Privacy Policy
Effective
This is the privacy policy for Signal Specialty as a company — it covers this website, the Broker Portal, and the systems behind them. It explains what information we collect, why, who we share it with, and the choices you have. We have tried to write it in plain language and to describe what actually happens rather than everything the law would permit.
1. Who we are
In this policy, “Signal Specialty,” “we,” “us” and “our” mean Signal Specialty, Inc. and its affiliates, including Signal Specialty Insurance Services, LLC, the operating entity through which our insurance activities are conducted. Our mailing address is 25 Bridge Street, Red Bank, New Jersey 07701.
Signal Specialty is a specialty managing general agency serving the construction economy. We work with licensed insurance agencies and brokerages, and with carrier partners.
2. What this policy covers
This is our single company-wide privacy policy. Rather than publish a different policy for each product, we keep one, so that what we say in one place cannot drift from what we say in another. It covers:
- This website
- www.signalspecialty.com — our public marketing site, including agency pre-registration and live chat.
- The Broker Portal
- broker.signalspecialty.com — the application appointed and onboarding agencies use to submit business and track quotes, binders and policies.
- The systems behind them
- Our internal policy management, underwriting and document systems, which are the systems of record for the information those two surfaces collect.
It does not cover websites or services operated by anyone else, even where we link to them. Your use of this website is also governed by our Terms of Service; use of the Broker Portal is governed by that application’s own terms and by any written agreement between us and your agency.
3. Who this policy is about
Three different groups of people appear in our systems, and the information we hold about each is different. Find yourself here and the rest of the policy will make more sense.
- Visitors to this website
- Anyone reading these pages. We hold very little about you — see section 4. If you pre-register an agency, we hold what you submitted.
- Broker Portal users
- Named individuals at an agency who sign in to the portal. We hold your identity, your role, and a record of what you did — see section 5.
- People whose information a broker submits to us
- Insured businesses and the individuals connected to them — owners, principals, officers, and, for surety bonds, indemnitors. You may never have visited any of our websites. Your information reaches us because your broker submitted it so that we could consider a risk. This is the group about whom we hold the most sensitive information — see section 6.
4. What we collect — this website
Agency pre-registration
When you pre-register an agency, we collect your name, business email address and phone number; your agency’s name, website, distribution channel and legal structure; its year of formation, National Producer Number and federal employer identification number (FEIN); its business and mailing addresses; the name, email address and phone number of an onboarding contact; details of its errors-and-omissions coverage, including carrier, limit and expiration date; business-mix information such as year-to-date premium and the share of that premium written in commercial lines; the states and lines of business you are interested in; anything you write in the free-text description; and your responses to the background attestation and the communications consent.
The pre-registration form does not ask for Social Security numbers, consumer credit information, payment card numbers, bank account details or government identification. A FEIN is a business tax identifier rather than a personal one; we collect it because appointing an agency requires it. (Section 6 describes the very different, and more sensitive, information that reaches us through the Broker Portal.)
Contacting us, and live chat
If you email or call one of the addresses or numbers published on this site, we receive whatever you choose to include. If you start a conversation in the chat window, we receive the messages you send, any contact details you volunteer in them, and the page you were reading when you opened the conversation.
Job applications
If you apply for a role, you email us directly, and we receive your résumé and whatever else you send.
5. What we collect — the Broker Portal
If you are a named user at an agency, signing in to the portal means we hold:
- Your identity and role — name, business email address, telephone number, the agency you belong to, and whether you hold an owner or staff role, which determines what you can see and change.
- Authentication information — your sign-in credentials are held by our identity provider, not by us directly. If you use a passkey, what is registered is a public key; the private key and any fingerprint or face data stay on your own device and are never transmitted to us.
- Session and security records — sign-in events, session refreshes and sign-outs, kept so we can secure accounts and investigate suspicious activity.
- What you did in the portal — the accounts, submissions, quotes, binders, policies and documents you created or accessed, and when. In insurance this is not optional bookkeeping; it is the audit trail our regulatory and recordkeeping obligations require.
- Support conversations — live chat is available in the portal from the same provider used on this website.
6. Information about insureds, principals and indemnitors
This section is about people whose information reaches us because a broker submitted it. If a broker has approached us about insurance or a surety bond for your business, this is the part that applies to you.
About the business
Legal and trading names, entity type, federal employer identification number, industry classification, addresses, contact details, year of formation, operational and exposure information relevant to underwriting, loss history, prior insurance, and, for surety, contract and financial information about the work being bonded.
About individuals connected to the business
Names, job titles, contact details and ownership share for owners, principals, officers and other listed personnel.
For surety bonds we also collect sensitive personal information about indemnitors — the individuals who personally guarantee a bond. That includes Social Security number, date of birth and driver’s license number, together with home address details. Personal indemnity is how surety credit works: the guarantee is the individual’s, so the individual has to be identified and their credit assessed.
We treat that information accordingly. Social Security numbers and driver’s license numbers are encrypted before they are stored, are left out of list and search responses, and are shown in our own interfaces as the last four digits unless someone with a specific need reveals the full value. Section 17 has the detail.
Documents
Applications, ACORD forms, loss runs, financial statements, contracts and other documents a broker uploads, along with the information inside them. Section 12 explains how documents are read.
How this information reaches us
Almost always from your broker, acting for you, rather than from you directly. When an agency submits information about you to us, it confirms that it is authorized to do so. If you would like to know what we hold about you and you are not sure where to start, contact us using section 24 — you do not have to go through your broker.
7. What we collect automatically
Our hosting and content delivery providers record standard web server and network logs when a page, file or interface is requested: the IP address the request came from, the date and time, what was requested, the referring page, and the browser and operating system your browser reports. We use them to serve our services, to diagnose faults, and to detect and block abuse.
The pre-registration form on this website also measures how long the form was open before it was submitted and includes a hidden field that a person never sees. Both exist to tell a person filling in a form from a script, and neither is used to build a profile of you.
We run no analytics and no advertising trackers on this website. We do not measure page views, and we do not track you across other websites.
8. Information from other sources
To underwrite responsibly we have to verify what we are told, which means obtaining information from third parties:
- Business verification
- Registration, identity and status information about a business, obtained from business-verification providers, often keyed on a federal employer identification number.
- Credit information
- Business credit information about an applicant business and, for individual indemnitors on surety bonds, consumer credit information obtained from a consumer reporting agency. See section 18 for your rights when we obtain a consumer report about you.
- Licensing
- Producer and agency licensing status, verified against insurance-regulator records.
- Insurance and public records
- Policy, coverage and public business information from insurance-data providers and publicly available records.
- Introductions
- Information from a carrier, technology partner or industry contact who introduces you to us.
9. How we use information
- evaluate a pre-registration and decide whether to move forward with an appointment;
- verify an agency’s licensing, producer number and errors-and-omissions coverage;
- provide the Broker Portal: authenticate users, control what each role can see, and operate the submission, quoting, binding and policy features;
- underwrite — assess and price risk, evaluate surety credit and indemnity, and decide whether to offer terms;
- issue and service quotes, binders, policies and bonds, and handle the administration that goes with them;
- communicate with you about a registration, a submission or a relationship;
- operate, maintain, secure and improve our services;
- detect, investigate and prevent fraud, abuse and security incidents; and
- comply with our legal, regulatory and recordkeeping obligations, which in insurance are substantial, and establish or defend legal claims.
10. Communications
When you pre-register, you are asked to agree that we and our representatives may contact you at the email address and telephone number you provided about your registration and any resulting business relationship, and that we may deliver notices, disclosures, agreements and other records to you electronically. That agreement is required to pre-register, because there is no way for us to act on a registration without being able to reach you.
You can withdraw it at any time by writing to us at the address in section 24. Withdrawing it means we stop sending you relationship-related messages; certain communications may still be delivered by mail where the law requires it, and withdrawing it may mean we cannot continue an appointment process. Operational messages about an active submission, policy or account are part of the service rather than marketing, and are not something we can switch off while the relationship is live.
12. AI and automated processing
When a document is uploaded — an application, an ACORD form, a loss run, a financial statement — we use an artificial-intelligence service to read it and propose values for the corresponding fields, instead of asking someone to re-key the whole thing. Doing that means the contents of the document are transmitted to that provider (currently Anthropic), including any personal information the document happens to contain.
Two things about how this is used matter:
- A person confirms the result. Extracted values are presented for review and are corrected or accepted by a person before they are saved. The model proposes; it does not decide.
- No automated decision-making about individuals. We do not use automated processing, including profiling, to make decisions that produce legal or similarly significant effects about an individual without human involvement. Underwriting decisions are made by our underwriters.
13. We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioral advertising — including as those terms are defined by California law. We have not done so in the twelve months before the effective date of this policy. We do not trade, rent or license contact lists to anyone, and we do not use information we hold for advertising of any kind.
15. How long we keep information
We keep information for as long as we need it for the purposes described in this policy, and then for as long as our legal, regulatory and recordkeeping obligations require. In insurance those obligations are the binding constraint, and they are usually measured in years after a relationship ends — underwriting files, policy records and the audit trail behind them have to survive the policy period, the claims tail and any examination. In practice:
- Underwriting, policy and bond records, and the documents and audit trail supporting them, are kept for the life of the relationship and then for the retention period our obligations in the relevant states require.
- Pre-registrations that do not lead to an appointment are kept for a reasonable period so we can tell you when our programs reach your states and lines, and so we have a record of why a decision was made.
- Email and chat correspondence is kept in line with our ordinary business records practice.
- Web server, network and application logs are kept for a short operational period and then deleted.
- Encrypted backups persist on their own cycle — daily copies for about a month, weekly for about a quarter, and monthly for about a year — so information deleted from our live systems may remain in a backup until that copy expires.
When information is no longer needed for any of these purposes, we delete it or de-identify it.
16. Where information is processed
Signal Specialty operates in the United States. Our services are intended for users in the United States, and information we collect is stored and processed there — in a primary US region, with encrypted backup copies held in a second US region for disaster recovery. We do not transfer personal information outside the United States. Some of our service providers are international companies, but the processing they do for us is done in the United States.
We do not offer our programs in, or direct our services to, the European Economic Area, the United Kingdom or Switzerland, and this policy makes no commitments under the privacy laws of those jurisdictions. If you access our services from outside the United States, you do so on your own initiative.
17. How we protect information
We design for security rather than bolting it on. Without describing our defenses in enough detail to help anyone get past them:
- In transit. Everything is served over encrypted connections only, with HTTP Strict Transport Security.
- At rest. Our databases, file storage and backups are encrypted. Beyond that, Social Security numbers and driver’s license numbers are separately encrypted by the application before they are written using AES-256-GCM, so they are protected even from someone reading the database directly. They are excluded from list and search responses, and are normally displayed only as the last four digits.
- In our logs. Sensitive fields — Social Security numbers, driver’s license numbers, employer identification numbers, credentials, tokens and cookies — are stripped out centrally before anything is written, and recursively, so a value nested deep inside a record is caught too. This is enforced by the logging system rather than left to each developer to remember.
- Access. Broker Portal accounts authenticate through a managed identity service and support passkeys; session tokens are held in memory rather than written to browser storage. Our internal systems are restricted to our own company accounts, and access is limited to people who need it.
- The perimeter. Public content is served from private storage that is not directly reachable from the internet, behind a web application firewall with rate limiting, under a strict content security policy that prevents unapproved third-party code from running on the page.
- Operations. Deployments use short-lived, federated credentials rather than long-lived keys. Backups are encrypted and held in a separate region.
No system is perfectly secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability in any of our services, please tell us at security@signalspecialty.com — our security contact details are also published at /.well-known/security.txt.
18. Insurance privacy and consumer reports
Much of what we hold is regulated as financial and insurance information rather than as ordinary website data, and that changes which rules apply.
Nonpublic personal information
Personal information we collect in connection with an insurance transaction — an application, an underwriting file, a policy, a bond, an indemnity — is nonpublic personal information under the Gramm-Leach-Bliley Act and the state insurance privacy regulations that implement it. We collect, use and disclose it for the insurance purposes described in this policy: to underwrite, quote, issue, service and administer coverage, to detect fraud, and to meet our legal and regulatory obligations. We do not disclose it to anyone for their own marketing purposes.
Where a state privacy statute exempts information or activity already governed by these financial-privacy rules, the rights in sections 20 and 21 may not apply to that information — but the protections above always do. Where both regimes apply, we follow whichever gives you the greater protection.
Consumer reports
For surety bonds we obtain a consumer report — a credit report — about individual indemnitors, because personal indemnity is what secures the bond. We obtain it for a permissible purpose under the Fair Credit Reporting Act: reviewing your application, and evaluating an obligation you are personally guaranteeing.
Under the FCRA you have the right to:
- be told if information in a consumer report was used against you, and which consumer reporting agency supplied it;
- obtain a copy of your report from that agency, free of charge if a decision was based on it; and
- dispute information you believe is inaccurate or incomplete directly with the consumer reporting agency, which must investigate.
We do not correct the contents of a consumer report ourselves — only the agency that compiled it can do that — but tell us and we will identify the agency and re-examine any decision once it is corrected.
19. Your choices
- Do not submit it. You can read this website without submitting anything.
- Stop the messages. Ask us to stop contacting you, or withdraw the communications consent described in section 10, by writing to the address in section 24.
- Correct or delete what we hold. Ask us to correct information that is wrong, or to delete information we no longer need to keep. See sections 20 and 21 for the formal rights that may apply to you, and section 18 for where insurance recordkeeping limits what we can delete.
- Ask us directly. If your information reached us through a broker, you can still come to us. You do not have to go through them.
- Turn off chat storage. Block cookies and local storage for this site in your browser, as described in section 14.
20. California privacy rights
This section applies to California residents and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”). It describes the same practices as the rest of this policy, in the categories the CCPA uses. Note that information governed by the financial-privacy rules described in section 18 is exempt from the CCPA; the categories below are stated in full so you can see everything we hold, whichever regime governs it.
Categories of personal information we have collected
In the twelve months before the effective date of this policy, we have collected the following categories — from the sources in sections 4 to 8, for the purposes in section 9, and disclosed for a business purpose to the recipients in section 11:
- Identifiers
- Name, postal address, business email address, telephone number, IP address, account identifiers and Social Security number and driver’s license number for surety indemnitors.
- Customer records information (California Civil Code § 1798.80(e))
- Name, signature, address, telephone number, insurance information and financial information relating to an agency, an insured business or an indemnitor.
- Protected classification characteristics
- Age or date of birth, collected for indemnitors in order to identify them for a credit assessment. We do not collect race, ethnicity, religion, sexual orientation, health information or any other protected characteristic.
- Commercial information
- Products and lines of business you have expressed interest in, submissions, quotes, binders, policies and bonds, and records of our correspondence.
- Internet or other electronic network activity
- Web server, network and application log entries; sign-in and session records; records of activity within the Broker Portal.
- Professional or employment-related information
- Job title, role, ownership share, National Producer Number, licensing status, and — if you apply for a role — the contents of your application.
- Financial information
- Business and, for indemnitors, personal credit information obtained from a consumer reporting agency; business-mix and financial statement information.
- Inferences
- We do not create profiles or draw inferences about your preferences, characteristics or behavior.
We do not collect geolocation data, biometric information, audio or video recordings, or education records. Passkey sign-in may use your device’s fingerprint or face recognition to unlock a credential, but that happens entirely on your device and no biometric data reaches us.
Sensitive personal information
We collect two categories of sensitive personal information, and only for surety indemnitors: Social Security number and driver’s license number. We collect them for one purpose — identifying an individual guarantor and obtaining the credit information needed to evaluate the indemnity — and we use and disclose them only for that purpose, for the related insurance purposes in section 9, and to meet our legal obligations.
Because we do not use or disclose sensitive personal information for any purpose beyond those permitted by the CCPA without a right to limit, the right to limit its use does not arise — there is no additional use to switch off. We do not use it to infer characteristics about you. We do not collect account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, health information, or the contents of your private communications.
Sale and sharing
We have not sold personal information and have not shared it for cross-context behavioral advertising in the twelve months before the effective date of this policy, and we do not do so now. We do not knowingly sell or share the personal information of anyone under 16.
Your rights
- Know and access. Ask what personal information we have collected about you, where we got it, why, who we disclosed it to, and receive a copy in a portable form.
- Delete. Ask us to delete personal information we collected from you, subject to the exceptions the CCPA allows — most often our legal and regulatory recordkeeping obligations, which for insurance records are extensive.
- Correct. Ask us to correct inaccurate personal information. For information in a consumer report, see section 18 — the consumer reporting agency, not us, corrects the report itself.
- Opt out of sale or sharing. We do neither, so there is nothing to opt out of. That is why there is no “Do Not Sell or Share My Personal Information” link.
- Limit sensitive personal information. As explained above, this right does not arise on our services.
- Non-discrimination. We will not deny you service, charge you a different price or give you a lesser quality of service because you exercised a privacy right.
How to exercise them
Use any of the contact routes in section 24. Tell us which right you are exercising and give us enough detail to find your records. We will verify who you are before we act — usually by matching the details you give us against what we already hold, and by corresponding with you at an email address or telephone number already in our records. Because some of what we hold is sensitive, we may ask for more assurance for a request that touches it. We will respond within the time the CCPA allows.
An authorized agent may make a request on your behalf if they provide written permission signed by you; we may still contact you directly to confirm it.
21. Other US state privacy rights
Several other states — among them Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia — give their residents privacy rights broadly similar to those in section 20. Depending on where you live, those may include the right to confirm whether we process your personal data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, or profiling that produces legal or similarly significant effects.
We do not conduct targeted advertising, we do not sell personal data, and we do not carry out profiling of that kind, so those opt-outs do not arise. Several of these statutes also exempt information or entities governed by the financial-privacy rules in section 18; where that exemption applies, those rights may not extend to the exempted information.
To exercise any of these rights, contact us using section 24. If we decline a request, you may appeal by replying to our response or writing to us again and saying you are appealing; we will review it and tell you the outcome in writing, along with how to raise the matter with your state attorney general if you are still not satisfied.
22. Children
Our services are intended for insurance and business professionals. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us at the address in section 24 and we will delete it.
23. Changes to this policy
We will update this policy when what we do changes — a new service provider, a new product, a new kind of information. When we do, we will change the effective date at the top of the page. If a change materially affects how we handle information we already hold about you, we will take reasonable steps to tell you directly rather than relying on you to notice.
Because this is our single company-wide policy, a change here applies to every Signal Specialty service that links to it.
24. How to contact us
For any privacy question, or to exercise a right described in section 18, 20 or 21:
- privacy@signalspecialty.com, or support@signalspecialty.com
- Telephone
- (888) 744-1605
-
Signal Specialty — Privacy
25 Bridge Street
Red Bank, New Jersey 07701
Our Terms of Service govern your use of this website. Use of the Broker Portal is governed by that application’s own terms.