PRIVACY POLICY

Privacy should be understandable.

This policy explains how Echelon Life OS LLC, doing business as Echelon LifeOS™, handles account, agency, and consumer information.

Effective: September 16, 2026

Information we handle

We may process account identity, agency profile, licensing documents, lead and client records, communications, consent evidence, appointments, policy workflow information, subscription and access status, campaign attribution, and product-usage records that customers choose to store in Echelon LifeOS™. Authentication and service systems may also process IP-derived approximate location, browser, device, session, diagnostic, and delivery-health information to protect accounts and operate the service.

How information is used

Information is used to provide and secure the service, authenticate users, organize agency workflows, deliver requested communications, support billing, improve reliability, prevent abuse, and comply with applicable obligations. Echelon LifeOS™ does not sell consumer records or use an agency’s private CRM data in the public product demo.

Service providers

Specialized providers may process limited information for identity, hosting, payment, email, messaging, calling, calendars, analytics, support, and AI-assisted workflows. Clerk provides account authentication and identity management, including sign-in session security that may use a client IP address to determine approximate city or country and recognize browser or device context. Card details are entered directly with Stripe and are not stored by Echelon LifeOS™; Echelon receives subscription, access, and transaction references needed to manage the account. Provider access should be limited to what is needed for the requested service.

Paid-ad measurement

On Meta-attributed public campaign visits, and only after an agency administrator authorizes the current disclosure, Echelon LifeOS™ may load Meta Pixel to record PageView and ViewContent and may record an accepted production request as a Lead through both the browser and Meta's server API. The browser and server Lead use the same random event ID for deduplication. The server event may include its event time, the exact Echelon funnel URL, a one-way SHA-256 hash of the random event ID, and a Meta click identifier when present. Meta's tag may receive browser, network, and device identifiers under Meta's terms. Meta automatic form matching is disabled by Echelon before the Pixel is initialized.

On Google-attributed public campaign visits, when the Google Ads tag and conversion label are configured, Echelon may load the Google tag with automatic page-view reporting disabled. After an accepted production request, Echelon may send the configured conversion reference and the same random event ID as a transaction ID for deduplication. Google's tag may receive browser, network, and device identifiers under Google's terms. Echelon does not send names, contact details, answers, health details, notes, CRM IDs, or rehearsal leads in its Meta or Google conversion calls. Direct and unpaid visits do not load these paid-ad tags. When a browser sends an enabled Global Privacy Control signal, Echelon suppresses both advertising tags and conversion transmissions for that visit.

Detached carrier prescreen

The underwriting workspace is separated from CRM records and runs only through Echelon's isolated underwriting service. It accepts controlled carrier factors and relative timing ranges; it does not accept or transfer a name, lead or case identifier, contact information, date of birth, exact event date, or narrative medical note. Prescreen inputs and results are used for the current browser session and are not saved as an applicant profile or decision record. A 15-minute encrypted token authorizes only a listed carrier handoff for the signed-in agent and contains no applicant health input. Pilot agents may submit an optional, controlled accuracy report containing only the signed-in account, a random run UUID, product, state, result category, and selected carrier—never the prescreen health inputs, applicant identity, notes, files, or screenshots. Open reports become eligible for automatic purge after 90 days and closed reports after 30 days; cleanup is enforced during subsequent service activity, and account deletion removes the reports immediately. Applicant-specific prices, outcomes, and application facts remain in the authorized carrier system.

Mobile applications

The Echelon LifeOS™ mobile applications connect to the same secure service at www.echelonlife.net. The apps may request microphone access only when a user places or answers a call. During a browser call, microphone audio is transmitted through Twilio in real time; the current LifeOS calling configuration does not request or store a call recording. Camera, photo, or file access occurs only when a user chooses a license, carrier material, campaign asset, or supporting document to upload. Optional device authentication can protect the workspace after the app has been in the background; biometric templates remain with the device operating system, and Echelon receives only the authentication result. The apps do not request precise location or contacts access and do not use advertising identifiers for cross-app tracking.

Agency responsibility and consent

Agencies control the consumer information they upload and are responsible for lawful collection, accurate consent records, required notices, licensing, approved sales practices, and honoring opt-outs. Echelon LifeOS™ tools support these duties but do not replace legal or compliance review.

Text messaging privacy

Mobile information and text-message opt-in consent are not sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. Text-message opt-in consent is not transferred to another party except service providers acting only as needed to deliver and support the messaging service. Message frequency varies. Message and data rates may apply. Reply STOP to opt out and HELP for help.

Retention and deletion

Records should be retained only as long as needed for the service, contractual obligations, fraud prevention, and applicable legal or regulatory requirements. Account owners may delete their account through account settings or follow the public instructions in the account deletion section, subject to required retention and secure backup cycles.

Security and incidents

Echelon LifeOS™ uses authenticated access, agency isolation, encrypted integration credentials, restricted file sharing, and activity controls. No system is completely secure. We maintain processes to assess, respond to, and recover from suspected security incidents and provide notices when required by law.

Choices and rights

Depending on location, individuals may have rights to access, correct, delete, or receive information and to limit certain processing. Requests can be sent to privacy@echelonlife.net. Identity verification may be required.

Children and sensitive information

The service is for insurance professionals and is not directed to children. Agencies should not enter direct identifiers, exact dates, or narrative medical information in the detached carrier prescreen and should follow carrier, state, and federal requirements for health and financial data.

Contact

Questions and privacy requests may be sent to privacy@echelonlife.net.