Privacy Policy
Last updated: July 20, 2026
Who we are
BindIQ is a commercial insurance intake platform for independent property and casualty brokers.
This policy explains what information we collect, why we collect it, how we protect it, and what choices you have. To reach us, see the Contact section at the end of this page.
Two kinds of people use BindIQ
This distinction matters, because our relationship with each is different.
Brokers create a BindIQ account, log in, and use the platform to collect information from their clients. If you signed up for BindIQ, you are a broker.
Clients are the businesses a broker is seeking insurance for. A client receives an intake link from their broker, answers questions about their business, and never creates an account or logs in.
When a client submits information through BindIQ, that information belongs to the broker who sent the link. The broker decides what to collect and what to do with it. BindIQ processes that information on the broker's behalf. If you are a client and you want your information corrected or deleted, the fastest path is to contact your broker directly. You can also contact us and we will work with your broker to resolve it.
What we collect
From brokers
- Account information — email address and agency name, provided at signup.
- Authentication data — we use passwordless sign-in, so we never collect, store, or transmit a password. Signing in generates a single-use link sent to your email.
- Usage data — the number of intakes you have used, your plan, and the timestamps of account activity, so we can operate your account and enforce plan limits.
- Payment information — when paid plans launch, payments will be processed by Stripe. Card numbers go directly to Stripe and are never stored on BindIQ systems. We retain only a customer reference and your subscription status.
From clients, on behalf of brokers
When a client completes an intake, we collect the business information needed to prepare a commercial insurance application (ACORD 125). Depending on what the broker asks for, this may include:
- Business name, DBA, mailing and physical address, website
- Federal Employer Identification Number (FEIN) and NAICS classification
- Contact name, email address, and phone number
- Business description, operations, and premises information
- Prior insurance carrier information and loss history
We do not intentionally collect Social Security numbers, financial account numbers, health information, or other sensitive personal information through the intake. The intake asks about a business, not about individuals. If a client volunteers such information in a free-text answer, it is stored as part of the submission and is subject to this policy.
Automatically
Standard technical data — IP address, browser type, and timestamps — generated by our hosting and logging infrastructure and used for security, debugging, and abuse prevention.
We do not use advertising cookies, tracking pixels, or third-party analytics that follow you across other websites. The only cookies we set are the ones required to keep you signed in.
How we use information
We use information to:
- Operate the platform — deliver intakes, generate ACORD forms, run broker dashboards
- Authenticate brokers and keep accounts secure
- Send transactional email: sign-in links, intake-ready notifications, and account notices
- Enforce plan limits and process payments
- Diagnose problems and improve the product
- Comply with legal obligations
We do not sell your information. We do not share it with advertisers or data brokers. We do not use client submission data to train artificial intelligence models.
Artificial intelligence and how we handle uncertainty
BindIQ uses an AI language model to conduct the intake conversation and to organize answers into the fields of an insurance application. Intake content is sent to Anthropic's Claude API for this purpose.
Two commitments about how that works:
The AI never invents an answer. If a client says they do not know something, that field is marked unknown and passed to the broker for review. It is never converted into "no," "none," or zero. Every field carries a record of where its value came from — answered directly, interpreted by the AI, unknown, or skipped — and the broker sees which is which.
Every form is reviewed by a human before it is used. BindIQ produces a draft, clearly watermarked as a draft, that the broker reviews, edits, and approves. BindIQ does not submit anything to a carrier on its own.
How we protect information
- Encrypted in transit and at rest. All connections use TLS. Stored data is encrypted at rest by our infrastructure providers.
- Database-enforced separation between agencies. Each broker can access only their own submissions, and this is enforced at the database level through row-level security — not merely by application logic. A broker cannot reach another agency's data even if a request is malformed or a link is shared by mistake.
- No passwords to steal. Passwordless sign-in eliminates password reuse and credential-stuffing as attack paths.
- Least-privilege access. Administrative database credentials are used only by server-side code and are never sent to a browser.
What we do not claim: BindIQ has not completed a SOC 2 audit, is not HIPAA-certified, and has not undergone third-party penetration testing. We would rather tell you that plainly than imply a certification we do not hold. No system is perfectly secure, and we cannot guarantee absolute security.
Where information is stored
Our primary database is hosted in the European Union (Ireland). Application hosting and email delivery are provided by vendors that may process data in the United States and other locations.
If you are located outside the country where information is stored, your information will be transferred across borders as part of providing the service.
Service providers
We use a small number of vendors to operate BindIQ. Each receives only what it needs:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication | EU (Ireland) |
| Vercel | Application hosting | United States / global edge |
| Anthropic | AI processing of intake content | United States |
| Resend | Transactional email delivery | United States |
| Google Workspace | Business email | United States |
| Stripe | Payment processing (when paid plans launch) | United States |
These providers process information on our instructions and are not permitted to use it for their own purposes.
How long we keep information
- Broker accounts — for as long as the account is active. If you close your account, contact us and we will delete your account data within 30 days.
- Submissions — retained so brokers have a record of their work. A broker may request deletion of specific submissions at any time.
- Backups and logs — routine backups may persist for a limited period after deletion, then age out automatically.
We may retain limited records longer where required by law.
Your choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your information, and to object to certain processing.
To exercise any of these, email doug@bindiq.io. We will respond within 30 days. We may need to verify your identity first.
If you are a client rather than a broker, contact your broker first — they control the submission and can act immediately. We will assist where they cannot.
You can opt out of non-essential email at any time. Transactional messages — sign-in links, intake notifications, billing notices — are part of the service and cannot be opted out of while your account is active.
Children
BindIQ is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children.
Changes to this policy
If we make material changes, we will update the date at the top and, for significant changes, notify account holders by email. Continued use after a change takes effect means you accept the updated policy.
Contact
Questions, requests, or concerns:
doug@bindiq.io
BindIQ
71 Willow Ct
Dorchester, MA 02125
United States