Policy edition: September 25, 2026
This notice describes the data practices built into this Insurance Plan Guide demonstration website. A production operator must review hosting, advertising, analytics, vendor, and retention practices before launch and update this notice whenever those practices change.
The request form can collect your first name, last name, email address, telephone number, policy topic, optional comparison details, consent selection, and the time the request reached the server. The home topic selector also places a policy topic in the page address when you continue to the contact form.
The site starts a PHP session to hold a security token and may create standard server records containing an IP address, request time, browser identification, and response status. The site also loads typefaces from Google Fonts, which can receive network information such as an IP address and browser details under Google's service terms.
Submitted details are used to answer the request, prepare a comparison follow-up, protect form submissions, diagnose delivery problems, and keep a record of contact consent. The optional details help a desk associate understand the existing policy, target limit, deductible, property, vehicle, operation, or trip that prompted the request.
The form uses the server's native mail function and sends validated request details to [email protected]. The sender uses the standardized Insurance Plan Guide address, and Reply-To uses the address entered in the form so a response can go back to the requester. The mail server and its administrator may retain messages under their own settings and legal duties.
The site is configured for https://www.insuranceplanguide.org. A production host must enforce HTTPS and protect server access. The form uses a session-bound CSRF token, validates topic choices, limits comment length, and escapes displayed values. No website form can guarantee that every message will be received or that an email address is accurate.
A request may be reviewed by the Insurance Plan Guide contact desk, a hosting administrator, or a technical service provider that supports the site. If the site routes a request, the relevant provider may receive the information needed to respond. Production disclosures must identify any advertising, analytics, call-tracking, or other vendor that receives visitor data.
The PHP session uses a session cookie for the security token. The quote reminder stores a short session value in browser session storage so it does not repeatedly open during one visit. This demonstration build does not load a third-party advertising tag. Browser settings can block cookies or site storage, although the request form may then fail its security check.
No single retention period is claimed for this demonstration. The host, mail server, backup process, provider, and applicable law may set different periods. A production operator should publish a documented schedule, explain why each period is needed, and securely dispose of records when the schedule ends.
You may ask what contact information the desk holds, request a correction, ask for deletion where applicable, or withdraw permission for future contact. State and federal consumer laws can place limits on deletion when records are tied to a transaction, fraud prevention, tax duties, or another valid purpose.
Send a privacy request to [email protected] or call +1 888 712 0692. Include enough detail to locate the request, but do not send a password, payment-card number, or unnecessary government identifier.
This decision guide is intended for adults who can enter a contract. A production operator should not collect information from a child without the review and consent required by applicable law.
Material changes should be reflected by a new edition date and, where appropriate, direct notice. The current edition is September 25, 2026. Questions about this notice can be sent to the contact desk.