Privacy Policy

Last Updated: August 17, 2026

GravityCerts (“GravityCerts,” “us,” “we,” or “our”) provides a website platform and web agency services for independent insurance agencies. This Privacy Policy explains how we collect, use, share, and protect personal information when you:

  • Visit gravitycerts.com or any of our marketing pages (“Marketing Site”);
  • Log in to your GravityCerts account, Client Center, or Agency Dashboard (“Platform”);
  • Purchase a product, plan, or add-on, or pay an invoice (“Purchases”); or
  • Book a demo, training session, or support appointment with us (“Scheduling”).

This policy applies to GravityCerts as a company, the operator of the platform, the seller of website products, and the employer/agency you contract with. It does not govern the privacy practices of the individual insurance agency websites we build and host for our clients. If you are a visitor, lead, or policyholder of one of our client agencies’ websites, that agency’s own privacy policy governs how your information is used. See “Our Role as a Service Provider / Processor” below.

By using our Marketing Site, Platform, or Services, you agree to the collection and use of information as described in this policy. Terms not defined here have the meanings given in our Terms and Conditions.

Privacy Statement

GravityCerts does not sell your personal information. We do not disclose the data our client agencies store in our Platform, including their end-customers’ data, except as necessary to provide the Platform, as authorized by our agreement with that agency, or as required by law.

Information We Collect

Information You Provide Directly

  • Contact and lead information: name, email address, phone number, company/agency name, and message content submitted through our contact form, demo request form, or chat.
  • Account information: username, password (hashed), billing contact details, and role/permissions when you create a GravityCerts account, Client Center login, or Agency Dashboard access.
  • Payment and billing information: When you make a purchase or pay an invoice, payment is processed directly by our payment processors, Stripe and, for a smaller portion of transactions, PayPal. GravityCerts uses Easy Digital Downloads (EDD) with a Stripe payment gateway for product purchases, and a separate Stripe-based invoicing system for recurring and custom invoices. We do not store full credit card numbers on our own servers; Stripe and PayPal handle and store payment card data directly, subject to PCI-DSS standards. We do retain records of transactions (amount, date, product/invoice purchased, billing name/email, and a payment processor reference ID).
  • Scheduling information: When you book a demo, training session, or support appointment, this is handled through GoHighLevel (GHL), which we use as our calendar and CRM tool. Information you provide when booking (name, email, phone, appointment details, and any notes) is passed directly to GoHighLevel and may be used by GravityCerts to follow up with you, including via email or SMS if you’ve opted in.
  • Support communications: information you provide when submitting a support ticket or communicating with our team, including any files, screenshots, or account details you share to help us troubleshoot.

Information Collected Automatically

  • Log Data: IP address, browser type and version, referring/exit pages, pages visited, time and date of visit, and time spent on pages.
  • Cookies and similar technologies: see “Cookies & Tracking Technologies” below.
  • Analytics data: via Google Analytics and Google Tag Manager, covering usage patterns, device/browser information, and approximate location (city/region level, derived from IP).

Information We Do Not Directly Collect (Client Agency Data)

GravityCerts hosts and operates websites on behalf of independent insurance agencies. Those websites may collect insurance-related personal information from their visitors and clients, including quote requests, driver’s license numbers, Social Security numbers (for certain commercial lines), financial account information, health information, and insurance history, through niche intake forms, the Client Center portal, video quote proposals, and similar tools.

That data belongs to, and is controlled by, the client insurance agency, not GravityCerts. GravityCerts stores and processes it only as a service provider, under contract, to operate the agency’s website and tools. We do not use it for our own marketing, do not sell it, and do not combine it with our own customer records except as needed to provide hosting, support, and platform functionality. See “Our Role as a Service Provider / Processor” below.

How We Use Your Information

We use the personal information described above to:

  • Provide, operate, maintain, and improve the Marketing Site and Platform;
  • Respond to inquiries, demo requests, and support tickets;
  • Process purchases, subscriptions, and invoices;
  • Schedule and manage demos, training, and support appointments through GoHighLevel;
  • Send you transactional communications (order confirmations, invoices, appointment reminders, service notices);
  • Send you marketing communications you’ve opted into (newsletters, product updates, integration announcements) — you can opt out at any time;
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Comply with legal, tax, and accounting obligations; and
  • Analyze usage of our Marketing Site and Platform to improve performance and user experience.

We do not use client agencies’ end-customer insurance data (see above) for any purpose beyond operating the Platform as directed by that agency.

Our Role as a Service Provider / Processor

GravityCerts hosts client agency websites, and GravityCerts’ own systems, on a shared multi-site network through Kinsta. When we host and operate a client agency’s website:

  • GravityCerts acts as a service provider/processor (as those terms are used under the CCPA/CPRA and similar state privacy laws) with respect to the personal information the client agency’s website collects from its own visitors and policyholders.
  • We process that data only to provide hosting, technical support, and platform functionality — under contract with the agency, and consistent with our Data Processing Addendum — not for GravityCerts’ own independent business purposes.
  • We do not sell that data, do not use it to build profiles for advertising, and do not retain it beyond what’s needed to provide the Platform or as the client agency directs.
  • Requests regarding an agency’s own website data (e.g., a policyholder asking to access or delete their information) should be directed to that agency; GravityCerts will assist the agency in fulfilling verified requests as required by our agreement and applicable law.

GravityCerts itself is not a licensed insurance agency, carrier, or broker. We do not quote, bind, service, or adjust insurance policies. Where our client agencies are subject to the Gramm-Leach-Bliley Act (GLBA) or state insurance privacy laws with respect to their own customers’ nonpublic personal information, those obligations belong to the licensed agency; GravityCerts supports that compliance through contractual safeguards, access controls, and the terms of our Data Processing Addendum.

How We Share Your Information

We share personal information with the following categories of recipients:

Payment processors: Stripe (primary) and PayPal (for a subset of transactions), to process purchases and invoice payments. These processors receive payment card and billing information directly and are independently subject to PCI-DSS and their own privacy policies.

Hosting infrastructure: Kinsta, which hosts gravitycerts.com and the multi-site network on which client agency websites also run.

Scheduling/CRM: GoHighLevel, which receives contact and appointment information when you book a demo, training, or support session, and which we use to manage follow-up communications.

E-commerce platform: Easy Digital Downloads (a WordPress plugin operating on our own infrastructure) processes product purchase records.

Analytics and advertising providers: Google Analytics, Google Tag Manager, and Google Ads remarketing, which receive usage data and cookie/device identifiers. This may constitute “sharing” for cross-context behavioral advertising under California law — see “Your California Privacy Rights” below.

Spam/security tools: Google reCAPTCHA and similar tools used to protect our forms from abuse.

Legal and regulatory recipients: courts, regulators, or law enforcement, where required by law, subpoena, or court order, or where necessary to protect the rights, safety, or integrity of GravityCerts, our clients, or the public.

Business transaction recipients: if GravityCerts is acquired, merged, or sells substantially all of its assets, personal information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a materially different privacy policy.

We do not sell personal information for money. We do not share client agencies’ end-customer insurance data with any of the above except as necessary to host and operate the Platform (e.g., Kinsta as infrastructure).

Cookies & Tracking Technologies

Cookies are small data files stored on your device when you visit our Marketing Site or Platform. We use cookies and similar technologies (such as pixels and local storage) to:

  • Keep you logged in and remember preferences;
  • Understand how visitors use our site (via Google Analytics/Tag Manager); and
  • Deliver and measure advertising (via Google Ads remarketing).

You can instruct your browser to refuse cookies or alert you when a cookie is set — check your browser’s Help feature for instructions. Disabling cookies may limit some site functionality.

Behavioral Remarketing

We use Google Ads remarketing to advertise on third-party sites to people who have previously visited our site.

Do Not Track / Global Privacy Control

We honor the Global Privacy Control (GPC) signal as a valid opt-out-of-sale/sharing request for the browser or device sending it. We do not currently respond differently to browser-level “Do Not Track” signals that are not GPC, as there is no common industry standard for interpreting them.

Sensitive Personal Information

GravityCerts’ own Marketing Site and account systems do not request Social Security numbers, driver’s license numbers, or health information. Where such information appears in our systems, it is client agency end-customer data described above, processed solely as a service provider under our Data Processing Addendum with that agency, not collected or used by GravityCerts for its own purposes.

Data Retention

We retain personal information for as long as needed to provide our Services, comply with legal and tax obligations, resolve disputes, and enforce our agreements. Specifically:

  • Account and billing records: retained for the duration of your account plus the period required by applicable tax and accounting law (generally 7 years).
  • Marketing/lead data: retained until you unsubscribe or request deletion, or until it becomes stale (no engagement for an extended period).
  • Client agency end-customer data: retained per the terms of our agreement with that agency, and generally deleted or returned upon termination of that agreement per our Data Processing Addendum.

Data Security

We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle, including access controls, encrypted connections (TLS) for data in transit, and reliance on PCI-DSS-compliant payment processors for card data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

If we experience a data breach affecting your personal information, we will notify affected individuals and/or client agencies as required by applicable law.

International Data Transfer

GravityCerts is based in, and its systems are hosted in, the United States. If you are located outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our Services, you consent to this transfer.

Links To Other Sites

Our Marketing Site may link to other sites, including client agency websites, that are not operated by us. We are not responsible for the content or privacy practices of any third-party site. We encourage you to review the privacy policy of every site you visit.

Children’s Privacy

Our Services are intended for use by individuals age 18 or older acting on behalf of a business. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will take steps to delete it.

Your California Privacy Rights

If you are a California resident, you have the following rights regarding personal information GravityCerts holds about you as a business contact, lead, or customer of GravityCerts (this section does not apply to client agencies’ end-customer insurance data, which is governed by that agency’s policy):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we’ve collected, the categories of sources, our business purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of personal information we’ve collected from you, subject to exceptions (e.g., information needed to complete a transaction, comply with a legal obligation, or maintain security).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell personal information for money. Our use of Google Ads remarketing may constitute “sharing” for cross-context behavioral advertising under California law. You may opt out via the methods in “Cookies & Tracking Technologies” above or by contacting us.
  • Right to Non-Discrimination: We will not deny you services, charge different prices, or provide a lower level of service because you exercised your privacy rights.

To exercise these rights, contact us using the information below. We will acknowledge your request within 10 business days and respond within 45 calendar days (extendable by an additional 45 days when reasonably necessary). We may need to verify your identity before processing your request. You may make a verifiable request no more than twice in a 12-month period. You do not need to create an account to submit a request.

You may also designate an authorized agent to submit a request on your behalf, subject to our ability to verify that authorization. Visit Your California Privacy Rights.

Changes To This Privacy Policy

We may update this Privacy Policy from time to time. Changes are effective immediately upon posting to this page, and we will update the “Last Updated” date accordingly. If we make material changes, we will notify you via the email address associated with your account or by posting a prominent notice on our site.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us:

GravityCerts
https://gravitycerts.com
541-903-8010
[email protected]