NexLife ("NexLife," "we," "us," or "our") is committed to protecting the personal information of the licensed insurance agents who use our platform ("Agents") and the prospective and current clients whose information is collected through our intake tools at the direction of an Agent ("Clients"). This Privacy Policy explains what information we collect, how we use and protect it, when we share it, how long we retain it, and the rights you have over it. It applies to the NexLife website, dashboard, intake forms, APIs, integrations, and all related services (the "Services"). Please read it carefully. By accessing or using the Services you acknowledge that you have read and understood this Privacy Policy.
1. Two Distinct Relationships
NexLife interacts with two categories of individuals, and the privacy treatment differs:
- Agents create accounts, log into the dashboard, and use the Services as licensed insurance producers. With respect to Agent account data (login credentials, agency information, billing data, support history, usage logs), NexLife is a controller.
- Clients are the prospective insureds whose information is collected through an intake link initiated by an Agent. With respect to Client underwriting information collected through an intake, the Agent (and ultimately the issuing insurance carrier) is the controller of that information; NexLife acts as a service provider / processor that transmits the information to the carrier on behalf of the Agent and discards it as described in Section 7.
2. Information We Collect from Agents
- Account & professional information: first and last name, business email, mobile phone, agency name, National Producer Number ("NPN"), state(s) of licensure, time zone, and password (stored as a one-way cryptographic hash; we never see or store the plaintext password).
- Billing information: billing address, last four digits and brand of payment card, and transaction history. Full payment card details are collected and stored directly by our payment processor in a PCI-DSS Level 1 environment; NexLife does not store full card numbers or CVVs.
- Communications: support tickets, emails, chat messages, and similar correspondence you send to us.
- Usage data: the carriers you've configured, the number of intakes you've sent, dashboard interactions, feature usage, and similar product analytics.
- Technical data: IP address, browser type and version, operating system, device identifiers, referring URL, pages viewed, timestamps, and similar log data.
3. Information Collected from Clients via Intake Links
- Identifiers: legal name, date of birth, sex assigned at birth, residential address, phone number, email address, marital status, dependents, and beneficiaries.
- Underwriting information: height, weight, tobacco/nicotine use, alcohol use, recreational-drug history, medical conditions and history, prescription medications, family medical history, occupation, income, net worth, hazardous activities, foreign travel, and military status.
- Sensitive identifiers: Social Security Number, driver's license number, and bank account or routing numbers, collected only when required by the destination carrier for underwriting, identity verification, or payment-of-premium setup, and processed under the zero-storage relay described in Section 7.
- Consent records: a timestamped record of the Client's acceptance of the TCPA and SMS Consent terms presented at the start of the intake, the IP address from which consent was given, and the user-agent string of the device used.
4. Information Collected Automatically
When you visit our website or use the Services, we and our service providers may automatically collect device, log, and analytics data through cookies, pixels, local storage, and similar technologies. This data may include your IP address, browser characteristics, the pages you view, the links you click, the time and duration of your sessions, referral sources, search terms, and aggregate usage patterns. We use this data to operate, secure, monitor, debug, and improve the Services, to detect and prevent fraud and abuse, and to produce de-identified analytics.
5. How We Use Personal Information
- To provide, operate, maintain, and support the Services.
- To authenticate Agents, manage accounts, and process subscription payments.
- To facilitate the transmission of Client intake submissions to the carriers selected by the Agent.
- To send transactional communications about your account, billing, security, and the Services (these are not promotional and cannot be unsubscribed from while your account is active).
- To send service updates, feature announcements, and educational content to Agents (you may opt out at any time).
- To detect, investigate, prevent, and respond to fraud, abuse, security incidents, unauthorized access, and violations of our Terms of Service.
- To comply with applicable legal, regulatory, tax, audit, and reporting obligations.
- To produce de-identified or aggregate statistics that do not identify any individual and that we may share or publish for any lawful purpose.
- To enforce or defend our legal rights and the rights of others.
6. Encryption & Security Safeguards
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction. These safeguards include:
- Encryption in transit: all connections to the Services use TLS 1.2 or higher with modern cipher suites; the dashboard enforces HTTPS via HSTS.
- Encryption at rest: Agent account data and operational metadata are stored in an encrypted-at-rest database using AES-256 encryption managed by our cloud provider.
- Access controls: production access is limited to authorized personnel via single-sign-on with multi-factor authentication, audited, and reviewed on a recurring basis.
- Least-privilege design: internal systems are segmented; production credentials are short-lived and rotated.
- Vulnerability management: dependencies are continuously monitored for known vulnerabilities and patched on a defined cadence.
- Logging and monitoring: we log authentication events and administrative actions and monitor for anomalies indicative of compromise.
No method of transmission over the internet or method of electronic storage is one hundred percent secure. While we use commercially reasonable measures to protect personal information, we cannot guarantee its absolute security. If we become aware of a security incident that materially affects the confidentiality of personal information, we will notify affected Users without undue delay and in accordance with applicable law.
7. Zero-Storage Relay for Client Underwriting Data
NexLife is designed so that the most sensitive elements of a Client's intake submission Social Security Number, driver's license number, bank account and routing numbers, and full medical and prescription history, are relayed to the destination carrier and not retained in NexLife's primary database. Specifically:
- The intake is rendered in the Client's browser over an encrypted connection and posted directly to our intake API.
- The submission is assembled into a structured underwriting packet and delivered to the carrier's underwriting email or API endpoint, addressed by the Agent.
- Sensitive fields are then purged from operational stores. We retain only (a) the non-sensitive metadata required to display the deal on the Agent's dashboard (Client name, carrier, coverage type, status, timestamps) and (b) consent records required by law.
- Encrypted transport logs may temporarily contain payload fragments for the period necessary for debugging and abuse detection, after which they are rotated and deleted in accordance with the retention schedule in Section 10.
After a Client's intake has been relayed to the carrier, the authoritative copy of the underwriting record lives with the carrier and the Agent of record. Requests to access, correct, or delete underwriting information after submission must generally be directed to the carrier.
8. When We Share Personal Information
- Insurance carriers selected by the Agent, to whom we transmit the Client's underwriting packet for quoting, application processing, and underwriting.
- Service providers that perform functions on our behalf and are contractually bound to use the information only to provide their services to NexLife, including our cloud-hosting provider, database provider, SMS gateway (e.g., GoHighLevel/Twilio), transactional email provider (e.g., Resend), payment processor, error-monitoring and analytics providers, and customer-support tooling.
- Professional advisors such as auditors, attorneys, and insurers, under obligations of confidentiality.
- Successors in interest in connection with a merger, acquisition, reorganization, financing, sale of assets, or bankruptcy, subject to standard confidentiality protections and continued application of this Privacy Policy or one materially similar.
- Law enforcement, regulators, and others when we believe in good faith that disclosure is required by law, subpoena, court order, or other valid legal process, or is necessary to protect the rights, property, or safety of NexLife, our Users, or the public.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not authorize any third party to use information collected through the Services for that party's independent marketing purposes.
9. International Data Transfers
The Services are operated from and intended for use in the United States. If you access the Services from outside the United States, you understand and consent to the transfer, processing, and storage of your information in the United States, which may not provide the same level of data-protection rights as the jurisdiction in which you reside.
10. Data Retention
- Agent account data: retained for the life of the account, plus a reasonable archival period after account closure (typically 24 months) to satisfy legal, tax, audit, and dispute-resolution obligations, after which it is deleted or de-identified.
- Deal metadata (non-sensitive): retained for as long as the Agent's account is active, then handled per the schedule above.
- Client sensitive fields (SSN, driver's license, banking, medical, prescription): purged from operational stores promptly after relay to the carrier as described in Section 7.
- Consent records: retained for at least the period required by the TCPA and applicable state SMS regulations (currently at least four years from the date consent was last refreshed) for evidentiary purposes.
- System logs: rotated on a defined cadence (typically 30-90 days) consistent with security best practices.
- Backups: encrypted backups may persist for up to 35 days after deletion from primary stores before they are overwritten on the standard rotation.
11. Your Rights
Depending on your jurisdiction, you may have one or more of the following rights with respect to your personal information: the right to confirm whether we process information about you, to access that information, to request correction of inaccuracies, to request deletion, to obtain a portable copy, to restrict or object to certain processing, to opt out of sale or sharing (NexLife does not sell or share for cross-context advertising), and to opt out of certain automated decision-making (NexLife does not engage in automated decision-making that produces legal or similarly significant effects on individuals). To exercise these rights, email privacy@nexlifecrm.org from the email address associated with your account, or in the case of a Client, from the email address used during your intake. We will verify your identity before fulfilling the request and respond within the time period required by applicable law. You will not be discriminated against for exercising your rights. If we deny a request, you may appeal by replying to our denial; in some jurisdictions you may also have the right to lodge a complaint with your state attorney general or applicable data-protection authority.
12. California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"). The categories of personal information we collect, the purposes for which we use them, the categories of recipients, and the retention periods are described elsewhere in this Privacy Policy. We do not sell or share (for cross-context behavioral advertising) personal information, and we do not knowingly collect personal information of consumers under the age of sixteen.
13. Communication Preferences & SMS
We collect your name, email, and phone number to communicate with you about the intake or application you requested through your licensed agent. If you provide SMS consent, we use your phone number solely to send customer care and operational text messages from Nex Life CRM about your intake/application (for example: confirming your opt-in, sending your secure intake link, delivery/status updates, and support replies). Message frequency varies. Message and data rates may apply. Reply STOP at any time to opt out or HELP for help. Consent is not a condition of purchase.
Nex Life CRM does not sell, rent, share, or otherwise disclose SMS opt-in consent, mobile phone numbers, or any information collected in connection with SMS consent to any third party for that third party's independent marketing, promotional, lead-generation, or advertising purposes. SMS consent and phone numbers are used only for the customer care and operational messages described above in connection with the client's requested intake/application. This restriction applies to affiliates, partners, and any third parties.
You may withdraw SMS consent at any time by replying STOP to any message from us. Transactional and service-related communications about your account (security alerts, billing notices, legally required disclosures) may continue while your account remains active.
14. Cookies & Similar Technologies
We use a minimal set of first-party cookies and local-storage entries strictly necessary to operate the Services (for example, to keep you logged in and to remember your preferences) and a limited number of analytics cookies to understand how the Services are used in aggregate. We do not use third-party advertising cookies. You can control cookies through your browser settings; disabling necessary cookies may impair the functionality of the Services.
15. Children's Privacy
The Services are intended for U.S. adults aged eighteen (18) and older. We do not knowingly collect personal information from anyone under thirteen (13), and we do not direct the Services to children. If you believe we may have collected information from a child under thirteen, please contact privacy@nexlifecrm.org and we will promptly investigate and delete the information as required by law.
16. Do Not Track
Some browsers transmit "Do Not Track" signals. Because there is no consistent industry standard for how to respond to these signals, the Services do not currently alter behavior in response to them. We will revisit this practice as standards develop.
17. Third-Party Sites & Services
The Services may link to or interoperate with third-party websites, applications, or services that we do not control. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy notices of any third-party site or service you interact with.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated by reasonable means, which may include in-product notice or email to your registered address. Your continued use of the Services after the effective date of a revised Privacy Policy constitutes acceptance.
19. Contact Us
Privacy questions, requests, and complaints may be directed to:
- Email: privacy@nexlifecrm.org
- Mail: NexLife, Privacy Office, Michigan, USA
- Security reports: security@nexlifecrm.org
