Privacy
Legal

Our Privacy Policy

Last updated: September 3, 2026

1. Introduction

Pie Group Holdings, Inc., and its property and casualty insurance carrier and agency subsidiaries (collectively, “Pie Insurance,” “Company,” “we,” “us,” or “our”) offers insurance products to small businesses in the states in which we are licensed (the "Service Area"). This Privacy Policy explains how we collect, use, disclose, and protect personal and business information in connection with our insurance products and services, including when you visit our website, apply for a quote, purchase a policy, or file a claim.

This Policy applies to information we collect from:

  • Prospective, current, and former policyholders and applicants
  • Named insureds, additional insureds, and covered employees (e.g., under Workers' Compensation policies)
  • Claimants and witnesses involved in a claim
  • Independent agents, brokers, and business partners
  • Visitors to our website and digital platforms

This Policy is designed to comply with applicable federal and state law, including the Gramm-Leach-Bliley Act ("GLBA") and its implementing regulations, applicable state insurance information and privacy protection statutes (many of which are based on the NAIC Insurance Information and Privacy Protection Model Act or the NAIC Privacy of Consumer Financial and Health Information Model Regulation), and applicable state consumer privacy laws to the extent they apply to GLBA-regulated entities.

2. Information We Collect

2.1 Information You Provide to Us

  • Identifying information: name, date of birth, Social Security number or Tax ID / EIN, address, phone number, email address
  • Business information: business name, entity type, industry/NAICS code, years in operation, number of employees, payroll data, revenue, business location(s), ownership structure
  • Insurance application data: prior insurance history, loss runs, claims history, licensing information, vehicle information (when applicable), professional credentials (for E&O/Professional Liability), safety programs and workplace policies (for Workers' Compensation)
  • Payment information: bank account or payment card details for premium payment or claims disbursement
  • Claims information: incident details, medical information (in connection with claims), witness statements, photos, repair estimates, and related documentation
  • Communications: records of calls, emails, chat, and correspondence with our agents, underwriters, and claims adjusters

2.2 Information Collected Automatically

When you interact with our website or online portals, we may automatically collect:

  • IP address, browser type, device identifiers, operating system
  • Pages visited, referring URLs, time stamps, and click behavior
  • Cookies and similar tracking technologies (see Section 9 and our Cookie Notice)

2.3 Information from Third Parties

We may obtain information about you or your business from:

  • Independent agents and brokers who submit applications on your behalf
  • Consumer reporting agencies and insurance-support organizations (e.g., credit information, loss history reports such as CLUE, motor vehicle records)
  • Medical providers and rehabilitation professionals (for claims), subject to applicable authorization requirements
  • Public records (e.g., business registries, licensing boards, court records)
  • Premium finance companies, reinsurers, and payment processors
  • Other insurers or industry databases used for fraud prevention and underwriting (e.g., ISO, NICB)

2.4 Sensitive and Health Information

In connection with policy administration, we may collect health and medical information about injured employees or insureds. This information is collected, used, and disclosed only as necessary to underwrite the policy, administer claims, coordinate benefits, and comply with state insurance laws, and is subject to heightened confidentiality protections described in Section 5.

3. How We Use Information

We use the information we collect to:

  • Evaluate insurance applications and determine eligibility, rates, and terms
  • Underwrite, issue, service, and renew policies
  • Process premium payments and billing (including collections)
  • Investigate, administer, and pay claims
  • Detect, investigate, and prevent fraud, and comply with anti-fraud reporting obligations
  • Communicate with policyholders, agents, and claimants
  • Comply with state insurance regulatory requirements, licensing, and reporting obligations
  • Conduct actuarial and statistical analysis, including for ratemaking
  • Improve our products, underwriting tools, website, and customer service
  • Comply with subpoenas, court orders, and other legal process
  • Protect the rights, property, and safety of the Company, our policyholders, and others

We do not use health information collected in claims for underwriting other lines of insurance without appropriate authorization, except as permitted by law.

4. How We Share Information

We may share information with:

  • Affiliates, for the purposes described in this Policy
  • Independent agents and brokers who help place or service your policy
  • Reinsurers, to manage risk
  • Third-party service providers, including but not limited to claims administrators, medical case managers, investigators, IT support vendors, and payment processors, all of which are under contracts that restrict their use of your information to the services provided to us
  • Cloud service and marketing vendors that support our public-facing website, with whom we have provider contracts, but over whom we cannot realistically control their use of your non-sensitive data, unless you opt-out through the various tools noted in this Policy
  • Insurance-support organizations and industry databases (e.g., for loss history reporting and fraud prevention)
  • Regulators and government authorities, including state departments of insurance, as required by law
  • Law enforcement, in connection with fraud investigations or as required by subpoena, court order, or other legal process
  • Other insurers, in connection with claims coordination or subrogation
  • Successors, in connection with a merger, acquisition, reorganization, or sale of some or all of our assets

We do not sell personal information to third parties for their own marketing purposes.

Pie Insurance reserves the right to share your nonpublic financial information with its affiliates for marketing purposes as permitted by the Gramm-Leach-Bliley Act. Where the Fair Credit Reporting Act or applicable state law (such as the California Financial Information Privacy Act or Vermont law) gives you the right to opt out of or requires your consent for affiliate or nonaffiliated marketing sharing, please see Section 12. Based thereon, we will honor your choice before using your information for those purposes. Our affiliates include Pie Group Holdings, Inc., Pie Carrier Holdings, Inc., The Pie Insurance Company, and Pie Casualty Insurance Company.

We do not sell personal information. As used here, "sell" has the meaning given by applicable state privacy law and is not limited to sales for a third party's own marketing purposes. Except for the advertising cookies and similar technologies described in Section 9, we also do not share personal information for cross-context behavioral advertising or targeted advertising. However, we do not have any control over what your broker or representative may do with your data prior to contacting us, nor can we rely on any consents you may have given your broker or representative.

Pie Insurance reserves the right to share your nonpublic financial information with its affiliates for marketing purposes as permitted by the Gramm-Leach-Bliley Act. Where the Fair Credit Reporting Act or applicable state law (such as the California Financial Information Privacy Act) gives you the right to opt out of or requires your consent for affiliate or nonaffiliated marketing sharing, you may exercise that right at any time by emailing privacy@pieinsurance.com, or writing to us at the address in Section 16. We will honor your choice before using your information for those purposes.

4.1 Your Right to Opt-out (Where Applicable)

In certain states, and for certain categories of information sharing (such as sharing with non-affiliated third parties for marketing purposes not necessary to service your policy), you may have the right to opt out. Where such rights apply, please see Section 12 describing how to exercise them, consistent with applicable state law (e.g., NAIC Model Act "opt-out" notices).

5. Special Protections for Health and Medical Information

Health and medical information collected in connection with claims is:

  • Used only for claims handling, benefit coordination, utilization review, and related purposes permitted by state Workers' Compensation law
  • Disclosed to medical providers, rehabilitation specialists, and third-party administrators only as necessary to administer the claim
  • Not disclosed for marketing purposes
  • Protected by administrative, technical, and physical safeguards consistent with applicable law

We do not disclose medical information for purposes beyond claims administration.

6. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal and business information against unauthorized access, use, disclosure, alteration, or destruction, consistent with GLBA Safeguards Rule requirements and applicable state insurance data security laws (e.g., laws based on the NAIC Insurance Data Security Model Law). These safeguards include access controls, encryption of sensitive data in transit and at rest, website security, employee training, vendor due diligence, and incident response procedures. We restrict access to your information to those within our organization who must use it to provide our products and services to you; access is monitored and granted only to employees or partner organizations that have a need to know.

No security program is completely immune from risk. In the event of a data breach affecting your personal information, we will notify affected individuals and applicable state regulators as required by law.

7. Data Retention

We retain personal and business information for as long as necessary to service your policy, administer claims, comply with legal, regulatory, and contractual obligations (including statutes of limitation and state record-retention requirements for insurers), resolve disputes, and enforce our agreements. Retention periods vary by document type and state requirement. We retain policy, underwriting, and claims records for the longer of 7 years after a policy, underwriting file, or claim is closed, or such longer period as required by the applicable state department of insurance or by the statute of limitations governing the type of claim involved - which in certain states or for certain lines of business (including Workers’ Compensation and general liability) may extent to 10 years or more. Website analytics and advertising data are retained for 14 months after which the information is deleted or de-identified in accordance with our applicable retention and deletion practices.

8. Text Messaging (SMS), Automated Calling, and AI in Marketing

8.1 Texting and SMS Communications for Transactional Matters

Pie Insurance may communicate with you by SMS (short message service) and text communications (collectively, “text messages”). "Text messages" refers generally to our practice of sending you messages to a mobile device via our texting platform and/or your wireless carrier's network. We may use these terms interchangeably in this Policy; where a distinction matters (for example, message formatting or carrier fees), your wireless carrier's terms will govern.

Types of transactional and service-related texts we may send:

  • Transactional/servicing texts: policy status and renewals, billing and collections payment reminders, claims status updates, appointment reminders, identity verification codes, and other messages necessary to service your policy or respond to your inquiries

Consent & Opt-in. By providing your mobile number to us or our agents — including through an application, our website, a customer portal, or a phone call — you consent to receive recurring automated text messages at the mobile number provided using an automatic telephone dialing system for the types of messages described above. Consent to receive text messages is not a condition of purchasing any product or service from Pie Insurance.

Opt-out. You may opt out of texts at any time by replying "STOP" to any text message, or by contacting us using the information in Section 16. Reply "HELP" for assistance. Message and data rates may apply. Message frequency varies. Carriers are not liable for delayed or undelivered messages.

Data collected via texting. We and our texting platform vendors may collect your mobile number, message content, delivery status, and engagement data (e.g., whether a message was opened or a link was clicked) in order to deliver, manage, and improve our texting program. This information is handled consistently with the rest of this Policy and is not sold to third parties. Text messaging originator opt-in data and consent records are not shared with any third parties, and information collected through your SMS opt-in is not shared with third parties for their own marketing purposes; it may be shared with service providers who assist us in operating our text messaging program, subject to confidentiality obligations. After you reply "STOP," you will receive a single confirmation message and no further texts will be sent, except as required by law. For help or more information, reply "HELP" to any message or contact us at service@pieinsurance.com.

8.2 Automated Calling for Transactional Matters (e.g., Overdue Bills)

Pie Insurance may contact you using artificial intelligence–assisted calling systems, including automated or AI-generated voice technology (collectively, "AI-assisted calls"). This refers generally to our practice of placing outbound calls to a mobile or landline device via automated telephone dialing systems and/or AI-generated voice platforms. Where a distinction matters (for example, call recording or carrier connectivity), your wireless carrier's terms and applicable state law will govern.

Types of transactional and service-related calls we may make:

  • Transactional/servicing calls: policy status and renewal confirmations, billing and payment reminders, claims status updates, appointment reminders, identity verification, and other calls necessary to service your policy or respond to your inquiries
  • These calls are limited to transactional and informational purposes and will not include marketing content

Consent & Opt-in. By providing your phone number to us or our agents — including through an application, our website, a customer portal, or a phone call — you consent to receive recurring automated or AI-assisted calls at the number provided using an automatic telephone dialing system for the transactional purposes described above. Consent to receive AI-assisted calls is not a condition of purchasing any product or service from Pie Insurance. Where required by the Telephone Consumer Protection Act ("TCPA") or applicable state law, we will obtain your prior express written consent before placing marketing calls using an automatic telephone dialing system or artificial or prerecorded voice. Consent to marketing calls is not a condition of purchasing insurance from us.

Opt-out. You may opt out of AI-assisted calls at any time by following the instructions provided during the call, or by contacting us using the information in Section 16. You may continue to receive certain non-marketing transactional calls (e.g., claims or legal notices) as permitted by law even after opting out of marketing calls. If you request a live representative during a call, we will make reasonable efforts to connect you with one.

Data collected via AI-assisted calling. We and our calling platform vendors may collect your phone number, call content or transcripts, delivery status, and engagement data (e.g., whether a call was answered or a message was listened to) in order to deliver, manage, and improve our calling program. Call recordings or transcripts, if generated, are retained and secured consistently with Sections 6 and 7 of this Policy and used only for servicing, quality assurance, and compliance purposes. This information is handled consistently with the rest of this Policy and is not sold to third parties. Calling originator opt-in data and consent records are not shared with any third parties, and information collected through your calling consent is not shared with third parties for their own marketing purposes; it may be shared with service providers who assist us in operating our calling program, subject to confidentiality obligations.

8.3 Use of AI in Marketing

We may use artificial intelligence and machine learning tools to support our marketing activities, including to:

  • Personalize marketing content, offers, and product recommendations based on information you have provided or that we hold about your business
  • Segment audiences and identify prospective customers who may benefit from our products
  • Generate or assist in drafting marketing content, including emails, website content, and advertisements

8.4 Use of AI in Automated Decisions

We use AI-powered tools to assist in the initial screening of applications; all outputs are still subject to human oversight and decision-making at multiple stages of the process. We also use automated tools to conduct premium audits for a subset of policies, as described in Section 10 under "Profiling and automated decision-making." Our AI systems process the same categories of personal information described elsewhere in this Policy, and we implement appropriate safeguards for those systems, including regular testing and monitoring for bias and accuracy, security measures to protect data used in AI processing, data minimization so that only information necessary for a specific AI purpose is used, and retention limits so that AI-processed data is retained only as long as necessary. Where we use AI services provided by third-party vendors, those relationships are governed by contractual requirements designed to comply with applicable laws and regulations.

9. Cookies and Online Tracking

Our website and online portals use cookies and similar technologies to operate the site, remember preferences, analyze usage, and support quoting and account management tools. You can control cookies through your browser settings. Note, however, that disabling cookies may limit some website functionality, including the ability to obtain an online quote. Detailed information about the specific cookies and similar technologies we use, the categories they fall into, their duration, the third-party vendors that set them, and how to manage your preferences is set out in our separate Cookie Notice, available at https://www.pieinsurance.com/legal/cookie-notice, which is incorporated into this Policy by reference. If this Section and the Cookie Notice conflict with respect to cookies and similar technologies, the Cookie Notice controls.

We treat a Global Privacy Control or other recognized opt-out preference signal as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for the browser or device transmitting it, in every state that recognizes such signals.

We, along with third-party vendors such as Google, use first-party cookies (including Google Analytics cookies) and third-party cookies or other third-party identifiers to compile data about user interactions with ad impressions and other ad service functions relating to our website. As part of overall performance and effectiveness monitoring, we use Google Analytics and the Enhanced Conversions tool from Google Ads Solutions to track customer activity and analyze the effectiveness of our website. For additional information on Google Ads' privacy practices, visit https://business.google.com/us/privacy/. Pages of our website and our emails may also contain small electronic files known as web beacons (also referred to as clear GIFs, pixel tags, and single-pixel GIFs) that permit us, for example, to count users who have visited those pages or opened an email, and to compile other related website statistics.

10. Your Rights and Choices

Depending on your state of residence and your relationship with us (applicant, policyholder, claimant), you may have rights to:

  • Request access to the personal information we maintain about you
  • Request correction of inaccurate information
  • Request an explanation of an adverse underwriting decision
  • Request a copy of the personal information you provided to us in a portable and, to the extent technically feasible, readily usable format
  • Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you
  • Opt out of certain information sharing, as described in Section 4.1
  • Direct that we do not share your information with affiliates for marketing, where applicable
  • Lodge a complaint with your state Department of Insurance

To exercise these rights, contact us using the information in Section 16. We will respond consistently with applicable state law and may need to verify your identity before processing your request. To review or change your personal information, you may send a request to privacy@pieinsurance.com. Changes will be made within the time period required by applicable state law (generally within 45 days of receipt, which may be extended as permitted by law); if a change cannot be made, we will send you a notice explaining why the change will not be completed.

Sensitive data (states requiring opt-in consent). Several states require your affirmative, opt-in consent before we process sensitive data. Where those laws apply to us and to the information at issue, we treat the following as sensitive data: personal information revealing racial or ethnic origin, religious or philosophical beliefs, or national origin; mental or physical health condition, diagnosis, or treatment; sex life or sexual orientation; transgender or nonbinary status; citizenship or immigration status; status as a victim of crime; genetic or biometric data processed to identify an individual; neural data; precise geolocation; and personal information of a consumer we know to be a child.

Sensitive personal information. To any extent that processing sensitive personal information is not granted to us by law, we rely on your consent as a back-up (but not as a substitute of our legal entitlements) upon the creation of your account. Based on such consent, we may collect precise geolocation, used to provide services to consumers; credit card information, collected for financial transactions; driver's license information and Social Security number, obtained to verify individuals and offer accurate ratings; and information concerning a consumer's health, used for claims management.

Exercising your rights to know, delete, or correct. You may submit a request by emailing us at privacy@pieinsurance.com or submitting a request at https://www.pieinsurance.com/legal/privacy/ccpa. Only you, or a person legally authorized to act on your behalf, may submit a request relating to your personal information, and you may submit no more than two requests to know within any 12-month period. Your request must provide information sufficient to allow us to reasonably verify that you are the person about whom we collected personal information, or an authorized representative, which may include authorized agent contact information, your relationship with Pie Insurance (e.g., policyholder or claimant), and matching pieces of personal information in a signed declaration. We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request. Except for a parent or guardian of a minor, or an authorized agent holding a power of attorney under California Probate Code sections 4000 to 4465, consumers must verify their identity directly with Pie Insurance and provide written permission for an authorized agent to act on their behalf. We use personal information provided in a request only to verify the requestor's identity or authority.

Response timing. We endeavor to respond substantively to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to an additional 45 days), we will inform you in writing of the reason and the extension period. If we are unable to fulfill a request, you will be notified in writing. We do not charge a fee to process or respond to a verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded; if we determine that a fee is warranted, we will explain why and provide a cost estimate before completing the request.

Appeals. If we decline to act on your request, we will tell you why and explain how to appeal. To appeal, reply to our response or contact us at privacy@pieinsurance.com or submit a request at https://www.pieinsurance.com/legal/privacy/ccpa. We will respond in writing within forty-five (45) days of receiving your appeal, or within such a longer period as applicable state law allows, describing the action we have taken or declined to take and the reasons for that decision. If we deny your appeal, we will provide you with a method to contact your state Attorney General or other applicable regulator to submit a complaint.

Non-discrimination. We will not discriminate against you for exercising any of your CCPA or CPRA or any other state provided rights. Unless permitted by law, we will not deny you goods or services; charge you different prices or rates for goods or services, including through granting discounts or other benefits or imposing penalties; provide you with a different level or quality of goods or services; or suggest that you may receive a different price, rate, level, or quality of goods or services.

Opt-in vs Opt-out consent. As noted above regarding “Sensitive Personal Information,” to any extent that processing sensitive personal information is not granted to us by law, we rely on the consent procured by the subscribing/covered employer or entity, third party or service provider. Assuming such consent, we will not condition the purchase of insurance on that consent except where the information is necessary to underwrite, issue, service, or administer a policy or claim. We will use sensitive data only for the purpose disclosed at the time consent was obtained, or as otherwise permitted or required by law, and we limit our collection of sensitive data to what is reasonably necessary for that purpose. In states that require notice and an opportunity to opt-out rather than opt-in consent please refer to the rest of this Privacy Policy and below to the sub-section entitled “Withdrawing your consent.”

Withdrawing your consent. You may withdraw consent to our processing of your sensitive data at any time, by a method at least as easy as the method used to give it. To withdraw consent, email privacy@pieinsurance.com or submit a request at https://www.pieinsurance.com/legal/privacy/ccpa. We will cease the affected processing as soon as practicable and in no event later than fifteen (15) days after receiving your request. Withdrawing consent does not affect processing that occurred before we received the request, and does not apply to information we are required to collect, use, retain, or disclose to underwrite, issue, service, or administer a policy or claim, to detect or prevent fraud, or to comply with legal, regulatory, or Workers' Compensation obligations.

Profiling and automated decision-making. As a general rule, we do not use artificial intelligence or automated tools to make final underwriting, pricing, or claims decisions about you without human review. However, we may conduct premium audits — the review of payroll, receipts, job classifications, and other exposure information used to determine the final earned premium for your policy — on a fully automated basis for a subset of policies. An automated premium audit may result in an additional premium charge or a return premium. As noted in Section 8.3, we implement appropriate safeguards for those systems, including regular testing and monitoring for bias and accuracy, security measures to protect data used in AI processing, data minimization so that only information necessary for a specific AI purpose is used, and retention limits so that AI-processed data is retained only as long as necessary. Where we use AI services provided by third-party vendors, those relationships are governed by contractual requirements designed to comply with applicable laws and regulations.

You may request human review of, and appeal, the result of any automated premium audit, and you may request an explanation of the principal factors that led to that result, using the contact methods described above under "Withdrawing your consent." Where state law gives you the right to opt out of profiling in furtherance of decisions that produce general legal or similarly significant effects concerning you, you may exercise that right using the contact methods described above under "Withdrawing your consent," and you may separately request an explanation of an adverse underwriting decision as described in Section 10. If we begin using automated decision-making technology to make a significant decision about you, we will provide notice describing that use and how to opt out before doing so, to the extent required by applicable law.

Biometric information. Where we collect biometric identifiers or biometric information — for example, fingerprint or facial-geometry data used to control access to our systems — we will, before collection, inform you in writing that the information is being collected or stored, inform you in writing of the specific purpose and the length of time for which it will be collected, stored, and used, and obtain your written release. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information, and we disclose them only with your consent, to complete a transaction you requested, or as required by law or valid legal process. We maintain a written retention schedule and destruction guidelines providing that biometric identifiers and biometric information are permanently destroyed when the initial purpose for collecting them has been satisfied or within three (3) years of your last interaction with us, whichever occurs first. A copy of that schedule is available on request using the contact information in Section 16.

11. Children's Privacy

Our products and services are intended for businesses and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children online.

12. State-Specific Provisions

California specifics. This sub-section supplements the rest of this Policy and applies solely to visitors, users, consumers, employees, applicants, businesses, and others who reside in the State of California ("consumers" or "you"). We adopt this notice to comply with the California Consumer Privacy Act of 2018 ("CCPA"), as amended by the California Privacy Rights Act of 2020 ("CPRA"). California consumers have the right to know the categories and specific pieces of personal information we collect, use, and disclose; the right to delete; the right to request correction of inaccurate information; the right to limit the use and disclosure of sensitive personal information; the right to receive personal information in a portable and, to the extent technically feasible, readily usable format; the right to opt out of the sale or sharing of personal information and, to the extent required by applicable law, of the use of automated decision-making technology to make a significant decision concerning you; and the right not to be discriminated or retaliated against for exercising these rights. We may limit our response to a request as permitted by law — for example, where we must retain information to provide services to you or for legal and compliance purposes, or where information is excluded from the CCPA's scope (including information covered by HIPAA, the California Confidentiality of Medical Information Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the California Financial Information Privacy Act, or the Driver's Privacy Protection Act of 1994).

To the extent we share personal information, and may somehow be construed as “sale” of such information, as those terms are defined by the CCPA, California requires us to post a “Do Not Sell or Share My Personal Information” link on our home page, which you can also access by clicking here: [hyperlink to Do Not Sell My Personal Information at home page]. Because we use and disclose sensitive personal information only for purposes permitted under California Civil Code section 1798.121 and 11 CCR section 7027, a “Limit the Use of My Sensitive Personal Information” link is not required. The “Do Not Sell My Personal Information” link is designed for you to instruct us on limiting our usage and/or sale of your information for non-exempt purposes, such as the general information of website visitors and advertising cookies.

In general, we, including our vendors and service providers, collect the following California-regulated categories of Personal Data (PI in below chart) from you.


CategoryExamplesCollected
A. Identifiers.A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers.YES
B. PI categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, license or state identification card number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some information included in this category may overlap with other categories.YES, after account creation
C. Protected classification characteristics under California or federal law.Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).YES, after account creation
D. Commercial information.Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.YES, after account creation
E. Biometric information.Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.YES, after account creation
F. Internet or other similar network activity.Browsing history, search history, information on a consumer's interaction with websites, services, or advertisement.YES
G. Geolocation data.Physical location or movements.YES, but not precise geolocation
H. Sensory data.Audio, electronic, visual, thermal, olfactory, or similar information.YES, after account creation
I. Professional or employment-related information.Current or past job history or performance evaluations.YES, after account creation
J. Non-public education informationEducation records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.NO
K. Inferences drawn from other PI.Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.YES


California Sharing Your Information for a Business Purpose. In the preceding twelve (12) months, we have disclosed the following categories of Personal Information for a business purpose with our affiliates and service providers:

  • Category A: Identifiers such as real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address
  • Category B: PI categories
  • Category C: Protected classification characteristics
  • Category D: Commercial information
  • Category E: Biometrics information
  • Category F: Internet or other similar network activity
  • Category G: Geolocation Data
  • Category H: Sensory data
  • Category I: Professional or employment-related information
  • Category K: Inferences drawn from other PI

California Sources of Personal Information. We collect the categories of personal information identified above from the following categories of sources: directly from you; from your employer or the entity contracting for our services; from your agent, broker, or producer; from other insurers, third-party administrators, and claims adjusters; from health care and vocational rehabilitation providers in connection with a claim; from consumer reporting agencies, data analytics providers, and public records; and automatically from your device and browser when you visit our website or online portals.

California Purposes for Collection and Use. We collect and use each category of personal information for the business and commercial purposes described in Section 3 of this Policy, including underwriting, rating, and issuing policies; servicing and administering policies and claims; billing and payment processing; detecting and preventing fraud; complying with legal and regulatory obligations; providing customer support; and, for the categories described in Section 9, website analytics and advertising. We will not collect additional categories of personal information, or use personal information for materially different purposes, without first providing notice to you.

California Sale and Sharing of Personal Information. Except for the advertising cookies and similar technologies described in Section 9, which may constitute “sharing” for cross-context behavioral advertising under the CCPA and which you may opt out of as described in that Section, we do not sell personal information and we do not share personal information for cross-context behavioral advertising. We do not have actual knowledge that we sell or share the personal information of consumers under eighteen (18) years of age, and we do not knowingly do so.

California Retention. We retain each category of personal information identified above for the period described in Section 7 of this Policy — generally the longer of seven (7) years after a policy, underwriting file, or claim is closed, or such longer period or by the statute of limitations governing the type of claim involved for identifiers, California Customer Records categories, protected classification characteristics, commercial information, professional or employment-related information, biometric information, and inferences used for underwriting or claims purposes; and fourteen (14) months for internet or other network activity, geolocation data, and inferences derived from website analytics and advertising — or for such longer period as required by applicable insurer record-retention requirements, statutes of limitation, or a legal hold. We retain sensitive personal information for no longer than is reasonably necessary for the purposes for which it was collected.

California Sensitive Personal Information. The sensitive personal information we collect consists of Social Security numbers; driver’s license, state identification card, account log-in, financial account, and payment card information; precise geolocation; and information concerning health, as further described above. We collect and use sensitive personal information only for the purposes permitted by California Civil Code section 1798.121 and 11 CCR section 7027 — including underwriting, issuing, servicing, and administering policies and claims, verifying identity, detecting and preventing fraud, and complying with legal obligations — and we do not use or disclose it for purposes beyond those permitted purposes.

California Shine the Light Law. Under California law, California residents are entitled, once per calendar year, to ask us for a notice identifying the categories of personal customer information that we share with certain third parties for the third parties’ direct marketing purposes, and providing contact information (i.e., names and addresses) for these third parties. If you are a California resident and would like a copy of this notice, please submit a written request to us via email at privacy@pieinsurance.com. You must put the statement “Your California Privacy Rights” in your request and include your name, street address, city, state, and ZIP code. We are not responsible for notices that are not labeled or sent properly, or do not have complete information.


Maryland specifics. For Maryland residents, we do not sell sensitive data, with or without consent, and we collect, process, and share sensitive data only where strictly necessary to provide or maintain a specific product or service you have requested, or as otherwise permitted by the Maryland Online Data Privacy Act.


Nevada consumer health data. For residents of Nevada, consumer health data — information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status — is collected only with your consent (which we procure through your employer or entity contracting for our services), and is not sold, although shared only pursuant to a separate, valid signed authorization that is distinct from that consent, as required by the Nevada Revised Statutes Chapter 603A, or pursuant to regulatory exemptions already noted in this Privacy Policy. We do not use consumer health data for targeted advertising, and we do not use geofencing around any facility that provides health care services to collect consumer health data or to send you health-related advertising. You may withdraw consent, request access to, or request deletion of your consumer health data using the contact methods noted above under “Withdrawing your consent.” Health and medical information collected in connection with a Workers' Compensation claim remains governed by Section 5 of this Policy and applicable Workers' Compensation law.

Washington consumer health data. For residents of Washington, we comply with the Washington My Health My Data Act ("MHMDA"), chapter 19.373 RCW. Information governed by and collected, used, or disclosed pursuant to the Gramm-Leach-Bliley Act or HIPAA is exempt from the MHMDA, as is other information exempted under the Act; these are data-level exemptions, so they do not exempt us as an entity. For any consumer health data we collect that is not exempt (i.e., information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status), we collect it only with your consent, and we do not sell it absent a separate, valid signed authorization that is distinct from that consent. We do not use consumer health data for targeted advertising, and we do not implement a geofence around any facility that provides in-person health care services. You have the right to confirm whether we collect, share, or sell your consumer health data, to withdraw your consent, to access it, and to request its deletion, and we will not discriminate or retaliate against you for exercising those rights. You may exercise these rights using the contact methods described in Section 16. Section 5 of this Policy and applicable Workers' Compensation law continue to govern health and medical information collected in connection with a Workers' Compensation claim.

Montana. The Montana Consumer Data Privacy Act ("MCDPA"), effective October 1, 2024, exempts financial institutions and their affiliates governed by Title V of the Gramm-Leach-Bliley Act, as well as information collected and processed under HIPAA and the Fair Credit Reporting Act. Because Pie is a GLBA-regulated insurer, the MCDPA does not apply to us at the entity level. As a matter of practice, we nonetheless honor requests from Montana residents to access, correct, delete, and obtain a portable copy of personal information that is not otherwise exempt — such as information collected from website visitors and through advertising cookies — and to opt out of targeted advertising, any sale of personal information, and profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.

Alaska, Hawaii, Maine, Missouri, North Dakota, Ohio, South Dakota, West Virginia, and Wyoming. For residents of these states, our collection, use, and disclosure of personal information is governed principally by each state's insurance privacy and information-practices laws; each state's insurance data security law, in states that have adopted the NAIC Insurance Data Security Model Law, including the information security program, cybersecurity event investigation, and regulator notification obligations described in Section 6; each state's data breach notification law; the Gramm-Leach-Bliley Act privacy and safeguards rules; HIPAA where applicable; and any narrower state privacy statute that applies to a particular category of information. Residents of these states may exercise the access, correction, deletion, and communication-preference choices described in Section 10, which we honor as a matter of practice, and may request the specific reasons for an adverse underwriting decision where state insurance law provides that right. If a comprehensive consumer privacy law is enacted or becomes effective in one of these states, we will comply with it and update this Policy accordingly.

Other states. Because Pie is a licensed insurer subject to the Gramm-Leach-Bliley Act, most state comprehensive consumer privacy laws that exempt GLBA-regulated financial institutions do not apply to us. In states that do not provide an entity-level GLBA exemption — including Oregon, Minnesota, and Connecticut — the following rights apply to personal information that is not otherwise exempt (such as information collected from website visitors and through advertising cookies): the rights to access, correct, and delete personal information; the right to obtain a copy of personal information you provided to us in a portable and, to the extent technically feasible, readily usable format; the right to opt out of targeted advertising, of any sale of personal information, and of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you; and, in Oregon and Minnesota, the right to obtain a list of the specific third parties to which we have disclosed personal information, and, in Delaware, a list of the categories of third parties to which we have disclosed personal information. Minnesota residents also have the right to question the result of profiling. Additional state-specific notices and rights — including opt-out notices, adverse underwriting decision explanation rights, and insurance data security law compliance certifications in states that have adopted the NAIC Insurance Data Security Model Law — apply in each state in which we are licensed and are provided throughout this Privacy Policy as required by applicable law.

13. Third-Party Links

Occasionally, at our discretion, we may include or offer third-party products or services on our website. These third-party sites have separate and independent privacy policies, and we have no responsibility or liability for the content or activities of these linked sites, nor do these links constitute an endorsement. We nonetheless seek to protect the integrity of our website and welcome feedback about other third-party sites.

14. Notice to Employees and Job Applicants

Pie Insurance collects personal and sensitive personal information about employees, job applicants, officers, directors, and contractors in the ordinary course of business, including identifiers and personal information (such as name, signature, Social Security number, address, telephone number, and government-issued identification numbers), characteristics of protected classifications, commercial information, internet or network activity information, geolocation data from Company devices, biometric information used for access to secured access points, audio, electronic and visual information, professional or employment-related information, non-public education information, and inferences drawn from the foregoing. We collect this information from you, prior employers, references, recruiters and job-related social media platforms, third-party sources of demographic information, background check companies and drug testing facilities, and claim administrators and investigators. We use it to operate, manage, and maintain our business; for hiring, retention, and employment purposes; and for related business purposes, including emergency services, research and analytics, facilities and infrastructure maintenance, quality and safety assurance, risk and security controls and monitoring, and any other purpose authorized by state or federal law. We disclose it to service providers (including HR, recruiting, benefits, wellness, and payroll providers), governmental agencies, affiliates for regulatory reasons, insurance agents and brokers, other insurers, reinsurance companies and claims administrators, insurance regulators and law enforcement officials, lienholders and other persons having a beneficial or legal interest, others to prevent fraud or respond to a subpoena or search warrant, companies providing motor vehicle reports, credit reports, or claims history, and contractors and other third parties who require the information to support our business. Applicants and employees have the rights to know, delete, opt out, correct, limit the use of information collected, go to court, and not to be discriminated or retaliated against for exercising these rights. Pie Insurance has never sold the personal information of any past or present employee or job applicant and has no intention of doing so.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last Updated" date at the top of this Policy indicates when it was last revised. Material changes will be communicated as required by applicable law. We reserve the right to modify this Policy at any time, and changes are effective immediately upon posting to the Privacy Policy page on our website.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:

Pie Insurance

Attn: Privacy

12162 S Business Park Drive, Suite 113

Salt Lake City, UT 84020

privacy@pieinsurance.com

https://www.pieinsurance.com/privacy

You may also contact your state Department of Insurance to file a complaint or ask questions about your rights as a policyholder or claimant.