1. California notice at collection
This is the notice required by the California Consumer Privacy Act as amended by the CPRA, given at or before the point at which we collect your information. The quote and application form on this site links to this section directly.
| Statutory category | What we actually collect | Business purpose |
|---|---|---|
| Identifiers | Name, mailing address, city, state, ZIP, telephone number, email address, IP address. | To prepare and submit an insurance application, to reach you about it, and to prevent abuse of the form. |
| Customer records (Civ. Code § 1798.80(e)) | Name, signature, address, telephone number, and insurance-policy information such as your current carrier and expiration date. | To complete the carrier application and the electronic signature record. |
| Commercial information | The collection classes you hold, the values and limits you enter, appraisal and inventory status, storage and security details, and the coverage you are considering. | To produce a pricing indication and to seek terms from specialist markets on your behalf. |
| Professional information | The title you enter on the signature page (for example Owner, Collector, Trustee). | To identify the capacity in which you sign. |
| Internet or other electronic network activity | Pages requested, referring page, campaign parameters, browser and device string, and the measurement events listed in section 7. | To operate the site, to measure which pages and campaigns produce inquiries, and for security. |
| Geolocation data | We do not ask for or collect precise geolocation, and this site sends a Permissions-Policy header that switches the browser’s geolocation API off entirely. Google Analytics derives an approximate, coarse location from IP address. | Aggregate audience measurement. |
| Inferences | The only derived value we produce is the premium indication range calculated from the values you enter. We do not build profiles reflecting preferences, characteristics, or behavior. | To show you an indication. |
| Sensitive personal information | None. This form does not ask for a Social Security number, driver’s license or state ID number, passport number, financial account or payment card number, account log-in credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or health information. Please do not send any of these through the site. | Not applicable. |
Sale and sharing. We do not sell your personal information for money, and we never have. This site does run a Google Ads conversion tag, and under California’s broad definitions that transfer can be treated as “sharing” personal information for cross-context behavioral advertising. Rather than argue the point, we give you the opt-out — see section 8.
Retention. Category-by-category retention is set out in section 9.
2. What this site collects
This is the actual field list from the application on this site, not a generic template.
- Contact and identity details — your full legal name as it will appear on the policy, street address, city, state, ZIP, telephone number, email address, and, on the signature page, your printed name and title.
- Collection details — which collection classes you hold (fine art, jewelry and watches, wine and spirits, silverware and goldware, coins and currency, stamps, furs, musical instruments, sports memorabilia, cameras and optics, china and crystal, rugs and tapestries, books and manuscripts, antique firearms, and anything you add as a custom type); the estimated value and the limit of insurance you want for each; free-text descriptions of other collections; whether you hold a current written inventory or appraisal and its date; whether items are on loan to a museum, gallery, or third party; and whether items are in transit or in storage away from the primary residence.
- Location, construction, and security details — the address where the collection is kept if it differs from your mailing address, the type of structure, construction type, year built, number of stories, square footage, whether covered property is stored in a basement, any history of water back-up, fire department proximity, smoke detectors, sprinklers, central-station burglar alarm, deadbolts, whether a third party such as a housekeeper or property manager holds keys, and — if you have one — the make, model, and UL rating of your safe and whether jewelry is kept in it and checked by a jeweler.
- Insurance and loss history — whether your collection is currently insured, the current carrier and policy expiration date, whether any insurer has cancelled or non-renewed a collections policy in the last three years, whether you have had a loss or claim in the last five years, and the loss details and underwriter notes you choose to write.
- Electronic signature record — appended to your signed PDF as a final audit page, and emailed to you with it. Because you can open that page and check this, here is exactly what is on it. In readable text: an audit reference (a UUID), the submission timestamp, your name, your email address, and your telephone number in full, the first 120 characters of your browser and device string, the exact consent wording you accepted and its version number, your contact-consent answer, and a summary of the collection limits you entered. Alongside those, four SHA-256 hashes — of your email address, of your IP address, of the submitted payload, and of the signature image. Those hashes exist so the record can be shown not to have been altered afterwards. They are not anonymization and we do not offer them as such: your email address is printed in full a few lines below its own hash, and an unsalted hash of an IPv4 address can be reversed by brute force in seconds. Your IP address is simply the one item that is not printed in readable form anywhere in the PDF. The signature itself is stamped onto the application’s signature line, and your printed name and title are filled into the application’s own fields.
- Contact consent record — if you check the optional box authorizing calls and texts, we record that you checked it, the exact wording you agreed to, its version, and the time. If you leave it unchecked we record nothing, and your application is submitted exactly the same way.
- Technical data — IP address, browser and device string, the pages you request, the page that referred you, any campaign parameters in the URL, and the measurement events listed in section 7. Your IP address is also used to rate-limit the submission endpoint against automated abuse, at five submissions per address per minute. That counter lives only in the memory of the server process and is never written to our disk: submissions older than sixty seconds stop counting, and the entry itself is dropped when the process recycles or when the table exceeds 5,000 addresses.
The form also contains a hidden field that only automated scripts fill in. If it is filled, the submission is discarded. Nothing you type is used for that check.
3. Where the information comes from
- From you — everything in the application, directly.
- From your browser and device — IP address, browser and device string, referring page, and campaign parameters, automatically.
- From our measurement providers — aggregate audience and campaign data, described in section 7.
- From carriers, wholesalers, and program administrators — their responses to a submission we make on your behalf.
- From public property records — where you leave construction year, square footage, or construction type blank, we verify those details from public property records before coverage is bound. The form says so at the point you are asked.
- From consumer reporting and insurance-support organizations — we do not order any such report through this website. If we or a carrier need a consumer report, an investigative consumer report, an inspection report, or a loss-history report about you in connection with your application, you will be told before it is obtained and you may ask to be interviewed and to receive a copy of the report. See section 13.
4. The draft saved in your own browser
So you can leave and come back, the application saves your answers in your own browser’s local storage under the key bestartins_wizard_v1. That draft stays on your device — it is not transmitted to us until you submit.
Be aware of what it contains, because it is more than a partial form: it holds every answer you have typed, including your name, address, phone number, email address, collection values, security details, and loss notes. It excludes your adopted signature image, which never leaves the page you drew it on until you submit.
The draft is removed automatically when your application submits successfully, and immediately when you choose Start fresh on the resume banner. Clearing your browser’s site data for this domain also removes it. If you are on a shared or public computer, use Start fresh or clear site data when you finish.
One other page on this site stores something on your device, and for completeness it belongs here: the tick-box list on our collection inventory checklist remembers which boxes you have ticked, in your browser’s session storage, which your browser discards when you close the tab. It records nothing but which numbered boxes are ticked, and it is never transmitted to us. Those two stores are the only things this site keeps on your device.
5. How we use it
We use your information to calculate the pricing indication, to prepare and complete the carrier application, to place your electronic signature on it, to submit it to the specialist insurance markets we believe fit your collection, to email you a signed copy for your records, to answer your questions and follow up as your broker, to keep the records an insurance brokerage is required to keep, to secure the site against automated abuse, and to measure which pages and campaigns produce inquiries.
We do not use your application information for unrelated marketing, we do not use it to train artificial-intelligence models, and we do not sell it.
6. Who receives it
- Insurance carriers, wholesalers, and program administrators — the specialist markets we approach on your behalf, which may include those profiled at bestartinsurance.com/carriers. What they do with an application once they receive it is governed by their own privacy notices and by insurance law, not by this page.
- A licensed surplus line broker — if a placement requires a non-admitted (surplus lines) market, it is placed through a licensed surplus line broker. This agency does not hold surplus line authority itself.
- Resend — our transactional email provider. A submission generates exactly two emails through it, both attaching the same signed PDF: a broker packet addressed to reviews@bollinsure.com and copied to one internal agency address, and your own confirmation copy addressed to you. Both are sent from reviews@bollinsure.com. Your confirmation copy replies to reviews@bollinsure.com; the broker packet replies to your address, so that the broker who opens it reaches you directly.
- Vercel — our hosting and content-delivery provider. It serves this site and keeps standard short-lived server request logs, which include IP addresses.
- Google — Google Tag Manager, Google Analytics 4, and Google Ads, described in section 7. Google Fonts also serves this site’s two typefaces from
fonts.googleapis.comandfonts.gstatic.com, which means Google receives your IP address on page load. - Our agency management system — the internal system our licensed staff use to work your inquiry. It picks your application up by reading our reviews@bollinsure.com mailbox; this website does not transmit anything to it directly. Access is limited to licensed staff of the agency.
- Legal and regulatory recipients — where we are compelled by law, subpoena, or a regulator such as the California Department of Insurance, or where disclosure is necessary to establish or defend a legal claim.
Service providers act on our written instructions and are contractually limited to using your information for the service they provide to us. We do not disclose your information to a data broker, and we do not license it to anyone for their own marketing.
7. What actually runs on this site
Everything in this section except the two Google account numbers can be confirmed by viewing the source of this page. Those two numbers identify tags configured inside the tag container, which is not part of this page’s source; we give them anyway so you know precisely who receives the data.
- Google Tag Manager, container
GTM-5QM55LTJ, loads on all thirty pages of this site and is the only tag loader we run. (The one other file we serve as HTML,/googlec535632ef187cb8d.html, is a single-line Google Search Console ownership token. It renders nothing and loads no tags.) - Configured inside that container are Google Analytics 4, property
G-2C0V0NWB3Z, and a Google Ads conversion tag, accountAW-18196791997. - Google Consent Mode v2 defaults are set by this page itself — in the script tagged
cw-gpc-consent-default, which runs before the container is requested, so the Google tags read the consent state on their first evaluation rather than after they have already fired. - Global Privacy Control. That same script reads
navigator.globalPrivacyControl. If your browser sends the signal, the three advertising consent signals —ad_storage,ad_user_dataandad_personalization— are set todeniedbefore any Google tag can run, so the Google Ads tag cannot use your visit for advertising. Analytics stays granted: first-party measurement is not a sale or a share. If your browser does not send the signal, all three default togranted. Both states are visible in this page’s source. Because GPC is browser-and-device specific, it does not carry across to a different browser or device, and it cannot identify you to us if you have not otherwise given us your details. - The script at
/assets/lead-events.jspushes a small, fixed set of named events into the container. Every one of them carries the event name, the brand keybestartinsurance, and the path of the page you are on. Individual events add a little:form_start, the first time you focus any form field on a page, adds the name or id of that field — for examplea_email. That is the field’s name, never anything you typed into it.phone_click,email_clickandquote_click, when you click a telephone, email, or quote link, add which region of the page the link sat in (nav, footer, or body) and the first 40 characters of the link’s own visible text.quoteFormSubmittedandgenerate_lead, once and only once on a confirmed submission, add the line of business (fine-art), a conversion value of 1.0 USD, and your submission’s audit reference in full — the same UUID printed on your PDF, of which your confirmation screen shows only the first eight characters.
form_start,phone_click,quoteFormSubmittedandgenerate_lead. - Cookies. We set no cookie of our own — there is no cookie-writing code anywhere in this site’s first-party JavaScript. Google Analytics sets its own first-party
_gacookies through the container to recognize a returning browser, and the Google Ads tag may set first-party advertising cookies unless you have opted out as above. The saved application draft described in section 4 uses local storage, not a cookie. - Google Fonts serves the two typefaces this site uses.
Equally, here is what this site does not run, stated so you can verify it: no session-recording or screen-replay software, no heat-mapping, no chat or co-browsing widget, no product-analytics SDK, no Vercel Web Analytics, no reCAPTCHA, no advertising pixel from any network other than the Google Ads conversion tag named above, and no third-party cookie set by us. We do not record telephone calls made to or from the number on this site.
8. Do Not Sell or Share My Personal Information
We do not sell your personal information for money. We do run a Google Ads conversion tag, and California defines “sharing” broadly enough that passing an identifier to an advertising platform for conversion or remarketing purposes can be treated as sharing personal information for cross-context behavioral advertising. We would rather give you a working opt-out than rely on that argument.
To opt out of any sale or sharing of your personal information, do any one of the following:
- Email reviews@bollinsure.com with the subject “Do Not Sell or Share My Personal Information”.
- Call 562-COVWELL and tell us you want to opt out.
- Turn on Global Privacy Control in your browser or extension. Every page of this site reads that signal before it loads any Google tag, and denies the three advertising consent signals outright when it is present — so the opt-out takes effect on the page you are reading, with nothing else to click, no charge, and no change to how the site works for you.
You do not need an account, and we will not ask you to create one. We will not treat you differently — in price, in service, or in the markets we approach — because you opted out. You may also use an authorized agent; see section 11.
We do not knowingly sell or share the personal information of consumers under 16 years of age.
9. How long we keep it
California law asks us to state the retention period for each category, or the criteria we use to set it. Where we can state an actual period we do; where the period depends on the life of your file and on record-keeping obligations, we give you the criteria rather than invent a number.
| Category | How long it is kept |
|---|---|
| Draft in your browser | Until you submit, choose Start fresh, or clear site data. Removed automatically on a successful submission. |
| Rate-limiting record (IP address) | Held only in the memory of the server process and never written to our disk. Submissions stop counting after 60 seconds; the entry itself is dropped when the process recycles or when the table exceeds 5,000 addresses. |
| Submitted application, signed PDF, and e-signature audit record | For the life of the client relationship and afterwards for as long as the agency’s insurance record-keeping, regulatory, tax, and legal-claim obligations require. Disposed of securely at the end of that period. |
| Lead and contact record in our agency management system | Same criteria as the application file. If you never become a client, until the inquiry is closed and the applicable regulatory and limitation periods run out. |
| Contact consent or revocation record | For as long as we may contact you, and afterwards for as long as we may need to evidence that the consent was given or withdrawn. |
| Hosting request logs | The short rotation period set by our hosting provider. |
| Measurement data held by Google | The retention period configured on the Google Analytics property and the standard period for Google Ads conversion data. That data is held by Google under Google’s terms, not on our servers. |
| Email in our brokerage mailbox | Same criteria as the application file. |
10. Security
The site is served over HTTPS with HSTS (max-age=31536000), and every response carries X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Referrer-Policy: strict-origin-when-cross-origin, and a Permissions-Policy that switches off camera, microphone, and geolocation.
The submission endpoint checks that your name, email address, telephone number, and street address are present, that the email address is well-formed, that a signature and an e-signature consent record accompany the submission, and that the consent wording and its version are recorded. It rejects the submission outright if any of those is missing, and it rate-limits to five submissions per IP address per minute. It does not validate your remaining answers — those are your statements to make, and a mistyped collection value is not something we can catch for you.
Access to submitted applications is limited to licensed staff of the agency. No method of transmission or storage is perfectly secure, which is why we also do not ask for information we do not need — this form asks for no Social Security number, no driver’s license number, no financial account number, and no payment details.
What we do not claim. The SHA-256 hashes on your PDF’s audit page are there as tamper evidence, not as concealment. Your name, email address, and telephone number appear in readable text on that audit page and throughout the application itself, which is what makes the document usable as proof of who signed it. Section 2 sets out exactly what that page contains.
We will never ask you for a payment card number, a bank account number, or a password by email or over the phone in connection with this website.
11. Your California privacy rights
If you are a California resident, you have the rights below. Some of the information we collect when you apply for insurance is subject to the federal Gramm-Leach-Bliley Act and may be exempt from parts of the CCPA — we do not use that as a reason to refuse a request. We will honor the rights below for the information we hold about you.
- Right to know — the categories of personal information we collected, the categories of sources, our business purpose, and the categories of third parties to whom we disclosed it.
- Right to know specific pieces — the specific pieces of personal information we hold about you, not just the categories.
- Right to delete — subject to the exceptions in the statute, including information we must keep for insurance record-keeping and legal obligations.
- Right to correct — inaccurate personal information we hold about you.
- Right to data portability — to receive the information in a portable and, where technically feasible, readily usable format.
- Right to opt out of sale or sharing — see section 8.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information through this site and do not use or disclose any for purposes that would trigger this right. If that ever changes, this page will say so and the limit will be offered.
- Right to non-discrimination — we will not deny you service, charge you a different price, or give you a different level of service because you exercised any of these rights.
- Authorized agents — you may use an authorized agent. We will ask the agent for proof of authorization and may confirm the request with you directly before acting on it.
12. How to exercise your rights
Use either method — both reach the same people:
- Telephone — 562-COVWELL (562-268-9355).
- Email — reviews@bollinsure.com.
How we verify you. We confirm your identity by contacting you at the email address or telephone number already in our records and by matching information you give us against what we hold. For a request for specific pieces of personal information we apply a higher standard and may ask for a signed declaration under penalty of perjury that you are the person whose information is at issue.
How quickly we respond. We confirm receipt of a request within 10 business days and tell you how we will handle it. We respond substantively within 45 calendar days. If we need longer we will tell you within that first 45 days and take up to 45 more, for a maximum of 90 days.
If you are dissatisfied with our response, you may contact the California Privacy Protection Agency or the California Attorney General.
13. Notice of insurance information practices (Insurance Code § 791)
Because we act as an insurance agent and broker, the California Insurance Information and Privacy Protection Act (Insurance Code § 791 et seq.) applies to us regardless of the thresholds in the CCPA. This is our notice of information practices under it.
Information may be collected from people other than you
Personal information about you may be collected from people other than the individual proposed for coverage. In connection with an application, that can include an insurance carrier or wholesaler you are placed with, a prior or current insurer, an appraiser or inventory service you engage, a property inspector, public property records, and — if one is ordered — a consumer reporting agency or insurance-support organization.
Types of information and how it may be gathered
The information gathered concerns your identity and contact details, the property to be insured, its location, storage, and protective devices, your insurance and loss history, and your general reputation for insurability. It may be gathered from your application, from documents you provide, from telephone or email correspondence with our licensed staff, and, where a report is ordered, from an inspection or an investigative consumer report. We do not order any such report through this website.
Investigative consumer reports
If an investigative consumer report is ordered in connection with your application, you will be given notice before it is obtained. You have the right to request to be interviewed in connection with the preparation of the report and to receive a copy of it.
Disclosure without your authorization
Information we hold about you may, in certain circumstances, be disclosed without your prior authorization to third parties — for example to an insurer, agent, or broker to place or service your coverage, to a person performing a business, professional, or insurance function for us, to a regulatory or law-enforcement authority, in response to a court order or subpoena, or for a permitted actuarial or research study. Information obtained from a report prepared by an insurance-support organization may be retained by that organization and disclosed to other persons.
Your right of access
You have the right to ask, in writing, what recorded personal information we hold about you, and to see and copy it in person or receive a copy by mail. We will tell you the identity of anyone to whom we disclosed it during the preceding two years, or, if that is not recorded, the names of those to whom such information is normally disclosed. Medical-record information may be disclosed to you through a medical professional you designate. There is no charge for a reasonable request; we may charge a reasonable fee for the cost of copying.
Your right to correct, amend, or delete
You may ask us in writing to correct, amend, or delete recorded personal information you believe is inaccurate. If we agree, we will make the change and notify you; we will also notify anyone you identify to whom we disclosed the information, any insurance-support organization that gave it to us, and any insurance-support organization to whom we disclosed it. If we refuse, we will tell you why and you may file a concise statement of what you believe is the correct information and why you disagree. We will file your statement with the disputed information, include it in any future disclosure of that information, and give it to anyone to whom the disputed information was previously disclosed.
Adverse underwriting decisions
If a declination, a termination, or an offer of coverage on terms less favourable than you applied for is made, you have the right to be told the specific reason in writing, or to be told that you may request those reasons in writing. That statement will identify the specific items of personal information that support the reasons and the source of the information, and it will describe the access and correction rights above.
14. Financial privacy (Gramm-Leach-Bliley Act)
As an insurance producer we are a financial institution under the federal Gramm-Leach-Bliley Act, and this page also serves as our privacy notice of information practices for that purpose. We collect nonpublic personal information about you from the application you complete and from your transactions with us. We disclose it only to place and service the coverage you asked for, to service providers acting for us under contract, and where the law permits or requires — we do not disclose nonpublic personal information about you to nonaffiliated third parties for their own marketing purposes. We maintain physical, electronic, and procedural safeguards to protect it.
15. This site does not bind coverage
Nothing this website returns is insurance. The pricing indication is a modeled estimate, not a quote, a binder, an offer to insure, or a guarantee of coverage, price, or eligibility. Completing and signing the application through this site is a request for coverage — it is not itself coverage, and it does not bind any carrier. No email, confirmation page, reference number, or reply from this site is a policy, a binder, a quote, or an offer to insure. Coverage exists only when a carrier issues it and says so in writing. Until then, do not cancel or let lapse any policy you already hold.
16. Children
This site is for adults seeking to insure a collection. It is not directed at children, we do not knowingly collect personal information from anyone under 16, and we do not sell or share the personal information of anyone under 16. If you believe a child has given us information, email reviews@bollinsure.com and we will delete it.
17. Changes to this page
If our practices change, we will update this page and the “last updated” date above before the change takes effect, and we will note any material change plainly at the top of the page. We review this page at least once every twelve months.
18. Contact us
WJB Services, Inc. dba Bollinsure Insurance Services
3625 E Thousand Oaks Blvd Ste 292, Westlake Village, CA 91362
562-COVWELL · reviews@bollinsure.com
California Department of Insurance agency license #0D94699
See also our Terms of Service.
This privacy policy was last updated on August 1, 2026, and is the version currently in effect.