What we collect, why we collect it, who receives it, and how to tell us to stop.
Note: Effective September 18, 2026.
JRF GROUP is an independent life and mortgage-protection insurance agency (National Producer Number 22276806). We are the controller of the personal information collected through https://jrfgrp.com. We are not an insurance carrier; policies are issued by third-party carriers.
This policy explains what we collect through this website, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. Questions, or a request about your information, go to jrf@jrfgrp.com.
We have not appointed a Data Protection Officer. We are not required to under the laws that apply to us, and we would rather say so plainly than imply a role that does not exist.
This policy covers everyone who visits this website, requests a quote, or contacts us through it — whether or not you become a client.
We are licensed to do business in 27 U.S. states and the District of Columbia, and our services are directed to U.S. residents. If you are in the European Economic Area, the United Kingdom, Brazil, or South Africa, we still honor the rights described below for any information we hold about you.
We collect only what we need to give you a meaningful answer about coverage. Most of it is information you type in yourself.
About the health questions
Your health and tobacco answers are used to point you toward relevant coverage and to brief the licensed professional who contacts you. They are never sent to Meta or any advertising platform, and they are not used to target ads to you.
We do not collect Social Security numbers, passport or other government identification numbers, payment card or bank details, precise GPS location, or biometric data through this website. If you go on to apply for a policy, the carrier — not this website — may collect additional information under its own privacy notice.
| Purpose | Legal basis (GDPR / LGPD / POPIA) |
|---|---|
| Responding to your quote request and connecting you with a licensed professional | Performance of a contract, or steps taken at your request before entering one |
| Contacting you by phone, text, or email about coverage | Your consent, which you give at the point of submission and can withdraw at any time |
| Measuring which ads and pages lead to quote requests | Your consent (advertising and analytics cookies) |
| Keeping the site secure, preventing fraud and abuse, and fixing faults | Our legitimate interests in operating a safe, working service |
| Keeping records required of a licensed insurance agency | Compliance with a legal obligation |
We do not use your information to make any automated decision that produces a legal or similarly significant effect about you. Nothing on this site determines whether you qualify for coverage, what you will pay, or whether a carrier will approve you — those decisions are made by the issuing carrier through its own underwriting process.
Under the California Privacy Rights Act, “sharing” means disclosing personal information to a third party for cross-context behavioral advertising — showing you ads based on your activity across different sites and services. Running the Meta Pixel meets that definition.
So, stated plainly: we share personal information with Meta for cross-context behavioral advertising. We do this so we can tell which of our ads lead to genuine quote requests and stop paying for the ones that do not.
We do not knowingly share or sell the personal information of anyone under 16.
Quote requests and related correspondence are kept for as long as needed to serve your request and to meet the recordkeeping obligations that apply to a licensed insurance agency, which in most states run several years past the last interaction. Website technical logs are kept for a short operational period. Your cookie choice stays in your browser until you clear it or change it.
Personal information is stored on servers in the United States. We protect it with encryption in transit and at rest, access limited to the people who need it to do their jobs, and periodic review of those permissions. Our hosting and email providers are selected on their security practices and are contractually bound to protect the data they process for us.
No method of transmission or storage is perfectly secure, and we will not claim otherwise. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires it, within the timeframes the law sets.
We operate in the United States and store information there. If you access this site from outside the United States, your information is transferred to and processed in the United States, where data protection law may differ from your own country's.
Where we transfer personal information out of the European Economic Area, the United Kingdom, Brazil, or South Africa, we rely on an appropriate safeguard — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the recipient's certification under the EU–US Data Privacy Framework, as applicable to that recipient. You can ask us which safeguard applies to a particular transfer.
Depending on where you live, some or all of the following rights apply to you. We extend them to everyone who asks, wherever they are, because maintaining two standards of respect is not worth the trouble.
Email jrf@jrfgrp.com and tell us what you would like us to do. We may need to verify your identity before we act, by matching what you send us against what we already hold — we will ask for the minimum that makes us confident, and we will not use it for anything else.
We respond within the period the applicable law sets — 30 days for most requests under U.S. state law and 15 days under Brazil's LGPD, extendable where a request is complex and we tell you why. Exercising any of these rights is free, and we will never treat you differently for doing so.
If we decline a request and you disagree, you may appeal by replying to our response, or by writing to jrf@jrfgrp.com with the word “Appeal” in the subject line, within 60 days. Include your original request and why you think the decision was wrong. We will reconsider and give you a written explanation of the outcome.
If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, or another state with a comprehensive privacy law, you have the rights listed above — to know, access, correct, delete, obtain a portable copy, and opt out of targeted advertising and of any sale or sharing of your personal information.
Use the “Your Privacy Choices” link at the foot of any page and switch Advertising off. That is the opt-out mechanism for this site; it takes effect immediately and applies to both the browser pixel and our server-side reporting to Meta.
California treats health information as sensitive personal information. We collect a general health self-description and a tobacco question, and we use them only to identify relevant coverage and to brief the licensed professional who contacts you — purposes for which the CPRA does not require a limitation right. We do not use them to infer characteristics about you, and we do not disclose them for advertising.
We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
Someone may submit a request on your behalf if they provide written proof of your authorization. Send it to jrf@jrfgrp.com; we may still contact you directly to confirm.
When you submit a quote request, you are asked to agree to be contacted about coverage. That consent is specific, separate from your cookie choices, and never required in order to browse this site.
If you ask us to stop contacting you, we keep the minimum record needed to make sure we honor that request — your contact details on a suppression list, used for nothing else.
This site is intended for adults. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the information of anyone under 16. If you believe a child has given us information, email us and we will delete it.
We update this policy when what we do changes. The effective date at the top always reflects the current version. If a change materially affects how we use your information, we will tell you before it takes effect and, where the law requires consent, ask for it again rather than assume it.
For any privacy question, request, or complaint, email jrf@jrfgrp.com. We read everything sent there and respond within the timeframes described above.