Legal

Data Privacy Policy

Last updated: June 19, 2026

OmniReach CRM is built for insurance agents who handle sensitive client information every day, including Protected Health Information under HIPAA. This policy explains what data we collect, how we use it, who we share it with, and the rights you have over it. We've tried to write it in plain English.

1.Who This Policy Covers

This Data Privacy Policy applies to anyone who interacts with OmniReach CRM — whether you're visiting our website, using the platform as a paying customer, or your information has been added to OmniReach by one of our customers.

There are three distinct groups of people whose data we handle, and the rules are different for each:

Who
How We Treat Their Data
Website Visitors
People browsing omnireachcrm.com. We collect minimal analytics and information they choose to give us (e.g., booking a demo).
Customers (Agents)
Insurance agents and agencies who pay for and use OmniReach. We hold their account data, billing info, and platform usage data.
End Clients
The leads, prospects, and clients whose information our Customers enter into OmniReach. This is the group most likely to include PHI under HIPAA. Our Customer is the "controller" of this data; we are the "processor" / Business Associate.

2.What Data We Collect

From Website Visitors

From Customers (Agents Using the Platform)

From End Clients (Data Customers Upload About Their Leads/Clients)

This is data about someone else that our Customer enters into OmniReach. We process this data on behalf of our Customer under the Business Associate Agreement.

3.How We Collect It

4.How We Use Your Data

We use data only for the purposes you'd reasonably expect:

What we don't do: We don't sell your data. We don't sell End Client data. We don't use PHI for marketing or analytics. We don't train AI models on your client data.

5.PHI and HIPAA

OmniReach CRM is designed to handle Protected Health Information (PHI) in compliance with HIPAA. When a Customer enters PHI into the platform — for example, Medicare ID numbers, health conditions, or coverage details about their leads — we act as a Business Associate as defined under HIPAA.

Specifically:

Customer responsibilities under HIPAA: our Customers are the "Covered Entity" or "Business Associate" with respect to their End Clients, and they remain responsible for obtaining authorizations, training their staff, applying minimum-necessary standards, and using the platform in a HIPAA-compliant manner. The BAA and Section 5 of our Terms and Conditions explain this shared responsibility in more detail.

6.Who We Share Data With

We share data only with parties necessary to operate the Service:

We do not sell your personal data. We do not sell End Client data. We do not rent it. We do not share it with advertisers for advertising purposes.

7.SMS, Calls & A2P Records

SMS and voice traffic in the United States is governed by carrier networks and the TCPA, CAN-SPAM Act, and A2P 10DLC rules. Some specifics worth understanding:

8.Cookies and Tracking

We use cookies and similar technologies for a small set of purposes:

Most browsers let you disable or delete cookies. If you disable essential cookies, parts of the platform may not work. We do not use cookies to build advertising profiles or track you across unrelated websites.

9.How We Protect Your Data

We take security seriously, especially given the sensitivity of insurance and health data:

No system is 100% secure. While we use commercially reasonable safeguards, no internet-connected system can be guaranteed against all attacks. You are responsible for keeping your account credentials safe and notifying us immediately of any suspected unauthorized access.

10.How Long We Keep Data

Retention periods vary by data type:

11.Your Rights and Choices

Depending on where you live, you may have the following rights regarding your personal data:

To exercise any of these rights, email info@omnireachcrm.com. We will respond within the timeframe required by applicable law.

Important: if you are an End Client whose information was entered into OmniReach by an insurance agent (our Customer), please contact the agent directly first. They are the controller of your data; we process it on their behalf.

12.State Privacy Laws

Several U.S. states have enacted comprehensive privacy laws that provide additional rights to their residents. We comply with applicable state privacy laws including:

We do not sell personal data as that term is defined under these laws. We do not engage in "targeted advertising" or use personal information for profiling that would produce legal or similarly significant effects.

13.International Users

OmniReach CRM is operated from the United States and primarily serves U.S.-licensed insurance agents. If you access the Service from outside the U.S., your data will be transferred to and processed in the United States, which may have different privacy protections than your home country.

If you are located in the European Economic Area, United Kingdom, or another jurisdiction with comprehensive privacy laws, you may have additional rights. Contact us at info@omnireachcrm.com to exercise them.

14.Children's Privacy

The Service is intended for licensed insurance professionals and is not directed to children. We do not knowingly collect personal information from anyone under the age of 18. If you become aware that a child has provided us with personal information, please contact us so we can delete it.

15.Breach Notification

In the event of a data breach that compromises personal information or PHI, we will notify affected individuals and applicable authorities in accordance with HIPAA Breach Notification Rule timelines and applicable state breach notification laws. Notifications will describe the nature of the breach, the data involved, steps being taken, and recommended actions for affected individuals.

If you suspect a breach involving your account or your End Clients' data, contact us immediately at info@omnireachcrm.com.

16.Changes to This Policy

We may update this Data Privacy Policy from time to time. For material changes, we will notify you by email and/or by posting a prominent notice on the website at least 30 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the current version.

Continued use of the Service after the effective date of a revised policy constitutes acceptance of the revised policy.

Privacy questions or data requests?

Email: info@omnireachcrm.com

Mail: TMS Insurance Brokerage, Inc. — 1901 NW Military Hwy, Ste 200, San Antonio, TX 78213

Inside the Service: click the blue support button in OmniReach CRM