Privacy Notice
Effective September 23, 2026
This notice describes information handled through the Thalos Life insurance application websiteDirect 130 agent contracting and case-management website. A carrier’s own privacy notice applies to information it handles in connection with an insurance policy.
Information and purposes
- Waitlist requests: your name, email address, chosen brand, request date, and approval decision. We use these to review access requests, send requested sign-in links after approval, and enforce access restrictions.
- Consumer application details: your name, email, date of birth, sex at birth, ZIP code, country and state of birth, citizenship or residency answers, family and financial needs, mortgage estimate, coverage selections, and other answers you submit. These support your requested estimate and application.
- Health information: nicotine use and answers about treatment, medication, and hospital stays. We use these to process your application. Read the separate Consumer Health Data Privacy Policy before providing these answers.
- Agent information: your NPN, name, resident state, email, birthdate, current contracting relationships, license records, producer-report contents, verification status, and screening authorization. These support licensing review, contracting, account administration, and appointment requests.
- Identity and screening: Stripe’s hosted verification may request an identity document and selfie. Our application stores the verification reference and result. The screening form requests a legal name and Social Security number with an authorization; the backend can store the number in Supabase Vault. An authorization is not proof that a credit report has been obtained.
- Agent case and transaction records: client names, products, carriers, premium amounts, case stages, appointments, commissions, and release requests entered or recorded for an account. These support the agent’s case-management services, including the customer-relationship management platform provisioned with contracting. Agents must have authority to submit another person’s information.
- Ad measurement: when we run Facebook and Instagram ads, the Meta pixel collects which of our public pages you visit, device and browser details, your IP address, and a cookie identifier, as described under Advertising. You can turn it off.
- Technical and communication records: service providers may process IP addresses, device and request details, timestamps, security logs, payment references, and account-related email records to deliver and protect the service, troubleshoot requests, and respond to you.
Information comes from you, agents acting for their clients, licensing sources and reports, identity and payment providers, and the operation of the service. We do not request access to your contacts, precise device location, microphone, or camera on these pages. A hosted identity provider may request camera access in its own flow.
Recipients and service providers
Information is handled by the people and providers needed to operate the requested service. The current integrations include hosting through Vercel; database, authentication, and protected storage through Supabase; payment and identity services through Stripe; transactional email through Resend when enabled; product analytics through PostHog when enabled; advertising measurement through Meta Platforms (the Meta pixel) when we run Facebook and Instagram ads; and licensing lookups through NIPR or state licensing sources. The jsDelivr content-delivery service supplies the authentication, number-display, and analytics libraries when a page uses them. Platform and infrastructure providers may support these services under their applicable agreements.
Approved Direct 130 agents are provisioned an account on the InsuraCentral customer-relationship management platform for the period they are contracted. Agent records and the client information an agent enters there are handled on that platform under its own terms and privacy notice, and access ends when the contract ends. Information an agent records about a client they serve is covered by this paragraph.
You do not receive an account on the customer-relationship management platform our contracted agents use. If one of those agents serves you, information they record about you there is handled under that platform’s own terms and privacy notice.
When you proceed with a carrier application or appointment, relevant information may need to be provided to that carrier under the applicable disclosure and authorization. Being appointed with a carrier does not mean your application has been transmitted to it.
Information may also be disclosed when necessary to comply with an applicable legal requirement, respond to a valid legal request, protect against fraud, or complete a business transfer subject to continuing privacy obligations. We do not use session-replay tools. The optional measurement tools we do use, PostHog analytics and the Meta pixel, are described under Requests and choices and Advertising.
Marketing
We send two different kinds of message, and they follow different rules.
- Service messages about something you asked for: a sign-in link, an application update, a payment receipt, a licence-renewal reminder. These are part of the service and are sent whether or not you opt in to marketing. They carry no unsubscribe link because you cannot opt out of being told your payment failed.
- Marketing messages about our products, offers, and services. These are sent only if you separately opted in, using the optional checkbox in the application. That choice is never a condition of getting a quote, applying, buying a policy, or being contracted as an agent, and declining it changes nothing about your application.
If you opted in, we record when you did and which channels it covered: email, telephone call, and text message, including messages sent with automated technology. Standard message and data rates may apply.
Withdrawing is meant to be easy. Use the unsubscribe link in any marketing email, reply STOP to a text message, tell us during a call, or email privacy@thaloslife.com. We record the withdrawal and act on it promptly. Withdrawing marketing permission does not stop service messages about an application or policy you hold.
We do not sell your information. Apart from the ad measurement described below, we do not share it with other companies so they can market to you.
Advertising on Facebook and Instagram
We advertise Thalos LifeDirect 130 on Facebook and Instagram. To measure those ads and show them to people who may want them, our public pages can run the Meta pixel, a small piece of code from Meta Platforms, Inc. It runs only while ad measurement is turned on for this site.
When it runs, the pixel sends Meta:
- The address of the page you visited and the page you came from, the time, and your browser, device, and IP address.
- A random identifier stored in the
_fbpcookie and, if you arrived from one of our ads, the ad click identifier stored in the_fbccookie. - One event, called a lead, when you send your answers to the quote questions. The event says only that the questions were sent.
It never sends your answers, your name, email address, phone number, date of birth, health information, or anything you type into a form. It does not run on the application and health questions, payment, sign-in, or the waitlistthe application, identity verification, sign-in, the waitlist, or agent accounts.
Meta may combine this with what it knows about your Facebook or Instagram account. It uses the information to report on our ads, to show our ads to you or to people like you, and for its own purposes as described in Meta's Privacy Policy. Under some state laws, including California's, this counts as sharing personal information for cross-context behavioral advertising. We do not sell personal information.
To opt out, use the Do Not Sell or Share My Personal Information link at the bottom of any page and turn ad measurement off. It takes effect immediately in that browser. Global Privacy Control and Do Not Track are honored automatically: when your browser sends either signal, the pixel does not load at all. You can also control the ads you see on Meta's services at facebook.com/adpreferences.
Storage, retention, and security
Submitted information is kept for application processing, account administration, insurance and financial recordkeeping, dispute handling, and security. A deletion request may require retaining limited records for a legal obligation; we will explain any limitation that applies to your request.
We keep records for the periods below. When a period ends, we delete the record or remove what identifies you.
| Record | Period | Why |
|---|---|---|
| Quote answers where no application follows | 24 months from the last activity | Lets you resume, and supports dispute handling. Deleted after that. |
| Application, including health answers | Life of the policy plus 7 years; if no policy is issued, 7 years from the decision | Insurance recordkeeping and contestability. Health answers are deleted with the application, not kept separately. |
| Payment and billing records | 7 years | Financial recordkeeping and tax. Card numbers are never held by us. |
| Agent contracting file and licence checks | Duration of contracting plus 7 years | Producer licensing, carrier appointment, and commission records. |
| Social Security number | Deleted from the vault once screening is complete and the retention obligation for the screening decision has passed | Held only to match a screening record; there is no reason to keep it afterwards. |
| Consent records | Same period as the record they relate to, plus 7 years | A consent is only useful if it can still be produced when questioned. |
| Security and access logs | 12 months | Investigating misuse and protecting accounts. |
| Waitlist entries not approved | 12 months from the decision | Prevents repeat submissions and records the decision. |
Where a carrier, a state regulator, or a legal hold requires longer, the longer period applies to that record.
Application handoff details are stored in this browser tab’s session storage. Agent authentication may persist in browser storage until sign-out, expiration, or removal. The Cookies and Browser Storage notice explains the entries and how to clear them. Clearing a browser does not delete records already submitted to the service.
Access restrictions and technical safeguards help protect information, but no website can promise that every risk is eliminated. This notice does not claim a security certification, an audit result, or a guarantee of HIPAA compliance.
Requests and choices
State privacy laws differ, and an insurance producer is exempt from several of them. Rather than ask you to work out whether your state's law reaches us, we extend the same core rights to every resident of the United States, whether or not a law compels it. You may:
- access the personal information we hold about you, and obtain a copy in a portable form;
- correct information that is inaccurate or incomplete;
- delete information, except where we must keep it for an insurance, financial, or legal recordkeeping obligation, which we will identify;
- withdraw a consent you gave us, including your consent to the use of health information;
- object to a particular use, and opt out of targeted advertising, including the ad measurement described under Advertising, and of any sale or profiling, which we do not carry out; and
- appeal a decision you disagree with, to a different reviewer, at no cost.
You may ask an authorised representative to act for you. We will not discriminate against you for exercising any of these rights, and exercising one will never affect an application or a policy.
These are in addition to the insurance rights below, which apply to information collected in an insurance transaction and in some respects go further.
Send a request to privacy@thaloslife.com and identify the website and the type of request. We aim to respond within 45 days, and will tell you if we need a permitted extension and why. Do not include your Social Security number, medical details, password, or payment-card information in an ordinary email. We may need proportionate identity verification before providing or deleting records. We will respond within the deadline required by the law that applies to your request, and explain any permitted extension, denial, or appeal route.
Product analytics (PostHog) records page views and clicks on links and buttons, never form contents, and never runs on application or health pages. Ad measurement (the Meta pixel) is described under Advertising. Neither loads when your browser sends Global Privacy Control or Do Not Track, and you can turn each one off in your privacy choices. These browser settings do not themselves submit an access or deletion request. Use to review the controls.
Insurance privacy and state rights
An insurance producer is a financial institution under the federal Gramm-Leach-Bliley Act. A separate Consumer Privacy Notice is provided in the form that law requires, and it explains what is shared, with whom, and how to limit sharing where a limit is available. Where the two documents differ about the handling of information collected in connection with an insurance transaction, the Consumer Privacy Notice governs.
Several states have adopted the insurance-specific privacy protections based on the National Association of Insurance Commissioners model act. If you live in Arizona, California, Connecticut, Georgia, Illinois, Maine, Massachusetts, Minnesota, Montana, Nevada, New Jersey, North Carolina, Ohio, Oregon, or Virginia, you may:
- ask, in writing, what recorded personal information we hold about you in connection with an insurance transaction, and see and copy it;
- be told the identity of anyone we disclosed that information to in the preceding period the applicable law specifies;
- ask us to correct, amend, or delete information you believe is inaccurate, and be told in writing if we decline and why; and
- if we decline, file a concise statement of dispute, which we will keep with the information and supply to anyone who receives it afterwards.
Write to the privacy address below and say which website and which right you are exercising. We may need to verify your identity in proportion to the sensitivity of the request. A request about information held by an insurer should be directed to that insurer.
Other state privacy laws. Many states have comprehensive privacy laws, and most of them exempt a licensed insurance producer, either as an entity or for information covered by the Gramm-Leach-Bliley Act. Among them are California, Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Some of these take effect on later dates, including Connecticut's revised exemption in 2026 and Delaware's in 2027. We do not rely on those exemptions to withhold the rights listed under Requests and choices, which we extend to residents of every state regardless.
Nevada residents. Nevada law allows residents to ask a company not to sell certain personal information. We do not sell personal information. You may still submit a request to the privacy address below, and you may contact the Nevada Attorney General, Bureau of Consumer Protection, 100 North Carson Street, Carson City, NV 89701, telephone (702) 486-3132, email aginfo@ag.nv.gov.
Vermont residents. We will not share information about you with companies outside our corporate family for their own marketing purposes, and will not share creditworthiness information within our corporate family, unless you authorise it.
California residents. California treats the two kinds of information we hold differently, so we describe them separately rather than claiming a single blanket exemption.
- Information you give us in an insurance application or transaction, including your health answers, is governed by the California Insurance Information and Privacy Protection Act and the Gramm-Leach-Bliley Act rather than the California Consumer Privacy Act. Your rights over it are the insurance rights described above: to see it, copy it, ask us to correct it, and file a statement of dispute. Medical-record information is not disclosed without your prior written authorization.
- Information collected from visiting these websites when you have not applied for anything is not part of an insurance transaction, and the California Consumer Privacy Act can apply to it. When we run Facebook and Instagram ads, the Meta pixel shares identifiers (a cookie identifier and IP address) and internet activity (the public pages visited, and whether the quote questions were sent) with Meta for cross-context behavioral advertising, as described under Advertising. We do not sell personal information, and we do not share sensitive personal information or health answers. You can opt out with the Do Not Sell or Share My Personal Information link, and your browser's Global Privacy Control signal is honored as an opt-out.
The California exemption for Gramm-Leach-Bliley information applies to the information, not to the company, and California regulations in force since 1 January 2026 confirm that an insurance agent must follow the California Consumer Privacy Act for personal information that is not subject to the Insurance Code. Where that Act applies to information we hold, the rights described under Requests and choices are available to you, we honour them, and we will not discriminate against you for exercising them.
Service scope and changes
These services are intended for adults. The application may ask about the number of children who depend on an adult applicant; it does not invite children to create accounts. Contact us if a child’s information has been submitted inappropriately.
Provider infrastructure may process information in the United States or other locations used by the provider. International processing and transfer requirements depend on the applicable relationship and law. If practices change materially, this notice and its date will be updated, and additional notice or consent will be provided where required.
Privacy contact
privacy@thaloslife.com
support@thaloslife.com
Thalos LifeDirect 130 privacy correspondence
8520 Allison Pointe Boulevard, Suite 220 #122
Indianapolis, IN 46250, USA