01 — Scope
Data collection scope and purposes
This Privacy Policy explains how Coverly collects and uses information when you visit Coverly, request an insurance quote, interact with a partner-branded experience, or use a Coverly partner account. “Coverly,” “we,” and “us” refer to the Coverly service operated through this application.
We use information to provide quote and comparison experiences, qualify and route leads, operate partner dashboards and integrations, send service communications, protect the service, understand usage, and meet legal or contractual obligations. We do not sell personal information.
Insurance carriers, brokers, agencies, and other partners may have their own privacy notices and obligations. When a lead is routed to one of them, that organization may process the information under its own notice and applicable law.
02 — Information
Information we collect
Quote and contact information
Depending on the product and entry point, a quote form may collect your name, email address, and other contact details you choose to provide; ZIP code and state; vehicle year, make, model, and preferred carrier; or household and eligibility inputs. Health quote inputs can include household size, member ages, tobacco status, household income or AGI, employer coverage, current insurance status, plan-tier and deductible preferences, HSA eligibility, and a must-have prescription or medication note. A life or auto flow may also ask for date of birth. We use these inputs to generate or display quote options, qualify intent, and connect a request with the relevant service professional or carrier.
Partner account and service-use information
For partner accounts, we may collect the organization profile, contact and notification details, website, phone, billing contact and address, branding and widget configuration, plan and status, trial or activation information, lead limits, and usage or API request activity. We also maintain account-security and support records needed to operate the account.
Technical and analytics signals
We may receive ordinary request and browser signals such as landing path, referring URL, truncated user-agent information, timestamps, and basic service or error activity. The site may also keep a Coverly visitor identifier in browser local storage for the Polsia analytics beacon. We use these signals for attribution, measurement, troubleshooting, abuse prevention, and service improvement.
03 — Quote results
Quote-session storage
Active quote results are held in application memory. Each result is placed in a process-local quotes Map with a generated identifier and a createdAt timestamp. This temporary store is not a durable user account or a promise that a result will remain available: a process restart, deployment, or memory eviction can remove an active result.
Separately, submitting a quote triggers the CRM capture path. That path can persist a contact record and queue follow-up work, and later actions can record contact events, a selected carrier, an application, or partner attribution. CRM persistence and the in-memory quote session are separate systems; storing one does not mean that every quote result is permanently archived.
04 — Partner accounts
Partner-account data
To provision and support a broker, MGA, FMO, carrier, or other partner relationship, Coverly may process:
- profile and contact information, including contact, notification, phone, website, logo, and billing details;
- branding and configuration, such as a logo, primary color, button style, website, subdomain, and notification preferences;
- plan, trial, status, activation, lead-quota, and usage information; and
- API-key metadata, including a key prefix, label, environment, creation time, last-used time, and revocation time.
Raw partner API keys are not stored. Coverly stores a hash and limited display or lifecycle metadata so keys can be verified, shown once, rotated, or revoked. Keep credentials confidential and contact us promptly if you believe one has been exposed.
05 — Attribution
Lead attribution data
When a visitor arrives through a partner, referral, affiliate, or campaign link, Coverly may associate the resulting request with source or UTM-style intent, a partner ID, a referral or affiliate code, and the relevant contact or lead record. This lets us route leads, report campaign performance, calculate partner attribution, prevent duplicate credit, and support partner payments or referrals.
Affiliate click records can include the click timestamp, landing path, referring URL, a user-agent value truncated before storage, and an IP-derived SHA-256 hash. The raw affiliate-click IP is not stored in that record. Referral and affiliate cookies are short-lived, HTTP-only, same-site cookies; the affiliate attribution cookie is normally cleared after a quote submission has been attributed.
06 — Email
Transactional email
Coverly currently sends application email through the Polsia email proxy configured by POLSIA_EMAIL_PROXY_URL. Depending on the message, the proxy may receive the recipient address plus the relevant subject and plain-text or HTML body. That content can include quote follow-up details, vehicle or household context, confirmation or policy links, partner notifications, and magic-link login URLs.
These messages support requested quotes, account and partner operations, transactional confirmations, and security workflows. We have not added a separate email integration to this application. The proxy and any downstream delivery provider may process message content as needed to deliver the email.
07 — Sharing
Sharing and service providers
We share information with the people and systems needed to provide the service. This can include a broker, agency, MGA, FMO, carrier, or other partner connected to a quote or lead; application hosting and database providers; the configured AI qualification endpoint; the Polsia email proxy; analytics or monitoring providers; and billing or payment services for partner accounts. The information shared depends on the flow and is intended to be limited to the relevant operational purpose.
We may also disclose information when required by law, to protect users or the service, to investigate fraud or abuse, or as part of a business transfer. We do not provide personal information to data brokers for sale or targeted advertising.
08 — Security
Security and responsible use
Coverly uses access controls, platform protections, encrypted connections in deployed environments, HTTP-only same-site cookies for supported sessions and attribution, and one-way hashing for partner API keys. We limit access to operational data based on role and need. No internet service or transmission method is completely secure, so please use care when sharing information and notify us of suspected compromise.
The health quote experience is not designed for medical records, claims files, diagnoses, or clinical notes. Please do not submit information that the form does not request. AI-assisted qualification is a service operation and is not itself an insurance underwriting or coverage decision.
09 — Retention
Retention and deletion
Retention depends on the type of information and why it is needed. Active quote results in the process-local store may disappear when the process ends, while CRM contacts, follow-up records, contact events, partner records, attribution records, security logs, and billing or accounting records may be retained for ongoing service operations, account administration, fraud prevention, dispute resolution, legal compliance, or a partner agreement.
We do not promise a single fixed retention period for every category on this page. Backups, logs, and records needed for legal or security purposes may remain until their normal rotation or the applicable obligation ends. Public trust and security pages describe service practices; an applicable written customer or partner agreement controls if it contains a more specific retention commitment.
10 — Your choices
Your requests and choices
You may ask us to identify, access, correct, or delete personal information, or to explain how a quote or partner record is being used. Send a request to coverly-8@polsia.app with enough detail for us to locate the record. We may need to verify your identity and may limit a request where keeping information is necessary for security, legal compliance, a transaction, or a partner’s service obligations. If your information came through a partner, you may also contact that partner directly.
We will consider requests under applicable law and respond with the outcome and any reason a limitation applies. A deletion or opt-out request may affect our ability to provide a quote, account, login link, notification, or partner service.
11 — Cookies
Cookies and local storage
Coverly uses cookies and browser storage for necessary service behavior and attribution. Examples include the 30-day coverly_ref referral cookie, the 30-day coverly_aff_ref affiliate cookie, and the short-lived partner_session cookie used for supported partner access. The site may store polsia_vid in local storage for analytics. Blocking or clearing these technologies can disable attribution, sign-in, or some site functionality.
12 — Contact
Contact us about privacy
For a privacy request, data question, or concern about a quote or partner record, email coverly-8@polsia.app. Please do not include passwords, API keys, or unnecessary sensitive information in your first message.