I-InsureCRM

Privacy Policy

Privacy Policy

Last Updated: December 13, 2025 (Version 4.5)

At I-InsureCRM, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our Customer Relationship Management (CRM) platform.

By using I-InsureCRM, you agree to the collection and use of information in accordance with this policy.

Information We Collect

1. Information You Provide Directly

  • Account Information: Name, email address, phone number, company name, professional title, and insurance license information.
  • Lead Data: Information about your insurance leads including names, contact details, addresses, dates of birth, insurance types, policy details, notes, and attachments.
  • Task & Activity Data: To-do items, calendar events, follow-up dates, and activity logs.
  • Payment Information: Billing details processed securely through Stripe (we do not store full credit card numbers).

Sensitive Personal Information

I-InsureCRM is designed to store certain types of sensitive personal information necessary for insurance operations. This includes:

  • Social Security Numbers (SSN): Stored encrypted for U.S. citizens and legal residents for policy underwriting purposes.
  • Payment Card Information: Card numbers, expiration dates, CVV codes, and cardholder names for first payment recording. Note: Actual payment processing is handled by Stripe (PCI DSS Level 1 certified).
  • Bank Account Information: Bank names, routing numbers, account numbers, and account holder names for ACH payment recording.
  • Identification Documents: Driver's licenses, passports, and other government-issued IDs.
  • Health Information: For health insurance leads, medical history and health-related information may be stored.

⚠️ CRITICAL SECURITY MEASURES:

  • Sensitive fields are encrypted at rest using AES-256 encryption
  • All data transmission uses TLS 1.3 encryption
  • SSN and payment data are masked in the UI by default
  • Only authorized users (assigned agent, creator, or admin) can view unmasked sensitive data
  • All access to sensitive data is logged for audit purposes

🔒 PCI DSS COMPLIANCE:

While payment card data fields exist in the CRM for recording first payment methods, I-InsureCRM does not process live payment transactions. All actual payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. You are responsible for ensuring your collection and storage of payment card data complies with PCI DSS requirements and applicable payment card industry standards.

🏥 HIPAA NOTICE FOR HEALTH INSURANCE:

If you handle health insurance leads and store Protected Health Information (PHI), you are solely responsible for HIPAA compliance. While I-InsureCRM implements security measures, it is not a HIPAA-covered entity. You must implement appropriate safeguards, obtain Business Associate Agreements (BAAs) where necessary, and ensure your workflows meet HIPAA standards. We strongly recommend consulting with a healthcare compliance attorney.

2. Information Collected Automatically

  • Usage Data: Log data, IP address, browser type, device information, pages visited, and time spent on the platform.
  • Cookies: We use cookies and similar tracking technologies to enhance user experience and analyze usage patterns.

3. Information from Third-Party Services

Google APIs (Growth Pro and Elite Plans)

When you choose to connect your Google account to I-InsureCRM (available on Growth Pro and Elite plans), we access the following Google services with your explicit permission:

Gmail API

  • • Send personalized emails on your behalf to your own clients
  • • Send messages from your own Gmail address
  • • Track email sending status

Google Calendar API

  • • Sync follow-up dates
  • • Add birthday reminders
  • • Sync license expiration dates
  • • Read and update calendar events

Google Drive API

  • • Create organized folder structure
  • • Upload lead attachments and documents
  • • Access files you upload through I-InsureCRM

DocuSeal (Elite Plan Only)

If you integrate your DocuSeal account (Elite subscription), we will collect and process your DocuSeal API key. We will send lead contact information (name, email) to DocuSeal to facilitate document signing requests.

How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve I-InsureCRM functionality, including lead management, task tracking, and integrations.
  • Communication: To send you service-related emails, support responses, and important updates about your account.
  • Personalization: To customize your experience, including dashboard layouts, language preferences, and theme settings.
  • Google Integrations: To sync data between I-InsureCRM and your Google services (Gmail, Calendar, Drive) as you have authorized.
  • DocuSeal Integration: To facilitate the sending, tracking, and management of electronic signature requests for documents with your leads, when you have an Elite subscription and have connected your DocuSeal account.
  • Analytics: To understand how users interact with our platform and improve features.
  • Security: To detect, prevent, and respond to fraud, abuse, security risks, and technical issues.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
Google API Services User Data Policy Compliance

I-InsureCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How We Share Your Information

We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:

  • With Your Consent: When you explicitly authorize us to share data with third parties (e.g., Google services integration, DocuSeal integration).
  • Service Providers: We use trusted third-party service providers (e.g., Base44 infrastructure, Stripe for payments) who process data on our behalf under strict confidentiality agreements.
  • DocuSeal: When you use the DocuSeal integration (Elite subscription), we share lead contact details (name, email) with DocuSeal solely for the purpose of initiating and managing electronic signature requests as authorized by you.
  • Legal Requirements: When required by law, court order, or governmental authority.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
  • Protection of Rights: To protect the rights, property, or safety of I-InsureCRM, our users, or the public.

✓ We do not share your Google user data (Gmail, Calendar, Drive) with any third parties except as explicitly stated in the Google API Services User Data Policy compliance section above.

Data Retention and Deletion

Retention Policy

  • Active Account Data: We retain your data for as long as your account is active or as needed to provide you services.
  • Deleted Leads: Leads you delete are moved to a 'Recovery Bin' for 90 days before permanent deletion.
  • Google Data: Data synced from Google services remains in your Google account. I-InsureCRM only stores references and metadata.
  • Backup Data: Backups are retained for 30 days for disaster recovery purposes.

Your Right to Delete

You have the right to request deletion of your data at any time:

  • Individual Records: You can delete individual leads, tasks, or attachments directly within the application.
  • Google Integration: You can disconnect your Google account at any time from the Google Integration settings page.
  • Full Account Deletion: Contact our support team to request complete account deletion within 30 days.
Data Security

We implement industry-standard security measures to protect your information:

⚠️ Important Security Notice

While we implement strong security measures and industry best practices, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request access to the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your data (subject to legal retention requirements).
  • Portability: Request a copy of your data in a machine-readable format (CSV export available in the app).
  • Objection: Object to certain types of data processing.
  • Withdraw Consent: Withdraw consent for data processing where consent is the legal basis.

To exercise any of these rights, please contact us at carpa.solutions@gmail.com.

Compliance with Laws

I-InsureCRM is committed to compliance with applicable data protection laws, including:

  • GDPR (General Data Protection Regulation): For users in the European Economic Area.
  • CCPA (California Consumer Privacy Act): For California residents.
  • HIPAA: While I-InsureCRM is not a HIPAA-covered entity, we recommend that users do not store Protected Health Information (PHI) without appropriate safeguards.
Children's Privacy

I-InsureCRM is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email or through a prominent notice in the application.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: carpa.solutions@gmail.com

Company: Carpa Solutions LLC

Address: 2643 SW 187 Ave, Hollywood, Florida, 33029

© 2025 I-InsureCRM. All rights reserved.

Engineered by Carpa Solutions LLC