Privacy Policy
How OtterQuote Collects, Uses, and Protects Your Data
Effective Date: March 16, 2026
⚠️ Legal Disclaimer
This Privacy Policy is provided for informational purposes. We strongly recommend having an attorney review this policy to ensure it meets your specific legal requirements. Privacy laws vary by jurisdiction and continue to evolve. OtterQuote is not a law firm, and this policy does not constitute legal advice.
1. Introduction
OtterQuote ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our website and associated services. This policy applies to all users of OtterQuote, including homeowners, contractors, and other users of our services.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.
2. Information We Collect
2.1 Information You Directly Provide
- Account Registration: Name, email address, phone number, password, profile information, address, and property details
- Insurance Documents: Insurance policies, claim information, coverage details, and related documents you upload
- Property Information: Property address, property type, size, condition, and photos
- Communication Data: Messages, emails, support requests, and correspondence with us or other users
- Contractor Information: Contractor details, quotes, estimates, and work descriptions
2.2 Information Automatically Collected
- Device Information: Device type, operating system, browser type, and unique device identifiers
- Usage Data: Pages visited, features used, actions taken, time spent on pages, and interaction patterns
- IP Address and Location: IP address, approximate geographic location, and referral source
- Cookies and Tracking: Cookies, web beacons, and similar tracking technologies
- Referral Information: How you accessed our platform (search engines, links, referral sources)
2.3 Information from Third Parties
- Google Analytics: Usage analytics and aggregated user behavior data
- Stripe: Payment processing information (we do not store full credit card numbers)
- Netlify: Server logs and performance data
- Supabase: Database and authentication service data
3. How We Use Your Information
3.1 Primary Uses
- Platform Operations: Maintaining and operating our platform, services, and features
- Service Delivery: Providing the services you requested, including claim matching and contractor recommendations
- Communication: Sending transactional emails, support responses, and service updates
- Payment Processing: Processing payments and managing billing transactions
- Analytics and Improvement: Analyzing usage patterns to improve our services and user experience
- Fraud Prevention: Detecting, preventing, and addressing fraud and security issues
- Legal Compliance: Complying with legal obligations and responding to lawful requests
3.2 Marketing and Promotional Communications
We may send you marketing emails and promotional materials about new features, services, and offers. You can opt out of marketing communications at any time by clicking the unsubscribe link in our emails or updating your preferences in your account settings.
3.3 Automated Decision-Making
We do not use your information for automated decision-making or profiling that would have a legal or similarly significant effect on you.
4. How We Share Your Information
4.1 Sharing with Contractors
If you request contractor recommendations or matching services, we will share relevant information (property details, project scope, insurance information) with contractors you connect with on our platform.
4.2 Sharing with Service Providers
We share information with third-party service providers who assist us in operating our platform and providing services:
- Supabase: Database hosting and authentication services
- Netlify: Website hosting and CDN services
- Google Analytics (GA4): Usage analytics and performance monitoring
- Stripe: Payment processing and billing services
4.3 Legal Requests and Obligations
We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to comply with legal obligations, court orders, or governmental requests.
4.4 Business Transfers
If OtterQuote is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice if this occurs.
4.5 No Sale of Personal Data
We do not sell your personal information to third parties. We do not sell personal information in the manner restricted by the California Consumer Privacy Act (CCPA) and similar regulations.
4.6 Sharing with Your Consent
We may share your information with third parties when you consent to such sharing, such as through your account settings or explicit requests.
5. Cookies and Analytics
5.1 Cookies
We use cookies and similar tracking technologies to enhance your experience on our platform. Cookies are small files stored on your device that help us remember your preferences, track your activity, and improve our services. Types of cookies we use include:
- Essential Cookies: Required for platform functionality and security
- Performance Cookies: Track usage and performance metrics
- Preference Cookies: Remember your settings and preferences
- Marketing Cookies: Track interactions for marketing purposes
5.2 Google Analytics (GA4)
We use Google Analytics to understand how visitors use our platform. GA4 collects data such as page views, session duration, user demographics, and device information. This data helps us improve our services and understand user behavior patterns. GA4 may set cookies on your device and may combine data from multiple sources. For more information about how Google uses data, please visit the Google Analytics Support Center.
5.3 Disabling Cookies
You can control cookie settings through your browser. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Disabling cookies may affect your ability to use certain features of our platform.
5.4 Do Not Track
Some browsers include a "Do Not Track" feature. Currently, there is no industry standard for recognizing DNT signals. If you enable DNT in your browser, our platform may not respond to these signals, but you can still manage cookies through your browser settings.
6. Data Security
6.1 Security Measures
We implement comprehensive security measures to protect your information:
- HTTPS Encryption: All data transmitted between your device and our servers is encrypted using HTTPS
- Encryption at Rest: Sensitive data is encrypted when stored in our databases
- Authentication: Multi-factor authentication and secure password policies
- Access Controls: Role-based access controls and least-privilege principles
- Regular Backups: Automated backups to ensure data availability and recovery
- Security Monitoring: Continuous monitoring for unauthorized access and suspicious activities
- Audit Logs: Detailed logging of all system access and data modifications
6.2 No Absolute Guarantee
While we strive to protect your information using industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data. You acknowledge that you use our services at your own risk.
6.3 Breach Notification
If we discover a data breach that compromises your personal information, we will notify you as required by applicable law. Notifications will be sent via email or posted on our website, along with information about the breach and steps we are taking to address it.
7. Data Retention
7.1 Retention Policy
We retain your information for as long as necessary to provide services and fulfill the purposes outlined in this Privacy Policy. The following table outlines our retention periods for different types of information:
| Data Type | Retention Period |
|---|---|
| Account Information | Deleted + 30 days |
| Insurance Documents | Deleted + 90 days |
| Transaction Records | 7 years |
| Google Analytics Data | 14 months |
| Login Logs | 1 year |
| Communications | 3 years |
7.2 Deletion Upon Request
You may request deletion of your personal information at any time. Upon deletion, your data will be removed from our active systems within the timeframes specified above. Some data may be retained for legal, tax, or operational purposes.
7.3 Data Residency
Your data is primarily stored in the United States. If you are located outside the United States, you acknowledge that your information will be transferred to and processed in the United States.
8. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will take steps to delete such information and terminate the child's account. If you believe we have collected information from a child under 18, please contact us immediately.
9. Your Privacy Rights
9.1 Right to Access
You have the right to request access to the personal information we hold about you. You can request a copy of your data by submitting a request through your account settings or by contacting us.
9.2 Right to Deletion
You have the right to request deletion of your personal information, subject to certain legal exceptions. We will delete your data within the timeframes specified by applicable law.
9.3 Right to Correction
You have the right to request correction or amendment of inaccurate information. You can update your information directly in your account settings or by contacting us.
9.4 Right to Opt-Out
You have the right to opt out of marketing communications, profiling, and certain types of data processing. You can manage these preferences in your account settings or by contacting us.
9.5 Right to Non-Discrimination
We will not discriminate against you for exercising your privacy rights. You will not face any adverse treatment or denial of services for exercising your rights.
9.6 Right to Appeal
If we deny your privacy request, you have the right to appeal our decision. Please contact us to initiate an appeal process.
9.7 CCPA/CPRA Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of your personal information.
10. Third-Party Services
10.1 Links to Third-Party Websites
Our platform may contain links to third-party websites and services. We are not responsible for the privacy practices of third-party websites. Please review the privacy policies of any third-party websites before providing your information.
10.2 Our Service Providers
We use the following third-party service providers:
Supabase (Database & Authentication)
- Hosts our database and provides authentication services
- Processes user credentials and account information
- Privacy Policy: https://supabase.com/privacy
Netlify (Web Hosting)
- Hosts our website and application
- Processes server logs and performance data
- Privacy Policy: https://www.netlify.com/privacy/
Google Analytics (GA4) (Analytics)
- Collects usage data and user behavior analytics
- Tracks page views, sessions, and user interactions
- Privacy Policy: https://policies.google.com/privacy
Stripe (Payment Processing)
- Processes payments and manages billing
- We do not store full credit card numbers
- Privacy Policy: https://stripe.com/privacy
10.3 Data Processing Agreements
We have Data Processing Agreements (DPAs) in place with our service providers to ensure they process your information in compliance with applicable privacy laws.
11. International Data Transfers
OtterQuote is based in the United States (Indiana). Your personal information is processed and stored in the United States. If you are located outside the United States, your information will be transferred to the United States and processed according to this Privacy Policy and applicable U.S. laws. By using our services, you consent to the transfer and processing of your information in the United States.
For users in the European Union, we acknowledge that the transfer of personal information from the EU to the United States may be subject to GDPR requirements. We implement appropriate safeguards to protect your information during international transfers.
12. California Privacy Rights (CPRA/CCPA)
If you are a California resident, you have additional privacy rights under the California Consumer Privacy Rights Act (CPRA) and the California Consumer Privacy Act (CCPA):
- Right to Know: You can request what personal information we collect, use, and share
- Right to Delete: You can request deletion of personal information we have collected from you
- Right to Correct: You can request correction of inaccurate personal information
- Right to Opt-Out: You can opt out of the sale or sharing of your personal information
- Right to Limit Use: You can limit our use of sensitive personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights
- Authorized Agent: You can designate an authorized agent to make requests on your behalf
To submit a CCPA/CPRA request, please contact us at dustinstohler1@gmail.com. We will verify your identity and respond to your request within 45 days.
13. Indiana-Specific Privacy Rights
OtterQuote is based in Indiana. If you are an Indiana resident, you may have rights under the Indiana Consumer Data Protection Act or other applicable Indiana privacy laws. We are committed to complying with all applicable Indiana privacy regulations and will notify you of any additional rights afforded to Indiana residents.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by posting the updated policy on our website and updating the "Effective Date" at the top of this policy. Your continued use of our services after changes have been posted constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.
15. Contact Us
If you have questions about this Privacy Policy, requests regarding your personal information, or concerns about our privacy practices, please contact us:
Email: dustinstohler1@gmail.com
Address: Indiana, United States
Website: otterquote.com
Response Time: We will respond to all inquiries within 30 business days.
For California residents submitting CCPA requests, we will respond within 45 days as required by law. For other privacy requests, we aim to respond within 30 business days.
16. Summary of Privacy Practices
What We Collect
We collect information you provide directly (name, email, property details, insurance documents), information collected automatically (usage data, device information, IP address), and information from third-party service providers.
Who We Share With
We share information with contractors (when you request matching), service providers (Supabase, Netlify, GA4, Stripe), and as required by law. We do not sell your personal information.
How Long We Keep It
We retain information for varying periods depending on type: account data (30 days after deletion), insurance documents (90 days), transactions (7 years), analytics (14 months), login logs (1 year), and communications (3 years).
Your Rights
You have rights to access, delete, correct, and opt out of your information. California residents have additional CCPA/CPRA rights. You can manage preferences in your account settings or contact us.
How Secure Is It
We use HTTPS encryption, secure authentication, access controls, and security monitoring. However, no method is 100% secure. We will notify you of any data breaches as required by law.
Questions?
Contact us at dustinstohler1@gmail.com or through our website at otterquote.com.