Privacy Policy

Effective February 1, 2026

Zion Underwriting Partners LLC ("we", "us", "our") operates a commercial transportation insurance quoting and policy-management platform (the "Service") for wholesale insurance producers, agencies, program administrators, and their insured commercial transportation operators. This Privacy Policy explains what information we collect, how we use it, how we share it, how we protect it, and the choices and rights you have. By accessing or using the Service you acknowledge you have read and understood this Policy.

1. Information we collect

We collect the following categories of information, each only to the extent necessary for the purposes described in Section 2: • Account information: your name, business email, phone, agency, licensing details, and role. • Business information: company name, US DOT number, MC number, EIN, operating classification (interstate/intrastate/private/for-hire), radius of operation, cargo type, garaging address, mileage, vehicles, drivers, prior policies, loss runs, prior carriers, MVR history, and inspection history. • Driver personally identifiable information (PII): driver names, dates of birth, home addresses, license numbers and states, license issue/expiration, motor-vehicle-record content, and CDL endorsements. This information is encrypted at rest, access-restricted to authorized underwriters and processors under written confidentiality obligations, and audit-logged on every read. • Payment information: bank routing / account numbers for ACH, card details for credit/debit — all processed by Stripe under PCI-DSS Level 1; we never see or store the full card number. • Communications: emails you send to us, in-app messages, ticket attachments, and inbound / outbound insurance correspondence. • Usage information: pages viewed, actions taken, timestamps, device and browser fingerprints, and IP addresses (used for fraud prevention, security, and quality assurance). • Cookies and similar technologies: session cookies (essential), CSRF tokens, and turnstile challenges (bot-protection). We do not use third-party advertising cookies.

2. How we use information

We use the categories above solely for the purposes for which they were collected, including: • Underwriting, quoting, binding, endorsing, cancelling, and renewing insurance policies. • Communicating with you about quotes, submissions, policies, endorsements, invoices, statements, renewals, service requests, and support inquiries. • Verifying identity, preventing fraud, and complying with anti-money-laundering / Office of Foreign Assets Control (OFAC) screening obligations. • Meeting legal, regulatory, and compliance obligations, including surplus-lines tax reporting, state insurance department filings, and record retention. • Improving the Service, debugging issues, monitoring system integrity, and detecting security threats. • Enforcing our Terms of Service and defending against or responding to legal claims. We do not use your information for marketing to third parties or for automated decision-making that produces legal or similarly significant effects without human review.

3. How we share information

We share information only as needed to deliver the Service and only with recipients under written contracts that restrict use to the disclosed purpose: • Insurance carriers, wholesalers, MGAs, and reinsurers underwriting or servicing your risk. • Sub-processors that support the platform under written data-protection agreements: Stripe (payments and Stripe-verified banking data), Resend (transactional email delivery), Zoho (email inbox mirroring), BoldSign (electronic signature), Lob.com (paper check issuance), Cloudflare (edge security, WAF, DDoS mitigation, and Turnstile bot protection), MongoDB Atlas (managed database), and cloud infrastructure providers whose data centers physically host our production environment. • Regulators, courts, and law-enforcement agencies when required by valid legal process, statute, subpoena, or lawful government request; when reasonably necessary to protect the rights, property, or safety of Zion Underwriting Partners, our users, or the public; or with your prior written consent. • Successor entities in the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of our assets, provided the successor is bound by terms at least as protective as this Policy. We do not, and will not, sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioural advertising.

4. Data retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law and insurance regulatory record-keeping obligations. Specifically: • Policy, quote, endorsement, and premium records: a minimum of seven (7) years after policy expiration or cancellation, per state insurance department requirements. Some states require longer. • Loss-run and claim data: a minimum of ten (10) years after the loss date, or the applicable statute of limitations, whichever is longer. • Financial records (invoices, statements, receipts): a minimum of seven (7) years from the transaction date. • Cybersecurity event data (NY DFS Reg. 500 § 500.16): a minimum of five (5) years from the event. • Account credentials and audit logs: retained for at least three (3) years after account closure. • Backup snapshots may retain otherwise-deleted data for up to ninety (90) days after their original deletion date before they are overwritten. When retention periods lapse we permanently delete or de-identify the affected records.

5. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, unauthorized access, disclosure, alteration, and destruction, including: • TLS 1.2+ encryption in transit for every network connection and at-rest encryption of PII fields in our database using industry-standard algorithms. • Role-based access controls with strict least-privilege permissioning; every access to driver PII, payment data, and financial records is audit-logged. • Multi-factor authentication is available for all administrative accounts and required for privileged access. • JWT-based session management with rotating refresh tokens, session timeouts, and automatic revocation on password change. • Cloudflare Web Application Firewall, DDoS mitigation, rate-limiting, and bot-protection (Turnstile) protect our public endpoints. • Continuous monitoring, anomaly detection, and quarterly access reviews. • Encrypted database backups replicated to a geographically separate region, tested for restoration on a defined schedule. While no system is perfectly secure, we designed and continue to operate the Service to meet or exceed reasonable industry standards, including where applicable the New York Department of Financial Services Cybersecurity Regulation (23 NYCRR 500). Breach notification: if a security event materially affects your personal information, we will notify affected users and applicable regulators in accordance with all applicable state breach-notification statutes, in most cases within seventy-two (72) hours of confirming the material impact.

6. Your choices and rights

Regardless of where you reside, you may: • Access, correct, or export the personal information we hold about you. • Request deletion of your personal information, subject to insurance-records-retention obligations that may require us to retain policy and financial records for a period defined by state law. • Opt out of non-essential marketing email at any time; transactional communications about your policies, invoices, and statements cannot be disabled while you have an active account or open balance. • Ask a human to review any automated determination affecting a submission you have made. Residents of California, Virginia, Colorado, Connecticut, and Utah additionally have the following rights under CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.), VA CDPA, CO CPA, CT CTDPA, and UT UCPA respectively: (a) the right to know the categories and specific pieces of personal information we have collected, sold, or shared about you; (b) the right to correct inaccurate personal information; (c) the right to delete personal information (subject to statutory exceptions including insurance-records retention, fraud-detection, and legal-claim exceptions); (d) the right to opt out of the "sale" or "sharing" of personal information (we do neither); (e) the right to limit use of sensitive personal information; and (f) the right to non-discrimination for exercising any of these rights. To exercise any right, email compliance@zionuw.com from the email address on your account. We will verify your request and respond within forty-five (45) days (or the applicable statutory window). If you appeal a decision, contact the same address with "APPEAL" in the subject line and we will respond within an additional sixty (60) days. You may also lodge a complaint with your state's Attorney General. You may authorize an agent to exercise these rights on your behalf; we will require signed authorization and proof of your identity.

7. GLBA financial-privacy notice

As a financial-services provider, we are subject to the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801) and its implementing regulations. This Policy serves as our Initial Privacy Notice and Annual Privacy Notice for GLBA purposes. We collect nonpublic personal information ("NPI") about you from the sources described in Section 1. We share NPI only as described in Section 3 and only for permitted purposes under 15 U.S.C. § 6802(b) and (e), including servicing or processing an insurance product or service you have requested, or as otherwise permitted or required by law. You have the right to opt out of NPI sharing with non-affiliated third parties beyond the permitted purposes; we do not share NPI outside those permitted purposes, so no opt-out is required, but you may confirm in writing to compliance@zionuw.com.

8. Children

The Service is intended for adult professionals engaged in commercial insurance transactions. It is not directed to and not designed for anyone under eighteen (18). We do not knowingly collect personal information from children. If you believe we have inadvertently done so, contact us at the address in Section 11 and we will delete it.

9. International transfers

The Service is operated from and its data are stored in the United States. If you access the Service from outside the United States, you consent to the transfer of your personal information to the United States and to processing under United States law. We do not currently market the Service to residents of the European Union, the United Kingdom, or Switzerland.

10. Changes to this policy

We may update this Policy from time to time to reflect changes to our practices or to comply with new legal or regulatory requirements. Material changes will be announced in-app and by email to your account address at least fourteen (14) days before they take effect. The "Effective" date at the top of this page always reflects the current version. Historical versions are retained internally and available on request.

11. Contact us

For any privacy question, request, complaint, or to exercise your rights under this Policy, write to us at compliance@zionuw.com. We treat every request with care and confidentiality.