Effective Date: December 1, 2021
Section 8.A is intended to provide the Notice of Collection required under the California Consumer Privacy Act.
Our customers (we’ll call them “Developers” here) integrate the Trellis Connect API to enable you (the “End User”) to consent to the collection and disclosure of insurance data, including Personal Information, that we’ve translated and standardized, so that the Developers can provide their services to you.
1. Personal Information Collected by Trellis
Information Provided by End User. When you connect your insurance accounts with a Developer software application or otherwise connect your insurance accounts through the Trellis Connect API, we collect login information required by the provider of your account, such as your username and password, answers to challenge questions, or a security token. When providing this information, you give the Developer and Trellis the authority to act on your behalf to access and transmit your information from the relevant insurance provider to the Developer.
Information Collected From Your Insurance Provider. The information we receive from the insurance providers that maintain your insurance accounts varies depending on the information made available by those providers. But, in general, we collect the following types of information from your insurance provider, including your:
- Name, address, phone number, email address;
- Social security number, driver’s license, date of birth, marital status;
- Vehicle information;
- Medical and financial information;
- Insurance coverages, limits and rates, and payment and claims history (including billing transaction amount, date, type, quantity, price, and a description of the transaction)
2. Personal Information Received by Trellis or Disclosed or Shared by Trellis
Personal Information is collected to:
Share with Developers with Your Consent. By connecting Trellis with your insurance provider, you are requesting and authorizing Trellis to disclose Personal Information within your insurance policy, as well as related terms and rates, to Developers to use, process and disclose in accordance with their notices provided at the time of collection.
Provide Trellis Services. Personal Information is collected to facilitate provision of the Services to:
- Provide, operate, maintain, and improve the Services;
- Respond to inquiries regarding the Services;
- Provide customer support and feedback;
- Develop new services;
- Detect, prevent, and investigate security incidents that compromise the availability, authenticity, integrity or confidentiality of stored or transmitted Personal Information;
- Protect against malicious, deceptive, fraudulent or illegal activity directed at Trellis;
- Debug to identify and repair errors that impair existing intended functionality;
- Analyze data to assess, understand and improve the Services and personalize user experiences, including creation of anonymized aggregated, statistical and benchmark data. Aggregated data is utilized to help develop and market products or services and present targeted content and advertising;
- Enable functionality of the Services to authenticate a user, prevent fraud, and implement security measures;
- Undertake activities to verify or maintain the quality of a service or product that is developed or provided, and to improve, upgrade, or enhance any service or product that is developed or provided by Trellis.
Share with Service Providers. Trellis has engaged with service providers to provide and maintain the Services and operate our business, including without limitation, database management hosting, information technology services, email delivery, customer support, analytics, data security and compliance services necessary to provide the Services. For each service provider, Trellis will have in place written contracts that describes the purpose of the service and disclosure of Personal Information and requires the service provider to not use Personal Information for any purpose except performing the services pursuant to such contract.
- Google Analytics. Trellis utilizes Google Analytics for data analytics to generate insights and recommendations. End Users can manage ad settings on Google Advertising Opt-Out and revisit their privacy preferences on Google’s Privacy Checkup tool.
- Amplitude. Amplitude collects data and information regarding the behavior and usage patterns of End Users of the Services. If you wish to opt out of sharing, you may adjust your cookie preferences settings.
3. Personal Information of Minors
4. Retention and Deletion of Personal Information; De-Identified Data
5. Trellis’s Security Practices
- Identifiers, such as a name, postal address, unique personal identifiers, email address, account username and password, telephone number, insurance policy number, account name, social security number, gender, driver’s license number, and other similar identifiers;
- Driving and claims history, including information about any prior accidents or insurance claims contained in your insurance policy file;
- Vehicle information, such as a vehicle identification number (VIN), vehicle details, including any customizations, and vehicle photos, contained in your insurance policy file;
- Professional and Employment related information contained in your insurance policy file;
- Financial identifiers, such as a bank account number, credit card number, debit card number, or other financial information contained in your insurance policy file;
- Medical information contained within your insurance policy file;
- Commercial information about consumer transactions and experiences with us and others, such as payment history, claims, coverage and vehicle changes, contained in your insurance policy file;
- Usage and device information, online identifier(s), Internet Protocol address, search history;
- Geolocation data.
- Performing services;
- Auditing related to a current interaction with you and concurrent transactions, including, but not limited to, counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance;
- To assess and improve our product and service offerings, including the development of new products and services;
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
- Service providers that assist us in providing Services;
- Service providers involved in our verification, data-processing, risk-assessment, security and anti-fraud efforts;
- Developers with your consent;
- Governmental and law enforcement authorities to serve our legitimate business interests as follows: (a) as required by law, such as to comply with a subpoena, or similar legal process, (b) to investigate, prevent, or take action regarding suspected or actual illegal activities or to assist government enforcement agencies as required by law; (c) enforce our agreements with you, and/or (d) investigate and defend ourselves against any third-party claims or allegations.
1. Request Trellis Disclose at No Charge (“Right to Know”):
- Specific pieces of Personal Information it has collected about you;
- categories of Personal Information collected, used, and/or disclosed about you;
- categories of sources from which Personal Information is collected;
- business and/or commercial purposes for collecting and disclosing your Personal Information;
- categories of third parties with whom your Personal Information has been disclosed/shared
Right to Know Requests can be submitted to Trellis by email at firstname.lastname@example.org.
2. Request Trellis to Delete at No Charge (“Right to Delete”):
Deletion Requests can be submitted to Trellis be email at email@example.com or by mail to Trellis at: Trellis, Inc., Attention: Privacy Request to Delete, 2093 Philadelphia Pike #7288, Claymont DE 19703.
- Trellis is obligated to disclose/delete only upon a verifiable Consumer request from the consumer or an authorized agent acting on behalf of Consumer.
- In certain states, consumers may only make a Personal Information request twice in a 12-month period.
- Deletion is not required if it is necessary for Trellis to maintain the Personal Information to fulfill applicable permissible purposes enumerated pursuant to applicable privacy laws.