify you, we will tell you why.
Timing. We acknowledge requests within 10 business days and respond within 45 calendar days. Where a request is complex we may extend once by a further 45 days and will tell you before we do.
Appeals.If we refuse your request and your state gives you a right of appeal, reply to our decision with “Appeal” in the subject line. We will respond within 45 days with our decision and reasons. If we deny the appeal, you may contact your state attorney general.
Nevada residents. Nevada law gives you the right to direct us not to sell certain covered information. Send that request to the address above.
Opt-out preference signals. We do not currently detect browser-based opt-out preference signals such as Global Privacy Control automatically. Until we do, the email route above is how to opt out of sale or sharing, and we act on it. We would rather tell you that than claim a capability we have not built.
11. How to stop calls, texts and emails
This is separate from a privacy request and is usually what a consumer actually wants.
- To stop us contacting you, email [email protected]with “Do Not Contact” in the subject line, from the address you used or including the phone number you submitted. We add you to our internal do-not-contact list.
- To stop an agent contacting you, tell that agent directly to stop — they are legally required to honour it. Tell us as well and we will pass a suppression request to any buyer who received your record, and tell you who they were.
- To withdraw the consent you gave when you submitted the form, use either route above. Withdrawal takes effect for future contact; it does not undo contact that already happened.
- Marketing emails from us carry an unsubscribe link, which works immediately.
- We will still send transactional or legally required messages to customers with an account, such as billing notices.
We keep a record of your opt-out itself, permanently, because suppression only works if we remember it.
12. Cookies, local storage and tracking
The site sets a session cookie only if you log into the application. Marketing attribution is stored in browser local storage rather than a cookie, under the key il_attribution. Analytics providers named in section 5 set their own cookies when they are active. You can clear stored attribution by clearing site data in your browser, and you can block analytics with a browser extension or by disabling JavaScript for this site. Blocking these does not stop you using the site.
13. How long we keep information
| Record | Retention | Why |
|---|---|---|
| Consumer enquiry record and consent artefacts | At least 5 years from capture | TCPA and state telemarketing claims can be brought years later; the consent record is the evidence that defends both us and the buyer |
| Do-not-contact and suppression records | Indefinitely | An opt-out only works if it is never forgotten |
| Business enquiry and contact-form submissions | Up to 3 years from last contact | Sales follow-up and dispute history |
| Customer account, order and billing records | 7 years after the relationship ends | Tax, accounting, audit and limitation periods |
| CRM data you uploaded | While your account is active; exportable for 30 days after termination | It is your data; see the Terms, section 20.4 |
| Server and security logs | Typically under 12 months | Security, abuse prevention and debugging |
Where we delete a record on request, we may keep the minimum needed to honour the deletion itself, to comply with law, to resolve a dispute, or to defend a legal claim — and we keep it isolated from active use.
14. Security
We implement administrative, technical and physical safeguards intended to protect personal information, including encryption in transit, access controls, and restriction of access to personnel who need it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We hold no security certification — we are not SOC 2 audited — and we do not claim one. If a breach affects your personal information we will notify you and any regulator as required by law.
15. Sensitive information and GLBA
Some final-expense products involve health and medication questions used to determine which policy tier you may qualify for. We collect that information only where the product you asked about requires it, use it only to route your enquiry to an agent who can help, and disclose it only to the purchasing agent. We do not use it to infer characteristics about you for any other purpose.
To the extent information we handle is nonpublic personal information subject to the Gramm-Leach-Bliley Act, or protected health information subject to HIPAA in the hands of a covered entity, that information is handled in accordance with those laws, and may be exempt from certain state privacy rights. Where an exemption applies we will tell you which one when we respond to your request.
We are not an insurance carrier, agency or producer, and we do not underwrite, price or decide any insurance application. We do not use or provide information for any purpose regulated by the Fair Credit Reporting Act, and we prohibit our buyers from doing so.
16. Children
The services are for adults. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell the personal information of anyone under 16. If you believe a child has given us information, email us and we will delete it.
17. Where we operate
We operate from the United States and offer our services for use in the United States. Information is stored and processed in the United States. We do not target the services at the European Economic Area, the United Kingdom or Switzerland. If you access the site from outside the United States, you do so on your own initiative and your information will be transferred to and processed in the United States, where data-protection law may differ from your own.
18. Changes to this policy
We may update this policy. The effective date at the top always reflects the current version. For a material change — particularly any change to what we sell or share — we will give notice by email to account holders or by prominent notice on the site before it takes effect. Continuing to use the services after that date means you accept the updated policy.
19. Contact us
H Holdings Group LLC (operating as InsureLeads)
30 N Gould St, STE R, Sheridan, WY 82801, United States
Email: [email protected]
Web: getinsureleads.com/contact
Use the subject line “Privacy Request”, “Do Not Contact” or “Appeal” so your message is routed correctly.
InsureLeads is an online business with no walk-in location. The address above is our registered address for legal notices.