Skip to main content

Privacy Policy

Last updated: July 10, 2026

1. Introduction

Policy Balance Hub, operated by [LEGAL ENTITY NAME] (“we,” “our,” or “us”), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our insurance reconciliation platform and marketing website at policybalancehub.com.

2. Information We Collect

2.1 Information You Provide

  • Account registration information (name, email, company name)
  • Billing information (processed securely by Stripe)
  • Insurance data you upload for reconciliation purposes
  • Communications you send to our support team
  • Contact form submissions

2.2 Information Collected Automatically

  • Log data (IP address, browser type, pages visited)
  • Device information (operating system, screen resolution)
  • Usage analytics (features used, session duration)
  • Authentication session data stored in your browser (sessionStorage)

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our reconciliation platform
  • Process your transactions and manage your account
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and requests
  • Monitor and analyze usage trends to improve user experience
  • Detect, investigate, and prevent fraudulent or unauthorized activity

4. Data Security

We implement industry-standard security measures to protect your data, including AES-256 encryption at rest, TLS 1.3 encryption in transit, and multi-tenant data isolation. Personal identifying information is tokenized before any AI processing. See our Security page for more details.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. Following termination, non-financial operational data that is not subject to regulatory retention (such as account settings, notifications, and processed import and email records) is permanently deleted after the 30-day export window described in our Terms of Service. Financial records (policies, transactions, commissions, and carrier statements), the personal information embedded in those records, and immutable audit logs are retained indefinitely to comply with insurance record-keeping obligations and the Gramm-Leach-Bliley Act (GLBA). When you submit a verified deletion request, we anonymize the personal identifiers within these retained records rather than deleting the records themselves, satisfying deletion rights while preserving the financial record for regulatory examination. For a complete, category-by-category schedule, see our Data Retention Policy.

6. Sharing of Information

We do not sell your personal information. We may share information with:

  • Service providers who assist in operating our platform (hosting, payment processing)
  • Professional advisors (lawyers, accountants, auditors)
  • Law enforcement when required by law or to protect our rights
  • Business transfer participants in the event of a merger or acquisition

6.1 Subprocessors

We engage a limited set of third-party service providers (“subprocessors”) to process certain data on our behalf. We enter into a data processing agreement (DPA) with each subprocessor that handles personal information, and we require each to maintain safeguards consistent with this policy. The current subprocessors are:

  • Stripe, Inc. — Billing and payment data (your name, email, billing address, and card metadata such as brand and last four digits). Card numbers are entered directly into Stripe and are never stored by us. Governed by Stripe’s Data Processing Agreement.
  • Anthropic, PBC — AI processing of carrier-statement text for reconciliation. Personally identifiable information (names, Social Security numbers, addresses) is redacted before any text is sent, so Anthropic receives only de-identified financial data. Governed by Anthropic’s commercial terms and data processing addendum.
  • [HOSTING PROVIDER] — Application and database hosting. The platform is currently self-hosted; this entry is a placeholder for a managed hosting provider if and when one is adopted.
  • [TRANSACTIONAL EMAIL PROVIDER] — Delivery of transactional email such as account, notification, and support messages.
  • [ERROR-MONITORING PROVIDER, e.g. Sentry] — Application error and performance monitoring.

A current list of subprocessors is available on request at [email protected]. We will update this section before adding a new subprocessor that processes personal information.

7. Your Rights

Depending on your location, you may have the right to access, correct, delete, or port your personal data. You may also have the right to opt out of certain data processing activities. To exercise any of these rights, please contact us at [email protected].

8. Cookies and Local Storage

Our platform does not use cookies. Authentication tokens are stored in your browser’s sessionStorage, which is automatically cleared when you close the browser tab. We do not use analytics cookies, tracking pixels, or similar technologies. Our marketing website does not set any cookies or use third-party tracking scripts.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date.

10. Contact Us

If you have any questions about this Privacy Policy, please contact [LEGAL ENTITY NAME] at [email protected], or by mail at [REGISTERED / NOTICE ADDRESS].