Legal

Privacy Policy

Last updated: July 1, 2026

This Privacy Policy describes how OmniReach CRM collects, uses, and shares information about you when you access or use our website at omnireachcrm.com and the OmniReach CRM platform. For our practices regarding Protected Health Information (PHI) under HIPAA, please also see our Data Privacy Policy.

1.About This Policy

This Privacy Policy describes how TMS Insurance Brokerage, Inc. ("OmniReach," "we," "us," or "our") collects, uses, and discloses information about you when you access or use the OmniReach CRM service, website at omnireachcrm.com, and related products (the "Service"). It also describes your rights with respect to your information and how to contact us.

OmniReach CRM is a HIPAA-compliant customer relationship management platform built on the GoHighLevel platform and marketed to insurance agents, agencies, and downline organizations. Our customers use the Service to manage their own contacts, communications, and business operations. This policy describes our practices with respect to information collected through our website and through our direct relationship with you as a Service user.

If you are a contact, lead, or end-client of an OmniReach user (rather than an OmniReach customer yourself), the OmniReach customer who maintains your information is the data controller of that information. Their own privacy policy governs how your information is collected and used. We process that information on their behalf as a service provider, and where Protected Health Information is involved, as a HIPAA Business Associate.

2.Definitions

For the purposes of this Privacy Policy:

"Account"
means a unique account created for you to access the Service.
"Business"
for CCPA/CPRA purposes, refers to the Company as the legal entity that determines the purposes and means of processing Consumers' personal information.
"Company"
(also "we," "us," or "our") refers to TMS Insurance Brokerage, Inc., 1901 NW Military Hwy, Ste 200, San Antonio, TX 78213.
"Consumer"
for CCPA/CPRA purposes, means a natural person who is a California resident.
"Cookies"
are small files placed on your device by a website that record browsing details for various purposes.
"Device"
means any device that can access the Service, including computers, mobile phones, and tablets.
"Do Not Track" (DNT)
is a setting that some browsers offer to signal that you do not wish to be tracked across websites.
"Personal Data"
means any information that relates to an identified or identifiable individual.
"PHI"
or Protected Health Information has the meaning given in the Health Insurance Portability and Accountability Act of 1996, as amended.
"Sale"
for CCPA/CPRA purposes, means selling, renting, releasing, disclosing, transferring, or otherwise communicating a Consumer's personal information to another business or third party for monetary or other valuable consideration.
"Service"
refers to the website at omnireachcrm.com and the OmniReach CRM platform and related products.
"Service Provider"
means any third party that processes data on the Company's behalf.
"Usage Data"
refers to data collected automatically through your use of the Service.
"You"
means the individual or entity accessing or using the Service.

3.Personal Data We Collect

While using our Service, we may ask you to provide certain personally identifiable information that can be used to contact or identify you. This may include:

When you pay for the Service, we may ask you to provide information to facilitate the transaction and verify your identity. This may include date of birth, government-issued ID, or other verifying information depending on the payment method.

Information We Do Not Collect Through the Website

Our public website at omnireachcrm.com is not intended to collect Protected Health Information. PHI is processed only within the authenticated Service environment by OmniReach customers who handle PHI in the course of their own business. See our Data Privacy Policy for our practices with respect to PHI.

4.Usage Data

Usage Data is collected automatically when you use the Service. Usage Data may include:

This information helps us understand how the Service is used, identify technical issues, and improve performance.

5.Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to operate the Service, analyze usage, and store preferences. The technologies we may use include:

Cookies (Browser Cookies)

Small files placed on your device. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some parts of the Service may not function properly.

Web Beacons

Certain sections of our Service and emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that allow us to count users who have visited pages or opened emails for related statistics and to verify system and server integrity.

Cookies We Use

We use cookies in the following categories:

Essential
required to authenticate users, prevent fraud, and provide core Service functionality. These cannot be disabled.
Functional
remember choices you make (such as login details, timezone, or preferences) so you don't have to re-enter them each visit.
Analytics
help us understand which pages are viewed and how the Service is performing in aggregate. These do not include PHI.
Notice Acceptance
record whether you have accepted our use of cookies on the website.

Your Cookie Choices

Most browsers let you disable or delete cookies. You can adjust your browser settings to refuse cookies or to alert you when cookies are being sent. If you disable essential cookies, parts of the Service may not work properly. We do not use cookies to build cross-site advertising profiles of you.

6.How We Use Your Personal Data

The Company may use Personal Data for the following purposes:

7.SMS and Text Message Communications

When you submit a form on omnireachcrm.com and provide your phone number, you may be asked to consent to receive text messages from TMS Insurance Brokerage, Inc., operating OmniReach CRM. If you provide that consent, the following applies:

8.How We Share Information

We do not sell your Personal Data. We do not share your Personal Data with third parties for their own marketing purposes. We share information only as described in this section.

Service Providers

We share information with third-party vendors that perform services on our behalf, such as cloud hosting, payment processing, customer support, analytics, email delivery, and security monitoring. These vendors are contractually obligated to use the information only as necessary to provide services to us and to protect the confidentiality and security of the information.

Platform Provider

OmniReach CRM is built on the GoHighLevel platform operated by HighLevel Inc. Information processed through the Service is hosted by HighLevel as our platform provider, under appropriate data processing terms.

Carrier Networks

When you send SMS, place voice calls, or send email through the Service, the content of those communications is routed through third-party carrier networks (such as Twilio and similar providers) for delivery. These providers process the communication metadata and content as needed to deliver the message.

Legal and Safety Disclosure

We may disclose information when we believe in good faith that disclosure is necessary to:

Business Transfers

If OmniReach is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets — including a future transition of OmniReach to a separate legal entity — your information may be transferred as part of that transaction. We will provide notice before your Personal Data becomes subject to a different privacy policy.

With Your Consent

We may share information for other purposes with your consent or at your direction.

9.Data Retention

We retain Personal Data for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. The Company will retain Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when used to strengthen security or improve Service functionality, or when we are legally required to retain it longer.

When Personal Data is no longer needed for these purposes, we delete or de-identify it, subject to technical limitations of backup and archival systems.

Customers can request deletion of their Personal Data as described in the Your Privacy Rights section below. PHI processed under a Business Associate Agreement is retained, returned, or destroyed in accordance with the terms of the applicable BAA.

10.International Transfer

OmniReach operates from the United States, and information we collect is processed and stored in the United States. Your information, including Personal Data, is processed at the Company's operating offices and in any other places where parties involved in the processing are located. This means your information may be transferred to and maintained on systems located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

If you are accessing the Service from outside the United States, please be aware that information you provide may be transferred to, stored in, and processed in the United States. The Company will take steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

11.Security

We take the security of your Personal Data seriously and implement reasonable administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of the information processed through our Services. These measures may include:

Our Services are powered in part by third-party technology providers, including HighLevel, which maintain security controls at the platform and infrastructure level. While we take reasonable steps to protect information entrusted to us, customers are responsible for maintaining the security of their account credentials, configuring available security settings, and managing user access permissions within their accounts.

No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to protect your Personal Data using commercially reasonable safeguards, we cannot guarantee absolute security. If you believe your account or information may have been compromised, please contact us immediately.

12.Payment Processing

We may provide paid products and services within the Service. In that case, we use third-party services for payment processing.

We do not store or collect your full payment card details on our servers. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their privacy policies. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council.

Payment processors we may use include:

13.Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, contact us at info@omnireachcrm.com. We will respond within the timeframes required by applicable law. We may need to verify your identity before responding.

14.California Privacy Rights (CCPA/CPRA)

This section supplements the rest of this Privacy Policy and applies solely to visitors, users, and others who reside in the State of California.

Categories of Personal Information Collected

We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. Below are the CCPA categories of personal information we may have collected from California residents within the last twelve (12) months:

Category
Examples
Collected
A. Identifiers
Name, alias, postal address, IP address, email, account name, similar identifiers.
Yes
B. Customer Records
Name, signature, address, phone, employment, financial info (Cal. Civ. Code §1798.80(e)).
Yes
C. Protected Classifications
Race, religion, age, gender, etc.
No
D. Commercial Information
Records and history of products or services purchased.
Yes
E. Biometric Information
Fingerprints, voiceprints, etc.
No
F. Internet Activity
Interaction with our Service or advertisements.
Yes
G. Geolocation Data
Precise geolocation tracking.
No
H. Sensory Data
Audio, visual, thermal, olfactory.
No
I. Professional Information
Business role, industry, licensing information.
Yes
J. Education Information
Non-public education records under FERPA.
No
K. Inferences
Inferences drawn from other personal information.
No

Under CCPA, "personal information" does not include publicly available government records, deidentified or aggregated consumer information, or information covered by certain sector-specific privacy laws such as HIPAA, the California Confidentiality of Medical Information Act (CMIA), the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), and similar laws.

Sources of Personal Information

We obtain personal information from:

Use of Personal Information

We may use or disclose personal information we collect for "business purposes" or "commercial purposes" (as defined under CCPA), which may include:

Sale or Sharing of Personal Information

OmniReach does not sell Personal Data and does not share Personal Data for cross-context behavioral advertising as those terms are defined under California law.

Disclosure of Personal Information

In the past twelve (12) months, we may have disclosed the following categories of personal information for business or commercial purposes:

When we disclose personal information for a business or commercial purpose, we enter a contract that describes the purpose and requires the recipient to keep the personal information confidential and use it only for the purpose of performing the contract.

Sale of Personal Information of Minors Under 16

We do not knowingly collect personal information from minors under the age of 16 through our Service. We do not sell the personal information of consumers we actually know are less than 16 years of age. If you believe that a minor has provided us with personal information, please contact us so we can delete it.

Your Rights Under CCPA/CPRA

California residents have the following rights regarding their personal information:

Authorized Agents

California residents may use an authorized agent to submit a request on their behalf. We will require verification of the agent's authority before responding.

Exercising Your Rights

To exercise any of your rights under CCPA/CPRA, contact us:

Your request must provide sufficient information to verify you are the person about whom we collected personal information (or an authorized representative) and describe your request with enough detail that we can properly understand, evaluate, and respond. We will disclose and deliver the required information free of charge within 45 days of receiving your verifiable request. The time period may be extended once by an additional 45 days when reasonably necessary, with prior notice.

California's Shine the Light Law

Under California Civil Code Section 1798 (Shine the Light), California residents with an established business relationship with us can request information once a year about whether we share their Personal Data with third parties for those third parties' direct marketing purposes. To make such a request, contact us using the information above. As stated above, we do not share Personal Data with third parties for their own direct marketing purposes.

California Privacy Rights for Minor Users

California Business and Professions Code section 22581 allows California residents under the age of 18 who are registered users of online sites, services, or applications to request and obtain removal of content or information they have publicly posted. To request removal, contact us at the email above with the email address associated with your account. Removal may not be complete or comprehensive in all circumstances.

15.Other State Privacy Laws

Residents of other U.S. states with comprehensive privacy laws may have similar rights. We comply with applicable state privacy laws including:

Residents of these states may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, as well as the right to opt out of certain processing activities. To exercise these rights, contact us at info@omnireachcrm.com.

16."Do Not Track" Policy

Our Service does not respond to Do Not Track (DNT) signals because no common standard for responding to such signals has been established. Some third-party websites may track your browsing activities. You can set your browser preferences to inform websites that you do not want to be tracked. You can enable or disable DNT by visiting the preferences or settings page of your web browser.

17.Children's Privacy

Our Service is intended for licensed insurance professionals and does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and become aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from anyone under the age of 13 without verification of parental consent, we take steps to remove that information from our servers.

Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

19.Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice on our Service before the change becomes effective and update the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of the Service after the effective date of a revised Policy constitutes acceptance of the changes.

20.Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, contact us using the information below.

Privacy questions or data requests?

Email: info@omnireachcrm.com

Mail: TMS Insurance Brokerage, Inc. — 1901 NW Military Hwy, Ste 200, San Antonio, TX 78213

Inside the Service: click the blue support button in OmniReach CRM