Version 2026.07.21-1 · The English version controls; the Chinese translation is for convenience only.
English controlling version
**Operator** POM Insurance Agency Inc, doing business as POM
Peace of Mind Insurance Agency, a California
corporation with S corporation tax status
**Domains** https://seminar.pom365.com/;
https://training.pom365.com/
**Version** 2026.07.21-1
**Effective date** Effective when accepted by the user after final
company approval
**Contact**
[email protected]; 1900 S Norfolk Street, Suite
350, San Mateo, California 94403
**PLAIN-LANGUAGE SUMMARY**
We use personal information to operate a U.S.-only training platform,
verify eligibility and licenses, communicate, secure accounts,
support approved professional workflows, analyze and improve the
service, and comply with law. We do not sell personal information or
share it for cross-context behavioral advertising. Marketing
communications are optional.
## 1. Scope and Controller
This Privacy Policy explains how POM Insurance Agency Inc, doing
business as POM Peace of Mind Insurance Agency, a California corporation
with S corporation tax status collects, uses, discloses, retains, and
protects personal information through POM365 and the domains listed
above. California insurance agency license 0N02495. The operator
determines the purposes and means of Platform processing. Marketing and
platform support may be provided to the operator by Peace Of Mind Global
Asset Management A Professional Corporation under service-provider and
confidentiality controls.
This Policy applies to visitors, account holders, candidates, consumers,
licensed professionals, agency owners, employees, contractors, and other
U.S. users. Separate privacy notices may apply to employment, background
checks, client transactions, insurance applications, mortgage or real
estate files, carrier contracting, or other regulated records. Those
more specific notices control the subject they address.
## 2. Personal Information We Collect
We collect information you provide, information generated through your
use, information from authorized partners and public licensing sources,
and information from service providers. The table describes current or
enabled categories and our intended retention framework. Retention may
be shorter, and legal holds or regulatory duties may require longer
retention.
**Category** **Examples** **Typical
retention**
Identifiers and Name, email, phone number, username, Account life plus 4
account data account ID, password hash, preferred years; credential
language, authentication data, and security
age/eligibility confirmation, and records may be
account status. retained longer if
needed for fraud
prevention or legal
claims.
Profile and Optional profile or demographic Account life plus 4
relationship fields, including gender if enabled; years, or longer if
data referrer or Member Code; organization, linked to
role, track, agency, team, or sponsor compensation,
information. contracting, or a
dispute.
Professional and Insurance license number and state, For the
licensing data license status, appointments, relationship plus
contracting status, agency or the longer of 7
hierarchy information, E&O status, years or the period
producer track, and compensation required by
eligibility. regulators,
carriers, lenders,
brokers, tax rules,
or a legal hold.
Training and Registrations, attendance, progress, Generally 4 years
engagement data completions, quiz or exam results, after the activity;
certificates, questions, chat, polls, longer if used for
downloads, support activity, and licensing,
content interactions. supervision,
compensation,
compliance, or a
dispute.
Communications Emails, support messages, displayed Communications
and recordings name, typed questions, chat, and, only generally 4 years.
when recording is activated with Operational
notice, audio, video, voice, image, or recordings
session recording data. generally 3 years
unless published
with permission,
needed for
compliance, or
subject to a legal
hold.
Payment and Purchase, invoice, billing, refund, Generally 7 years
transaction data subscription, tax, and transaction after the
data. Stripe or another processor transaction or
receives full payment credentials; we longer if required
generally receive tokens, status, for tax,
amount, and limited card details. chargeback, fraud,
or legal purposes.
Device, network, IP address, device and browser type, Security logs
and usage data operating system, user agent, cookies, generally up to 24
session identifiers, login and months; aggregated
security logs, referring pages, pages analytics may be
viewed, and feature interactions. retained longer
without direct
identifiers.
Geolocation data Approximate location inferred from IP Precise location is
and, where a feature requests retained only as
permission, precise location used for long as reasonably
U.S.-only access, fraud prevention, necessary,
security, regional content, or generally no more
compliance. than 30 days unless
needed for an
incident, legal
obligation, or
user-requested
feature.
AI and inference Prompts, inputs, outputs, summaries, Generally 2 years
data translations, recommendations, scores, or the related
classifications, risk signals, account or
learning preferences, and other compliance-record
inferences generated through AI or period, whichever
analytics. is reasonably
necessary.
### Future sensitive or onboarding data
If a future paid, licensing, contracting, compensation,
identity-verification, or background-check workflow requires it, we may
collect address, date of birth, Social Security or tax identification
number, government ID or image, W-9 or tax forms, bank or
commission-payment details, resume and work history, background-check
information, or other sensitive records. We will present a supplemental
notice at or before collection, use a designated secure channel, collect
only what is reasonably necessary, and obtain any separate authorization
required by law. A consumer report or background check will require a
separate standalone disclosure and authorization. Do not send these
items through live chat, open Q&A, or ordinary email.
## 3. Sources of Information
- Directly from you, including registration, profile, forms, payments,
communications, questions, uploads, and consent choices.
- Automatically from browsers, devices, cookies, logs, analytics,
location permissions, and security tools.
- From a referrer, Member Code owner, agency, employer, contractor,
broker, carrier, MGA, lender, training administrator, or other party
involved in an authorized relationship.
- From public or authorized licensing and regulatory sources,
including state insurance databases, DRE, NMLS, and disciplinary or
appointment records, as applicable.
- From payment, communications, hosting, analytics, video, identity,
fraud, and artificial-intelligence service providers acting for us.
## 4. How We Use Personal Information
- Create, authenticate, administer, support, personalize, and close
accounts; enforce age and U.S.-only restrictions.
- Deliver courses, track attendance and progress, answer questions,
issue completion records, provide replay, and manage events.
- Verify licenses, appointments, affiliations, sponsorships, E&O
coverage, contracting, eligibility, professional status, and
compliance.
- Administer Member Codes, relationship records, agency structures,
leads, compensation eligibility, chargebacks, or other approved
professional workflows.
- Process separately authorized payments, subscriptions, refunds, tax
records, and transaction support.
- Send service messages and, with the required choice or consent,
marketing emails, texts, calls, or other promotions.
- Operate analytics and AI-assisted features, improve content and
usability, detect fraud and abuse, secure systems, troubleshoot, and
conduct quality assurance.
- Comply with law, regulation, subpoenas, audits, licensing, tax,
recordkeeping, dispute, safety, and enforcement obligations; protect
users, Company, and others.
- Evaluate or complete a merger, financing, restructuring, asset
transfer, or sale, subject to confidentiality and applicable law.
We do not use precise geolocation, government identifiers, financial
credentials, or other sensitive information to infer characteristics
unrelated to the disclosed purpose. We do not materially expand a
purpose or collect a new sensitive category without an updated or
supplemental notice when required.
## 5. How We Disclose Personal Information
We may disclose information only as reasonably necessary for the
purposes above, subject to contracts and access controls where
appropriate, to the following categories:
- Hosting and infrastructure providers, including Microsoft Azure.
- Payment processors, including Stripe, for separately authorized
transactions.
- Communications providers, including Twilio, for enabled email, text,
telephone, or verification functions.
- Analytics providers, including Google Analytics, and embedded video
providers such as YouTube or Vimeo.
- Artificial-intelligence and technology providers, including OpenAI
or other providers used for enabled AI features, under service terms
and configurations intended to restrict use to our instructions.
- Professional and regulated partners, such as brokers, carriers,
MGAs, lenders, NMLS, licensing bodies, compliance providers, or
contracting parties, when needed for a workflow you request or an
existing authorized relationship.
- Attorneys, auditors, insurers, investigators, regulators, law
enforcement, courts, and other parties when reasonably necessary to
comply with law, enforce rights, investigate misconduct, protect
safety, or respond to a claim.
- A successor, buyer, lender, or transaction advisor in a merger,
financing, reorganization, asset transfer, or sale, subject to
appropriate confidentiality and notice where required.
Marketing and platform support may be provided to the operator by Peace
Of Mind Global Asset Management A Professional Corporation under
service-provider and confidentiality controls.
We do not sell personal information. We do not share personal
information for cross-context behavioral advertising. We do not
currently use Meta Pixel, TikTok Pixel, retargeting pixels, or
third-party advertising networks on the Platform. If that practice
changes, we will update the notice and provide legally required choices
before the change takes effect.
## 6. Cookies, Analytics, Embedded Media, Do Not Track, and GPC
We use essential cookies and similar technologies for login, security,
session continuity, preferences, language, and fraud prevention. Google
Analytics may set analytics cookies or receive device and usage
information to help us understand aggregate Platform use. Embedded
YouTube or Vimeo content may allow those providers to collect device,
cookie, and viewing information under their own policies.
Browser settings may block or delete cookies, but essential functions
may stop working. Because browsers do not provide a universally accepted
Do Not Track standard, the Platform may not respond to legacy Do Not
Track signals. Where applicable, we will process legally valid opt-out
preference signals, including Global Privacy Control, as required by
law. Because we do not sell or share personal information for
cross-context behavioral advertising, such a signal generally will not
change current practices but will be recorded or honored if required.
## 7. Artificial Intelligence and Automated Analysis
AI and analytics may generate summaries, translations, recommendations,
learning suggestions, scores, classifications, or security signals.
These tools support people and do not replace required human judgment.
We do not intend to make a decision that produces a significant legal or
similarly significant effect solely through AI without a separate
legally compliant process, notice, review, and any required right to
access, correct, appeal, or opt out.
Do not place client secrets, government identifiers, financial
credentials, confidential carrier or lender information, or other
sensitive data into an AI prompt unless the feature is expressly
approved for that information. We may review or filter prompts and
outputs for safety, security, compliance, and quality.
## 8. Communications Choices
We send service communications needed to operate an account, such as
verification, security, legal, licensing, course, schedule, and policy
messages. Marketing email may be stopped through the unsubscribe link or
by contacting us. Marketing text messages, automated or prerecorded
calls, and artificial or AI-generated voice calls require the applicable
separate consent and may be revoked by any reasonable method.
Withdrawing marketing consent does not prevent account creation or
continued access to otherwise available services.
## 9. Session Recordings and Media
Not every session is recorded. When recording is enabled, we provide
notice and obtain the applicable consent before entry. A recording may
capture a displayed name, typed question, chat, poll, or other
submission. Operational recordings may be used for compliance, quality
assurance, replay, internal training, and dispute resolution.
Identifiable public, advertising, recruiting, or social-media use
requires a separate optional media release, unless the content is
de-identified or another lawful basis applies.
## 10. Retention and Deletion
We retain each category only as long as reasonably necessary for the
disclosed purpose, the typical periods in Section 2, and applicable
legal, licensing, carrier, lender, tax, accounting, security, dispute,
or contractual requirements. We consider the sensitivity, volume,
business need, risk of harm, availability of alternatives, and whether
information can be aggregated or de-identified. We delete, de-identify,
or securely destroy information when the retention purpose ends, unless
a legal hold or other lawful exception applies.
Deletion of an account does not require deletion of agreement versions,
checkbox records, IP and device evidence, license or contracting
history, compensation and chargeback records, transaction and tax
records, regulatory records, opt-out suppression records, security
incidents, or dispute evidence that we reasonably need to retain.
## 11. Security
We use reasonable administrative, technical, and physical safeguards
appropriate to the nature of the information. Measures include encrypted
transmission, encryption at rest for sensitive fields, strong one-way
password hashing, role-based access controls, logging, backups, vendor
controls, incident response, and retention and deletion procedures. No
system is completely secure. You must protect credentials, use secure
devices, and promptly report suspected unauthorized access.
## 12. Your Privacy Choices and Requests
Depending on your state and the law that applies, you may have rights to
know or access personal information, correct inaccuracies, delete
information, obtain a portable copy, opt out of sale, targeted
advertising, or certain profiling, limit certain sensitive-data uses,
appeal a refusal, or avoid unlawful discrimination for exercising
rights. Even when a statute does not require a particular right because
of Company's size or status, we generally will consider verified access,
correction, and deletion requests in good faith, subject to legal and
operational exceptions.
Submit a request to
[email protected]. State the brand, account email,
request type, state of residence, and enough information for us to
verify the request. We may request additional verification and may deny
or limit a request where permitted, including to protect another person,
preserve security, comply with law, retain required records, complete a
transaction, exercise legal claims, or protect trade secrets. An
authorized agent must provide proof of authority, and we may verify the
request directly with the account holder. Where an appeal right applies,
reply with "PRIVACY APPEAL."
California residents may also request information under California's
Shine the Light law regarding certain disclosures for another business's
direct marketing. We do not disclose personal information to third
parties for their own direct marketing in the manner covered by that
law.
## 13. Sensitive Information and Data Minimization
We limit sensitive-data access to people and providers with a legitimate
need, use secure workflows, and seek to collect the minimum information
reasonably necessary. Do not upload sensitive information unless the
Platform specifically requests it through a secure field. If a field is
optional, you may leave it blank. Gender or other demographic
information should be optional and will not be used to make unlawful
eligibility, licensing, employment, contracting, compensation, credit,
housing, or insurance decisions.
## 14. Children and U.S.-Only Service
The Platform is not directed to children and does not knowingly permit
accounts for anyone under 18. If we learn that a minor created an
account, we may close it and delete information as appropriate. The
Platform is intended only for users in the United States and U.S.
territories. Information is processed in the United States and may not
be protected by laws of another country.
## 15. Changes to this Policy
We may update this Policy to reflect legal, technology, vendor,
security, data, or service changes. We will post the updated version and
effective date. For a material change, we may provide email or
in-platform notice and obtain new consent where law requires it. We will
not use previously collected information for a materially incompatible
purpose without the required notice and consent.
## 16. Contact
Privacy requests and questions:
[email protected]. Correspondence
address: 1900 S Norfolk Street, Suite 350, San Mateo, California 94403.
Please identify the POM365 account and request type. Version
2026.07.21-1.