Group Protection Strategies, LLC ("we," "us," "our") operates the AncillaryGPS website and SaaS application (the "Service"), a cloud-based platform designed to assist insurance professionals, agencies, brokers, and carriers with the planning, quoting, and tracking of ancillary employee benefit insurance plans. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at www.ancillaryGPS.com, use the Service, or interact with us.
1. Information We Collect
We may collect the following types of information:
a. Personal Information
Contact and account information (name, email, phone, company name, job title)
Billing information (credit card details, billing address — typically processed by third-party payment processors)
Authentication credentials (passwords, MFA data)
b. Insurance-Related Data
Policyholder / applicant information uploaded or entered by you (plan sponsor names, addresses, demographic data, health/benefit election data, contribution data, etc.)
Quoting, enrollment, and administration data related to ancillary insurance products
Note: If the Service processes protected health information ("PHI") under HIPAA, we act as a Business Associate and are bound by a separate Business Associate Agreement (BAA). This Privacy Policy does not govern PHI; the BAA does.
c. Automatically Collected Information
Device and usage data (IP address, browser type, OS, pages viewed, time spent, referring URLs)
Cookies, web beacons, analytics data (Google Analytics, Mixpanel, etc.)
Log data and error reports
2. How We Use Your Information
We use the collected information to:
Provide, maintain, and improve the Service
Process subscriptions, payments, and account management
Facilitate insurance quoting, enrollment, policy administration, and carrier reporting
Communicate with you (service updates, support, marketing with opt-out)
Comply with legal obligations (insurance regulations, tax, anti-fraud)
Detect fraud, abuse, and security incidents
Aggregate/anonymize data for analytics, benchmarking, and product improvement
3. Sharing of Information
We may share your information with:
Insurance carriers, MGAs, TPAs, and other partners as necessary to provide the Service
Payment processors (Stripe, etc.)
Cloud hosting / infrastructure providers (AWS, Azure, etc.)
Analytics and support tools (under data processing agreements)
In the event of merger, acquisition, or sale of assets
When required by law, subpoena, insurance department examination, or to protect rights/safety
We do not sell your personal information.
4. Data Retention
We retain personal and insurance-related data as long as your account is active, plus a reasonable period thereafter to comply with insurance record-retention laws (often 5–7 years), tax obligations, or dispute resolution.
5. Your Rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data, or opt out of certain processing. Contact us at support@ancillaryGPS.com. For California residents: see CCPA section below. For EU/UK residents: see GDPR section below.
6. Security
We implement reasonable administrative, technical, and physical safeguards. However, no method of transmission over the Internet is 100% secure.
7. International Transfers
Data may be transferred to and processed in the United States or other countries. We use appropriate safeguards (e.g., Standard Contractual Clauses) for international transfers.
8. Children's Privacy
Our Service is not directed to individuals under 16. We do not knowingly collect data from children under 16.
9. Changes to This Policy
We may update this policy. We will post the new version and update the "Last Updated" date.
10. Contact Us
Group Protection Strategies, LLC
523 Benfield Road, Suite 203, Severna Park, MD 21146
Email: support@ancillaryGPS.com
CCPA / CPRA Notice (California Residents) — We do not sell personal information. You may request access, deletion, or opt-out of sale/sharing at the email above.
GDPR / UK GDPR Notice (EEA / UK Residents) — Our legal bases include contract performance, legitimate interests, consent, and legal obligations. You have rights under Articles 15–22 GDPR. Our EU representative (if required): [details or "not required"].