Privacy Policy
This Privacy Policy explains how Polca LLC ("Polca," "we") handles personal information in connection with polca.ai and the Polca platform (the "Service"). The Service is built for insurance agencies ("Agencies"). Two roles matter: for Agency account and website data, Polca is the controller; for Consumer data an Agency submits or generates through the Service (leads, clients, recordings, application information), the Agency is the controller and Polca is a processor/service provider acting under the Data Processing Addendum — Consumers should direct requests to the Agency that contacted them, and we support Agencies in fulfilling them.
1. Information we collect
From Agencies and their users
- Account data: names, business email and phone, agency details, seat assignments, roles, authentication data.
- Billing data: processed by Stripe; we store subscription status and invoice metadata, never full card numbers.
- Platform activity: logins, feature usage, configuration, and audit logs.
- Support communications.
Processed for Agencies (Agency-controlled Consumer data)
- CRM data synced from the Agency's GoHighLevel: contact names, phone numbers, tags, notes, appointment records.
- Call data: recordings, transcripts, summaries, dispositions, caller ID, timestamps. Calls are recorded; Agencies are responsible for any recording notices or consents their jurisdictions require.
- Uploaded materials: scripts, guides, presentations, and application-related documents, which may include health-related answers and banking details the Agency collects from its clients.
From website visitors
- First-party, cookie-free website analytics measuring page views and interactions. We do not use advertising identifiers, cross-site tracking, or analytics data intended to identify individual visitors; any technical network information processed to deliver or secure the site is not used for advertising or cross-site profiling.
- Access requests you submit (name, agency, email, phone, team details).
- Functional cookies only: the platform sets a session cookie to keep signed-in users signed in. We do not use advertising or third-party analytics cookies, and we do not respond differently to "Do Not Track" because we do not track.
2. How we use information
To provide and secure the Service (placing and answering calls, transcription and summarization, CRM sync, dashboards, provisioning); to bill; to provide support; to prevent fraud and abuse and protect network reputation; to comply with law; to communicate service and account notices; and, for website leads, to respond to your request. We use de-identified, aggregated data for service operation and improvement; when we use or disclose de-identified or aggregated information, we take reasonable measures to prevent it from being associated with an individual, do not attempt to reidentify it, and require any recipients to preserve its de-identified status. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use Agency-controlled Consumer content to train generalized AI models.
3. How information is shared
- Sub-processors that run the Service: payment processing (Stripe), cloud hosting (DigitalOcean), telephony carrier and caller-identity partners, and AI speech/language providers used to conduct and transcribe calls. Each is bound to confidentiality and use limited to providing services to us; the current list is published at polca.ai/subprocessors.
- The Agency you interact with: if you are a Consumer, your information is processed within and under the control of the applicable Agency's account.
- Legal: to comply with law, enforceable requests, or to protect rights, safety, and the Service. When we receive a government or legal request for data, we review it for legal validity, seek to narrow overbroad requests, disclose only what we are legally required to disclose, and — where lawful — notify the affected Agency before disclosure.
- Business transfers: in a merger, acquisition, or asset sale, data may transfer subject to this policy's commitments.
4. Retention
- Call recordings: up to 90 days, then deleted — unless a different period is stated in an Order Form or a legal hold requires longer retention.
- Transcripts, summaries, CRM-synced records: the life of the Agency account plus the 30-day export period.
- Account and billing records: life of account plus the period required for tax, accounting, and legal obligations.
- Raw website analytics events: up to 90 days; aggregate counts may be retained longer.
- Backups: encrypted and deleted or overwritten within 35 days.
- After termination: a 30-day export window, then deletion from production systems, subject to the backup schedule above and any legal holds.
5. Security
Every Agency's data is isolated with database-enforced row-level security; access is least-privilege and logged; data is encrypted in transit; credentials are hashed with modern algorithms; production access is restricted to authorized personnel. No system is perfectly secure; we notify affected Agencies of qualifying incidents without undue delay (see the DPA).
6. Your rights
Consumers: contact the Agency that contacted you — including to opt out of further calls; opt-outs are enforced automatically across the platform. If you contact us, we will route your request to the responsible Agency and assist in its fulfillment.
Agency users and website visitors: depending on your state of residence and subject to applicable exemptions, you may have rights to confirm whether we process your personal data; access, correct, delete, or obtain a portable copy of it; and opt out of targeted advertising, the sale of personal data, or profiling used to make decisions producing legal or similarly significant effects. Polca does not currently sell personal data, use it for cross-context behavioral advertising, or engage in such profiling.
Submit requests to privacy@polca.ai. We generally respond within 45 days, subject to any extension permitted by law, and we do not discriminate against anyone for exercising privacy rights. Authorized agents may submit requests with proof of authority. If we deny your request, our response will explain the reason and how to appeal: reply to the denial or email privacy@polca.ai with "Privacy Appeal" in the subject line, and we will respond to your appeal within the period required by applicable law.
7. State privacy notices (including California)
For applicable state laws (including CCPA/CPRA): the categories collected are identifiers, commercial information, internet activity, professional information, audio (call recordings), and — within Agency-controlled content — data that may reveal health or financial information. Sources: you, your Agency, and your use of the Service. Purposes: as in Section 2. Disclosures: to the service providers in Section 3 for business purposes only. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. We act as a "service provider" for Agency-controlled data. California residents may exercise rights via privacy@polca.ai.
8. Financial and health information
Agencies may be subject to the Gramm-Leach-Bliley Act and state insurance data-security laws for Consumer financial and health information; Polca processes such information solely as the Agency's service provider under the DPA's safeguards. Polca is not a HIPAA business associate by default (see DPA Section 4), and Agencies remain responsible for assessing state consumer-health-data and insurance-privacy laws applicable to their own workflows. Agencies may upload application-related materials containing health-related or financial information when necessary for supported workflows, but must not upload full payment-card data, account credentials, or other sensitive information the Service is not designed and authorized to process.
9. Children; international
The Service is for businesses and not directed to children under 18. The Service is operated from the United States and intended for U.S. Agencies; data is stored in the U.S.
10. Changes & contact
We will post updates here with a new effective date and notify account owners of material changes. Contact: privacy@polca.ai · Polca LLC, Nebraska, USA.