No cost to you
Local & remote

Information Security Policy

Adopted: August 30, 2026
Last reviewed: August 30, 2026

This policy is adopted by Pursuit RP LLC doing business as American Senior Choices. It is the written information-security practice we follow for the public website, agency records, and tools we use to advise people on Medicare coverage. It is not a SOC 2 report, a HIPAA certification, or a claim that we are a covered health-care provider.

1. Purpose and scope

Protect client and prospect information, keep insurance and CMS recordkeeping intact, and use only lawful data sources when we build plan-comparison tools. This policy covers the public site, the agency CRM, email and calendar, appointment booking, enrollment vendors we are contracted to use, and public CMS or carrier APIs.

2. Roles

Timothy Jones (NPN 8353426) is the responsible operator. Access to client systems is limited to that operator and to vendors named in the Privacy Policy. There is no offshore application-development staff.

3. Systems we operate

  • Public website: hosted on Vercel
  • Agency CRM (client files, medications, SOA, commissions): operator-controlled NocoDB
  • Email and calendar: Google Workspace
  • Appointments: Setmore
  • Newsletter (opt-in): Mailchimp
  • Website analytics: Google Analytics (consent) and/or Plausible
  • Optional site chatbot: Groq API, with minimized prompts
  • Enrollment / comparison tools we are appointed to use (for example Sunfire Matrix)
  • Public CMS and carrier directory or formulary APIs (no member login, no scraping of consumer Find-a-Provider sites)

Client records are stored in the United States in our CRM. We do not send application development or production client files to staff or contractors outside the United States.

4. Access and credentials

  • Unique logins; no shared passwords for production systems
  • Multi-factor authentication on email, CRM admin, and developer portals where the vendor offers it
  • API keys and client secrets stay in environment variables or an offline secret store — never in git or the public site
  • Tax identifiers are not published on the website
  • CRM and admin routes are not indexed and are gated by operator authentication

5. Data handling

  • Public marketing: plan education, office address, licenses, and CMS disclaimers
  • Client records: contact details, Medicare identifiers, medications, doctors, SOA, and enrollment notes needed to advise and enroll — stored in the CRM, used only for that purpose and required recordkeeping
  • Application logs: event types, timestamps, counts, and ids. We do not write names, emails, phone numbers, or Medicare IDs into application logs
  • Directory and formulary tools: public, CMS-mandated or carrier-published data only. We do not scrape carrier consumer portals whose terms forbid crawling

6. Retention

We keep producer and TPMO records for as long as insurance, CMS, and carrier rules require. Website analytics follow the vendor’s settings and your cookie choice. When a person asks us to delete information we are not required to keep, we remove it from active systems.

7. Incidents

If we discover unauthorized access to client records, we will contain it, determine what was involved, notify affected people and any regulator the law requires, and record what we changed so it does not happen again. Contact us at (360) 472-4261 or healthplanguide@gmail.com.

8. Review

We review this policy at least once a year, and whenever we add a system that stores client information or a developer API that receives credentials. Material changes are posted on this page with a new review date.

9. Related pages

Privacy Policy · Disclosures · Broker Co-Pilot extension privacy