Legal
Privacy Policy
How we collect, use, and protect information in connection with the ParrotNow service.
Last updated August 19, 2026
1. Who we are
ParrotNow is a performance-tracking application for insurance agencies ("we", "us"). For any privacy question or request, contact privacy@parrotnow.com.
2. Two kinds of data, two different roles
Agency data. When an insurance agency uses ParrotNow, the agency decides what to put into the system and why. For that data the agency is the controller and we act as a processor on its instructions. If you are an employee or customer of an agency and want your data accessed, corrected, or deleted, contact that agency first — we will refer your request to them.
Our own data. For information we collect directly — demo requests from this website, support correspondence, and billing records — we are the controller.
3. Information in the service
Agencies use ParrotNow to store:
- Team member records — name, work email, phone, role, reporting manager, employment type, hire and termination dates, and licence details.
- Compensation records — salary records, score plans, computed bonus amounts, and payroll periods.
- Activity records — the work a team member logs, such as calls made, quotes given, or referrals obtained. Where the agency configures an activity type to capture one, these may include the name of a customer or a referring party.
- Time records — timesheet entries, clock-in/clock-out punches, absences, and leave balances.
- Documents — files an agency administrator uploads to a team member's profile. Agencies may use this for employment paperwork, which can include sensitive identifiers. Access is restricted to agency administrators and, where the administrator marks a folder or file as member-visible, the team member it belongs to.
- Audit records — a log of who created, changed, or deleted a record, and when, including an entry each time a document is downloaded.
4. Information we collect from this website
If you submit a demo request we collect your name, email address, and phone number so we can contact you. We also record the IP address and browser user-agent the request arrived with, and keep them alongside it, so we can identify and block automated abuse of the form; we do not use them to build a profile of you or to track you across sites. Separately, our hosting and content-delivery providers process standard server logs, including IP address, user agent, and requested URL, to deliver the site and protect it from abuse.
We do not use advertising or analytics cookies on this site. Cookies set within the signed-in application are strictly necessary: they keep you authenticated and remember interface preferences such as light or dark theme.
5. How we use information
We use information to:
- Provide, secure, and support the service.
- Authenticate users and enforce access rules within an agency.
- Compute bonus and payroll figures as configured by the agency.
- Respond to demo requests, support enquiries, and legal obligations.
- Diagnose faults and improve reliability and performance.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use agency data to train machine-learning models.
6. Isolation and access controls
Every agency's records are isolated at the database level using PostgreSQL row-level security, which constrains queries to the requesting agency rather than relying on application code to filter correctly. Within an agency, access follows role: compensation figures — bonuses, salary, and pay rates — are restricted to the person they describe and the agency's administrators, and a manager sees only their own reporting line. Uploaded documents are administrator-only unless explicitly shared with the team member.
Data is encrypted in transit with TLS and at rest by our hosting provider. Access to production systems by our staff is limited to personnel who need it to operate and support the service.
7. Service providers
We share information with a small number of vendors who process it on our behalf:
- Microsoft Azure — Application hosting, database, file storage, and transactional email (United States regions).
- Clerk — User authentication, session management, and organization membership.
- Google Fonts — Web font delivery (receives visitor IP address and user agent).
We may also disclose information where required by law, to enforce our Terms of Service, or in connection with a merger or acquisition, in which case we will give notice before your information becomes subject to a different policy.
8. Retention
We keep agency data for as long as the agency's account is active. After an account closes we delete or anonymise the data within 90 days, except where we must retain records to meet a legal, tax, or accounting obligation. Deleted files are recoverable from backup for a short window before being purged permanently.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Residents of California, Colorado, Connecticut, Utah, Virginia, and other states with comprehensive privacy laws have these rights under those statutes; we do not discriminate against anyone for exercising them.
To make a request, email privacy@parrotnow.com. If your information was entered by an agency using ParrotNow, we will pass your request to that agency, which controls the record.
10. Children
ParrotNow is a workplace tool sold to businesses. It is not directed to children, and we do not knowingly collect personal information from anyone under 16.
11. International users
Data is stored in United States regions (see the hosting provider named above). If you access the service from elsewhere, you are transferring information to the United States.
12. Changes
We will post any revision to this policy on this page and update the date above. Material changes will also be communicated to agency administrators directly.
13. Contact
ParrotNow
privacy@parrotnow.com