OBLQ LLC ("OBLQ," "we," "us," or "our") builds software for independent insurance agencies. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the choices you have. It covers:
- our website, oblq.ai (the "Site"), including the demo-request form;
- the OBLQ Quote customer portal (the "Portal"); and
- the OBLQ Quote service we operate for agency customers (the "Service").
OBLQ is a software company. We are not an insurance company, agency, broker, or managing general agent, and we do not sell, quote, underwrite, or bind insurance. Agencies use our software to prepare quotes with the carriers they are appointed with.
1. Who this policy applies to
- Visitors and prospects - people who browse the Site or request a demo.
- Customer users - staff of an agency that has signed up for the Service and who have Portal accounts.
- Consumers - the people whose information an agency customer sends through the Service to obtain quotes. We process that information on the agency's behalf and under its instructions (see Section 4).
2. Information we collect
Information you give us
- Demo and contact requests: name, agency name, email address, phone number, approximate number of agents in your office, approximate new leads per week, and anything you write to us.
- Communications: the content of emails, calls, texts, and support conversations with us.
Portal account information (customer users)
- Name, email address, role, agency, and sign-in activity. Passwords are handled by our authentication provider and stored only in hashed form; we never see them.
- Configuration your agency enters so the Service can work: the usernames and passwords for the carrier portals your agency is appointed with (stored encrypted - see Section 8), access your agency grants to its CRM / agency management system, and the connection to your agency's own cloud storage account (for example Dropbox or Google Drive) where quote documents are saved.
Consumer information processed for an agency ("Lead Data")
When an agency runs a lead through the Service, we receive from the agency's CRM the information a carrier's quote form asks for. Depending on the carrier this can include:
- name, mailing address, and the address of the property to be insured;
- phone number and email address;
- date of birth;
- property details such as year built, square footage, construction, roof type and age, and distance to fire protection;
- answers to the carrier's standard eligibility and underwriting questions, including prior insurance and claims history where the carrier asks;
- coverage selections; and
- the results the carrier returns: premium, coverage summary, the carrier's quote number and link, decline or additional-information reasons, and the quote document (PDF).
We do not collect Social Security numbers, driver's license numbers, or payment card numbers of consumers. Carriers may obtain reports (for example credit-based insurance scores or property reports) under their own authority and privacy notices; we do not receive those reports.
Billing information (customers)
- Usage counts (leads run), invoice amounts and status. Payment card details are collected and stored by our payment processor, Stripe; OBLQ never receives or stores card numbers.
Information collected automatically
- Server and edge logs: IP address, browser type, pages requested, and timestamps, processed by our hosting and security provider (Cloudflare) to deliver the Site and protect it from abuse.
- Bot protection on forms (Cloudflare Turnstile), which analyzes browser signals to distinguish people from bots.
- A session token the Portal stores in your browser to keep you signed in. This is strictly necessary for the Portal to function and ends when you sign out or close the tab.
- We do not use analytics cookies, advertising cookies, pixels, or other cross-site tracking on the Site or the Portal, and we do not show third-party advertising. Because we do not track visitors across other sites, we do not respond differently to browser "Do Not Track" signals.
3. How we use information
- To respond to demo and contact requests, schedule and hold demos, and follow up by email, phone, or text (text messages only with your consent, see Section 7).
- To provide the Service: run each lead through the carriers your agency selects, present the results in the Portal, save quote documents to your agency's storage, and, when you click, file a document to your CRM.
- To provide support, send service and account notices, and bill for the Service.
- To secure, monitor, debug, and improve the Site, the Portal, and the Service. Operational logs may include lead identifiers for a limited time (see Section 6).
- To produce aggregated or de-identified statistics (for example the number of quotes produced or total premiums quoted). These statistics do not identify any person or agency and we do not re-identify them.
- To comply with law, enforce our agreements, and protect rights, safety, and property.
4. Lead Data: how we act on an agency's behalf
We process Lead Data only to do what the agency has asked us to do - prepare quotes with the carriers it chooses. Specifically, our software enters the information into each carrier's own quoting portal using the agency's own appointment and credentials, exactly as an agent would by hand, reads what the carrier returns, and shows it to the agency.
- We do not sell Lead Data, share it for advertising, use it to build profiles, or use it to contact consumers.
- Each carrier receives Lead Data as it would if the agent had keyed it in directly, and handles it under the carrier's own privacy notice and agreements with the agency.
- Insurance agencies are "financial institutions" under the Gramm-Leach- Bliley Act. OBLQ acts as the agency's service provider, keeps Lead Data confidential, and maintains safeguards designed to protect it (Section 8).
- Our contract with each agency (our Data Processing Addendum) limits our use of Lead Data to providing the Service and requires us to help the agency respond to consumer requests.
If you are a consumer and have a question about information an agency ran through our software, the agency you dealt with is the business responsible for that information; you can also contact us and we will route your request to the agency and help resolve it (Section 7).
5. When we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- Service providers that help us run OBLQ, under contracts that limit their use of the information to providing services to us: Cloudflare (hosting, content delivery, security, bot protection), Supabase (database and authentication, hosted in the United States), GitHub (cloud automation environments that execute quote runs), Stripe (billing and payments), and an email delivery provider for notifications.
- Your agency's own systems, at your agency's direction: its CRM / agency management system, its cloud storage account, and the insurance carriers it selects. These are the agency's providers, not ours.
- Professional advisers (lawyers, accountants) under confidentiality.
- Legal and safety: to comply with law, subpoenas, or lawful requests; to enforce our agreements; or to protect the rights, safety, or property of OBLQ, our customers, or others.
- Business transfers: if OBLQ is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
Mobile phone numbers and text-message opt-in information are never shared with third parties or affiliates for their marketing or promotional purposes.
6. How long we keep information
- Demo and contact requests: as long as needed to respond and follow up, and no longer than 24 months after our last contact with you, unless you ask us to delete it sooner.
- Portal accounts and agency configuration: for the life of the customer relationship and up to 90 days after it ends. Carrier credentials can be changed or removed by the agency at any time in the Portal and are deleted when the relationship ends.
- Lead Data: within 31 days after a quote run we permanently delete everything in our systems that identifies or links to the lead: name, address, phone number, email address, the carrier's quote number and links, document links, and any carrier message text. What remains is a de-identified statistical record - carrier, premium amount, coverage amount, result codes, dates, and the lead's reference number in your agency's own CRM - which contains no personal information and is kept for your dashboard, reporting, and billing. Quote documents (PDFs) are stored in your agency's own cloud storage and remain under your agency's control; carriers keep their own copies of quotes under their own retention policies.
- Billing and usage records: kept, de-identified, for as long as tax and accounting rules require (up to 7 years).
- Operational logs: up to 31 days on systems we control; edge and security logs per our providers' standard short retention.
- Backups: encrypted backups may hold copies of deleted data for up to 30 days before they cycle out.
7. Your choices and rights
Anyone may ask us to access, correct, or delete the personal information we hold about them by emailing [email protected]. We will confirm receipt, verify that the request comes from you (or your authorized agent), and respond within 45 days. We will not treat you differently for exercising these rights. Where the information belongs to an agency's Lead Data, we will work with the agency: we delete on the agency's instruction, or on a verified direct request unless the agency has a legal reason to keep it (for example a policy that was written).
Marketing communications: every marketing email we send includes an unsubscribe link; you can also reply and ask us to stop. To stop text messages, reply STOP to any message. To stop calls, tell us and we will note it.
Text messaging (SMS): if you give us your mobile number and agree to be texted, we may text you about your demo request and related follow-up. Message frequency varies. Message and data rates may apply. Reply STOP to opt out at any time and HELP for help. Consent to receive texts is not a condition of any purchase. See the SMS terms in our Terms of Service.
California residents have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; to opt out of the sale or sharing of personal information (we do not sell or share it); to limit use of sensitive personal information (we use it only to provide the Service); and not to be discriminated against for exercising these rights. You may use an authorized agent; we will ask for proof of authorization. California's "Shine the Light" law: we do not disclose personal information to third parties for their direct marketing.
Residents of other states with privacy laws (for example Colorado, Connecticut, Virginia, Texas, Oregon) may use the same contact to exercise similar rights.
8. How we protect information
- All connections to the Site, the Portal, and our systems use TLS encryption in transit, and data is encrypted at rest.
- Carrier credentials are encrypted with AES-256 inside the database. They are decrypted only by server-side processes at the moment a quote is being prepared, never in the browser and never written to logs.
- Each agency's data is logically isolated with row-level security; the browser has no direct access to database tables.
- Access to production is limited to the people and processes that need it; staging and production are separate environments.
- We do not store payment card data (Stripe does), and we do not store Social Security numbers.
No system is perfectly secure. If we learn of a security incident that affects your information, we will notify affected customers without undue delay and as required by law. Agency customers can request our security overview and Data Processing Addendum at any time.
9. Children
The Site and the Service are for businesses and professionals. We do not knowingly collect personal information from anyone under 18. If you believe we have, contact us and we will delete it.
10. Changes to this policy
When we change this policy we will update the effective date above. For material changes we will also notify customers through the Portal or by email. Continued use of the Site or the Service after a change means you accept the updated policy.
11. Contact us
Privacy questions, access, correction, or deletion requests:
- Email: [email protected]
- OBLQ LLC, California, USA