EFFECTIVE DATE: May 22, 2018
LAST UPDATE: November 2022
Do you want to view this page in Spanish? Click here.
Welcome! BOXX Insurance Inc. are a leading specialist insurer and cyber services provider that targets specific types of insurance in which we develop expertise, often focusing on areas other insurers find too complex to insure. BOXX Insurance Inc. and its affiliates are collectively referred to in this privacy statement as “BOXX”, “we”, “us” or “our”.
We wrote this privacy statement to help you understand what information we collect, how we use it, what choices you have and other important information. Although some of the concepts below are a bit technical, we tried our best to explain things in a straightforward and transparent way.
This Policy applies to all of our customers across the world. Some customers, including residents of the European Economic Area, may have additional rights depending on where they are located, which are described in this Notice.
When This Privacy Statement Applies
This privacy statement applies to information collected through boxxinsurance.com/us and any other websites, mobile apps or other online products and services that display or link to this privacy statement (collectively, “online environments”).
When This Privacy Statement Does Not Apply
This privacy statement does not apply to:
If you have any questions as to whether this privacy statement applies to you, please do not hesitate to contact us using the information provided in the “Contact Us” section at the end of this privacy statement.
Information We Collect
We collect information in a few different ways: (i) information you submit or give us permission to obtain; (ii) technical information collected automatically; and (iii) information provided by our partners. Each of these ways is discussed below.
Information You Submit Or Give Us Permission to Obtain
We collect information from you when you choose to provide it to us through our online environments. For example, if you:
Technical Information Collected Automatically
We may collect certain technical information about your visits to our online environments without you actively submitting such information. This information can make your use of our online environments easier and more meaningful by allowing us to provide better service, customize our online environments based on your preferences, compile statistics, provide you with more relevant advertisements, analyze trends and otherwise administer and improve our online environments. As discussed in the “HOW BOXX AND OUR PARTNERS USE COOKIES FOR ADVERTISING” section below, such information may also be collected by our advertising vendors and other partners.
Some of the types of technical information collected automatically when visiting our online environments include:
Information Provided By Our Partners
Our advertising vendors and other partners may share with us the information they collect. For example:
We may also combine the information we collect through one or more of our online environments with information we collect through other online environments. We may also combine information collected through our online environments with information collected through our offline environments, as well as with information provided by our partners. We use this consolidated information to help us improve our online environments, products and services, communicate information to you, enhance our marketing and research activities and engage in any other uses described in the “HOW WE USE THE INFORMATION WE COLLECT” section below.
How We Use The Information We Collect
We use the information we collect to provide our products and services to you, improve our products and services, develop new products and services and protect ourselves and our customers.
If you request a quote from us, the information we collect will be used to generate the quote, allow you to create an account to save quotes, and provide you with information about other relevant products and services.
If you manage or request changes to your policy, the information we collect will be used to update your policy and provide you with information about other relevant products and services;
If you make a purchase through our online environments and authorize us to use your credit or debit card information, we will use this information to charge you as authorized. In these situations, we may also save your payment information and contact information so that you can use them the next time you want to order something from us.
If you register or open an account with us, the information we collect may be used to maintain your account, provide you with access to some features of our online environments or offer you the benefits and privileges that typically come along with account registration.
We also use the information we collect for other legitimate business purposes, such as to:
We may also use the information we collect to offer you customized content, including to:
Some of our applications and mobile-optimized online environments may have location-based features. To deliver these features, we may access and use location data provided by your mobile device if you give us permission. For example, we may offer features that allow you to find the nearest broker. Location information will be collected solely to deliver the requested feature, and it will not be further retained or stored by us.
Finally, in certain limited circumstances, we may be called upon to release the information we collect in response to a court order, subpoena, search warrant, law or regulation. We plan to cooperate in responding to such requests, taking appropriate measures to ensure that the requester understands the potentially-sensitive nature of the information they may receive. We also reserve the right to cooperate with law enforcement authorities in investigating and prosecuting customers who violate our rules or engage in behavior that is illegal or harmful to others or their property.
How BOXX Insurance And Our Partners Use Cookies For Advertising
We use common tools, such as cookies and similar technologies (discussed in the “TECHNICAL INFORMATION COLLECTED AUTOMATICALLY” section above), to collect information about your use of our online environments for purposes of enhancing your online experience and delivering more meaningful advertisements. Like many companies, we may also utilize third party advertising vendors and other partners to collect this information.
One way in which we deliver more meaningful advertisements is through a common form of online advertising known as “retargeting” or “remarketing.” Retargeting works by serving ads on one site based on consumer’s online activities on a different site. For example, if you visit pages on our online environments, you may later see advertisements for BOXX products and services when you visit third party websites. To do this, BOXX or our advertising vendors may use a device ID, cookie or similar technology placed by us or the advertising vendor when you visit our online environments or third party websites or apps. The placing of these cookies or other technologies on your device may enable you to be identified across multiple websites and you should consult the privacy policies of our advertising vendors to understand how they collect and use your data.
Your ability to control the use of tracking tools, such as cookies, and opt-out of retargeting activities is described in the “CHOICES YOU HAVE ABOUT YOUR INFORMATION” section below.
When We Share Your Information & Our Relationship To Third Parties
We may use third parties to perform a variety of functions on our behalf. We may also use third parties to analyze data collected through our online environments. We will not disclose your personally identifying information to anyone other than our employees and those third parties with whom we have a business relationship. If we allow a third party vendor to have access to your personally identifying information, we will not authorize them to take it or use it for any purpose that is not consistent with this privacy statement.
We will not sell or disclose any personally identifying information collected from you to an unrelated third party without your express permission, except as explained in this privacy statement.
Other Important Information About Our Relationship With Third Parties
Choices You Have About Your Information
You may always limit the amount and type of information that we collect from you by choosing not to enter or provide any information requested from you on our online environments (for example, quotes and support requests can be made through our call center agents). However, some of our products and services can only be provided to you if you provide us with requested information. Some of the products and services offered through our online environments may ask whether you wish to opt out or opt into our contact lists for offers, promotions and additional products and services that may be of interest to you.
You can opt out of marketing emails we may send to you by following the “unsubscribe” instructions provided in such emails. If you opt out of our marketing emails, we may still send you transactional and relationship emails, such as emails about your orders and account.
You may also be provided with preference questions or preference boxes allowing you to indicate that you do not want our online environments to use tracking technologies, such as cookies, to “remember” the information collected on return visits, such as user IDs or mailing addresses. In addition, you may be able to control the use of tracking tools and limit retargeting activities as follows:
Do-Not-Track Signals and Similar Mechanisms
Some web browsers may transmit “do-not-track” signals to websites with which the browser communicates. As of the Effective Date of this privacy statement, an industry standard has not yet been established on how to respond to these signals. Therefore, we do not currently respond to these signals, but we may reassess our response approach once a standard is established.
How We Secure Your Information
We have instituted physical, technical and procedural safeguards to store and maintain information we collect in a secure environment. For example, when any confidential information is transmitted over public infrastructure it is encrypted. You may also be required to use a password to access certain pages on our online environments where certain types of your information can be changed or deleted. It is therefore important for you to protect against unauthorized access to your password and to your device. You take full responsibility for maintaining the complexity and confidentiality of your password. While we have implemented safeguards, you should be aware that Internet security technology rapidly changes. We cannot guarantee that the safeguards we employ today can protect your information from the threats of tomorrow. You should also be aware that despite our efforts, factors beyond our control may result in disclosure of information. Accordingly, we are not in a position to guarantee that your information will be secure under all circumstances.
Our Policy On Children’s Information
We do not knowingly collect or use any information from children (we define “children” as minors younger than 13) on our online environments. We do not knowingly allow children to order our products or services, communicate with us or use any of our online environments. If you are a parent and become aware that your child has provided us with information, please contact us using one of the methods specified below, and we will work with you to address this issue.
International Data Transfer
BOXX operates globally. Consequently, some of our affiliates, subcontractors, distributors, and partners are located in multiple countries, including outside the European Economic Area to ensure the global reach and availability of our services. Depending on the scope of your interactions with BOXX, your personal information will only be stored in the region where it is collected. No other copies of personal data would be stored in other regions.
If a personal data transfer was found to be required, we only do so for a good reason and after assessing the resulting privacy risk. In the rare case that data would be transferred to another region we would first attempt to appropriately de-personalize the private data prior to transmission. In any case regardless if de-personalisation is possible we transfer personal / de-personalised data to other jurisdictions, including outside the European Economic Area, we secure such transfers of data according to the requirements of the law. We do this by imposing appropriate technical and contractual safeguards on relevant subcontractors and BOXX group companies, for example by using data transfer clauses that are approved by the European Union — the fixed content of such clauses is available here..
We store more sensitive customer data within each regional jurisdiction and keep it under our own control.
Residents of the European Economic Area and the United Kingdom
If you are in the European Economic (EEA) or the United Kingdom (UK), the following additional disclosures apply.
Data Controller
Where you purchase one of our consumer products, BOXX Insurance Inc. acts as the Controller of your Personal Data.
Legal Basis for Processing
When we process your Personal Data, we will only do so in the following situations:
Consent
If you initially consented to our processing of your Personal Data, you may withdraw your consent by contacting us using the contact information below.
Contact Us
If you have any questions or comments about this privacy statement or the ways in which BOXX uses the information we collect, please do not hesitate to contact us using the following contact methods:
If you’re based in the EU/EEA and wish to contact us via our Data Protection Representative, DataRep, you may do so by:
Changes To This Privacy Statement
We reserve the right to amend this privacy statement without prior notice to reflect technological advancements, legal and regulatory changes and good business practices. If we change our privacy practices, a new privacy statement will reflect those changes and the effective date of the revised privacy statement will be set forth at the top of this privacy statement.
This Privacy Notice for California Residents supplements the information contained in the Company’s general Privacy Notice and applies solely to all visitors, users, and others who reside in the State of California (“consumers” or “you”). We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA) and any terms defined in the CCPA have the same meaning when used in this Notice.
Categories of Personal Information Collected & Disclosed
The following identifies the categories of Personal Information we may collect about you (and may have collected in the prior 12 months). Note that our collection, use and disclosure of Personal Information about you will vary depending upon the circumstances and nature of our interactions or relationship with you. Depending on how you use our Services, we may collect the following categories of Personal Information:
Sources of Personal Information
We generally collect Personal Information from the following categories of sources:
Purposes for Collecting and Disclosing Personal Information
In general, we collect and otherwise process the personal information we collect for the following business or commercial purposes:
Sensitive Personal Information
Notwithstanding the purposes described above, we do not collect, use, or disclose “sensitive personal information” beyond the purposes authorized by the CCPA. Accordingly, we only use and disclose sensitive personal information as reasonably necessary and proportionate: (i) to perform our services requested by you; (ii) to help ensure security and integrity, including to prevent, detect, and investigate security incidents; (iii) to detect, prevent and respond to malicious, fraudulent, deceptive, or illegal conduct; (iv) to verify or maintain the quality and safety of our services; (v) for compliance with our legal obligations; (vi) to our service providers who perform services on our behalf; and (vii) for purposes other than inferring characteristics about you.
Retention of Personal Information
We retain the Personal Information we collect only as reasonably necessary for the purposes described in this Privacy Policy or otherwise disclosed to you at the time of collection. For example, we will retain certain identifiers for as long as it is necessary to comply with our tax, accounting and recordkeeping obligations, to administer certain policies and coverage, and for research, development and safety purposes, as well as an additional period of time as necessary to protect, defend or establish our rights, defend against potential claims, and to comply with our legal obligations. From time to time, we may also deidentify your Personal Information, retain it and use it for a business purpose in compliance with CCPA.
Disclosure of Personal Information to Third Parties and Other Recipients
The categories of Personal Information we have disclosed for a business purpose in the preceding twelve (12) months include: identifiers, online identifiers, customer records, financial information, characteristics of protected classifications, usage data, biometric information, education information, geolocation data, audio, video, and other electronic data, professional or employment-related information, inferences, and sensitive personal information.
The categories of third parties and other recipients to whom we may disclose personal information for a business purpose may include:
Additionally, the CCPA defines “sale” as disclosing or making available personal information to a third-party in exchange for monetary or other valuable consideration, and “sharing” includes disclosing or making available personal information to a third-party for purposes of cross-contextual behavioral advertising. While we do not “sell” Personal Information, we may “share” the following categories of Personal Information: online identifiers, and usage data. We disclose this information to third-party advertising networks, analytics providers, and social networks for purposes of marketing and advertising. We do not sell or share “sensitive personal information,” nor do we sell or share any Personal Information about individuals who we know are under sixteen (16) years old.
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request (see Exercising Access, Data Portability, and Deletion Rights), we will disclose to you:
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request (see Exercising Access, Data Portability, and Deletion Rights), we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
Exercising Access, Data Portability, and Deletion Rights
Email us at privacy@boxxinsurance.com
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.
Making a verifiable consumer request does not require you to create an account with us.
We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
For instructions on exercising sale opt-out rights, see Personal Information Sales Opt-Out and Opt-In Rights.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Personal Information Sales Opt-Out and Opt-In Rights
We do not sell personal information.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
Changes to Our Privacy Notice
We reserve the right to amend this privacy notice at our discretion and at any time. When we make changes to this privacy notice, we will post the updated notice on the Website and update the notice’s effective date. Your continued use of our Website following the posting of changes constitutes your acceptance of such changes.
Contact Information
If you have any questions or comments about this notice, the ways in which BOXX Insurance collects and uses your information described here, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us at:
Email: privacy@boxxinsurance.com
Postal Address:
BOXX Insurance
801 Brickell Ave, Suite 800
Miami, FL 33131