BrokerGreatness

Privacy Policy

Version 2026-08

Effective Date: August 1, 2026

BrokerGreatness (“BrokerGreatness,” “we,” “our,” or “us”) provides software tools for health insurance brokers, agencies, and related organizations. This Privacy Policy explains how we collect, use, disclose, store, and protect information processed through our platform.

Information We Collect

We may collect and process the following categories of information:

  • Account and user information: name, email address, login/session information, organization, role, team assignment, subscription status, and product/module access.
  • Broker and agency information: broker name, National Producer Number, agency name, phone number, email address, organization details, and related Scope of Appointment information.
  • Client information: client name, email, phone number, address, ZIP code, county, state, date of birth, Medicare information, Part A/Part B dates, and related intake details.
  • Health and plan workflow information: doctors, provider details, specialties, prescription drug names, dosage, quantity, days supply, notes, plan research, report outputs, and diligence workflow records.
  • Forms, links, and reports: tokenized client intake links, report links, passcode-protected access records, first-open information, generated report records, and related audit data.
  • Billing and subscription information: product selections, module access, Stripe customer/subscription identifiers, checkout status, referral codes, and payment metadata. We do not store full payment card numbers.
  • Technical and security information: IP address, browser/user agent, timestamps, audit events, error/debug metadata, and system activity needed to operate and secure the service.

How We Use Information

We use information to:

  • Provide broker workflow tools, client intake forms, doctor and prescription reports, plan research, Scope of Appointment workflows, and related services.
  • Generate, update, and display reports requested by brokers or authorized users.
  • Manage users, teams, organizations, product modules, subscriptions, billing, referrals, and access permissions.
  • Send transactional emails, client form links, report links, notifications, and service-related messages.
  • Maintain security, audit access and changes, troubleshoot issues, prevent abuse, and enforce access controls.
  • Comply with applicable legal, regulatory, contractual, security, and accounting obligations.

Protected Health Information and ePHI

Some information processed through BrokerGreatness may include protected health information or electronic protected health information (“ePHI”). BrokerGreatness is designed to support minimum-necessary collection and role-based access for broker workflows. Users are responsible for ensuring they have appropriate authority and consent to enter, access, or disclose client information through the platform.

How We Share Information

We may share information only as needed to operate the service, including with:

  • Authorized brokers, agency users, team members, administrators, and organization owners based on role, ownership, team, servicing-agent, and module permissions.
  • Clients or authorized recipients through tokenized and passcode-protected intake forms or report links.
  • Service providers that support hosting, databases, background processing, email delivery, payment processing, reporting, backups, security, and technical operations.
  • Carrier, provider directory, or public reference-data APIs when a broker initiates a targeted lookup or report workflow.
  • Legal, regulatory, or security authorities when required by law or necessary to protect rights, safety, or the integrity of the service.

We do not sell client health information.

Security Measures

We use administrative, technical, and operational safeguards designed to protect information, including:

  • Authenticated user access with role, organization, team, servicing-agent, and subscription/module controls.
  • Tokenized public intake and report links with passcode/session gates where applicable.
  • HTTPS-secured access in production and secure session cookie settings.
  • Audit logging for material access, configuration, workflow, and ePHI-related events.
  • SQLite module databases and report outputs stored outside the web root under protected server data paths.
  • Redaction of sensitive debug fields such as tokens, secrets, passwords, API keys, authorization headers, client identifiers, prescriptions, and provider payloads.
  • Carrier/API/OAuth secrets stored in server environment or server configuration references rather than browser-editable database fields.
  • Restricted access to backups, report outputs, uploaded files, and operational logs.

Data Retention

We retain information for as long as needed to provide the service, support broker workflows, comply with legal or contractual obligations, maintain audit records, resolve disputes, and enforce agreements. Generated reports, uploads, cached files, logs, and backups may have separate retention schedules. Authorized administrators may request deletion or correction of records subject to legal, security, audit, and backup limitations.

Cookies and Sessions

BrokerGreatness uses cookies and session technologies to authenticate users, maintain secure sessions, remember access state for authorized forms or reports, and protect the service from unauthorized use. Disabling cookies may prevent parts of the platform from working.

Your Choices and Requests

Depending on your relationship with BrokerGreatness and applicable law, you may request access, correction, deletion, restriction, or a copy of certain personal information. Client health information requests may need to be directed to the broker, agency, plan, provider, or other organization responsible for the client relationship.

Third-Party Services

BrokerGreatness may use third-party services for payment processing, email delivery, hosting, background jobs, carrier/provider lookups, and public reference data. These providers may process information only as needed to provide their services to us, subject to applicable agreements and safeguards.

Children

BrokerGreatness is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the platform.

Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted with a new effective date. Material changes may also be communicated through the platform or by email where appropriate.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

Contact Us