Version counsel-approved-2026-07-24 · Effective July 24, 2026

Privacy Policy

Questions: privacy@theclaimsninja.com. Back to home

CLAIMS NINJA U.S. PRIVACY POLICY

Version: counsel-approved-2026-07-24
Effective date: July 24, 2026 (2026-07-24)
Privacy contact: privacy@theclaimsninja.com

Claims Ninja — U.S. Privacy Policy (Master)


1. Who we are

Field — Value

Legal entity — The Claims Ninja LLC (from Consulting Agreement)
Principal place of business — 442 E Iris Drive, Berry Hill, Tennessee 37204 (from Consulting Agreement)
Services — Professional consulting for property claim estimating and negotiation, Client Portal / platform tools, and related operations

Privacy contact channel: privacy@theclaimsninja.com
Agreement notices may also use the designated contract email on file or certified mail (Agreement §25).

Service-contract governing law (Agreement §18): Laws of the State of Tennessee; exclusive venue in courts located within Davidson County, Tennessee, unless otherwise required by applicable law. The Consulting Agreement is governed by Tennessee law with venue in Davidson County, Tennessee, unless otherwise required by applicable law.


2. Scope of this notice

This Policy describes how The Claims Ninja LLC (“Claims Ninja,” “we,” “us”) collects, uses, discloses, and protects personal information in connection with:

• our marketing website;
• public contractor / claim onboarding (native journey on the marketing site);
• account creation, email one-time passcodes (OTP), authentication, and platform usage;
• claim / job, property-related, company, contractor, contact, and uploaded document data;
• internal claims operations and role-based access;
• billing contact data and (when product gates allow) processor-tokenized payment-method references; and
• support and service communications.

This Policy is written for a U.S. nationwide audience. State-specific rights are summarized in the
U.S. State Privacy Rights Addendum.
State-law applicability and threshold review for this package has been verified; this Policy still uses “where applicable” language and does not assert that every state privacy law applies to every request.

Scope note: HubSpot and Jotform are excluded from this onboarding/privacy package and are not disclosed as processors or workflows here.


3. Categories of personal information we collect

Depending on how you interact with us, we may collect the following categories
(examples are illustrative of current product flows):

Category — Examples (actual flows)

Identifiers — Name, email, phone, account identifiers, organization identifiers
Commercial / company information — Legal company name, DBA, address, website, branding identifiers, license numbers (if provided), billing contact/address (Agreement §2.3)
Claim / job / property-related information — Property or job name/title, claim details, documentation, photos, and related file materials
Internet / technical information — Session/intake technical identifiers, IP address, user-agent (including as legal-acceptance evidence when acceptance is enabled), security and application logs
Account authentication data — Password (handled by auth provider; not stored in intake autosave), OTP codes (transient; not retained in acceptance evidence)
Billing / payment-related — Billing contact fields; when capture is enabled, processor token / vault references and limited display metadata (e.g., last-four / brand)
Inferences / AI-assisted outputs — Outputs generated by AI-assisted tools used in claim/workspace or marketing-site assistive features (see §10) — not used as a substitute for human professional judgment in delivering consulting services

We do not intentionally collect government ID numbers, precise geolocation tracking for advertising, biometric templates for identification, or similar sensitive identifiers as part of standard public onboarding. Claim files may contain sensitive or regulated content depending on what customers upload — treated as confidential under Agreement §3 and handled under role-based access and security controls.


4. Sources of personal information

• Directly from you (website forms, onboarding, portal uploads, account/OTP, support).
• Your organization / authorized users (company admins, teammates, Client Portal users).
• Service providers that process data on our behalf (e.g., authentication, hosting, email delivery, malware scanning, AI inference, accounting sync) — see §7.
• Automatically from your device/browser when you use our sites or apps (functional technical data; see §12).


5. Purposes of collection and use

We use personal information to:

1. Perform the Consulting Agreement — estimate writing, documentation, negotiation support, supplements, and related deliverables; use Client company identifiers as authorized (Agreement §2.3).
2. Operate onboarding and the Client Portal / platform — create accounts, verify email via OTP, provision workspaces, store and organize claim files after malware scanning.
3. Communicate — service, onboarding, resume, support, and operational messages (e.g., via email providers).
4. Billing under the Agreement — maintain billing profiles; when enabled, store processor-tokenized payment-method references; allow billing staff to manually initiate authorized charges (see §6). No charge occurs merely for completing onboarding.
5. Security and integrity — access control, abuse prevention, malware scanning/quarantine, auditing, incident response.
6. Internal operations — quality, training of staff (not “sale” of data), troubleshooting, product improvement of Claims Ninja systems.
7. AI-assisted features — where enabled, process claim/workspace or assistive-chat content to generate draft analyses, estimates assistance, or similar outputs for human review (see §10).
8. Legal / compliance — enforce agreements, respond to lawful requests, maintain acceptance evidence, and meet recordkeeping needs.

We do not use onboarding Terms/Privacy clickwrap as marketing opt-in. Marketing consent is omitted from the current clickwrap package.

Confidential Information (including financial data, client lists, and claim details) is subject to Agreement §3 and is not disclosed or used except as necessary to perform obligations, as required by law, or with express prior written consent of the disclosing party.


6. Billing and payment data (Agreement-aligned)

• No onboarding charge. Completing public onboarding or acknowledging legal documents does not itself cause a fee.
• Authorized charges under the Consulting Agreement may include approved invoices, authorized pass-through expenses, and applicable undisputed past-due amounts (Agreement §§5, 7.6). This Privacy Policy does not require a separate per-charge approval beyond the Agreement and ordinary invoice/approval workflows.
• Manual operational initiation through QuickBooks. Billing staff initiate approved invoice and payment-request workflows operationally through QuickBooks, consistent with the signed Consulting Agreement. The external-onboarding product does not enable recurring or automatic charging as a self-running product feature. (Counsel note: Agreement §5 contains broader ACH/electronic-debit language that contemplates one-time or recurring payments; product/ops currently do not enable automatic recurring charging.)
• No raw card/bank storage by Claims Ninja. We do not store raw card numbers, CVV/CVC, routing numbers, or bank account numbers. QuickBooks is the billing/payment processor and financial source of truth. Public onboarding does not capture a payment method unless a verified QuickBooks-hosted payment-link or session workflow is explicitly configured; until then, onboarding may collect billing contact/address only, and payment setup occurs later through an authorized QuickBooks invoice or payment request.


7. Disclosures and service providers / processors

We disclose personal information to service providers / processors that help us operate the service, subject to contractual and technical controls appropriate to the relationship. Based on current architecture in scope for this package:

Provider — Disclosure / processing role

Supabase — Authentication, database, file storage (quarantine and claim files)
Vercel — Application hosting / delivery
Resend — Transactional email (OTP, resume, similar)
Cloudmersive — Malware / virus scanning of upload bytes
OpenAI — AI inference for platform claim/estimate assistance and (where enabled) website assistive features
QuickBooks — Billing/payment processor and accounting / invoice workflows as configured

We may also disclose information to:

• professional advisers (legal, accounting) under confidentiality;
• authorities when required by law or to protect rights, safety, and security;
• successor entities in a corporate transaction, subject to appropriate protections.

Sale / share / targeted advertising (based on actual practices in scope for this package):

• Claims Ninja does not sell personal information for money as a business model.
• The public onboarding and marketing surfaces reviewed for this package do not load Google Analytics, Google Tag Manager, or similar advertising/analytics scripts for cross-context behavioral advertising.
• QuickBooks / OpenAI / Cloudmersive / Supabase / Vercel / Resend are used as service providers / processors for business operations described above, not as purchases of advertising audiences.

This Policy does not state that Claims Ninja “sells” or “shares” personal information. If cookie, pixel, or data flows later constitute sale/share/targeted advertising under applicable law, this Policy and related UX must be updated before those practices go live.


8. Sensitive personal information

Some claim files or communications may include information that certain state laws treat as sensitive (for example, depending on contents of uploaded documents). We:

• collect such information only as needed to provide services you or your organization request;
• restrict access via role-based controls and confidentiality obligations (Agreement §3);
• do not, based on current architecture, use sensitive personal information for cross-context behavioral advertising.

Where a state law that applies to Claims Ninja requires consent or a “limit the use” right for sensitive data beyond service performance, Claims Ninja will follow the process in the
State Privacy Rights Addendum and the
Privacy Request Operating Procedure.


9. Retention and deletion

No fixed retention periods are published in this package . A written retention schedule is maintained operationally.

Agreement-aligned baseline:

• Upon termination or request, Confidential Information is returned or destroyed except as required to comply with legal or regulatory obligations (Agreement §3.3).
• Certain obligations survive termination (payment, confidentiality, Work Product protections, etc.) (Agreement §§1.3, 26).
• Legal acceptance evidence is designed to be append-only / immutable and may be retained for contract proof.
• We do not promise universal deletion on demand where retention is required for fraud prevention, security, legal obligations, contract performance, accounting, disputes, or immutable evidence.


10. Automated decision-making / profiling / AI

Claims Ninja uses AI-assisted tools (including OpenAI-backed features) to help staff and users with claim analysis, estimate assistance, documentation support, and (on the marketing site, where enabled) assistive chat / analysis features.

Based on current product design:

• AI outputs are assistive; consulting deliverables and material claim decisions remain subject to human professional processes.
• We do not, based on current architecture, use AI as a fully automated decision system that alone determines legal rights or eligibility for essential services without human involvement.

Whether any feature requires additional “profiling” / “automated decision-making” notices under applicable state laws this Policy does not invent such product behaviors.


11. Security and breach response

We implement commercially reasonable administrative, technical, and organizational safeguards appropriate to the nature of claim and account data, including access controls, encrypted transport in transit for application traffic, malware quarantine/scanning for uploads, and fail-closed gates for unapproved legal acceptance and payment capture (Agreement §16 commercially reasonable safeguards; no absolute cybersecurity guarantee).

We do not promise 24/7 monitoring, perfect security, or zero-incident operations.

If we become aware of a security incident affecting personal information, we will investigate and provide notifications as required by applicable law and our incident-response process. Specific breach-notification timelines follow applicable law and internal incident-response procedures.


12. Cookies and similar technologies

Current marketing-site onboarding (verified in product code for this package):

• Functional cookies/identifiers only, including opaque intake session handle, CSRF protection, and locale preference.
• No Google Analytics / GTM / similar marketing analytics scripts found on the public onboarding surface.

Open implementation decision: Whether to add analytics, advertising, or non-essential cookies later — and any required cookie notice/consent — is not decided in this package. If added, this Policy and related notices must be updated before enablement.


13. Children’s personal information

Claims Ninja services are directed to businesses and adult professionals engaged in property claim consulting — not directed to children.

We do not knowingly collect personal information from children for these services.
Age threshold and parental-consent edge cases (e.g., under 13 / under 16 for certain sale/share rules) are assessed if claim files could ever involve minors’ data.


14. International transfers

Claims Ninja is a U.S. business. Service providers may process data in the United States and potentially other locations where they operate.

This Policy does not assert EU/UK adequacy, SCCs, or other international-transfer mechanisms unless they are needed and implemented. If Claims Ninja serves residents outside the U.S. in a way that triggers such rules, transfer language must be supplied before publication of that claim.


15. Your privacy rights

Depending on your state of residence and whether applicable law covers Claims Ninja’s processing of your personal information, you may have rights such as:

• access / know;
• correction;
• deletion (subject to exceptions);
• portability;
• opt-out of sale, sharing, and/or targeted advertising where those activities occur and the law applies;
• appeal a denied request (where required);
• use an authorized agent (where permitted).

See the U.S. State Privacy Rights Addendum below.

How to submit a request: privacy@theclaimsninja.com
Formal Agreement notices may also use Agreement §25 channels (designated contract email / certified mail). Operational handling is described in the
Privacy Request Operating Procedure.

We will not discriminate against you for exercising privacy rights where prohibited by applicable law.


16. California “Shine the Light” (Civ. Code § 1798.83)

Based on current practices in scope for this package, Claims Ninja does not disclose personal information to unaffiliated third parties for those third parties’ direct marketing purposes in exchange for consideration in the manner typically addressed by Shine the Light.

California residents may request information about any such disclosures (if any) via privacy@theclaimsninja.com.


17. Nevada “do not sell” consideration (NRS Chapter 603A)

Nevada residents may have a right to opt out of the “sale” of covered information under Nevada law.

Based on current architecture in scope for this package, Claims Ninja does not sell covered information as a business practice. Nevada residents may still submit a request via privacy@theclaimsninja.com.


18. Changes to this Policy

Claims Ninja maintains a versioned notice of this Policy. Material changes will be communicated as required (for example, updated notice, email to designated contract contacts, and/or new clickwrap version for onboarding).


19. Contact

Item — Value

Entity — The Claims Ninja LLC
Address — 442 E Iris Drive, Berry Hill, Tennessee 37204
Privacy email — privacy@theclaimsninja.com
Agreement notices — Designated contract email on file or certified mail (Agreement §25)


20. Relationship to the Consulting Agreement

If you are a Client under the Consulting Agreement, that Agreement (including confidentiality, payment authorization, electronic systems, and survival clauses) continues to govern the service relationship. This Privacy Policy explains privacy practices; it does not modify fee schedules or Work Product terms.


End of master Policy. Companion documents in this folder complete the nationwide package. Not published; acceptance not enabled.

================================================================================

U.S. STATE PRIVACY RIGHTS ADDENDUM

Version: counsel-approved-2026-07-24
Effective date: July 24, 2026 (2026-07-24)
Privacy contact: privacy@theclaimsninja.com

U.S. State Privacy Rights Addendum


This Addendum supplements the Claims Ninja U.S. Privacy Policy.
If there is a conflict for a resident of a particular state, the more specific
state disclosure approved for that state controls for that resident.


1. How to read this Addendum

U.S. states have enacted comprehensive consumer privacy laws with similar themes
(access, deletion, correction, portability, opt-outs, appeals, sensitive-data
rules) but different definitions, thresholds, and exemptions. As of early 2026,
multiple states (including California and numerous others) have comprehensive
laws in force or scheduled; the landscape continues to evolve.

Claims Ninja will honor applicable rights under laws that apply to Claims Ninja
and to the requesting consumer. This Addendum is written so that:

1. rights are described in plain language;
2. Claims Ninja is not falsely declared “subject to every state law”; and
3. a durable “other states with similar rights” clause covers new or amended
   laws without requiring an immediate full rewrite.


2. Applicability

State-law applicability and threshold review for this package has been verified
(business/counsel direction, 2026-07-24). Public copy continues to use “where
applicable” language — not “we comply with every statute.”

Whether a particular request is covered still depends on the consumer’s state of
residence, the law’s definitions, and the facts of the processing.


3. Rights that may be available (where applicable)

Depending on your state and applicable law, you may have some or all of the
following rights regarding personal information we control:

Right — Typical meaning

Know / Access — Confirm whether we process your personal information and obtain a copy / categories
Correct — Request correction of inaccurate personal information we maintain
Delete — Request deletion, subject to legal and operational exceptions
Portability — Obtain a copy in a portable format, where required
Opt out of sale — Direct us not to “sell” personal information, where that activity occurs and the law applies
Opt out of share / targeted advertising — Direct us not to “share” for cross-context behavioral advertising or process for targeted advertising, where those activities occur and the law applies
Limit use of sensitive personal information — Where required (e.g., California), limit SPI to permitted purposes
Opt out of certain profiling — Where required by state law and profiling is performed for covered decisions
Appeal — Appeal our decision on a request, where the law requires an appeal process
Authorized agent — Submit certain requests through an authorized agent, where permitted

How to exercise: privacy@theclaimsninja.com. Internal handling:
03-privacy-request-operating-procedure.md.


4. Sale, share, and targeted advertising (practice-based)

Based on architecture and marketing/onboarding surfaces in scope for this package:

• Claims Ninja does not operate a business model of selling personal
  information for money.
• Public onboarding does not currently load common third-party advertising
  analytics stacks (e.g., GA/GTM) for cross-context behavioral advertising.
• Named integrations in scope (Supabase, Vercel, Resend, Cloudmersive, OpenAI,
  QuickBooks) are used as service providers / processors for hosting,
  security, communications, AI assistance, billing/payments, and accounting.

Therefore, this Addendum does not state that Claims Ninja currently “sells”
or “shares” personal information. If any cookie, pixel, or data flow later
constitutes sale/share/targeted advertising under applicable law, Claims Ninja must:

1. update the Master Policy and this Addendum;
2. implement any required opt-out link, preference-signal handling, or consent UX
   before that practice goes live in Production; and
3. update the data-practices matrix.

HubSpot is excluded from this onboarding/privacy package scope and is not
analyzed or disclosed here.


5. California-specific considerations (where CCPA/CPRA applies)

Where CCPA/CPRA applies, California residents may have, among other rights: know,
delete, correct, portability, opt-out of sale/share, limit use of sensitive
personal information, and non-discrimination — subject to statutory exceptions.

Notice at collection: Categories, purposes, retention approach, and
sale/share statements appear in the Master Policy and matrix. Notice-at-collection packaging appears in this Policy and related notices.

Do Not Sell or Share / Limit Sensitive PI links: Required only if Claims
Ninja sells/shares or uses SPI beyond permitted purposes. Based on current
practices described above, those homepage links are not asserted as currently
mandatory for the in-scope architecture.

Shine the Light (Civ. Code § 1798.83): See Master Policy §16.

Minors / under-16 sale-share rules: Services are not directed to children.


6. Nevada consideration

Nevada residents may request to opt out of the “sale” of covered information
under Nevada law. Practice-based position: Claims Ninja does not sell covered
information as a business practice. Residents may contact privacy@theclaimsninja.com.


7. Other states with comprehensive privacy laws

Residents of other states with comprehensive consumer privacy laws (for example,
laws in force or taking effect in states such as Virginia, Colorado, Connecticut,
Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey,
Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and additional
states as enacted — illustrative, not exhaustive) may have similar rights to
access, correct, delete, obtain portability, opt out of sale/targeted advertising,
appeal, and related rights, subject to each law’s definitions, thresholds, and
exemptions.

Durable clause — other states with similar rights

If you are a resident of a U.S. state that has enacted a consumer privacy law
conferring rights similar to those described in this Addendum, and that law
applies to Claims Ninja’s processing of your personal information, we will
process your request in accordance with that law. Where this Addendum and a
newer state statute differ, Claims Ninja will apply the rights and timelines
required by the applicable statute.

This clause is intended to reduce obsolescence as additional state laws take
effect, without claiming universal present applicability.


8. Exceptions (summary)

Requests may be denied or limited where permitted, including when necessary to:

• complete a transaction or perform a contract (including the Consulting Agreement);
• detect, prevent, or investigate security incidents or fraud;
• protect legal rights or comply with law;
• retain records we are legally required to keep;
• debug / repair errors;
• engage in certain research or internal uses compatible with context; or
• other exceptions recognized by the applicable statute.

Deletion and correction are not absolute. See the Master Policy retention
section and Agreement §3.3 (return/destroy except legal/regulatory obligations).


9. Metrics and recordkeeping

Some laws encourage or require logging of request volumes and outcomes. Claims
Ninja’s internal SOP provides for request tracking. Public metrics reporting is
implemented if and when a specific applicable statute requires it.


End of State Privacy Rights Addendum. Not published; acceptance not enabled.