Last updated: July 1, 2026
This Privacy Policy describes how TMS Insurance Brokerage, Inc. ("OmniReach," "we," "us," or "our") collects, uses, and discloses information about you when you access or use the OmniReach CRM service, website at omnireachcrm.com, and related products (the "Service"). It also describes your rights with respect to your information and how to contact us.
OmniReach CRM is a HIPAA-compliant customer relationship management platform built on the GoHighLevel platform and marketed to insurance agents, agencies, and downline organizations. Our customers use the Service to manage their own contacts, communications, and business operations. This policy describes our practices with respect to information collected through our website and through our direct relationship with you as a Service user.
If you are a contact, lead, or end-client of an OmniReach user (rather than an OmniReach customer yourself), the OmniReach customer who maintains your information is the data controller of that information. Their own privacy policy governs how your information is collected and used. We process that information on their behalf as a service provider, and where Protected Health Information is involved, as a HIPAA Business Associate.
For the purposes of this Privacy Policy:
While using our Service, we may ask you to provide certain personally identifiable information that can be used to contact or identify you. This may include:
When you pay for the Service, we may ask you to provide information to facilitate the transaction and verify your identity. This may include date of birth, government-issued ID, or other verifying information depending on the payment method.
Our public website at omnireachcrm.com is not intended to collect Protected Health Information. PHI is processed only within the authenticated Service environment by OmniReach customers who handle PHI in the course of their own business. See our Data Privacy Policy for our practices with respect to PHI.
Usage Data is collected automatically when you use the Service. Usage Data may include:
This information helps us understand how the Service is used, identify technical issues, and improve performance.
We use Cookies and similar tracking technologies to operate the Service, analyze usage, and store preferences. The technologies we may use include:
Small files placed on your device. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some parts of the Service may not function properly.
Certain sections of our Service and emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that allow us to count users who have visited pages or opened emails for related statistics and to verify system and server integrity.
We use cookies in the following categories:
Most browsers let you disable or delete cookies. You can adjust your browser settings to refuse cookies or to alert you when cookies are being sent. If you disable essential cookies, parts of the Service may not work properly. We do not use cookies to build cross-site advertising profiles of you.
The Company may use Personal Data for the following purposes:
When you submit a form on omnireachcrm.com and provide your phone number, you may be asked to consent to receive text messages from TMS Insurance Brokerage, Inc., operating OmniReach CRM. If you provide that consent, the following applies:
We do not sell your Personal Data. We do not share your Personal Data with third parties for their own marketing purposes. We share information only as described in this section.
We share information with third-party vendors that perform services on our behalf, such as cloud hosting, payment processing, customer support, analytics, email delivery, and security monitoring. These vendors are contractually obligated to use the information only as necessary to provide services to us and to protect the confidentiality and security of the information.
OmniReach CRM is built on the GoHighLevel platform operated by HighLevel Inc. Information processed through the Service is hosted by HighLevel as our platform provider, under appropriate data processing terms.
When you send SMS, place voice calls, or send email through the Service, the content of those communications is routed through third-party carrier networks (such as Twilio and similar providers) for delivery. These providers process the communication metadata and content as needed to deliver the message.
We may disclose information when we believe in good faith that disclosure is necessary to:
If OmniReach is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets — including a future transition of OmniReach to a separate legal entity — your information may be transferred as part of that transaction. We will provide notice before your Personal Data becomes subject to a different privacy policy.
We may share information for other purposes with your consent or at your direction.
We retain Personal Data for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. The Company will retain Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when used to strengthen security or improve Service functionality, or when we are legally required to retain it longer.
When Personal Data is no longer needed for these purposes, we delete or de-identify it, subject to technical limitations of backup and archival systems.
Customers can request deletion of their Personal Data as described in the Your Privacy Rights section below. PHI processed under a Business Associate Agreement is retained, returned, or destroyed in accordance with the terms of the applicable BAA.
OmniReach operates from the United States, and information we collect is processed and stored in the United States. Your information, including Personal Data, is processed at the Company's operating offices and in any other places where parties involved in the processing are located. This means your information may be transferred to and maintained on systems located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
If you are accessing the Service from outside the United States, please be aware that information you provide may be transferred to, stored in, and processed in the United States. The Company will take steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
We take the security of your Personal Data seriously and implement reasonable administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of the information processed through our Services. These measures may include:
Our Services are powered in part by third-party technology providers, including HighLevel, which maintain security controls at the platform and infrastructure level. While we take reasonable steps to protect information entrusted to us, customers are responsible for maintaining the security of their account credentials, configuring available security settings, and managing user access permissions within their accounts.
No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to protect your Personal Data using commercially reasonable safeguards, we cannot guarantee absolute security. If you believe your account or information may have been compromised, please contact us immediately.
We may provide paid products and services within the Service. In that case, we use third-party services for payment processing.
We do not store or collect your full payment card details on our servers. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their privacy policies. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
Payment processors we may use include:
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at info@omnireachcrm.com. We will respond within the timeframes required by applicable law. We may need to verify your identity before responding.
This section supplements the rest of this Privacy Policy and applies solely to visitors, users, and others who reside in the State of California.
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. Below are the CCPA categories of personal information we may have collected from California residents within the last twelve (12) months:
Under CCPA, "personal information" does not include publicly available government records, deidentified or aggregated consumer information, or information covered by certain sector-specific privacy laws such as HIPAA, the California Confidentiality of Medical Information Act (CMIA), the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), and similar laws.
We obtain personal information from:
We may use or disclose personal information we collect for "business purposes" or "commercial purposes" (as defined under CCPA), which may include:
OmniReach does not sell Personal Data and does not share Personal Data for cross-context behavioral advertising as those terms are defined under California law.
In the past twelve (12) months, we may have disclosed the following categories of personal information for business or commercial purposes:
When we disclose personal information for a business or commercial purpose, we enter a contract that describes the purpose and requires the recipient to keep the personal information confidential and use it only for the purpose of performing the contract.
We do not knowingly collect personal information from minors under the age of 16 through our Service. We do not sell the personal information of consumers we actually know are less than 16 years of age. If you believe that a minor has provided us with personal information, please contact us so we can delete it.
California residents have the following rights regarding their personal information:
California residents may use an authorized agent to submit a request on their behalf. We will require verification of the agent's authority before responding.
To exercise any of your rights under CCPA/CPRA, contact us:
Your request must provide sufficient information to verify you are the person about whom we collected personal information (or an authorized representative) and describe your request with enough detail that we can properly understand, evaluate, and respond. We will disclose and deliver the required information free of charge within 45 days of receiving your verifiable request. The time period may be extended once by an additional 45 days when reasonably necessary, with prior notice.
Under California Civil Code Section 1798 (Shine the Light), California residents with an established business relationship with us can request information once a year about whether we share their Personal Data with third parties for those third parties' direct marketing purposes. To make such a request, contact us using the information above. As stated above, we do not share Personal Data with third parties for their own direct marketing purposes.
California Business and Professions Code section 22581 allows California residents under the age of 18 who are registered users of online sites, services, or applications to request and obtain removal of content or information they have publicly posted. To request removal, contact us at the email above with the email address associated with your account. Removal may not be complete or comprehensive in all circumstances.
Residents of other U.S. states with comprehensive privacy laws may have similar rights. We comply with applicable state privacy laws including:
Residents of these states may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, as well as the right to opt out of certain processing activities. To exercise these rights, contact us at info@omnireachcrm.com.
Our Service does not respond to Do Not Track (DNT) signals because no common standard for responding to such signals has been established. Some third-party websites may track your browsing activities. You can set your browser preferences to inform websites that you do not want to be tracked. You can enable or disable DNT by visiting the preferences or settings page of your web browser.
Our Service is intended for licensed insurance professionals and does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and become aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from anyone under the age of 13 without verification of parental consent, we take steps to remove that information from our servers.
Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice on our Service before the change becomes effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of the Service after the effective date of a revised Policy constitutes acceptance of the changes.
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, contact us using the information below.
Email: info@omnireachcrm.com
Mail: TMS Insurance Brokerage, Inc. — 1901 NW Military Hwy, Ste 200, San Antonio, TX 78213
Inside the Service: click the blue support button in OmniReach CRM