Privacy Policy
Updated Apr 19, 2026
1. Who they are and scope of the policy
Usually starts with:
-
Identification of the company:
-
“Zen Insurance Services” (legal name, possibly “Zen Insurance Services, LLC” or similar)
-
Physical address in California, contact email (e.g., binta.patel@zeninsuranceservices.com), phone number.zeninsuranceservices+1
-
-
Statement that the policy applies to:
-
The website https://www.zeninsuranceservices.com
-
All interactions (phone, email, in‑person, online forms) where they collect your information in connection with insurance quotes, enrollments, and servicing.
-
2. Types of information they collect
For a Medicare/health insurance agency, this typically includes:
a) Personal identifying information
-
Name, address, email, phone number
-
Date of birth, gender
-
Social Security Number (for Medicare/plan enrollment)
-
Driver’s license or other ID (if used for verification)
b) Health and insurance information
-
Current health coverage details (Medicare Parts A/B, employer coverage, etc.)
-
Medical conditions, medications, doctors, hospitals (to assess plan fit)
-
Prescription drug lists
-
Prior insurance claims or coverage history (as relevant)
c) Financial information (limited)
-
Bank account details if setting up automatic premium payments (often via carrier forms, but sometimes collected by the agency)
-
Payment method details for any fees they charge (if applicable)
d) Technical / website data
-
IP address, browser type, device info
-
Pages visited, time spent, referral source
-
Cookies and similar tracking technologies (Google Analytics, Facebook Pixel, etc.)
e) Communication records
-
Call recordings (if they record calls for quality/compliance)
-
Emails, chat transcripts, notes from consultations
3. How they use your information
Typical purposes:
-
Provide insurance services
-
Evaluate eligibility for Medicare/health plans
-
Compare plan options
-
Submit applications and enroll you with carriers
-
Service your policy (changes, renewals, claims support)
-
-
Compliance and legal obligations
-
Meet state insurance department and CMS (Centers for Medicare & Medicaid Services) requirements
-
Maintain required records for audits
-
Detect and prevent fraud
-
-
Business operations
-
Improve website and services
-
Internal training and quality assurance (e.g., call monitoring)
-
Communicate with you about your policies, renewals, and relevant plan changes
-
-
Marketing (with consent where required)
-
Send educational materials about Medicare/health insurance
-
Contact you about plan options during eligible enrollment periods
-
Offer webinars, workshops, or newsletters (if you opt in)
-
Under HIPAA, uses related to treatment, payment, and health care operations are allowed with appropriate safeguards; for marketing, stricter consent rules apply.
4. How they share or disclose your information
A California Medicare agency will usually state they do not sell your personal information in the CCPA sense, but they do share it with:
-
Insurance carriers (to quote, enroll, and service your policies)
-
Government agencies as required by law (e.g., CMS, state insurance department)
-
Service providers (e.g., CRM, email marketing, website hosting, telephony, e‑signature tools) under contracts that require them to protect your data
-
Professional advisors (lawyers, accountants, auditors)
-
Law enforcement or regulators when legally required (subpoenas, investigations, fraud prevention)
They should explicitly say whether they sell or share for targeted advertising under CCPA; most reputable agencies say they do not.
5. Cookies and tracking technologies
This section typically covers:
-
Use of essential cookies (login, form submissions, security)
-
Analytics cookies (e.g., Google Analytics) to understand site usage
-
Advertising / retargeting cookies (e.g., Google Ads, Meta Pixel) if used
-
How you can manage or disable cookies via browser settings
-
A link to a separate Cookie Policy (sometimes combined with the Privacy Policy)
For a small agency, this may be relatively simple but must still disclose major third‑party trackers.
6. Your privacy rights (especially for California residents)
Under CCPA/CPRA, California residents generally have the right to:
-
Know what personal information is collected, used, shared, or sold
-
Access a copy of their personal information
-
Correct inaccurate personal information
-
Delete personal information (with some exceptions, e.g., where retention is required by law)
-
Opt out of “sale” or “sharing” of personal information (if applicable)
-
Non‑discrimination for exercising privacy rights
The policy should explain:
-
How to submit a request (web form, email, phone, mail)
-
That they may need to verify your identity before fulfilling requests
-
Typical response timelines (e.g., 45 days under CCPA, with possible extension)
-
That they may keep certain data as required by insurance regulations (e.g., records of enrollments for several years).
If they serve people outside California, they may also reference other rights (e.g., GDPR‑style rights for EU visitors, though that’s less likely for a purely California Medicare agency).
7. Data security measures
They’ll usually describe, in general terms, that they:
-
Use encryption for data in transit (HTTPS on the website, secure email where possible)
-
Limit access to personal information to authorized staff who need it
-
Use password‑protected systems, role‑based access, and secure CRM/insurance platforms
-
Require written agreements with vendors to protect your data
-
Maintain administrative, physical, and technical safeguards consistent with HIPAA and state insurance privacy rules
They typically add a disclaimer that no method of transmission or storage is 100% secure, but they commit to reasonable safeguards.
8. Data retention
They’ll state how long they keep your information, for example:
-
As long as you remain a client or prospect
-
Plus additional years to comply with state insurance regulations, CMS rules, and tax/legal requirements (often 5–10 years, depending on the record type)
-
After that, data is securely deleted or anonymized where possible
Exact periods depend on their internal policies and regulatory obligations.
9. Children’s privacy
Since they deal with Medicare (65+) and adult health insurance, they’ll usually state:
-
The site and services are not intended for children under 18 (or under 13, per COPPA)
-
They do not knowingly collect personal information from children
-
If they discover such data, they will delete it
10. Changes to the Privacy Policy
Standard language includes:
-
They may update the policy to reflect changes in law, technology, or business practices
-
The effective date will be shown at the top of the page
-
Continued use of the site or services after changes constitutes acceptance
-
Material changes may be communicated via email or a notice on the website
11. Contact information for privacy questions
The policy should end with clear contact details, such as:
-
A dedicated email (e.g., privacy@zeninsuranceservices.com or the main contact email)
-
Mailing address in California
-
Phone number
-
Instructions on how to submit privacy requests or complaints
They may also reference how to contact the California Department of Insurance or other regulators if you have unresolved concerns.
How this ties into their overall business
Understanding the Privacy Policy in context:
-
Their core asset is trust: seniors are sharing sensitive health and financial data. The privacy page is a key trust signal.zeninsuranceservices+1
-
Compliance with HIPAA, CCPA, and insurance regulations is not optional; violations can lead to fines, license issues, and reputational damage.
-
The policy supports their sales and service process:
-
Collecting detailed health and coverage info to recommend plans
-
Sharing that data with carriers to enroll clients
-
Retaining records for renewals, audits, and compliance.
-
-
From a marketing standpoint, the policy must balance:
-
Using data for lead nurturing, retargeting, and analytics
-
Respecting opt‑outs and minimizing intrusive tracking, especially for an older demographic.
-