Privacy policy

Effective August 25, 2026

HealthBrokerPro (“we”, “us”) provides a client and policy management platform for licensed health insurance agencies. This policy describes what information the platform handles, how it is used, and the choices you have. It applies to the HealthBrokerPro application at healthbrokerpro.com.

Information we collect

  • Account information — your name, work email address, phone number and password (stored only as a salted cryptographic hash).
  • Client records — information that agency users enter or import about their clients and prospects: names, contact details, household members, dates of birth, and insurance-related information including health details collected during quoting. This information belongs to the agency; we process it on the agency's behalf.
  • Communications — text messages, call logs, call recordings and voicemails exchanged with clients through the platform's built-in phone and SMS tools (provided via Twilio), and emails exchanged through a connected Google account.
  • Usage records — an audit log of actions taken in the platform (who changed what and when), used for security and accountability.

Google user data

Connecting a Google account is optional and done per user through Google's consent screen. If you connect one, HealthBrokerPro accesses only the following, only to provide features you use:

  • Google Calendar (calendar events) — to two-way sync your appointments: bookings made in HealthBrokerPro appear on your Google Calendar, and events created in Google appear as busy time in HealthBrokerPro.
  • Gmail (send) — to send email messages that you write in HealthBrokerPro, from your own address.
  • Gmail (read) — to file replies from people who are already clients or prospects in your agency's records into their conversation thread. Mail from senders who are not in your records is not stored.

HealthBrokerPro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide the user-facing features described above; we do not transfer it to third parties except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice; we do not use it for advertising; and we do not allow humans to read it except with your affirmative agreement, when necessary for security or to comply with law, or when the data is aggregated and anonymized.

Google OAuth tokens are stored encrypted (AES-256-GCM). You can disconnect Google at any time in User settings, or revoke HealthBrokerPro's access at myaccount.google.com/permissions; disconnecting deletes the stored tokens.

How we use information

  • To provide the platform's features to agency users.
  • To send and receive the communications that agency users initiate with their clients.
  • To secure the platform and keep an audit trail.
  • To comply with legal obligations.

We do not sell personal information, and we do not use it for third-party advertising.

Text messaging (SMS)

Agencies use HealthBrokerPro to text clients who have consented to be contacted. Message frequency varies by conversation. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help. Opt-outs are honored across the platform through per-person do-not-disturb controls. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties.

Sharing

We share information only with the service providers that run the platform, and only as needed to provide it: Amazon Web Services (hosting, database and file storage), Twilio (phone calls and SMS), and Google (the optional Calendar and Gmail integrations described above). We may also disclose information when required by law. We do not share or sell information to data brokers or advertisers.

Security

Data is encrypted in transit (TLS) and at rest. Uploaded files live in private storage reachable only through short-lived signed links. Access is limited to the agency's own users under role-based permissions, and administrative actions are recorded in an audit log. Given the sensitivity of insurance information, we deliberately keep identifying details out of system logs and URLs.

Retention and deletion

Information is retained while the agency's account is active, because insurance servicing requires a durable record. Agencies control their own client records and can delete them in the product. To request deletion of your account or data, contact us at the address below; we will honor verified requests within 30 days except where law requires retention.

Changes

If this policy changes materially, we will update this page and its effective date. Continued use after a change means the updated policy applies.

Contact

Questions or requests: support@premierprovideroptions.com. See also our terms of service.