Legal
Privacy Policy
Effective . This is also our initial and annual privacy notice under the Gramm-Leach-Bliley Act.
This is a fictional demo agency. Greene Insurance Group, LLC does not exist, holds no insurance licence, and collects no real personal information. This document is an illustrative template showing the shape of a privacy policy an independent insurance agency would publish. It is not the enforceable policy of a real business, it creates no rights or obligations, and it is not legal advice. Do not adopt it for a real company without a lawyer.
Insurance runs on personal information — where you live, what you drive, what you own, what has gone wrong before. This page explains what we collect, why, who sees it, and what you can tell us to stop doing.
Who this covers
This policy applies to Greene Insurance Group, LLC ("Greene Insurance", "we", "us") and to this website, our quote and service forms, our email and text correspondence, and the work we do placing and servicing insurance for you. It covers you whether you are a client, a prospective client, someone named on a policy we service, or a claimant.
It does not cover what an insurance carrier does with your information once a policy is placed with them. Carriers are separate companies with their own privacy notices, and they will send you one. When we hand your information to a carrier at your request, their notice governs from that point forward.
We offer insurance services only in the United States, and only in the states listed in our footer.
GLBA / Regulation P privacy notice
Under the Gramm-Leach-Bliley Act (GLBA) and the federal privacy rule known as Regulation P, an insurance agency is treated as a financial institution. That means we owe you a privacy notice when we first establish a relationship and, where required, on a continuing basis. This section is that notice. Your state insurance department may also apply a state insurance privacy regulation on top of the federal rule.
Why we can collect and share
Financial companies choose how they share personal information. Federal law gives you the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect it. Here is what we do:
| Reasons we can share your personal information | Does Greene share? | Can you limit this sharing? |
|---|---|---|
| For our everyday business purposes — processing your quote requests and applications, servicing and renewing your policies, reporting and following claims, maintaining your file, and responding to court orders and legal investigations | Yes | No |
| For our marketing purposes — to offer our own products and services to you | Yes | Yes — see “Marketing, calls, and texts” below |
| For joint marketing with other financial companies | No | We do not share |
| For our affiliates' everyday business purposes — information about your transactions and experiences | No | We do not share |
| For our affiliates' everyday business purposes — information about your creditworthiness | No | We do not share |
| For our affiliates to market to you | No | We do not share |
| For nonaffiliates to market to you | No | We do not share |
The honest summary: we share what a carrier, a wholesaler, or a rating service needs in order to quote, issue, service, or pay a claim on your policy, and we do not share your information with anyone so they can market their own products to you. We have no corporate affiliates.
What you cannot opt out of
GLBA does not let you opt out of the sharing that makes insurance work. If you ask us to quote your home, we have to send your address and loss history to the carriers we are quoting. If you report a claim, we have to send it to the carrier. Those disclosures are made "as necessary to effect, administer, or enforce a transaction you requested", and there is no opt-out for them. You can always stop asking us to do that, which is the real control you hold.
What we collect
The categories of nonpublic personal information we collect depend entirely on what you ask us to insure. We collect it from you, from your current or former insurance company, from carriers and wholesalers we quote you with, and from consumer reporting agencies.
From you
- Identifiers and contact information — name, mailing and property addresses, email address, phone number, date of birth.
- Household and risk details — everyone in the household who drives or is to be insured, occupation, marital status, and homeownership.
- Property and vehicle information — VINs, year and mileage, square footage, roof age and construction, alarm and sprinkler systems, mortgagee or lienholder details.
- Business information — for commercial lines: entity type, operations, revenue, payroll, class codes, locations, vehicle schedules, and contract requirements.
- Existing coverage — your current carrier, limits, deductibles, premium, renewal date, and any declarations page you choose to send us.
- Correspondence — emails, form submissions, texts, voicemails, and the notes an agent writes about a conversation.
From third parties
- Consumer reports — motor vehicle records, and loss history reports (the industry's shared claims database) obtained through consumer reporting agencies, when you have asked us to quote you.
- Credit-based insurance scores, where state law permits a carrier to use one in rating. Several states restrict or prohibit this, and where the restriction applies, it is not used.
- Carrier and claims data — policy, billing, and claims information that flows back to us from the carriers we placed you with, so that we can service the policy.
- Public records — property tax and assessor records, recorded liens, and business registrations.
Sensitive information
Some lines need information that is sensitive by any definition: a Social Security number for a life or benefits application, health information for underwriting, or a driver's licence number for auto. We ask for these only when a specific carrier's application requires them, we tell you why at the time, and we do not collect them through this website's forms. We do not process payment card numbers or bank account details on this site at all — premium payment happens through the carrier or a dedicated payment processor.
Under the Fair Credit Reporting Act, if a consumer report contributed to a carrier declining you, charging more, or offering less favourable terms, you are entitled to an adverse action notice telling you which agency supplied it — and you can get a free copy of that report from the agency and dispute anything inaccurate in it.
How we use it
- To answer your question, prepare quotes, and submit applications.
- To service policies: endorsements, certificates, ID cards, billing questions, and cancellations you ask for.
- To re-market your coverage at renewal across our carrier panel.
- To report claims, advocate for you during them, and follow them to close.
- To keep the records our errors-and-omissions insurer and state regulators require us to keep.
- To send you renewal reminders, payment-due notices, and claim status updates.
- To send you agency marketing — which you can stop at any time.
- To detect and prevent fraud, and to protect our systems.
- To comply with law, subpoenas, regulatory examinations, and lawful requests.
We do not use your information to make automated decisions that produce legal or similarly significant effects about you. Underwriting decisions are made by carriers, under their own rules, and a person at this agency can always explain to you what happened and why.
Who we share it with
- Insurance carriers we quote you with or place you with, and their underwriting and claims staff.
- Wholesalers, managing general agents, and surplus lines brokers, when a risk needs a market we do not access directly.
- Comparative raters and quoting platforms, which take one set of risk details and return indications from multiple carriers.
- Consumer reporting agencies, to order the reports described above.
- Premium finance companies, if you choose to finance a premium.
- Service providers that run our business under contract — our agency management system, email and calendaring, CRM, document storage, e-signature, SMS delivery, accounting, and hosting. They may use your information only to provide that service to us, and are contractually barred from using it for their own purposes. The tools we run are listed publicly on our colophon.
- Professional advisers — our attorneys, auditors, and errors-and-omissions carrier — where necessary.
- Regulators, courts, and law enforcement, when the law requires it or a valid legal process compels it.
- A successor, if the agency is ever sold or merged, subject to this policy.
We do not sell your personal information. We do not rent mailing lists. We do not hand your details to lead aggregators, comparison sites, or anyone who wants to market their own products to you.
Cookies, analytics, and this website
This website is deliberately boring. It is a set of static pages that:
- set no cookies and use no local storage;
- load no third-party scripts, font CDNs, icon kits, maps, chat widgets, or advertising pixels — the typefaces we use are served from this site, so no font vendor sees your visit;
- run no advertising or cross-site tracking of any kind;
- make zero cross-origin requests, so no other company learns you visited us.
Our web host records ordinary server logs — IP address, timestamp, page requested, user agent — to serve the site, spot abuse, and diagnose faults. Those logs are kept briefly and are not used to build a profile of you.
If we ever add analytics or any embedded third-party feature, we will update this section and add a consent mechanism before it loads, not after. Until then, there is nothing here for a cookie banner to ask you about.
Your privacy rights
Around twenty US states now have comprehensive consumer privacy laws, and more take effect each year. The details differ, but the rights they grant look broadly the same. Rather than publish a state list that goes stale, we extend the following to anyone who asks, wherever you live:
- Know and access — what personal information we hold about you, where we got it, why we have it, and who we disclosed it to.
- Copy / portability — a copy in a portable, machine-readable format where that is practicable.
- Correct — fix information that is wrong. Worth doing: an incorrect garaging address or roof age changes your premium.
- Delete — have information deleted, subject to what we must keep by law or to service a policy still in force.
- Opt out of sale, sharing, and targeted advertising — we do none of these, but the right stands.
- Opt out of profiling that produces legal or similarly significant effects. We do not do this either.
- Limit the use of sensitive personal information to what is needed to provide the service you asked for.
- Non-discrimination — exercising a right will never get you worse service, a worse price, or a refusal to quote.
- Appeal — if we refuse a request, you can appeal, and we will give you a written reason. If we still say no, your state attorney general will hear a complaint.
One nuance worth being straight about. Most state comprehensive privacy laws contain an exemption for information collected, processed, or disclosed under the Gramm-Leach-Bliley Act — and in some states, for GLBA-regulated businesses entirely. A great deal of what an insurance agency holds about you sits inside that exemption. We honour the requests above as a matter of agency policy whether or not an exemption technically applies, but where insurance law requires us to retain a record, we will keep the record and tell you so.
Do Not Sell or Share My Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no advertising network, data broker, or lead-buying arrangement on the other end of this website.
Because there is nothing to opt out of, this section exists to say so plainly rather than to hide it. If you want the opt-out recorded against your file anyway, ask and we will record it — no justification needed, no account required.
Global Privacy Control
We honour Global Privacy Control (GPC) signals. If your browser or extension sends the GPC signal, we treat it as a valid opt-out of sale and of sharing for targeted advertising for that browser, automatically, without asking you to fill in a form or prove who you are. You can turn GPC on at globalprivacycontrol.org.
An opt-out is tied to the browser that sent it, so if you use another device or clear your settings you may need to send it again. If you would rather the opt-out attach to you instead of a browser, email us and we will apply it to your client record.
Authorised agents
Someone else can make a request on your behalf. We will ask for written permission signed by you, or proof of a power of attorney, and we may still verify your identity directly with you before we act.
How to make a request
Email privacy@greeneinsurance.example, call (828) 555-0142, or write to us at the address below. Tell us what you want us to do. You do not need to use particular words or a particular form.
- Verification. Before we hand over or delete personal information we confirm you are who you say you are — usually by matching details already in your file, or by a call to the number on it. We ask for the minimum that will do the job, and anything you send solely to verify identity is used only for that and then discarded.
- Timing. We acknowledge within 10 days and respond substantively within 45 days. If a request is complex we may take one further 45-day extension, and we will tell you before we do.
- Cost. Free, unless a request is repetitive or manifestly unfounded — in which case we will tell you what it would cost before doing anything.
- Appeals. Reply to our decision saying you want to appeal. A different person reviews it and answers you in writing.
Marketing, calls, and texts
- Email. Every marketing email has an unsubscribe link, and it works. You will still get transactional messages about a policy you hold — renewal notices, cancellation warnings, claim updates — because those are not marketing and you need them.
- Texts. Reply STOP to any message to stop all of them, or HELP for help. Message frequency varies; message and data rates may apply. We only text a number where you gave express consent, and that consent was never a condition of buying anything from us.
- Calls. Ask any agent to put you on our internal do-not-call list and it is done on the call. We maintain that list independently of the national registry.
- Mail. Ask and we will stop.
How long we keep things
We keep client and policy records for as long as you are a client and then for the period our state licensing rules and our errors-and-omissions coverage require — generally several years after the last transaction, and longer for claims files, life policies, and anything under a legal hold. That retention is not optional: an agency that destroys a policy file early cannot defend itself, or you, when a coverage question surfaces years later.
Quote requests that never turn into a policy are kept for a shorter period so we can pick the conversation back up at your renewal, then deleted. Server logs are kept briefly. Marketing suppression lists are kept indefinitely on purpose, because the only way to remember not to contact you is to remember you.
How we protect it
We maintain physical, electronic, and procedural safeguards that comply with the GLBA Safeguards Rule and with the data security standards our states apply to insurance licensees. In practice that means encrypted transport and storage, multi-factor authentication on every system that holds client data, least-privilege access reviewed when someone changes role or leaves, background checks on staff, annual security training, written incident response and business continuity plans, and diligence on the vendors listed above before we send them anything.
No safeguard is perfect. If we discover a breach affecting your personal information we will notify you and the relevant regulators within the deadlines the applicable state law sets. If you have found a security problem with this website, our security page tells you how to report it.
Children
This website is meant for adults. We do not knowingly collect personal information from anyone under 16, and nothing on this site is directed at children. We do hold information about minors when a parent lists a teenage driver on an auto policy or names a child as a dependent or beneficiary — that comes from the adult client, not from the child, and it is used only to place and service the coverage. If you believe a child has sent us information directly, email privacy@greeneinsurance.example and we will delete it.
Changes to this policy
When we change this policy we update the effective date at the top. If a change materially affects how we handle your information — a new category of sharing, for instance — we will tell you directly rather than relying on you to re-read the page, and we will give you the notice and any opt-out that GLBA or your state law requires before it takes effect.
Contact us
Privacy questions, requests, and appeals all go to the same place.
Greene Insurance Group, LLC — Privacy118 Ridgeline Court, Suite 240, Asheville, NC 28801
Email: privacy@greeneinsurance.example
Phone: (828) 555-0142
Related: Terms of Use · Accessibility · Security