AgencyRoot's Privacy Policy

Late Updated: June 23, 2026

 This Privacy Policy (the “Policy”)describes how AgencyRoot, LLC (“AgencyRoot,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information and Farm Data in connection with our website (www.agencyroot.com), our web and mobile applications, and our related products and services(collectively, the “Services”). This Policy replaces all previous versions.

We provide a software platform used by insurance agencies, agents, brokers, related businesses, and their customers. Because of this, the personal information we handle generally falls into two categories, and our role differs for each. Please read the section “Our Two Roles: Controller and Service Provider/Processor” below, because it determines which parts of this Policy apply to you.

Before accessing or using the Services, please ensure that you have read and understood our collection, storage, use and disclosure of your personal information and Farm Data as described in this privacy policy. By accessing orusing the Services, you are accepting and consenting to the practices described in this Policy.

1. Our Two Roles: Controller and ServiceProvider/Processor

AgencyRoot acts in two distinct capacities depending onwhose information is involved:

(1) As a business /controller. When you visit our website, create an account, communicate with us, or we market our Services to you, AgencyRoot determines the purposes and means of processing your personal information. In these situations, we are acting as a “business” or a “controller,” and this Policy governs how we handle that information.

(2) As a service provider /processor. When our agency, agent, broker, carrier, or other business customers and their respective users (“Customers”) use the Services to manage their own clients, policy holders, applicants, leads, data and related records, AgencyRoot processes that information only on behalf of, and under the instructions of, the relevant Customer. In these situations, the Customer is the “business” or “controller,” and AgencyRoot is a “service provider” or “processor”. We process that information solely to provide the Services and as permitted by our written agreement with the Customer.

Ifyou are a policyholder, applicant, insured, or other end client whose information was entered into the Services by an insurance agency or other business, that business (not AgencyRoot) is responsible for its own privacy practices. Privacy rights requests about that information should generally be directed to the business you are involved with. We will assist our Customers in responding to such requests as required by law and our agreements.

2. What Personal Information We Collect

We must collect basic information that identifies you as an individual (“personal information”) in order to transact business with you, your business, or your employer. We may collect the following categories of personal information, depending on how you interact with us:

Category Examples Collected?
Identifiers Name, postal address, email address, telephone number, IP address, account username, unique online identifiers, device identifiers Yes
Customer records Billing and payment information, company name, job title, contact details, content of support communications Yes
Commercial information Subscription and product records, services purchased or considered, transaction history Yes
Internet/network activity Browsing and usage data, log data, cookie and similar-technology data, referring pages, search terms Yes
Services Specific data Device data (manufacturer, model, IP address), Application data (version, date of activation, update status), product serial number Yes
Geolocation data Approximate location derived from IP address Yes
Professional/employment information Agency or company affiliation, professional role, licensing-related details provided by Customers Yes
Audio/electronic information Recordings or transcripts of support calls (where disclosed and permitted), activity logs Yes, where applicable
Sensitive personal information See “Sensitive Personal Information” below Limited — see below

We do not intentionally collect Social Security numbers, driver’s license numbers, biometric data, or precise geolocation through our public website. To the extent such data is entered into the Services by our Customers in the course of their business, we process it as a service provider/processor under our agreements, not for our own purposes

3. Sensitive Personal Information

The definition of “sensitive” personal information varies from state to state, but it generally includes personal financial account information, precise geolocation, government identifiers, and health information. In our role as a business/controller (our website, marketing, and account administration), we generally do not collect sensitive personal information. To the extent we do, it is in order to provide the Services. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted by law.

In our role as a service provider/processor, our Customers may input information that qualifies assensitive (for example, financial account information relevant to insurance transactions). We process that information only on the Customer’s instructions and only to provide the Services. We do not sell it or use it to build profiles.

4. How We Collect Personal Information

We collect personal information from:

  1. you directly, when you register, contact us, oruse the Services;
  2. your device and browser, automatically, throughcookies and similar technologies;
  3. our Customers, who input information into theServices;
  4. service providers and analytics partners; and
  5. publicly available sources and our businesspartners and affiliates.

If any content or informationthat you upload to or store on the Services contains personal information of other individuals or Farm Data of other persons, you must be legally permitted to share the personal information and Farm Data with AgencyRoot.

5. Cookies and Tracking Technologies

We and our analytics partners usecookies, pixels, and similar technologies to operate the Services, rememberyour preferences, and understand usage. Some browsers and extensionstransmit a Global Privacy Control (GPC) or other Universal Opt-Out MechanismsignWhere required by law, we treat a recognized opt-out preference signal as avalid request to opt out of sale/sharing/targeted advertising for that browseror device. You can also manage cookies through your browser settings.

We use the following cookies, pixels, and similar technologies:

Type Explanation
Strictly Necessary Cookies Essential to enable you to use the Services
Performance Cookies Collect information about how users use the Services and help improve the Services
Functionality Cookies Allow us to remember what choices you make (e.g., your username, language, or the region you are in) to provide enhanced, more personal features
Advertising and Marketing Cookies Used to send you advertising and marketing-related material tailored to you and your interests, limit the number of times you see an advertisement, and help measure advertising campaigns’ effectiveness
Flash Cookies and Web Beacons Collect and store information about your preferences and navigation to, from, and on our Services

6. How We Use Personal Information

AgencyRoot uses the personal information we collect as abusiness/controller for the following purposes:

Purpose Explanation
To provide the Services Create and administer accounts, authenticate users, deliver new features, process payments, and provide customer support
To communicate with you Send service, security, billing, and administrative messages and responses to inquiries
To operate and improve Analyze usage, diagnose and fix problems, develop new features, and ensure reliability and security
For marketing Send information about our products, services, and offers.
For security and fraud prevention Detect, investigate, and prevent fraudulent, unauthorized, or illegal activity, and protect our users, employees, and systems
To comply with the law Meet legal, regulatory, tax, and investigative obligations, as well as respond to lawful requests from public authorities.

We use the information we receive from our Customers as a service provider / processor solely to provide the Services and as permitted by our written agreement with the Customer. Unless we notify you separately, we do not process your personal information for profiling in furtherance of “decisions that produce legal or similarly significant effects” as such term is defined under applicable law.

7. How We Disclose Personal Information

We disclose personal information to the categories of third parties described below in order to operate our business, provide our services, and comply with our legal obligations. We do not authorize these recipients to use your personal information for their own independent purposes except as described in this policy.

Within AgencyRoot. We may share information within AgencyRoot, and with our employees as necessary, for internal management and administrative purposes or where necessary for the performance or conclusion of our contractual obligations to you or for your benefit.

Service providers and processors. We share personal information with vendors that process data on our behalf and under our instructions, including:

  • Cloud hosting and infrastructure providers: to store data and host our Services.
  • Integrations: to incorporate the functionality of third-party technologies, including artificial intelligence, with the Services.
  • Payment processors: to process transactions and prevent payment fraud.
  • Analytics providers: to understand how users interact with our services and to improve them.
  • Customer support and communications vendors: to respond to inquiries and send service-related marketing messages (e.g., email, SMS, and helpdesk platforms).
  • Security and fraud-prevention services: to protect our systems and detect malicious activity.
  • Professional advisors: including legal, accounting, audit, and insurance providers, as needed.

Advertising & Marketing. We may share personal information with third parties in order to communicate with you about our new services, offers, promotions, and upcoming events, as well as display our advertising to you.

Corporate transactions. We may disclose personal information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, in which case personal information may be transferred to the successor entity.

Legal compliance and protection. We may disclose personal information to law enforcement, regulators, courts, or other government authorities where required by law or legal process, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Affiliates. We share personal information with our corporate affiliates for internal management and administrative purposes and where necessary for the performance or conclusion of our contractual obligations to you or for your benefit.

We do not sell personal information for monetary compensation. However, under some U.S. state laws, certain sharing of data for marketing purposes may be considered a “sale.” For example, the use of cookies to deliver advertisements about our services to you can be considered such a “sale” because the mechanism requires the sharing of information (like an IP address). We do share personal information for such purposes.

8. Farm Data

Our Customers may provide us with Farm Data that they either own or control. “Farm Data” refers that data that is linked or reasonably linked to an agricultural producer (a person that is the owner, lessee, or renter of a farm, livestock, land, device, or equipment from which Farm Data originates). Farm Data includes:

Category Examples
Management Related to financial, tax, employment, commodity price, regulatory compliance, supply chain, and other management data
Agronomic Crop and field information, such as planting data, seed type, yield, disease and pest management application, fertilization, and prescriptions
Land Soil and fertility data, topographical, elevation, watershed, and drainage data, geospatial information, and tillage and conservation data
Machine Telemetry, location, fuel usage, operator, and similar information from agricultural machines
Weather and Climate Non-public data on localized weather and climate conditions
Livestock Animal identification and pedigree, genetic and genomic information, feed consumption, and other data related to livestock
Sustainability Greenhouse-gas emissions, carbon sequestration, and water-quality impact, and any other environmental or conservation practice

We do not sell Farm Data withoutthe express written consent of the agricultural producer that owns the data.

9. Automated Processing and AI Features

Certain features of the Services useartificial intelligence to draft or summarize text, answer questions, surfacerelevant information, or streamline workflows. To provide these features, wesend relevant information to a third-party AI service provider that processesit on our behalf and returns output to us. We share only the information neededto provide the feature.

When you use our AI-poweredfeatures, the information transmitted to our AI provider may include: theprompts, inputs, questions, and instructions you submit; the content, files, ordata (including metadata) you upload; or the outputs generate within thefeature. This may include personal information if you choose to include it inyour inputs.

The AI service providers we useare contractually prohibited from using your information to train or improve theirown AI models, and from using it for any purpose other than providing theservice to us. AgencyRoot does not collect, use, or sell personal informationto train or improve AI models.

To keep our services safe,content submitted to our AI features may be subject to automated and, inlimited cases, human review for the purpose of detecting and preventing misuse,fraud, or violations of our terms.

10. Data Retention

We retain personal informationand Farm Data for as long as necessary to fulfill the purposes described inthis Policy, including to provide the Services, comply with our legal,regulatory, tax, accounting, and reporting obligations, resolve disputes, andenforce our agreements. When information is no longer needed, we delete,de-identify, or anonymize it. Retention of information processed in ourservice-provider/processor role is governed by our agreements with the relevantCustomer.

11. Security

We maintain reasonableadministrative, technical, and physical safeguards designed to protect personalinformation and Farm Data, including access controls, encryption in transit andat rest, and monitoring. No method of transmission or storage is completelysecure, and we cannot guarantee absolute security. In the event of a securitybreach affecting personal information, we will notify affected individuals andregulators as required by applicable state breach-notification laws.

12. Privacy Rights

Depending on your state ofresidence and applicable law, you may have some or all of the following rightswith respect to personal information we process about you as abusiness/controller:

  • Right of access and portability. The right to obtain access to your personal information and to receive that personal information.
  • Right to correct. The right to correct inaccurate personal information.
  • Right to delete. The right to obtain the deletion of your personal information.
  • Right to opt out of sale and targeted advertising. The right to opt-out of the sale of your personal information and the right for the sharing of your personal information for the purposes of targeted advertising.
  • Right to opt out of profiling. The right to opt-out of the processing of your personal information in furtherance of decisions that produce legal or similarly significant effects, where applicable.
  • Right to non-discrimination. The right to non-discrimination for exercising your rights as outlined in this policy.
  • Right to appeal. The right to appeal a decision we make about your request, where your state provides this right.

Where we act as a service provider/processor, please direct your request to the relevant Customer (the business that controls your information); we will support that business as required by law.

13. How to Exercise Your Rights

You or your authorized agent may submit a request to exercise your rights to us using the contact information below.

To protect your information, we will take reasonable steps to verify your identity before responding, which may include matching information you provide against information in our records. We will not require you to create an account to submit a request. Authorized agents must provide proof of authorization, and we may require the consumer to verify their identity directly.

We will respond to verifiable requests within the timeframe required by applicable law, generally within 45 days, with the ability to extend by an additional 45 days where reasonably necessary and permitted, after notifying you. There is no fee for most requests unless they are excessive, repetitive, or manifestly unfounded.

If we decline to take action on your request and your state provides an appeal right, you may appeal by contacting us at support@agencyroot.com within a reasonable time. We will respond to your appeal within the period required by your state’s law (generally 45–60 days) and explain our decision.

14. Protecting Your Child's Privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 13. We do not knowingly sell or share the personal information of consumers under 16. If you believe a child has provided us their personal information, please contact us and we will delete it.

15. Financial and Insurance Data

Because the Services are used by insurance businesses, some information processed through the platform may also be subject to sector-specific laws such as the federal Gramm-Leach-Bliley Act (GLBA) and state insurance data-security and privacy laws. Many state comprehensive privacy laws exempt data or entities already regulated under GLBA. Where such laws apply, we handle covered information in accordance with those requirements and our Customer agreements.

16. Data Transfers

We are based in the United States, and the information we process is generally stored and processed in the United States. Our service providers and subprocessors, including our AI providers, may process information in other locations. Where information is transferred across borders, we take steps to ensure appropriate protections consistent with applicable law.

17. Third-Party Links

The Services may contain links to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their policies.

18. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last Updated” date and provide notice as required by law, such as by posting on the Services or notifying you directly. Your continued use of the Services after an update indicates your awareness of the changes to the extent permitted by law.

19. Contact Us

If you have questions about this Policy or our privacy practices, or to exercise your privacy rights, contact us at:

Email: support@agencyroot.com

Phone: +1 (765) 267-3437

Mailing address: 4400 State Hwy 121, Suite 520, Lewisville, TX 75056