Privacy Policy
Version 2026-09-25.2
Draft — attorney review required before commercial launch. Bracketed items are still being filled in.
The short version
- We don't sell or share personal information, and we never have. No ads, no ad trackers, no analytics tools that send your data to other companies.
- Your agency's data is your agency's. For information about an agency's team and customers, the agency decides what goes in, and we process it only on the agency's behalf.
- We keep very little. Customers of agencies appear by name only: no Social Security numbers, birthdays, policy numbers, or contact details.
- AI never trains on your data. AI runs through AWS Bedrock, and people review every AI suggestion. See AI & Data Use.
- You have rights to see, correct, delete, and get a copy of your information. Make a privacy request or email drewtekellcareers@gmail.com.
1. Who we are and what this policy covers
AgencyHuddleHQ, LLC ("AgencyHuddleHQ," "we," "us") makes AgencyHuddleHQ, online software that insurance agencies use to track activity, sales, team pay, and agency finances. Our address is 9611 Salem Ct, Highlands Ranch, CO 80130.
We handle personal information in two different roles:
- For agencies (most of what's in the app). When an agency uses AgencyHuddleHQ, the agency is the "business" (California) or "controller" (Colorado and other states) for information about its team members and its customers. We are the agency's service provider or processor: we use that information only to run the app for that agency, under a written contract (our Data Processing Addendum). If you work at or are a customer of an agency, that agency's own privacy notice also applies to you, and the agency is the right place to start with most requests (see section 13).
- For ourselves (a small amount). We are the business or controller for information we collect for our own purposes: people who visit our website, contact us, or ask for a demo; the agency owner's billing and account contact details; people who make privacy requests; and security records such as sign-in history and accepted agreements.
This policy covers both. It includes our California notice at collection (section 2), California employee and business-contact notice (section 14), and Colorado section (section 15).
2. Notice at collection: what we collect and why
This table is our notice at collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"). It uses the CCPA's category names. Section 10 gives details on how long we keep each type.
| Category (CCPA) | What it means in AgencyHuddleHQ | Where it comes from | Why it's used | Kept |
|---|---|---|---|---|
| Identifiers | Name, email address, account ID, internet protocol (IP) address, browser type | You; the agency that invited you; your device | Create and secure your account, sign you in, send account emails, record agreement acceptance, prevent abuse | While the account is active, then per section 10 |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, employment details, and pay information entered by an agency | The agency and its team | Show each person their own pay, calculate payroll reports the agency approves | Per the agency's account, then deleted per section 10 |
| Professional or employment-related information | Role, office, start date, activity counts, sales credited, win-the-day results, leaderboard rank, pay plan, pay rates, hours, payroll amounts, performance history | The agency and its team | Run the agency's daily scoreboard, goals, pay plans, and payroll reports | Per the agency's account |
| Commercial information | Names of an agency's customers and leads, the products they bought, premium and deposit amounts, sale status, lead source. Agency subscription and billing history. | The agency and its team; our payment processor | Sales log, pipeline, commission tracking, and marketing reports for the agency; billing the agency | Per the agency's account; billing records per section 10 |
| Internet or other electronic network activity | Sign-in times, pages requested, error logs, office TV link last-used time | Your device and our servers | Keep the Service working and secure, investigate problems | Server logs 30 days today, up to 1 year as security logging expands |
| Sensitive personal information: account log-in | Your email together with your password (stored only as a one-way scrambled hash) | You | Only to sign you in and protect your account | While the account is active |
What we don't collect. We don't collect Social Security, driver's license, state ID, or passport numbers; dates of birth; bank or card numbers (card payments go directly to our payment processor); precise location; health, biometric, or genetic information; racial or ethnic origin, religion, union membership, sexual orientation, or citizenship status; or the contents of your email or texts. The app is built to hold an agency's customers by name only, and our Terms tell agencies not to enter anything more sensitive.
Selling and sharing. We do not sell personal information or share it for cross-context behavioral advertising (section 6).
Inferences. We don't build profiles about you. The app shows performance numbers (for example, win-the-day streaks and pacing) that the agency sets up; it doesn't predict or infer your characteristics.
3. How we use personal information
- To provide the Service to each agency: counting activity, logging sales, ranking leaderboards, calculating pay and payroll reports, tracking commissions, and running budgets and cash flow.
- To create, secure, and support accounts, including password resets and two-step sign-in.
- To detect, prevent, and investigate security incidents, fraud, and misuse.
- To fix bugs and keep the Service running.
- To run AI features the agency uses, as described in AI & Data Use. We never use personal information to train AI models.
- To bill agencies and keep business records.
- To keep records of who accepted which version of our agreements, and when.
- To respond to privacy requests and meet legal obligations.
We don't use agency data for our own marketing, and we don't combine it with data from other sources.
4. Where it comes from
- From you, when you sign up, accept an invite, or use the app.
- From your agency, when an owner or office manager adds or updates information about the team, sales, pay, or finances.
- From your device and our servers, automatically, when you use the Service (IP address, browser type, sign-in times).
- From our payment processor, for billing status.
5. Who we disclose it to
- Inside your agency. Agency data is visible only to people in the same office, according to their role. Team members see their own pay, never anyone else's. Only owners and office managers see agency financials and payroll. No agency can see another agency's data.
- Our service providers, under contracts that limit them to providing their service to us:
- Amazon Web Services (hosting, database, backups, logs, email, and the Bedrock AI service), in the United States.
- Our payment processor (for example, Stripe) for subscription billing, when billing is live.
- When the law requires, such as a valid court order. When allowed, we tell the agency first.
- In a sale or merger of our business, to the new owner, who must honor this policy.
We have disclosed the categories in section 2 to our service providers for the business purposes in section 3 in the past 12 months. We have not disclosed personal information to anyone else.
6. We do not sell or share personal information
We do not sell personal information. We do not "share" it (the CCPA's term for giving it out for cross-context behavioral advertising). We have not done either in the past 12 months, and we have no actual knowledge of selling or sharing information of anyone under 16. We don't use advertising cookies, ad pixels, or third-party analytics that send your data to other companies.
Because we don't sell, share, or use personal information for targeted advertising, there is nothing to opt out of. We still honor opt-out preference signals such as Global Privacy Control: if your browser sends one, we treat it as a request not to sell or share, which is already our practice.
7. Sensitive personal information
The only sensitive personal information we collect is your account log-in (email and password). We use it only to sign you in and keep your account secure, which the CCPA allows without offering a "limit the use" choice. We don't use sensitive personal information to infer anything about you.
8. AI
AI features run through AWS Bedrock using Anthropic's Claude models, inside AWS in the United States. AWS doesn't use Bedrock inputs or outputs to train models and doesn't share them with the model's maker. We don't either. AI suggestions are drafts that a person reviews and confirms, and AI doesn't make decisions about people. Full details: AI & Data Use.
9. Cookies and browser storage
We use only what's needed for the app to work:
| Name | Type | What it does | How long |
|---|---|---|---|
ahq_session | Essential cookie | Keeps you signed in | Up to 30 days, or until you sign out |
| Offline tap queue | Browser storage on your device | Holds activity taps made while offline until they're sent | Until the taps are sent |
No advertising, analytics, or social media cookies. Because these are strictly necessary, there's no cookie banner. If we ever add a non-essential cookie, we'll update this policy and ask first where the law requires.
10. How long we keep information
| Information | How long |
|---|---|
| Agency data (team, activity, sales, customer names, pay, payroll, finances, change history, uploaded files) | While the agency subscribes. After it cancels, the owner has 30 days to export; we then delete it within 60 days. |
| Your account (name, email, password hash) | While you belong to at least one office. If an agency removes you, your history stays with that agency's records. |
| Backups | Overwritten on a rolling schedule of no more than 35 days (7 days today) |
| Server and security logs (IP address, browser, sign-in times) | 30 days today, up to 1 year as security logging expands |
| Sign-in sessions | Expire after 30 days at most |
| Password reset links | Expire within hours; the record of the request is kept up to 1 year for security |
| Records of accepted agreements (who, which version, when, IP address) | While the account exists and for 6 years after, to show what was agreed |
| Privacy requests and our responses | 24 months, as the CCPA regulations require |
| Billing and tax records | 7 years |
| AI setup guide conversation | Stored with the agency's setup until the agency's data is deleted |
| AI help chat questions | Not stored by us after the answer is sent |
11. How we protect information
- Encryption in transit on every connection (TLS 1.2 or newer) and encryption of stored data.
- Passwords stored only as bcrypt hashes; sign-in, invite, reset, and TV links stored only in scrambled form.
- Each agency's data is walled off from every other agency in the code and in the database.
- Role-based access, a change history on sales, pay, and settings, and nightly backups.
- Data stored in the United States (AWS, Oregon region).
No system is perfectly secure. If a breach affects your personal information, we'll notify the agency and, where the law requires, you and the authorities.
12. Your privacy rights
Depending on where you live, you may have these rights. We honor them for everyone in the United States, not only where a law requires it.
- Know and access: what personal information we have about you, where it came from, why we use it, who we've disclosed it to, and a copy of the specific pieces.
- Correct information that's wrong.
- Delete information about you, with some exceptions (for example, records the law requires us or the agency to keep, such as payroll records).
- Portability: a copy in a common format you can take elsewhere.
- Opt out of the sale or sharing of personal information, targeted advertising, and profiling that produces significant effects. We don't do any of these.
- Limit the use of sensitive personal information. We only use it as the law allows without a limit request (section 7).
- No retaliation. We won't treat you differently for using these rights. California law also protects employees from retaliation by their employer for exercising CCPA rights.
- Appeal if we turn down your request (section 13).
Automated decisions. We don't use AI or other automated decision-making technology to make, or to materially influence, significant decisions about people, such as hiring, firing, pay, or promotion. If that ever changes, we'll update this policy, and the notices, opt-outs, and human review California (from January 1, 2027) and Colorado (from January 1, 2027) require will be in place first.
13. How to make a request
If your request is about an agency's data (you work at an agency, or you're a customer of one), the agency controls that information. Contact the agency first; it can see, correct, export, and delete your information in the app, and we help it respond. If you contact us, we'll tell you which agency holds your information, pass your request to it when you ask us to, and help the agency answer it.
For anything else, or if you're not sure, contact us:
- Online: Make a privacy request
- Email: drewtekellcareers@gmail.com
Verification. To protect you, we confirm your identity before acting, usually by matching the request to the email on your account or asking you to sign in. We ask only for what we need to verify you.
Authorized agents. Someone can make a request for you with your signed permission. We may still ask you to confirm your identity with us directly.
Timing. We confirm we received your request within 10 business days and answer within 45 days. If we need more time (up to 45 more days), we'll tell you why. There is no charge, unless requests are clearly excessive or repetitive.
Appeals. If we deny your request, you can appeal by replying to our answer or emailing drewtekellcareers@gmail.com with "Appeal" in the subject line. We answer appeals within 45 days (Colorado allows us 60 more days when needed, and we'll tell you if we need them). If you're not satisfied, you can contact your state attorney general. California residents can also contact the California Privacy Protection Agency.
14. California notice for employees and business contacts
Since January 1, 2023, the CCPA covers information about employees, job applicants, contractors, and business contacts. This section explains how that applies here.
If you work at an agency that uses AgencyHuddleHQ. Your employer (the agency) decides what to enter about you and is responsible for its own notice to you. Through the app, the agency may hold: your name, work email, role, office, start date, activity counts, sales you're credited with, win-the-day and leaderboard results, pay plan, pay rates, raises, hours, payroll amounts, and performance history. The app doesn't hold your Social Security number, home address, date of birth, bank account, tax forms, or benefits information.
- Purposes: the agency's daily scoreboard, goals, coaching history, pay calculations, and payroll reports.
- Our role: we're the agency's service provider. We use your information only to run the app for the agency, and never for our own purposes, advertising, or AI training.
- Not sold or shared. Ever.
- Retention: as long as the agency keeps its account (section 10). Agencies may have legal duties to keep pay records for a number of years.
- Your rights: as in section 12. Start with your agency; we'll help.
If you're a business contact (for example, an agency owner, office manager, or billing contact dealing with us). We collect your name, business email, role, and agency, plus billing history, to run the customer relationship, bill for the Service, and support you. We keep it while the relationship lasts and as section 10 describes. It's not sold or shared, and section 12 rights apply.
15. Colorado
Who this applies to. The Colorado Privacy Act ("CPA") protects Colorado residents acting in an individual or household context. It doesn't cover people acting in a commercial or employment context, so most information in AgencyHuddleHQ (team members at work, agency owners doing business) falls outside it. The CPA also has thresholds for which businesses it covers. We honor the rights below for Colorado residents anyway.
For agency data, we're the agency's processor under a written contract that includes the CPA's processor terms (Data Processing Addendum). The agency is the controller.
Your Colorado rights: confirm whether we process your personal data and access it; correct it; delete it; get a portable copy (up to twice a year); and opt out of targeted advertising, sale, and profiling in furtherance of decisions that produce legal or similarly significant effects. We don't do targeted advertising, sales, or that kind of profiling. We honor universal opt-out signals such as Global Privacy Control.
Sensitive data. We don't process "sensitive data" as the CPA defines it (for example, racial or ethnic origin, religious beliefs, health, sex life or sexual orientation, citizenship, genetic or biometric data, or children's data), so we don't need to ask for consent to it.
How to exercise them and appeal: section 13. If we deny your appeal, you can contact the Colorado Attorney General at coag.gov.
16. Other states, and insurance privacy laws
Other states (including Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) give residents similar rights. We extend the rights in section 12 to everyone in the United States.
Insurance agencies are also subject to insurance and financial privacy laws, such as the Gramm-Leach-Bliley Act and state laws based on it (for example, California's Insurance Information and Privacy Protection Act), and state insurance data security laws. Where those laws cover information in the app, they may apply instead of, or in addition to, the state privacy laws above. We support agencies' compliance through our Data Processing Addendum and security program.
17. Children
AgencyHuddleHQ is a business tool for adults. It isn't meant for anyone under 18, and we don't knowingly collect information from children.
18. Changes to this policy
Each version has a version date at the top. For material changes, we'll post the new version here and tell account holders in the app or by email before it takes effect. When the version changes, we ask users to review it the next time they sign in.
19. Contact us
AgencyHuddleHQ, LLC · 9611 Salem Ct, Highlands Ranch, CO 80130
Privacy requests and questions: drewtekellcareers@gmail.com or make a privacy request
Everything else: drewtekellcareers@gmail.com
