1. Scope and Who This Covers
1.1 Two Groups
This Privacy Policy describes how XVLT LLC ("XVLT," "we," "us") collects, uses, shares, discloses, and retains personal information processed through the XVLT SaaS platform about two distinct groups:
- Agents — licensed insurance producers who hold accounts on the platform.
- Consumers — individuals who place inbound telephone calls that are routed through the platform to an Agent.
1.2 XVLT's Role
XVLT operates a technology platform that routes inbound consumer calls to licensed producers. XVLT is not an insurance company, agency, or licensed producer, and does not sell, solicit, or negotiate insurance.
As between XVLT and its call suppliers, personal information about consumers who call the platform is controlled by XVLT (and, under typical supplier contracts, is treated as XVLT's property as between XVLT and the supplier). Call suppliers, telecommunications providers, and infrastructure vendors process that information solely as service providers on XVLT's behalf where applicable.
Agents who receive consumer information through the platform act as independent controllers of the information they retain in their own systems, and their own privacy practices govern that information. Agents must maintain a privacy policy adequate for their independent use of consumer data and must not use platform-sourced data in a manner inconsistent with this Policy or the Terms of Service. This Policy does not govern the privacy practices of insurance carriers, call suppliers, or Agents beyond the Agent obligations stated herein.
This Policy is published at https://xvlt.io/privacy and is incorporated into the Terms of Service. Consumers and Agents may review it there. Where XVLT plays or displays a recording or privacy notice on a call, that notice is for convenience and does not transfer Agent compliance duties described in the Terms.
1.3 Not Directed to Children
The platform is not directed to anyone under eighteen (18) and XVLT does not knowingly collect personal information from minors. If we learn we have collected such information, we will delete it.
1.4 No Consumer Contract With XVLT
Consumers who call a number routed by XVLT do not enter a contract with XVLT by placing that call. Any insurance sale, advice, or follow-up is solely between the consumer and the Agent (and, where applicable, the insurance carrier). XVLT's processing of call data is described in this Policy and does not make XVLT a party to the insurance transaction.
1.5 Third-Party Privacy Practices
This Policy does not control the privacy or security practices of Agents, insurance carriers, call suppliers, payment processors, identity verification providers, or other independent third parties. Those parties' own policies apply to information they collect or retain independently of XVLT. XVLT is not responsible for their practices.
2. Information We Collect
2.1 Agent Account Information
- Identity and contact: Name, date of birth, email address, telephone number, mailing / business address
- Professional data:National Producer Number (NPN), state license numbers and status, carrier appointments where provided, proof of E&O coverage where requested, agency affiliation, downline or hierarchy placement
- Identity verification status and metadata from our verification provider (we do not receive or store the government identification documents submitted to that provider)
- Authentication credentials, session data, and multi-factor authentication status
2.2 Agent Financial Information
- Wallet balance and full transaction history
- Subscription tier, status, and billing history
- Payment processor customer and subscription identifiers
We do not store full payment card numbers. Payment card data is collected and stored by our PCI-DSS compliant payment processor (for example, Stripe).
2.3 Agent Activity Information
- Online, waiting, and availability status
- Calls offered, accepted, declined, and completed
- Call durations, dispositions, and outcomes
- Production metrics, close rates, and premium written
- Support tickets, disputes, and correspondence
- Device, browser, IP address, pages viewed, features used, session duration, and audio device selections
2.4 Consumer Information from Calls
When a consumer calls a number routed by XVLT, we may receive and store:
- Telephone number and any caller identification data (ANI)
- Geographic origin and routing metadata, including derived location where the caller's state is inferred
- Age, gender, and tobacco status where captured in pre-route forms or disclosed on the call
- Call audio recordings and transcripts
- Call date, time, duration, and routing history
- Information the consumer provides during the call, which may include name, date of birth, address, health information relevant to underwriting, coverage sought, beneficiary information, and existing coverage
- Call outcome and disposition recorded by the Agent
- Automated summaries derived from recordings or transcripts
Health-related information disclosed during an insurance call is sensitive personal information and is handled with heightened care consistent with applicable law. XVLT collects such information only as necessary to route and support the insurance inquiry and related compliance, billing, and quality functions.
2.5 Consent Documentation from Suppliers
Where a call supplier provides consent documentation for a routed call, such as a TrustedForm certificate or a Jornaya LeadID, XVLT retains that documentation in association with the corresponding call record for compliance and audit purposes.
XVLT does not generate consumer calls directly and does not capture consumer consent at the point of origin. XVLT relies on its call suppliers' representations regarding the lawful basis for contacting any consumer.
2.6 Automatically Collected Information
Log data, cookies, and similar technologies used for authentication, session management, security, and platform analytics. We do not use advertising cookies and do not serve third-party advertising on the platform.
2.7 Mobile Information and SMS (XVLT Quote Summaries)
Mobile information. Mobile phone numbers collected for SMS are never sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Numbers are used solely to deliver the transactional message the consumer requested. No mobile information is shared with third parties for their own marketing.
SMS consent records. When a consumer requests a quote summary, XVLT collects and stores the mobile number and a consent record (consent timestamp, producer identifier, call identifier / CallSid, and a reference to the call recording). Quote SMS is rejected server-side unless that recording reference exists. Consent records are retained for five years and call recordings for forty-eight months, consistent with applicable recordkeeping requirements.
XVLT Quote Summaries is a one-time transactional SMS program (one message per requested quote). We do not use mobile numbers collected for that purpose for marketing, advertising, or promotional campaigns, and we do not add them to marketing lists, drip campaigns, or affiliate sharing programs. Consumers may opt out at any time by replying STOP to any message; they will receive one confirmation and no further messages. For help, reply HELP or contact support@xvlt.io. Carrier delivery partners (for example, Twilio) process numbers only as service providers to transmit the requested message. Program details and the verbal opt-in script are published at xvlt.io/sms.
3. How We Use Information
3.1 Agent Information
- Create, verify, secure, and administer accounts
- Determine call routing eligibility based on licensing, availability, tier, and wallet balance
- Process wallet funding, transfer charges, passthrough charges, subscriptions, and disputes
- Provide analytics, leaderboards, and reporting
- Provide support and communicate about the service
- Detect fraud, abuse, and violations of the Terms of Service
- Comply with legal, tax, and regulatory obligations
3.2 Consumer Information
- Route the call to an appropriately licensed Agent
- Deliver pre-call context and enable the Agent to service the specific inquiry
- Verify call duration for billing and dispute resolution
- Maintain do-not-call suppression records
- Monitor for compliance and quality assurance
- Verify billing with call suppliers using limited metadata where appropriate
- Respond to regulatory inquiries, complaints, and legal process
- Deliver one-time transactional XVLT Quotes SMS messages the consumer requested on a recorded call, and retain SMS consent records as described in Section 2.7
3.3 Recordings, Transcripts, and Automated Analysis
Call recordings and transcripts may be processed by automated tools for transcription, summarization, quality scoring, and compliance detection. XVLT may use this data to develop and improve those tools. Where used for machine learning or model training, personally identifying information is masked or scrubbed prior to training where feasible.
XVLT does not sell personal information and does not share personal information for cross-context behavioral advertising.
3.4 Aggregated and De-Identified Data
XVLT may create aggregated or de-identified data from platform activity and use it for analytics, benchmarking, and product development. Such data does not identify any individual and is not re-identified.
4. Call Recording
4.1 Recording
Calls routed through the platform are recorded by Twilio (XVLT's telephony provider) and may be transcribed, monitored, and analyzed for compliance, quality assurance, training, billing verification, dispute resolution, and security. Recordings are retained for forty-eight (48) months as stated in Section 4.4. XVLT can produce retained recordings on request for compliance, dispute, or regulatory review.
XVLT Quotes SMS is sent only when a Twilio recording reference exists for the associated CallSid. That requirement is enforced by the platform before message delivery, so every call that produces an XVLT Quotes SMS is recorded and the recording is retained.
4.2 Notification and Agent Responsibility
When an Agent is available to take an inbound call, the platform plays an audible pre-bridge recording disclosure of approximately five (5) seconds—the same message on every bridged call: "This call is recorded for quality assurance." That short IVR is intended to give callers a consistent recording notice for quality assurance and recording-compliance purposes before the Agent bridge. It is a convenience feature and is not a substitute for the Agent's independent legal duties. Agents consent to recording of their own participation as a condition of platform access and must not disable or circumvent recording.
Agents are solely responsible for complying with all-party / two-party consent and other call-recording laws applicable to each call, including confirming that the consumer agrees to being recorded before discussing personal, financial, health, or insurance information, and ending the call if the consumer objects. Details of those Agent duties are set out in the Terms of Service.
4.3 No Biometric Templates
XVLT does not intentionally create consumer voiceprints or other biometric identifiers for identification. Audio may be processed for transcription and operational analysis as described in this Policy.
4.4 Retention
Audio recordings are retained for forty-eight (48) months. Transcripts and summaries are retained for twenty-four (24) months, unless a longer period is required by law or legal hold. SMS consent records associated with XVLT Quotes are retained for five (5) years as described in Section 2.7.
4.5 Consumer Requests
Consumers may request a copy or deletion of their call recording, subject to statutory retention limits, by emailing privacy@xvlt.io. Identity verification is required.
5. How We Share Information
5.1 Licensed Agents
Consumer details necessary to service the specific inquiry are made available to the Agent who receives the call.
5.2 Agency Leaders and Organizational Hierarchy
Designated agency administrators, FMO or IMO administrators, and team managers may access call recordings, transcripts, and performance metrics generated by Agents operating within their organizational hierarchy, for compliance monitoring and coaching.
5.3 Service Providers
Infrastructure hosts (for example, AWS or Vercel), telephony providers (for example, Twilio), payment processors (for example, Stripe), identity verification providers, email delivery providers, and transcription services, each under contractual confidentiality and data protection obligations, and each permitted to process personal information only on our instructions.
5.4 Call Suppliers
Redacted call metadata such as timestamps, duration, and caller identifier, shared strictly to verify billing and dispute claims. We do not share call recordings, transcripts, or the substance of consumer conversations with call suppliers except where necessary to resolve a specific dispute or as required by law.
5.5 Legal and Regulatory
Pursuant to valid subpoena, court order, regulatory inquiry, or where necessary to establish or defend legal claims, prevent fraud, or protect the safety of any person.
5.6 Business Transfers
In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred information.
5.7 No Sale of Data; Mobile Numbers
We do not sell or rent personal information or consumer data to data brokers, list vendors, or third-party marketers. We do not share personal information for cross-context behavioral advertising.
Mobile phone numbers collected for SMS are never sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Numbers are used solely to deliver the transactional message the consumer requested and are not used for marketing. Consumers may opt out by replying STOP. No mobile information is shared with third parties for their own marketing.
5.8 Aggregated Sharing
We may share aggregated or de-identified statistics that do not identify any individual Agent or consumer.
5.9 No Responsibility for Downstream Recipients Beyond Contractual Controls
Where we share information with service providers under contract, we require confidentiality and limited-purpose processing. Where Agents receive consumer information as independent controllers, those Agents—not XVLT—are responsible for their subsequent use, retention, and disclosure. Where carriers receive applications or underwriting data from an Agent, the carrier's privacy practices govern that relationship.
6. Agent Obligations and GLBA Compliance
Agents receiving consumer information through the platform act as independent controllers and must:
- Use consumer data solely to service the specific insurance inquiry that generated the call
- Comply with the TCPA, federal and state Do Not Call rules, state call-recording and all-party / two-party consent laws, state insurance privacy laws, and the GLBA Safeguards Rule
- Not add platform-sourced consumer data to any outbound dialer, marketing list, SMS campaign, email campaign, or third-party database
- Not sell, rent, share, or transfer consumer data obtained through the platform
- Not enter, store, or retain consumer banking credentials through unauthorized platform fields
- Honor do-not-call and deletion requests in their own systems
- Delete consumer data when no longer required for a legitimate business or carrier purpose
- Maintain reasonable technical, administrative, and physical safeguards
- Notify XVLT immediately in writing of any suspected or actual security breach involving platform-sourced data
- Indemnify XVLT as provided in the Terms of Service for third-party claims arising from the Agent's misuse of consumer data
- Not represent to consumers that XVLT is the insurer, agency of record, or party collecting premium
Failure to comply is a material breach of the Terms of Service and may result in suspension, termination, and reporting to carriers or regulators where appropriate.
7. Retention Schedule
| Category | Retention Period | Purpose |
|---|---|---|
| Agent account and license records | Account duration + 7 years | Tax, audit, regulatory defense |
| Call audio recordings | 48 months | Dispute resolution, billing verification, SMS consent audit, carrier audit |
| Transcripts and summaries | 24 months | Platform analytics, compliance review |
| Consumer prospect records | 24 months | Servicing and recordkeeping |
| Consent documentation from suppliers | 5 years | TCPA and state telemarketing compliance |
| SMS consent records (XVLT Quotes) | 5 years | Mobile number, consent timestamp, producer ID, call ID, recording reference |
| Transaction and wallet records | 7 years | Financial and tax recordkeeping |
| Suppression and DNC lists | Permanent | Compliance enforcement; never deleted |
| Support tickets and disputes | 3 years | Service history and dispute defense |
Records may be retained longer where required by law, regulation, or an active legal hold.
8. Security
XVLT maintains administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, row-level authorization, and audit logging.
No system is completely secure. XVLT does not warrant that unauthorized access will never occur. XVLT will notify affected individuals and regulators of a security incident as required by applicable law.
Agents are responsible for securing their own devices, credentials, multi-factor authentication, and any consumer data they export or retain outside the platform. XVLT is not liable for unauthorized access resulting from Agent credential compromise, shared logins, or failure to enable available security controls.
9. Cookies, Analytics, and Do Not Track
We use essential cookies and similar technologies for authentication, session security, fraud prevention, and platform analytics. We do not use advertising cookies and do not serve third-party advertising on the platform.
Some browsers offer a "Do Not Track" signal. There is no uniform industry standard for responding to such signals. The platform does not currently alter its collection practices based solely on a Do Not Track signal, beyond the practices described in this Policy.
10. Legal Process, Regulators, and Law Enforcement
We may disclose personal information in response to a subpoena, court order, civil investigative demand, regulatory examination, or other lawful process, or where we believe in good faith that disclosure is necessary to protect XVLT, Agents, consumers, or the public from fraud, harm, or illegal activity.
Where legally permitted and practicable, we may notify the affected Agent before producing Agent-account records. We may decline to notify where prohibited, where notice would risk evidence spoliation, or where the request relates to an investigation of the Agent.
11. International Users and Transfers
The platform is operated from the United States for U.S.-licensed producers and U.S.-originating call traffic. If you access the platform from outside the United States, you understand that personal information may be processed in the United States, where privacy laws may differ from those in your jurisdiction.
12. California and State Privacy Disclosures
12.1 Categories Collected
Depending on your relationship with XVLT, we may collect identifiers (name, email, phone, IP address, NPN); commercial information (subscription and wallet activity); professional information (licenses, appointments); internet or network activity (logs and usage); audio information (call recordings); and, for consumers on calls, inferences and health-related information disclosed for insurance underwriting purposes.
12.2 Sources and Purposes
Sources include you (Agents), callers, call suppliers, service providers, and automated platform logging. Purposes are those described in Section 3.
12.3 Sale / Share
We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are commonly defined under state privacy laws. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.
12.4 Sensitive Personal Information
We use sensitive personal information (such as health-related disclosures on insurance calls, and account login credentials) only as reasonably necessary to provide the platform, route and bill calls, maintain security, and comply with law—not to infer characteristics for unrelated marketing.
12.5 Authorized Agents
You may designate an authorized agent to submit certain privacy requests. We may require proof of authorization and identity verification directly from the consumer or Agent whose information is at issue.
13. Your Privacy Rights and Contact
13.1 Rights
Residents of Pennsylvania, California, Texas, Virginia, Colorado, Connecticut, Utah, and other jurisdictions with comprehensive privacy laws may have rights to access, correct, delete, or obtain a portable copy of personal information held by XVLT, and to appeal a denial of such a request. Exercising these rights will not result in discriminatory treatment.
13.2 How to Exercise
Submit a verified request to privacy@xvlt.io. Identity verification is required. We will respond within the period required by applicable law. If we deny a request, you may appeal by replying to our decision email with the word "Appeal" and the basis for your appeal.
13.3 Limits
Some information cannot be deleted where retention is required by law, regulation, or an active legal hold, including suppression list entries, transaction records, and records subject to insurance recordkeeping requirements. Requests that seek deletion of another party's independent records (for example, an Agent's own CRM copy or a carrier's policy file) must be directed to that party.
13.4 Changes to This Policy
XVLT may update this Policy. Material changes take effect thirty (30) days after notice by email or in-platform posting. The effective date at the top of this Policy reflects the most recent revision.
13.5 Relationship to Terms of Service
Agents' commercial relationship with XVLT is governed by the Terms of Service. If this Policy and the Terms conflict on billing, liability, indemnity, or dispute resolution, the Terms control.
13.6 Contact
XVLT LLC
Attn: Privacy and Legal Operations
819 Scott Way, Lansdale, PA 19446
Email: privacy@xvlt.io | support@xvlt.io