ClientHatch Privacy Policy
Version: 2026-10-03
Last updated: October 3, 2026
ClientHatch is a marketplace where licensed insurance agents and agencies buy consumer leads. It is operated by Optimize Inc. This Policy explains what personal information we handle, why, who receives it, how long we keep it, and what choices you have.
This Policy has three parts. Part A is for insurance agents, agency staff and other people who use our websites and platform. Part B is for consumers whose information reaches the platform because they asked to be contacted about insurance. Part C applies to everyone.
The short version for consumers. If you filled in a form asking to be contacted about Medicare or health insurance coverage, your information may have been sold through ClientHatch to a licensed insurance agent or agency. Depending on the type of request, it is sold to one agent or agency only, or shared among no more than three, as Section 11.1 explains. You can ask us to stop contact, to delete your information, to tell you what we hold, to correct it, or to opt out of its sale, by emailing contact@optimize.ad.
1. Who we are and what this Policy covers
1.1 Who we are. “ClientHatch”, “we” and “us” mean Optimize Inc, 2306 Lake Austin Blvd, Austin, TX 78703, United States. You can reach us about anything in this Policy at contact@optimize.ad.
1.2 What is covered. This Policy covers the Services (defined in Section 1.4). In practice that means the website at clienthatch.com, the platform at app.clienthatch.com, our programming interface and webhooks, our support channels, and the emails, texts and notifications we send in connection with them.
1.3 What is not covered. This Policy does not cover (a) the consumer websites where insurance request forms are completed (the “Funnels”), which carry their own privacy notices at the point where information is collected, even where Optimize Inc operates them; (b) other products and businesses of Optimize Inc; (c) what an insurance agent or agency does with your information after receiving it, which is governed by that agent’s own privacy notice and the laws that apply to insurance producers; or (d) third-party websites and tools we link to.
1.4 Words we use. “Terms” means the ClientHatch Platform Terms of Service at https://clienthatch.com/terms and the documents they incorporate. The following words are defined in the Terms and have the same meaning here. We repeat those definitions word for word. Where a repeated definition says “you” or “your”, it means the business that holds the Account.
- “Account” means your organization’s account on the Services, including every user profile inside it.
- “Agency” means an Account held by an insurance agency or other organization that has more than one Member, or that pays for or supports the Lead purchases of other agents.
- “Campaign” means a set of instructions you create in the Services that tells us which Leads to bid on for you and the most you will pay.
- “Lead” means a record of a consumer who submitted an insurance quote request on a quote form, including the contact details, Consent Record and other data we deliver with it.
- “Member” means each individual you invite or allow to use your Account, in any role.
- “Services” means the ClientHatch marketplace, auction, customer relationship management tools, delivery integrations, application programming interface, websites and support.
- “Balance”, “Promotional Credit”, “Return” and “Return Allowance” also have the meanings given in the Terms.
In this Policy only:
- “Platform User” means any person who visits our website, holds or uses an Account, or contacts us on behalf of an insurance business.
- “Lead Information” means the personal information in a Lead.
- “Consent Record” means the record we keep of the consent a consumer gave on a quote form: the consent language the quote form reported showing (or, where it reported none, the language we supplied for it to show), the businesses it named, the time, and technical details of the submission. This is the same meaning the Terms give it.
- “Buyer” means the Account that purchases a Lead.
1.5 Our role. For Lead Information, we decide why and how it is used on the platform, so we are a “business” or “controller” under state privacy laws, and each Buyer is a separate business responsible for its own use. For information a Platform User uploads about its own existing customers (for example an imported book of business), we act only on that Platform User’s instructions as its service provider.
Part A. Platform Users
2. Information we collect about Platform Users
2.1 Information you give us.
- Account details: your name, email address, mobile number, time zone and sign-in credentials. We store a protected (hashed) form of your password, never the password itself. If you sign in with Google, we receive from Google your name, email address, a link to your profile picture, your Google account identifier, whether Google has verified your email address and, for a Google Workspace account, its domain, and we keep the sign-in token Google issues, which carries those details.
- Business details: legal business name, trade name, business address, business phone number and, if you choose to provide it, your Employer Identification Number, which we check and then keep only in the reduced form described in Section 2.4.
- Licensing details: your National Producer Number, the states and lines of authority you tell us you hold, any license document you upload for manual review, and the compliance statements you make during onboarding.
- Payment details: the payment method you add. Card and bank details are entered directly with our payment processor. We receive and keep the card brand, last four digits, expiry date and the processor’s reference numbers, never a full card number.
- Agreement records: which version of our Terms and other documents you accepted or signed, when, from which IP address and browser, and a copy of what you were shown. If you turn on auto-refill, we keep the exact authorization text you agreed to.
- What you do in the Account: your Campaigns and settings, the dispositions, notes, tasks, appointments, Scope of Appointment records and sales you record against Leads, the Returns you file, and the connections you set up to your own systems.
- Communications: support tickets, chat messages, emails and calls with us, and your notification preferences.
- Files you upload: for example a list of your existing customers for import. You are responsible for having the right to upload it.
2.2 Information we collect automatically.
- Device and log information: IP address, browser type and settings, pages and actions in the platform, dates and times, and session records.
- An audit trail: a record of significant actions taken in your Account and when. For most actions it also records who took them and whether a member of our support staff was signed in on your behalf at the time, but the record kept when a consumer’s contact details are opened does not always say who opened them.
- Notification endpoints: if you turn on browser or phone notifications, the technical address your browser gives us to deliver them.
- How you found us: see Section 4.1.
2.3 Information we receive from others.
- License verification: we look up your National Producer Number with the National Insurance Producer Registry (NIPR) and keep the license states, lines of authority, status and dates it returns. We do not keep the Social Security number, date of birth or home address that a NIPR record may contain.
- Identity verification: above certain deposit amounts we ask you to verify your identity through Stripe Identity. Stripe collects your identity document and, where used, a selfie. We receive the result of the check and a summary of what was verified. We do not receive or store the document images.
- Sanctions screening: we check Account names against the U.S. Treasury sanctions list. We do this on our own systems using the published list.
- Phone verification: our telephony provider delivers, by call or text message, the one-time code we send to your business phone. We check the code you enter on our own systems.
- Payment events: our payment processor tells us about payments, refunds, disputes and fraud warnings on your payments.
- Complaints: consumers, regulators, carriers or others may contact us about how an Account has contacted consumers.
- Your Agency: if you are a Member, your Agency gives us your name, email and role, and sets your spending limits.
2.4 What we do not keep. We keep the result of each verification check and protected (hashed) references. We do not keep images of identity documents, Social Security numbers, dates of birth or full Employer Identification Numbers of Platform Users. For an Employer Identification Number we keep only the last four digits, the two-digit prefix, and a protected (hashed) form used to detect the same number being used on more than one Account.
3. How we use Platform User information
We use the information in Section 2 to:
- open and run your Account, and confirm that you are a licensed insurance producer in the states where you buy;
- take payments, maintain your Balance and Promotional Credit, apply sales tax, issue receipts and statements, and process Returns and refunds;
- run the auction, deliver Leads and send you alerts about them;
- verify identity, screen against sanctions lists, and detect and prevent fraud and misuse;
- respond to payment disputes, including by sending records of your agreement, your activity and your purchases to the payment processor and card issuer;
- provide support, including, where needed, signing in to your Account on your behalf (we record the reason and a support ticket reference, and limit the session in time; Section 14.1 of the Terms describes the notice we try to send afterwards);
- calculate your Agent Score, which can affect auction ranking and your Return Allowance, from how you work the Leads you buy;
- monitor consumer complaints and compliance with our Terms, and suspend or close Accounts where needed;
- meet our legal, tax, accounting and regulatory obligations, and establish or defend legal claims;
- understand how the Services are used and improve them; and
- tell you about the Services. If we send you marketing email, each message will include a way to stop receiving it.
We do not sell Platform User personal information, and we do not share it for cross-context behavioral advertising.
Agent Score. The Agent Score is calculated automatically from how you work the Leads you buy. You can see your Agent Score in your Account. If you think it is wrong, you can ask us to review it by emailing contact@optimize.ad.
Google Sign-In. If you choose to sign in with Google, we ask Google only for basic sign-in information (the “openid”, “email” and “profile” permissions), and Google sends us the details listed in Section 2.1. We use them only to create your Account, sign you in, and confirm that a member of our own staff is signing in with a company Google account. We do not ask for or access your Gmail, Google Drive, Google Calendar, contacts or any other Google data. We do not sell information we receive from Google, we do not use it for advertising, and we do not share it except with the service providers in Section 5.1 that host and run our systems. You can remove ClientHatch’s access to your Google account at any time at https://myaccount.google.com/permissions. ClientHatch’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Cookies and similar technologies
4.1 clienthatch.com. Our public website sets one cookie, named __attr. It is written on the first page you visit that sets it, which is most pages (a few fixed pages, such as this Policy and our Terms, do not), and records that page, the website that referred you to it, the time, and any campaign tags or advertising click identifiers that were on the link you followed. It lasts 90 days, cannot be read by scripts in your browser, and is read by our platform when you sign up so we can tell which advertising brought you to us. Our public website carries no third-party advertising or analytics tags.
4.2 app.clienthatch.com. The platform sets its own cookies only for these purposes: to keep you signed in, to remember a device you have already verified with a two-step code, to remember which Account you are working in, to mark a support session, to remember for one day which setup steps your Account still needs so that the platform opens the right page, and to remember for seven days whether you left the side menu open or closed. It also keeps a few preferences in your browser’s local storage, such as your color theme and notices you have dismissed. If you turn on notifications, the platform installs a small background script whose only job is to show them.
4.3 Other companies’ technologies inside the platform. On billing screens, our payment processor (Stripe) loads its own code and may set its own cookies to process payments and detect fraud. If the support chat is enabled, our support-desk provider (Front) loads its chat window and receives your name and email address, so that our staff know who they are talking to, together with details of your Account that help them answer you: your user and Account reference numbers, the name of your Agency and whether you are one of its owners or managers, your Account balance and lifetime spend, the lead types your Campaigns cover, the states you are licensed in, your number of active Campaigns, your sign-up date, whether auto-refill is on, your verification status and a link to your Account in our staff console. If browser error monitoring is switched on, our error-monitoring provider (Sentry) loads its code and sends reports of errors in the platform from your browser directly to Sentry, as Section 5.1 describes. If you sign in with Google, Google processes that sign-in. These companies handle that information under their own privacy policies.
4.4 Your controls. You can block or delete cookies in your browser settings. If you block the platform’s cookies you will not be able to sign in. We do not respond to “Do Not Track” signals. Because we do not sell Platform User information or use third-party advertising cookies on our sites, there is no sale or sharing on these sites for a browser opt-out signal to switch off. For consumers, see Section 13.6.
5. Who receives Platform User information
5.1 Service providers. We use other companies to help run the Services. They may use the information only to provide their service to us. The categories, and the providers we use today, are:
- Payments, payment fraud prevention, identity verification and dispute handling: Stripe.
- License verification: the National Insurance Producer Registry (NIPR), to which we send your National Producer Number.
- Phone verification and text-message alerts: Twilio, and the mobile carriers that deliver the texts. See Section 7 for how we treat your mobile number.
- Customer support desk and in-app chat: Front.
- Website delivery, email delivery and private file storage: Cloudflare.
- Sign-in, if you choose it: Google.
- Error monitoring: Sentry. Error reports from our servers are filtered to keep personal details out. Where error monitoring is switched on in the browser, reports go from your browser directly to Sentry without passing through that filter, and can include the full address of the page you were on and of the page that referred you to it, your browser type, and the steps that led to the error; Sentry also receives your IP address as any website your browser contacts does.
- Browser and phone notifications: the notification service run by the maker of your browser or device (for example Apple, Google or Mozilla).
- Server hosting and database infrastructure: our hosting provider.
- Electronic signature: agreements signed electronically are currently signed inside the platform. If we appoint an outside e-signature provider, it will receive the signer’s name, email address and the document.
5.2 Agencies. If you are a Member of an Agency, its owners and managers can see your activity, spending and performance in the Account, and may show you on the Agency’s leaderboard. An owner or manager can remove you from the leaderboard. You cannot do this yourself, so ask them if you want to be removed.
If an Agency pays part of the cost of the Leads you buy, its owners and managers can see your name and organization, the number of Leads you bought, what you and the Agency paid for them, your Agent Score, how quickly you first contact Leads, how completely you record call outcomes, your contact rate, the sales you report and your Return rate. They may see you ranked against others on the Agency’s leaderboard. They cannot see the consumers in your Leads. You can see the Agency’s name and what it paid on each Lead. An Agency can set this up without any action by you. If you object, tell us at contact@optimize.ad.
5.3 Consumers. For a type of Lead whose consent wording is designed to name the buying agency, the legal name on your Account is supplied to the Funnel for that wording. When you win a Lead, the legal name on your Account may also be recorded with the Consent Record. If a consumer asks who received their information, we may give them your legal name.
5.4 Payment networks. If a payment is disputed, we send evidence to the payment processor and the card issuer, as described in the Terms.
5.5 Legal and safety. We disclose information where we believe in good faith that it is needed to comply with law or legal process, to respond to a regulator (including insurance regulators and the Centers for Medicare and Medicaid Services), to investigate complaints about contact with consumers, to protect the rights, property or safety of any person, or to establish or defend legal claims.
5.6 Business transfers. If all or part of our business is sold, merged or reorganized, information may pass to the successor, which must continue to honor this Policy for information already collected.
5.7 With your direction. We send information to the systems you connect to your Account, and to anyone else you ask us to.
6. How long we keep Platform User information
We keep Platform User information for as long as the Account is open and, after it closes, for as long as we need it for the purposes it was collected for, including tax, accounting, dispute, fraud-prevention and legal requirements. In particular:
- Financial records (deposits, purchases, Returns, refunds, disputes and the ledger of your Balance) are permanent accounting records and are not deleted on request.
- Agreement records (what you accepted or signed, and when) are kept for as long as any claim about that agreement could be brought.
- Records of what we delivered to your connected systems keep the delivery outcome, but the copy of the consumer’s details in that record is deleted 30 days after the delivery.
- The
__attrcookie expires after 90 days. What it recorded is kept on the Account record.
7. Platform User choices
- Your details. You can view and change your profile, business details and notification preferences in the platform’s settings.
- Text alerts. We use your mobile number to send the account texts you turned on and to operate your Account. We do not sell, rent or share your mobile number or your text messaging consent with third parties or affiliates for their marketing or promotional purposes. We share it only with the service providers that deliver our messages for us, such as our messaging provider and the mobile carriers. Reply STOP to any text alert from us to stop them, or ask us in any other reasonable way. Section 15.7 of the Terms says more about text alerts.
- Browser and phone notifications. Turn them off in the platform’s settings or in your browser or device settings.
- Marketing email. Use the unsubscribe link in the message, or email us. Notices about your Account, your payments, security and support access to your Account are not marketing, and you cannot opt out of them while your Account is open. You can choose which channels deliver Lead alerts in your notification settings.
- Closing your Account. Email us from the address on the Account.
- Privacy rights. Depending on where you live, you may have the rights described in Section 13. Email contact@optimize.ad from the address on your Account.
Part B. Consumers whose information reaches us as a Lead
8. Notice at collection: a summary
If you completed a Funnel form asking to be contacted about Medicare or health insurance coverage, this is what happens to the information on the ClientHatch platform:
- What we collect: your contact details, date of birth, gender, location, the fact that you asked about Medicare or health insurance coverage, technical details about your visit, and the record of your consent. Section 9 has the full list.
- Why: to connect you with a licensed insurance agent or agency that can talk to you about your options, to keep proof of your consent, to honor your do-not-contact and privacy requests, to prevent fraud, and to meet legal obligations. Section 10 has the full list.
- Whether it is sold: yes. Depending on the type of Lead, we sell your Lead to one Buyer, a licensed insurance agent or agency, or to no more than three Buyers. Section 11 explains this and Section 13 explains how to opt out.
- Whether it is shared for cross-context behavioral advertising: no.
- How long we keep it: see Section 14.
- Your rights: see Sections 12 and 13. To use them, email contact@optimize.ad.
9. Lead Information we collect, and where it comes from
9.1 Where it comes from. Lead Information comes from the form you completed on a Funnel. Funnels that feed ClientHatch are operated by Optimize Inc and pass information to the platform through Optimize Inc’s own lead-distribution system. After a sale, further information comes from the Buyer who contacted you, and from you if you contact us.
9.2 What we collect.
- Identifiers and contact details: first and last name, email address, telephone number, street address, city, state and ZIP code, and the IP address you used.
- Characteristics: date of birth, age, gender and preferred language.
- Insurance interest: that you asked to be contacted about Medicare or health insurance coverage options and, if the form asked, which kind of coverage.
- Internet and device activity: the page where you completed the form, the page or advertisement that brought you there, the type of advertising channel, your browser type, and technical identifiers attached to your visit.
- Your Consent Record: the consent wording the Funnel reports you were shown (or, where the Funnel does not report it, the wording we supplied for the Funnel to show), the legal names of the platform and of the Buyer (for a shared Lead, the first Buyer) that we record with it, the address of the page where you completed the form and of the page that referred you there, the date and time, and, where the Funnel supplies them, a reference issued by an independent consent-certification service. If the Funnel reports that it confirmed your phone number with a one-time code, we also keep how and when it was confirmed. A proof-of-consent document generated from the Consent Record also shows your name, telephone number, email address, IP address and browser type, as the Lead held them when the document was generated.
- Inferences: from your date of birth we work out your age and how close you are to age 65, which indicates likely Medicare eligibility.
- What happens after the sale: the Buyer’s records in the platform of their contact with you, such as call outcomes, notes, appointments, any Scope of Appointment, and whether you enrolled.
- Your requests: any do-not-contact, privacy or deletion request, and any complaint, that you or someone on your behalf sends us.
9.3 What we do not collect. The Funnels that feed ClientHatch do not ask health-status questions, and we do not ask for your Social Security number, Medicare number, or bank or card details. A Buyer may record what you choose to tell them during a call.
9.4 Sensitive information. Some state laws treat information about health, or information that reveals it, as sensitive. A request about Medicare or health insurance coverage, together with your age, may be treated that way. We use this information only to do what you asked (connect you with a licensed insurance agent), to keep proof of your consent, to honor your requests, to prevent fraud and keep the Services secure, and to meet legal obligations. We do not use it to build a profile of you for other purposes. NOTICE: We may sell your sensitive personal data.
10. How we use Lead Information
We use Lead Information to:
- find a Buyer for your request. Before any Buyer is chosen, we run an auction among licensed agents whose Campaigns match, using only details that do not include your name or contact details (such as state, ZIP code, date of birth, age, gender, language and a coded reference to your request). Agents whose Campaigns were considered for your request, including those that did not win it, can receive these details of the request, including your ZIP code, state, date of birth and gender, in reports that explain why their Campaign did or did not win. They never see your name or contact details unless they become a Buyer. Your name and contact details move only once the Buyer has been selected;
- deliver your Lead to the Buyer, in the platform and, where the Buyer has connected one, in the Buyer’s own customer-management system;
- keep proof of your consent for you, for the Buyer and for regulators;
- avoid selling a repeat of the same request on the platform, using protected (hashed) versions of your phone number and email address;
- honor do-not-contact, deletion and other privacy requests, including by keeping a protected record of your phone number or email address on a do-not-contact list;
- decide Returns, where a Buyer says a Lead was a duplicate, outside what they asked for, or lacked consent evidence;
- detect fraud and misuse, investigate complaints about how a Buyer contacted you, and enforce our Terms against Buyers;
- meet legal and regulatory obligations and establish or defend legal claims; and
- produce statistics that do not identify anyone, such as the number of requests by state.
We do not use the Services to place sales calls or send sales texts to consumers ourselves. Contact about your request comes from the Buyer. We do not use Lead Information to make decisions about you that have legal or similarly significant effects.
11. Sale and disclosure of Lead Information
11.1 Who buys your Lead. When you submit a Funnel form and consent to be contacted, we sell your Lead through ClientHatch to a licensed insurance agent or agency, the Buyer. Because the Buyer pays us for it, this is a “sale” of personal information under California law and similar state laws, and we describe it that way. How many Buyers receive a Lead depends on the type of Lead. A Medicare Lead (Medicare Supplement, or Medicare Advantage and Part D) is sold as exclusive on this platform: we sell it to one Buyer on ClientHatch and do not offer it to a second Buyer on ClientHatch. A health insurance (ACA) Lead is sold either as exclusive on this platform or shared with no more than two other Buyers, each a different agent or agency. Where a Lead is shared, everything this Policy says about the Buyer applies to each of them.
11.2 What the consent names. For a Medicare Advantage and Part D request, the consent wording the platform supplies for the Funnel to show is designed to name the specific agency that will receive your information, as well as the platform. For other types of request, the consent wording the platform supplies names the platform and its licensed insurance agency partners rather than a particular agency. So for a shared Lead, the consent names the platform and none of the Buyers individually. Section 9.2 says what the Consent Record keeps.
11.3 What the Buyer receives. The Buyer receives the identifiers and contact details, characteristics, insurance interest and Consent Record described in Section 9, and where you were when you submitted the form. The Buyer receives your Lead in the platform. Email to the Buyer is switched on unless the Buyer turns it off, and if the Buyer does not acknowledge a new Lead in the platform within a short time, the platform can email the Buyer a copy of your full Lead. The Buyer may also choose to get alerts about your Lead by text message or browser notification. Section 11.6 says what those messages can contain.
11.4 What the Buyer may and may not do. Every Buyer is a licensed insurance agent or agency that has agreed to our Terms. Those Terms prohibit reselling or passing your Lead to anyone outside the Buyer’s own agency, require the Buyer to follow telemarketing, do-not-call and Medicare marketing rules, and require the Buyer to honor your do-not-contact and deletion requests. The Buyer is an independent business. Once it holds your information, its own privacy notice and the privacy laws that apply to insurance producers govern what it does. A Buyer who markets Medicare Advantage or Part D plans may be required by Medicare rules to record its sales and enrollment calls with you, and should tell you if a call is recorded.
11.5 No other sale, and no advertising sharing. We do not sell Lead Information on ClientHatch to anyone other than the Buyer or Buyers described in Section 11.1, and we do not share it for cross-context behavioral advertising. Other agents whose Campaigns were considered for your request receive only the details of the request described in Section 10, which do not include your name or contact details, do not pay for them, and are bound by our Terms. If your request is not bought through ClientHatch, what happens to it is governed by the Funnel’s privacy notice, not this Policy.
11.6 Service providers. These companies handle Lead Information for us, under contract and only to provide their service: Cloudflare (private storage of proof-of-consent documents and other files; delivery of our emails, including Lead emails to the Buyer that can contain your full record); Twilio and the mobile carriers (text-message alerts to the Buyer, which can include your city, state, ZIP code and age and, if the Buyer has turned it on, your phone number); the notification services run by browser and device makers such as Apple, Google and Mozilla (alerts to the Buyer showing your city, state and age); our hosting and database provider, Sentry (error monitoring, which can receive details of the page or action that failed, as Section 5.1 describes), and Front (our support desk, if a Buyer or you write to us about your record).
11.7 Legal and safety. We disclose Lead Information, including your Consent Record, where we believe in good faith that it is needed to comply with law or legal process, to respond to a regulator, to investigate a complaint, or to establish or defend legal claims, including a claim about whether you consented to be contacted.
11.8 Business transfers. As in Section 5.6.
11.9 States we exclude. We may exclude consumers in particular states from sale. We currently exclude consumers whose request gives a Maryland or Washington State address.
11.10 Summary of categories. We collect the categories of information listed in Section 9.2. We sell identifiers and contact details, characteristics, insurance interest, internet activity relating to the form submission, and Consent Records, in each case to licensed insurance agents and agencies. We disclose all the categories in Section 9.2 to our service providers for the business purposes in Section 10. We do not sell or share the personal information of consumers we know to be under 16. This summary also describes our practices for the 12 months before the date at the top of this Policy.
12. Stopping contact (do-not-contact requests)
12.1 How to ask. You can tell the agent who contacts you to stop, and they must record it. You can also email contact@optimize.ad with the phone number or email address you used on the form, and we will record your request as Section 12.2 describes. Section 12.4 explains what reaches a Buyer of a request you make later.
12.2 What we do. A stop request is recorded in the platform, in protected (hashed) form, on the do-not-contact list of a Buyer that holds your record. The Buyer records it when you tell the Buyer. When you write to us, our staff record it for each Buyer that holds your record. Once it is recorded:
- the Buyer it was recorded for, and every other Buyer on the platform that currently holds a Lead with the same phone number or email address, sees that record marked do-not-contact, and the platform’s calling controls for it are disabled;
- we send a stop request to each system to which the platform delivered your Lead for those Buyers; and
- the entry cannot be edited or removed by a Buyer.
We record a request we receive by email as soon as we can, and in any case within 10 business days.
12.3 What we cannot do. We cannot reach into a Buyer’s own phone system or files. The Buyer is required by its contract with us, and by law, to honor your request in its own systems. If a Buyer contacts you after you asked it to stop, please tell us.
12.4 If you submit a new form later. A do-not-contact request applies to the information we hold when it is recorded. If you later complete a Funnel form again and give a new consent, that is a new request from you, and it can be sold. A stop request recorded for a Buyer stays on that Buyer’s list, so that Buyer will see it if it receives your new request, but a different Buyer may not. If you asked us to delete your information, we also put your phone number and email address, in protected (hashed) form, on our platform-wide do-not-contact list, and any Buyer who receives a new request from you will see that you previously asked not to be contacted.
12.5 The National Do Not Call Registry. Registering your number at donotcall.gov limits telemarketing calls you have not agreed to. A consent you give on a Funnel form is an agreement to be called by the company named in it, until you withdraw it.
13. Privacy rights
13.1 Your rights. Depending on the state you live in, you may have the right to:
- know and access: be told what personal information we hold about you, where it came from, why we use it and who received it, and receive a copy in a portable form;
- delete: have personal information we collected from you deleted, subject to the exceptions in Section 13.4;
- correct: have inaccurate personal information corrected;
- opt out of sale and sharing: tell us not to sell your personal information or share it for cross-context behavioral advertising;
- limit the use of sensitive personal information to the purposes in Section 9.4;
- opt out of targeted advertising and profiling. We do not do either with Lead Information;
- appeal a decision we make about your request; and
- not be treated differently for using any of these rights.
We extend these rights to every consumer whose Lead reaches the platform, whichever state they live in. California residents: this Section, with Sections 8 to 11 and 14, is our notice under the California Consumer Privacy Act.
13.2 How to make a request. Email contact@optimize.ad. Tell us which right you want to use, and give us the phone number or email address you entered on the form, because that is how we find your record. You do not need an account, and there is no charge.
13.3 How we verify a request. For a request to know, delete or correct, we check that the person asking is the person the record is about, by matching the phone number or email address in the request to our record and, where needed, asking you to confirm that you control it. We may ask for more if the request involves a copy of specific information. We do not ask you to verify your identity for a request to stop contact or to opt out of sale beyond what we need to find your record.
13.4 What deletion means here. When we complete a deletion request:
- we erase from the Lead record your name, email address, telephone number, street address, IP address, browser details and the original form submission;
- we erase the text of the notes and other entries on your Lead’s timeline in the platform;
- we tell each Buyer that holds your record on the platform, mark your record do-not-contact for that Buyer, and send a deletion request to each system to which the platform delivered your Lead for that Buyer. A Buyer must honor it under its contract with us, but we cannot delete from a Buyer’s own systems ourselves; and
- we add your phone number and email address, in protected (hashed) form, to our platform-wide do-not-contact list.
We keep, as the law allows: your Consent Record, which we and the Buyer need to show that contact with you was lawful and which telemarketing rules require to be kept; any proof-of-consent document already generated for your Lead, which shows your name, telephone number and email address with the consent and which the Buyer can still download; protected (hashed) versions of your phone number and email address, so that your do-not-contact status continues to work; the financial record of the sale; limited details that do not let anyone contact you, such as state, ZIP code, date of birth, gender and language; and the Buyer’s other records about you in the platform, such as tasks, appointments (including any meeting place), Scope of Appointment records and any document stored with them.
13.5 What opting out of sale means here. A Lead is sold at the moment you submit the form, and the platform does not offer a Lead it has already sold to a further Buyer afterwards. If you opt out after that, we cannot undo a sale that has already happened. An opt-out does not stop a new request you make later on a Funnel from being sold, because that is a new request with a new consent. If you also want contact to stop, see Section 12, and if you want your information deleted, see Section 13.4.
13.6 Browser opt-out signals. A browser opt-out signal, such as the Global Privacy Control, can only be read by the website you are visiting. For a Lead, that is the Funnel, not the ClientHatch platform, which never sees your browser.
13.7 When we respond. We confirm that we received a request to know, delete or correct within 10 business days, and we respond within 45 days. If we need longer, we tell you why and may take up to a further 45 days where the law allows. We act on a request to opt out of sale or to limit the use of sensitive information as soon as we reasonably can, and no later than 15 business days after we receive it.
13.8 Appeals. If we decline your request, we tell you why. You can appeal by replying to our decision or emailing contact@optimize.ad with the word “Appeal” in the subject line. We respond to an appeal within the time your state’s law requires, and if we deny it we tell you how to contact your state’s Attorney General.
13.9 Authorized agents. You can ask someone else to make a request for you. We ask them for your signed permission, and we may ask you to confirm it with us directly, unless they hold a power of attorney that the law recognizes.
13.10 No different treatment. We do not deny a service, charge a different price or provide a different quality of service because you used a privacy right. We do not offer financial incentives for personal information.
13.11 California “Shine the Light”. California residents may ask us, once a year and free of charge, for the categories of personal information we disclosed to other companies for their direct marketing in the previous calendar year and the names of those companies. Email us with “Shine the Light” in the subject line. You can instead simply opt out under this Section.
13.12 Nevada. Nevada residents may ask us not to sell their covered information by emailing us.
13.13 Platform Users. A Platform User who has rights under these laws can use them in the same way. Some information about Platform Users must be kept, as Section 6 explains.
13.14 Data broker laws. We collect Lead Information from you directly, through Funnels operated by Optimize Inc, rather than buying it from others.
14. How long we keep Lead Information
- Lead Information (your contact details and the rest of the Lead): we do not currently delete it on a schedule, so we keep it until you ask us to delete it, and then as Section 13.4 describes.
- Consent Records: we keep them for at least five years, including after a deletion request. Our systems delete the Consent Record itself seven years after the consent was given. A proof-of-consent document generated from it, which also shows your name, telephone number and email address, is kept in storage and is not currently deleted, either at that point or after a deletion request.
- Do-not-contact entries (protected versions of your phone number or email address): we keep them indefinitely, because removing one would allow contact to start again.
- Copies sent to a Buyer’s connected system: our own copy of what was sent is deleted 30 days after delivery. The record that a delivery happened is kept.
- Financial records of the sale: these are permanent accounting records.
- Privacy requests: we keep a record of each request and what we did for at least 24 months.
15. Medicare and insurance notices
15.1 We are not an insurer or an agent. ClientHatch does not sell insurance, is not an insurance company or agency, and does not recommend plans. ClientHatch is not connected with or endorsed by the United States government or the federal Medicare program.
15.2 Medicare marketing. Optimize Inc is a third-party marketing organization under the Medicare marketing rules. We do not offer every plan available in your area; any information we provide is limited to those plans we do offer. Please contact Medicare.gov or 1-800-MEDICARE to get information on all of your options.
15.3 Financial and health privacy laws. We are a marketing company. We are not a health plan, health care provider or insurer, and the information in a Lead is not protected health information under HIPAA while we hold it. The Buyer who receives your Lead is an insurance producer, and federal and state financial privacy laws that apply to insurance producers, including the Gramm-Leach-Bliley Act and state insurance information privacy laws, govern how the Buyer handles your information once you deal with it about insurance. The Buyer must give you its own privacy notice where those laws require one.
Part C. Everyone
16. Security
We use technical and organizational measures designed to protect personal information, including:
- encryption of information in transit between your browser and the Services;
- encryption of the contact details in a Lead at the level of the individual field, and database controls that prevent the web application from reading those details or the original form submission directly (a copy of the original form submission, which contains the same contact details, is protected by those controls but is not encrypted);
- lookups by protected (hashed) versions of phone numbers and email addresses rather than the numbers and addresses themselves;
- separation of each Account’s data from every other Account’s, enforced in the database;
- access for our staff according to role, a record kept each time a consumer’s contact details are opened (which records the Account and the time, but does not always record who opened them), and a record of each support session in which a member of staff signs in to an Account;
- storage of access keys only in hashed or encrypted form, and notifications to connected systems that carry reference numbers rather than consumer details;
- payment card data handled by our payment processor rather than by us; and
- error monitoring that filters personal details out of the reports our servers send (reports sent from a browser are described in Section 5.1).
These measures protect information inside the platform. Ordinary email and text messages are not encrypted from end to end, so a Lead sent to the Buyer by email, or an alert by text message, travels without the protections above. No system is completely secure, and we cannot guarantee security. If we learn of a breach that the law requires us to tell you about, we will notify you and the relevant authorities as the law requires. Platform Users are responsible for keeping their sign-in details and access keys confidential, and for the security of the systems they connect to an Account.
17. Where information is processed
We are based in the United States and the Services are offered only in the United States. We store and process personal information in the United States. If you use the Services from another country, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you live.
18. Children
The Services are for licensed insurance professionals and for adults asking about Medicare or health insurance coverage. They are not directed to anyone under 18. We do not knowingly collect personal information from children under 13, and we do not sell or share the personal information of anyone we know to be under 16. If you believe a child’s information has reached us, email us and we will delete it.
19. Changes to this Policy
We may update this Policy. Each update is published as a new version, and the version shown at the top of this page identifies the one in force and when it was published. If a change materially affects how we use information we already hold, we will tell Platform Users by email or in the platform before it takes effect, and we will take any other step the law requires.
20. Contact us
Optimize Inc, 2306 Lake Austin Blvd, Austin, TX 78703, United States.
Privacy requests and legal notices: contact@optimize.ad. Help with an Account: support@clienthatch.com.