LEGAL · EFFECTIVE JULY 1, 2026
Privacy Policy.
The short version: we store your book, we encrypt the sensitive parts, we never store medical records or claims, and we never sell any of it. The longer version follows.
01
What we store
Client names, dates of birth, contact details, language preference, and consent records. Policies with carriers, plans, premiums, and effective dates. Commissions, splits, and carrier contracts. Notes and tasks your team writes. Files in secure document storage with per-agency isolation.
02
What we refuse to store
Medical records, diagnoses, treatment history, and claims data never enter the system. Velo is deliberately PHI-free: that information stays in your carrier portal under the carrier's HIPAA umbrella, and our Terms of Service forbid uploading it. This is a design decision, not a disclaimer.
03
How SSNs are handled
Social Security numbers are encrypted at rest, displayed masked, and decryptable only by the agency owner. Every full-SSN view writes a permanent audit row. A one-way hash lets us detect duplicate clients without decrypting anything.
04
Whose data it is
Your agency's book is your agency's property. We process it only to run the service. We do not sell it, share it with data brokers, use it for advertising, or train models on it. Row-level tenant isolation keeps every agency's data invisible to every other agency.
05
Who can see what, inside your agency
Owners set per-agent visibility scopes by state, carrier, product line, and ownership. Assistants never see commission dollars. Changes to scopes, people, policies, and splits are recorded in an audit log the owner can review.
06
Subprocessors
Velo runs on Supabase (database, authentication, storage), Vercel (hosting), Resend (transactional email), and Stripe (billing, which handles card details so we never see them). Documents live in secure document storage with per-agency isolation.
07
Cookies and analytics
We use cookies for sign-in sessions and your language and theme preferences. No third-party advertising trackers, no cross-site profiles.
08
Retention, export, deletion
Your data stays as long as your account does, plus a 90-day export window after cancellation. Ask for deletion at any time and we remove your workspace, except audit rows the law or fraud-prevention requires us to keep. Write to hello@goldenanchor.life; privacy or security specifics to security@goldenanchor.life.
Companion documents: the Terms of Service and the security page, which explains how these promises are built.