Information we collect
We collect account information such as your name, email address, login information, subscription status, and security events. When you use the vault, we also collect the information you choose to enter or upload, including policy details, beneficiary and emergency-contact information, family instructions, claim checklists, notes, and policy documents.
Invited beneficiaries provide account and access information when they accept an invitation. We record invitation, authorization, and portal activity needed to provide and protect that access.
How we use information
We use personal information to:
- create and authenticate accounts;
- store, organize, search, and display vault records;
- send account, security, recovery, and beneficiary-invitation emails;
- process subscriptions and maintain billing status;
- prevent fraud, abuse, and unauthorized access;
- diagnose errors and maintain reliability; and
- comply with law and enforce our terms.
Document extraction and artificial intelligence
If you choose automated document extraction, the uploaded document is processed to identify policy fields and help prefill your record. This feature may send the document content to our contracted AI service provider for that requested processing. You can instead enter policy information manually.
Service providers
We disclose information only as needed to companies that operate the service on our behalf. These currently include Supabase for accounts, database, and private file storage; Netlify for application hosting and backups; Cloudflare for bot and abuse protection; Resend for email delivery; Stripe for subscription billing; Sentry for privacy-configured error monitoring; and OpenAI when you request automated document extraction. These providers process information under their own service terms and security obligations.
No sale or advertising use
HIG Legacy Vault does not sell personal information, share it for cross-context behavioral advertising, or use vault contents to advertise to you.
Beneficiary information
A policyholder may enter another person’s contact information and invite that person to limited portal access. Invited users see only information the policyholder authorizes. An invitation does not change a policy’s legal beneficiary designation or create insurance rights.
Security
We use access controls, private storage, encrypted connections, multi-factor protection for administrative services, rate limiting, bot protection, backups, monitoring, and data minimization. No online service can guarantee absolute security. Protect your password and notify us if you believe your account has been compromised.
Your choices and privacy rights
You may review and correct vault information from your account. You may delete individual policies and documents, revoke beneficiary access, or permanently delete your account and its associated live vault data from Settings. You may also request access, correction, or deletion where applicable law provides those rights. We will not discriminate against you for exercising a privacy right.
If you cannot access your account, email privacy@huffmaninsurancegroup.com. We may need to verify your identity before acting on a request.
Retention
We retain information only for the purposes described here and follow the schedule in our Data Retention Policy. Account deletion removes live vault data, while encrypted backups expire on their normal rotation schedule.
Children
The service is intended for adults and is not directed to children under 13. Do not create an account for a child or upload information that is not reasonably needed for organizing a policy.
Changes to this policy
We may update this policy when the service or legal requirements change. We will post the updated effective date and provide additional notice when a material change requires it.
Contact
Privacy questions and requests may be sent to privacy@huffmaninsurancegroup.com.