HealthSherpa Privacy Notice
Effective Date: June 1, 2026
Welcome to the website of HealthSherpa, a company that provides information and services to help you find, enroll in, and make the best use of your marketplace health insurance! As used in this Privacy Notice, the terms "HealthSherpa," "we" and "us" refer to Geozoning, Inc. dba HealthSherpa. To the extent applicable, they also refer to our affiliates, service providers and licensors, and their respective officers, directors, employees, contractors and agents. If you are accepting the terms of this Privacy Notice as an employee or representative of a company or other legal entity, the terms "you" and "your" will refer to both you, personally, and the entity you represent.
HealthSherpa is committed to protecting and respecting your privacy. This Privacy Notice describes how we collect, use, protect, and share information about you that we obtain when you access and use our Website (what we call "Personal Information," defined below), including when you register for an account, request a quote, or submit questions or feedback. This Privacy Notice also applies to information that we obtain when you communicate or interact with us outside of the Website, including by e-mail, telephone and otherwise.
Your use of our Website is also governed by our Consumer Terms of Use and/or Agent Terms of Use, as applicable (the "Terms of Use"), any additional terms made available to you in connection with certain features, functionality, tools, content and promotions available on or through the Website ("Supplemental Terms"), and any and all policies and rules referenced herein or therein, posted on the Website, or otherwise communicated to our Users (the "Website Policies").
Please read this Privacy Notice carefully before you use our Website or communicate with us.
For purposes of this Privacy Notice:
- "Users" means any and all individuals that access or use the Website, including applicants for health insurance, insurance agents, and other registered users. References to "access" and/or "use" of the Website (and any variations thereof) include the acts of accessing or browsing the Website, and accessing or using the services, information, content, features, functionality, tools and promotions available on or through the Website.
- "Website" refers to any website owned, operated, or powered by HealthSherpa (including the website currently located at https://acrisure.healthsherpa.com/). References to the "Website" include any and all services, information, content, features, functionality, tools, and promotions available on or through each such website.
BY ACCESSING OR USING OUR WEBSITE OR COMMUNICATING WITH US OUTSIDE OF THE WEBSITE, YOU ACKNOWLEDGE THAT YOU HAVE REVIEWED THIS POLICY AND ARE FAMILIAR WITH THE PRACTICES DESCRIBED HEREIN. THIS PRIVACY NOTICE MAY BE UPDATED AND AMENDED FROM TIME TO TIME.
Please click on the sections below to learn more about our Privacy Notice:
- INFORMATION WE COLLECT
- HOW INFORMATION MAY BE USED
- HOW INFORMATION MAY BE SHARED
- COOKIES, PIXELS, BEACONS, AND OTHER TRACKING TECHNOLOGIES
- YOUR CHOICES
- DATA RETENTION
- SECURING YOUR INFORMATION
- CHILDREN
- LINKS TO THIRD-PARTY WEBSITES
- INTERNATIONAL JURISDICTIONS
- USE OF ARTIFICIAL INTELLIGENCE (AI)
- CHANGES TO OUR PRIVACY NOTICE
- CONTACT US
INFORMATION WE COLLECT
Information You Provide to Us
We may collect personal information and other types of information when you interact with this Website or our affiliates, including when you register for an account, solicit a health insurance quote, prepare or submit a health insurance application directly or on behalf of another individual, update your email preferences, respond to a survey or provide other feedback about the Website, or contact us with questions or comments about the Website.
We may also collect information about you when you opt in to receive text messages from us (for example, when you sign up for health insurance). You may opt in to receive such updates and offers by providing your mobile telephone number through the Website.
We may also collect information about you when a company or organization authorizes you to manage its account or use this Website on its behalf.
Personal Information
We, or third parties on our behalf, may collect information that identifies you ("Personal Information"). This includes:
- contact information (such as name, address, email address and telephone number);
- date of birth;
- gender;
- payment card information;
- information associated with your account;
- Social Security number;
- protected health information, including health or medical history; and
- geographic location.
Information Generated from Use of the Website
We also collect certain information when you access, browse, and use our Website, including information that we automatically receive and record from your browser or mobile platform on our server logs. This information helps us operate and provide our Website to you, and includes standard information about visits and system capabilities, such as:
- information about the device(s) you use to access our Website, including MAC address, IP address, browser type and version, your location, time zone setting, browser plug-in types and versions, operating system and platform, device type, device and application identifiers, operating information, mobile carrier, and cookies;
- information about your visits to the Website, including the full URL clickstream to, through, and from the Website, including dates and times;
- information we need and use to facilitate your use of our Website (including to provide access to third party websites and services), such as URL requests, destination IP addresses, or device configuration details;
- pages you view, searches you run, length of time browsing search results, specific search results you select to view, length of visits to other pages, page interaction information (such as scrolling, clicks, and mouse-overs), your engagement with certain variable/dynamic elements of a page and methods used to browse away from the page;
- page response times and download errors; and
- information generated using cookies and beacons. See below for more details regarding our use of cookies and beacons, and your choices with respect to such tracking technologies.
Information from Other Sources
We may receive certain information about you from the organizations or entities on behalf of which we provide the Website to you and/or on behalf of which you access or use the Website. We may also supplement the information we collect from your use of the Website with information collected by third parties. Such third parties may include service providers, such as Google Inc., advertising partners, and ad networks that help us understand and provide better service to our Users.
On occasion, we may compare or combine Personal Information from third party sources to/with other information we have collected. For example, we may obtain contact information from other sources in order to contact you if we think you or the company you represent would be interested in our Website.
We may also receive certain information from third parties with which we partner. For example, health insurance providers may share information with us about your use of their services or websites to help us provide our services to you.
HOW INFORMATION MAY BE USED
We, or third parties acting on our behalf, may use the Personal Information for various purposes, including to:
- create and manage your account;
- provide you with Website content;
- operate our Website, including, without limitation, providing quotes, and submitting and monitoring health insurance applications, access management, payment processing, Website administration, internal operations, troubleshooting, data analysis, testing, research, statistical and survey purposes;
- understand how users interact with this Website and our services;
- send you information that enables you to use our Website;
- contact you about activity on your account;
- provide you access to, and updates regarding health insurance and other related offers via text message;
- respond to your requests, feedback or inquiries;
- notify you about updates, information, or alerts regarding our Website;
- process payments;
- protect and enforce our rights and the rights of other Users against unlawful activity, including identify theft and fraud, and other violations of our Consumer and Agent Terms of Use;
- protect and enforce our rights arising under any agreements entered into between you and us, including billing and collection;
- protect the integrity and maintain the security of our Website, including secured areas of the Website;
- operate, evaluate, and improve our business, as well as our products and services, including conducting surveys and market research; developing new products, services, and promotions (such as, for example, special events, programs, offers, contests); analyzing and enhancing existing products, services, and promotions; debugging our offerings or Website; managing our communications; and performing accounting, auditing, and other internal functions;
- provide you with information and advertisements about products, services, and promotions, from us or third parties, that may interest you, including targeted advertising;
- comply with requirements imposed by law, regulations, contracts, and programmatic recordkeeping requirements; or
- evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, including as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us is among the assets transferred.
We may also use Personal Information for any purpose for which you may provide consent.
We may also aggregate or anonymize data about your use of the Website or our other products and services, to the extent permitted by Law, for similar purposes.
HOW INFORMATION MAY BE SHARED
We will not sell or share your Personal Information with third parties for the third party's own purposes without at least providing you an opportunity to opt out of such sale or sharing, if required by law. We may disclose your Personal Information to third parties, including:
- The Centers for Medicare and Medicaid Services ("CMS") in order to obtain an eligibility determination for you and to enroll you in health insurance plans offered on the federal healthcare exchange;
- Organizations or entities on behalf of which we are providing the Website to you and/or on behalf of which you access or use the Website, such as your employer, and other companies associated with those organizations or entities in order to enable their systems to operate with the Website;
- Third party insurance companies to which you submit an application for health insurance on or through the Website;
- Your employer(s), affinity group, and/or benefits administrators or consultants, if you are referred to the Website by such respective parties;
- If you are a licensed insurance agent using HealthSherpa's agent platform, the designated administrator of your account, if you have an individual subaccount, regarding use of the Services by individual subaccounts;
- Your licensed insurance agent, if applicable;
- Our service providers, to operate our business and provide our Website and services to you;
- A buyer or other successor in interest to HealthSherpa in the event of a merger, divestiture, restructuring, reorganization, dissolution, liquidation, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which Personal Information held by us about our Users is among the assets transferred;
- Other third parties with your consent for any purpose disclosed by us when you provide the information; and
- Other third parties, including government authorities and law enforcement authorities, if required by law, regulation, or legal process; to protect users, HealthSherpa, or the public; or to investigate and defend against legal claims; or
- Any other sharing or disclosure permitted by law with your consent.
In addition, we may share information about your use of our Website, including in aggregated or anonymized form, in the following circumstances:
- with our partners about how our Users collectively use our Website, so that our partners may also understand how often people use their services and our Website;
- with analytics companies, search engines, or other service providers that help us improve our Website;
- to report to our affiliates, licensors and service providers, advertising partners and ad networks about the use of various aspects of the Website;
- with other Users or prospective Users of the Website; and
- to advertisers and advertising networks to select and serve relevant advertisements.
Where our disclosure of Personal Information involves Protected Health Information subject to HIPAA, we enter into a Business Associate Agreement with the applicable third party prior to disclosure if required by HIPAA.
Notice to California Residents / Your California Privacy Rights
The California Consumer Privacy Act ("CCPA") provides California residents with certain rights with respect to their Personal Information that is collected by businesses. If you are a California resident, please review HealthSherpa's California Privacy Notice.
COOKIES, PIXELS, BEACONS, AND OTHER TRACKING TECHNOLOGIES
We, and third parties working on our behalf, may use cookies, beacons and similar automatic data collection technologies, now or in the future, to support the functionality of our Website and for other purposes described in this Privacy Notice. These technologies help us provide a better experience when you visit our Website, analyze and compile the usage of this Website, provide advertising, and allow us to improve our Website. The technologies we may use for this automatic data collection may include:
- Browser Cookies. A browser cookie is a small file placed on the hard drive of your computer. That cookie then communicates with our servers or those of other companies that we authorize to collect data for us, and allows recognition of your personal computer. We associate cookies with Personal Information only if you use the logged in areas of the Website, request a service, use the personalization services available as part of the Website, or ask us to contact you with additional marketing information. We do not otherwise collect Personal Information from browser cookies and we do not associate browser cookies with your Personal Information. You may use the tools available on your computer or other device to set your browser to refuse or disable all or some browser cookies, or to alert you when cookies are being set. However, if you refuse or disable all browser cookies, you may be unable to access certain parts or use certain features or functionality of our Website. Unless you have adjusted your browser settings so that it refuses all cookies, we may use cookies when you direct your browser to our Website.
- Beacons. Our Website and e-mails may contain small electronic files known as beacons (also referred to as web beacons, clear GIFs, pixel tags and single-pixel GIFs) that permit us to, for example, count Users who have visited those pages or opened an e-mail and for other website-related statistics. Beacons in e-mail marketing campaigns allow us to track your responses and your interests in our content, offerings and web pages. You may use the tools in your device to disable these technologies as well.
- Other Tracking Technologies. Our Website may also use other tracking technologies such as device fingerprinting, pixels, web caching, device session identifiers, embedded scripts, location-identifying technologies, and other similar technologies. These technologies execute on our Website or in your browser and allow us to recognize you when you return to the Website and understand how our Users use and interact with our Website.
Cookies deployed on the Website may be classified into the following categories:
| Cookie Type | Description |
|---|---|
| Essential Cookies | These are cookies that our Website needs in order to function, including to detect fraud and to support security on the Website. Without these essential cookies, the Website will not perform as intended. Website visitors cannot disable these cookies, and exercising the right to opt out of cookies will not impact the placement of essential cookies. |
| Performance/Analytics Cookies | Performance/Analytics cookies provide us with information regarding how visitors navigate and interact with the Website, such as how many visitors browsed the Website. |
| Advertising Cookies | Advertising cookies help us, or other third parties, conduct targeting advertisements on our Website and third-party sites. |
The Website currently deploys tracking technologies from the following parties:
- Mixpanel
- HubSpot
- Google Tag Manager
- Google Analytics
- LocalizeJS
- FreshChat
- NiceCXOne
- Sentry
- Datadog
- LogRocket
- Osano
You may opt out of the placement of non-essential cookies by opting out of all non-Essential categories of cookies through the cookie preference management platform that is displayed when you access the Website and select the cookie icon. You may change your preferences at any time using the cookie preference management platform on the Website. We use third parties, including Osano, to help manage your cookie preferences for non-essential cookies. Please note that exercising the right to opt out of non-essential cookies on the Website will not impact your cookie preferences on the websites owned or managed by our affiliates, business partners, or other third parties, and you must manage your cookie preferences for each of those websites.
While many web browsers accept cookies by default, many browsers also include tools to manage or disable cookies. You can visit the help function on most browsers to modify how your browser handles cookies. However, if you disable cookies, certain features of this website may not function properly.
Additionally, you may enable the Global Privacy Control ("GPC") or other universal opt-out tool to communicate your opt-out preferences, if your browser or device supports such a tool. For more information about GPC, please visit: https://globalprivacycontrol.org/.
Some web browsers allow "Do Not Track" signals or settings, which may allow you to request that you do not want certain information about your web page visits tracked and collected across websites. At this time, this Website does not respond to "Do Not Track" signals or settings.
Our service providers, advertising partners and ad networks may use cookies, beacons, and other similar tracking technologies to collect and share information that may identify you or your device about your activities on our Website. In addition, third parties that are unaffiliated with us may collect information about you, including tracking your browsing history, when you use our Website. We do not have control over these third-party collection practices. If you wish to minimize these third-party collections, you can adjust the settings of your browsers or install plug-ins and add-ins.
YOUR CHOICES
Depending on applicable laws or the jurisdiction in which you reside, you may have certain privacy rights. These may include the rights:
- To access, know about, or confirm the processing of your Personal Information, including the categories of, and sources of, Personal Information we collect about you, the business or commercial purpose(s) for collecting, selling, or sharing your Personal Information, the categories of third parties to which your Personal Information is disclosed, and the specific pieces of Personal Information we have collected about you.
- To correct inaccurate Personal Information held by us.
- Subject to certain limitations, to request that we delete your Personal Information.
- To receive a copy of your Personal Information in a portable format, where technically feasible.
- To opt-out of the "sale" or "sharing" of your Personal Information, or the use of your Personal Information for "targeted advertising" (as these terms are defined under applicable privacy laws). Please note that we do not sell your Personal Information, but we may share your Personal Information for advertising purposes.
- To limit the use and disclosure of sensitive Personal Information.
- To not be discriminated against for exercising your privacy rights.
Certain exceptions under applicable laws may apply, which may limit our ability to fulfill your request to exercise your privacy rights. We will inform you of any such limitation, consistent with our legal obligations.
To exercise your choices and rights, please contact us using the contact information provided in this Privacy Notice. We may request or require additional information to verify your identity in order to fulfill your request.
You may designate an authorized agent to make a request on your behalf. Authorized agents will be required to provide proof of their authority to act on your behalf by providing relevant documentation. We may contact you to confirm an authorized agent's representation and to verify your identity.
Limit Use of Personal Information for Health Insurance Purposes
You may request that we limit the collection, creation, disclosure, access, maintenance, storage and use of your Personal Information for the sole purpose of our assisting you in applying for health insurance or obtaining an eligibility determination, facilitating payment for your first premium, assisting you in updating or canceling your enrollment in a health insurance plan, and for performing other authorized functions specified in our agreements with CMS. You may request such a limitation by sending an email to privacy@healthsherpa.com or calling us at (855) 772-2663.
Email Communications
You may have the opportunity to receive certain communications from us related to our Website. If you provide us with your e-mail address in order to receive communications, you can opt out of marketing e-mails at any time by following the instructions at the bottom of our e-mails and adjusting your e-mail preferences. Please note that certain e-mails may be necessary for the operation of our Website. You will continue to receive these e-mails, if appropriate, even if you unsubscribe from our optional communications.
Text Alerts
You may have the opportunity to receive certain information, updates and/or offers from us via text communications. If you provide us with your mobile number in order to receive such communications, you can opt out of receiving text messages at any time by contacting us at customer_support@healthsherpa.com.
Updating Information
The accuracy of the information we have about you is very important. To review, correct or delete your Personal Information, please contact us at customer_support@healthsherpa.com. For more information about your choices, or to review or correct your Personal Information, please follow the prompts on the Website, or contact us as indicated in the "Contact Us" section of this Privacy Notice.
DATA RETENTION
We will retain your Personal Information for as long as your account is active or as needed to provide our services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, enforce our agreements, or as otherwise described in this Privacy Notice.
Please note that once your application has been submitted to your chosen health insurance company or any other relevant party (such as the federal government in the case of an application involving advanced premium tax credits) you may be required to contact the insurance company or such other party directly to update your application or other information that they may have collected about you.
SECURING YOUR INFORMATION
The security of your information is important to HealthSherpa, and we have established administrative, technical, and physical safeguards designed to protect your Personal Information against unauthorized alteration, access, loss, theft, use or disclosure. However, no method of transmission or storage can guarantee complete security of your information. As a result, HealthSherpa cannot guarantee the absolute security of your personal information.
You are responsible for protecting your password(s) and for the security of information that you transmit to us over the internet.
CHILDREN
Our Website is directed to and is intended to be used only by persons who are 18 years of age or older. We do not knowingly collect information from children under 18. If you are under 18 years of age, you are not permitted to register for an account or otherwise submit any Personal Information to us, including your name, address or e-mail address. By registering for an account or submitting any Personal Information to us, you represent and warrant that you are 18 years of age or older.
If we discover that we have received any Personal Information directly from a child under the age of 18, we will suspend the associated account and remove that information from our database as soon as possible. For the avoidance of doubt, this does not apply to information collected from a parent or legal guardian who provides information regarding a dependent child under the age of 18 in connection with a health insurance application or other related purpose.
LINKS TO THIRD-PARTY WEBSITES
Our Website may contain links to third-party websites and services, including those of third-party insurance providers and advertisers. Please note that these links are provided for your convenience and information, and the websites and services may operate independently from us and have their own privacy policies or notices, which we strongly suggest you review. This Privacy Notice applies to HealthSherpa and our Website only. We do not accept any responsibility or liability for the policies or practices of any third parties. If you choose to access any websites or services linked from our Website, please check the applicable policies before you use or submit any personal data to such website or service.
INTERNATIONAL JURISDICTIONS
The Website is hosted in the United States of America and is subject to U.S. state and federal law. The Website is not intended to subject HealthSherpa to the privacy laws or jurisdiction of any state, country or territory other than that of the United States, including the European Union. HealthSherpa does not represent that the Site is appropriate for use in any particular jurisdiction. Those who access the Site do so at their own initiative and are responsible for complying with all local laws, rules and regulations. If you are accessing our Website from other jurisdictions, please be advised that you are transferring your personal information to us in the United States, and by using our Website, you consent to that transfer and use of your personal information in accordance with this Privacy Notice. You also agree to abide by the applicable laws of applicable states and U.S. federal law concerning your use of the Website and your agreements with us. Any persons accessing our Website from any jurisdiction with laws or regulations governing the use of the Internet, including personal data collection, use and disclosure, different from those of the jurisdictions mentioned above may only use the Website in a manner lawful in their jurisdiction. If your use of the Website would be unlawful in your jurisdiction, you may not use the Website.
USE OF ARTIFICIAL INTELLIGENCE (AI)
HealthSherpa may use third-party artificial intelligence ("AI") tools to support internal business operations, including functions such as customer support, software development, data analysis, and administrative tasks. When we use AI tools, we are committed to doing so responsibly and in a manner consistent with our obligations to protect the privacy and security of the information entrusted to us. Specifically:
- Enterprise-grade tools only. We use enterprise or business versions of AI tools, which are designed with enhanced privacy and security controls appropriate for commercial use.
- No training on your data. The AI tools we use are configured so that data we input is not used to train the underlying AI models.
- HIPAA compliance. Where our use of an AI tool involves Protected Health Information ("PHI") or other data subject to HIPAA, we enter into a Business Associate Agreement ("BAA") with the applicable vendor prior to use, consistent with our obligations as a HIPAA business associate.
- Vendor oversight. We evaluate AI vendors for their data handling practices, security posture, and contractual commitments before deployment.
CHANGES TO OUR PRIVACY NOTICE
HealthSherpa may, in its sole discretion, change this Privacy Notice from time to time. Any and all changes to this Privacy Notice will be effective as of the Effective Date stated at the top of this Privacy Notice. Unless stated otherwise, our current Privacy Notice applies to all information that we have about you and your account. Users should regularly check this page for any changes to this Privacy Notice. To the extent required by law, we may notify you of amendments or updates of this Privacy Notice, such as by posting a notification to the home page of the Website, or sending a notification to you at the address we have on file for you, if any.
Your continued use of the Website or communication with us after the updated Privacy Notice has been posted (or any other indication of your consent) will constitute your acceptance of the updated Privacy Notice.
Please note that we may condition your continued access to our Website on your consent to changes to this Privacy Notice.
CONTACT US
If you have questions or comments relating to this Privacy Notice, or if you would like us to update information we have about you or your preferences, please contact us by email at privacy@healthsherpa.com, or call us at (855) 772-2663, or write to us at:
HealthSherpa
Attn: Legal Department
PO Box 1739
Sacramento, CA, 95812