What this page is
BestCyberLiability.com is operated by WJB Services, Inc. dba Bollinsure Insurance Services — an independent California insurance brokerage, CA DOI Agency License #0D94699. This page explains, in plain language, exactly what this website collects, what runs on it, who receives it, how long we keep it, and the choices you have. Where we make a commitment here, it is tied to something you can check.
Nothing on this site binds coverage. A pricing indication is a modeled estimate. A completed and signed application is a request for terms. Neither one, and no message you receive from this website, is a policy, binder, quote, or offer to insure. Coverage exists only when a carrier issues it in writing.
California notice at collection
This notice is given at or before the point of collection, as California’s Consumer Privacy Act requires. It is linked from the application form itself and from the footer of every page on this site.
(Civ. Code § 1798.80(e))
What this site actually collects
This is the real list, taken from the application form on this site rather than from a template.
- Risk and rating answers — annual revenue band, industry, requested aggregate limit, the approximate number of unique personal records you hold, multi-factor authentication status, whether you have had a prior cyber incident, and whether you handle protected health information or payment card data.
- Business identity and contact details — legal name, DBA, website addresses, year established, employee count, entity type, requested effective date, street address, city, state and ZIP, a description of the business, and the name, title, telephone number and email address of your contact.
- Security control answers — endpoint protection, email security, patch management, backups and backup testing, incident response planning, security awareness training, encryption of sensitive data, vendor security controls, and wire-transfer verification controls, plus your EDR vendor, primary cloud providers, and any free-text security notes you add.
- Coverage selections — the coverage sections you ask us to request, such as privacy and security liability, breach response, cyber extortion, data restoration, business interruption and dependent business interruption, funds transfer fraud, social engineering, media liability, and regulatory defence.
- Electronic signature record — the authorized representative’s name and title, the signature you type or draw, the three consent boxes you tick, and an audit record captured at the moment you sign: IP address, browser user agent, accept-language header, referring page, host, time zone, the times the preview was generated and consent was given, a fingerprint of the reviewed document, and SHA-256 hashes of your signature and of the final PDF. That record exists so the signature can be proven later, which is the point of signing electronically.
- Technical data — standard server request data, plus the analytics and advertising identifiers described under Analytics and advertising.
Please do not send us health records, individual medical information, or payment card numbers through this site. Nothing in the application asks for them, and the form is not built to carry them.
Where the information comes from
- From you — everything you type into the application, and anything you tell a broker by phone or email.
- From your browser and device, automatically — IP address, user agent, referring URL, campaign parameters, and the analytics identifiers described below.
- From our advertising and analytics providers — Google reports which campaign, keyword, or referral your visit came from.
- From third-party reports, if we order one — a brokerage sometimes obtains information about an applicant from someone other than the applicant. If we order an investigative consumer report, a loss-history report, or an external security-scanning report about your business in connection with your application, we will tell you before we obtain it, and you may ask us in writing for the name and address of the agency that prepared it. See Insurance information practices.
- From carriers and wholesale brokers — when a market responds to a submission we made on your instruction, their response becomes part of your file.
How we use it
We use what you give us to produce the preliminary indication you asked for, to complete the carrier application, to submit that application to markets when you ask us to, to answer your questions and follow up, to service and renew any policy we place for you, to keep the records an insurance producer has to keep, to prevent fraud and abuse of the form, and to measure which pages and campaigns actually generate enquiries.
An indication is not a quote. The number this site shows you is modeled from rating tables held in the page’s own JavaScript. It is not returned by a carrier, it is not a quote, binder, or guarantee of coverage, price, or eligibility, and a submitted application is a request for terms rather than a bindable application. Coverage exists only when a carrier issues it.
We do not use your application information for unrelated marketing, and we do not use it to build advertising audiences.
Who receives it
These are the actual categories of recipient, named.
- Insurance carriers and wholesale brokers — when you ask us to market your submission. Cyber liability is frequently written on non-admitted paper; where a placement is made in the surplus lines market, it is placed through a licensed surplus line broker. This agency does not hold surplus line authority itself.
- Google LLC — Google Tag Manager, Google Analytics 4, and Google Ads receive online identifiers and event data from this site. See Analytics and advertising.
- Vercel Inc. — our hosting provider, which serves every page and runs the function that builds your application PDF. It therefore handles your submission in transit and keeps standard server request logs. We do not run Vercel’s analytics product on this site.
- Resend — the transactional email service that carries two separate messages when you submit. The broker packet goes to our team and carries your signed application PDF and the e-signature audit certificate as attachments. The confirmation goes to the email address you gave us and contains your business name, the limit you requested, and your audit ID — it carries no attachments, so it is not a copy of your signed application. If you want that copy, ask us and we will send it.
- Our own team, by email — the broker packet is delivered to reviews@bollinsure.com, with a copy to one internal agency address, and our internal system ingests that mailbox so a licensed broker can work the submission. Nothing about your application is written to a database on this website; the server builds your PDF in memory, emails it, and keeps no copy.
- Professional advisers and service providers under contract — each limited by contract to using the information only to perform the service for us.
- Regulators, courts, and law enforcement — where we are legally compelled, or where disclosure is necessary to establish or defend a legal claim.
We do not sell your information, and we do not disclose your application answers to anyone for their own marketing.
Analytics and advertising — exactly what runs here
Some of this is written into the page and some of it is loaded by the tag manager once the page is running. Those are different things and we label them differently, because telling you to “check the source” for something that was never in the source is not transparency.
Written into this page — view source and you will find it
- Google Tag Manager, container GTM-5QM55LTJ — loads on every page of this site and manages the Google tags described below.
- Google Consent Mode v2 defaults, and the Global Privacy Control check — the
<script id="cw-gpc-consent-default">block at the very top of this page, deliberately placed before the tag manager so it takes effect before any Google tag can fire. It readsnavigator.globalPrivacyControland, when your browser sends that signal, setsad_storage,ad_user_dataandad_personalizationtodenied. See Do Not Sell or Share. - Our own event script,
/lead-events.js— pushes exactly four events into the tag manager’s data layer:form_startthe first time you focus any form field on a page, andphone_click,email_clickandquote_clickwhen you click a telephone, email, or quote link. Each one carries the event name, this site’s brand key, the path of the page you are on, which region of the page the link sat in, and up to 40 characters of the link’s own visible text. It does not send your name, email address, telephone number, or any of your application answers.
Loaded by the container, not written into this page
These are configured inside container GTM-5QM55LTJ. You will not find them by viewing source; you will find them in your browser’s network panel, which is where we suggest you look.
- Google Analytics 4, property G-2C0V0NWB3Z — measures pages viewed and the four events listed above.
- Google Ads, account AW-18196791997 — present in the same container for campaign measurement. We will be exact about one thing rather than let the word “conversion” do work it has not earned: no code on this site currently fires a completed-application conversion event. Nothing on this site tells Google Ads that you finished and signed an application.
Two things worth saying out loud
The tag manager is fetched from Google on every page, so Google receives your IP address and the address of the page you are reading before any of its tags decide what to do — including on this page, right now, while you read a privacy policy. We would rather you learn that here than deduce it later.
What does not run on this site: no Vercel Web Analytics or any other host-level page-view counter, no session or screen recording, no keystroke capture, no chat or heat-mapping tool, no reCAPTCHA, and no advertising pixel from Meta, LinkedIn, TikTok, X, or any other network. If that ever changes, this section changes first.
Do Not Sell or Share My Personal Information
We have never sold personal information for money, and we do not. We also do not disclose your application answers for anyone else’s advertising.
We are direct about the harder question. This site loads Google Tag Manager on every page, and Google Analytics 4 and a Google Ads account are configured in that container. California law can treat passing an online identifier to an advertising platform for remarketing or conversion purposes as “sharing” personal information for cross-context behavioral advertising. Rather than assert our way past that, we give you a working opt-out and describe how it works.
Your browser can do it for you
We process opt-out preference signals in a frictionless manner. If your browser or an extension sends the Global Privacy Control signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser and device, and we act on it — we do not merely note it as a preference.
Here is the exact mechanism, so you can check it rather than trust it. Every page on this site carries a script with the id cw-gpc-consent-default, placed above the tag manager so that it runs first. It reads navigator.globalPrivacyControl. If that value is true, the script sets Google’s Consent Mode v2 signals ad_storage, ad_user_data and ad_personalization to denied before any Google tag has loaded, and pushes gpc_opt_out: true into the data layer. Google’s advertising tags then run without advertising identifiers for that browser and device.
What that opt-out does not switch off, stated plainly rather than glossed over: analytics measurement continues. analytics_storage stays granted, so Google Analytics still counts your page view and the four events listed under Analytics and advertising. We take that position because first-party measurement of our own site is not a sale or a share, and we would rather tell you where we drew the line than imply the signal turns off more than it does. If you want the analytics off too, email us using the address below and we will confirm it in writing, or block the tag in your browser.
Processing the signal costs you nothing, does not change your experience of this site, does not trigger a pop-up asking you to confirm, and requires no additional step from you. Because the signal is stored by your browser, you will need to send it from each browser and device you use, and it can be lost if you clear your browser’s storage.
Or ask us directly
Email reviews@bollinsure.com with the subject line Do Not Sell or Share, or call 562-COVWELL (562-268-9355). You do not need an account and we will not ask you to create one. An authorized agent may make the request for you; we will confirm it with you directly before acting on it. We will never charge you, deny you service, or give you a worse price for opting out.
The draft saved in your browser
So you can leave the application and come back to it, the form saves your progress in your own browser’s local storage under the key bestcyber_wizard_v3. That draft holds the answers you have entered so far, including your contact details and your adopted signature image. It stays on your device, it is not a cookie, it is not readable by any third party, and it is not transmitted anywhere on its own. It is deleted automatically when your application is submitted successfully, and you can delete it at any time by clearing site data for this site in your browser.
One thing to know: when you click Generate preview, your answers are sent to our server so the filled PDF can be built and returned to you. Your signature image is not included in that preview request — it is sent only when you submit the signed application. The preview is generated in memory and sent straight back to your browser; it is not stored, and no email is sent until you sign and submit.
How long we keep it
California law asks for the period each category is kept, or the criteria used to work it out. This is our schedule.
How it is protected
The site is served over HTTPS. Every submission is validated on the server, not only in your browser, and the endpoint is rate-limited to 20 requests per minute from any one IP address. The server builds your PDF in memory and writes nothing to disk, so there is no store of applications on this website to breach. The signed PDF and its audit certificate are transmitted by email over authenticated, encrypted transport, and access to them is limited to licensed staff of the agency. We also reduce risk by not collecting what we do not need — there is no payment field, no Social Security number field, and no credential field anywhere in this application.
No method of transmission or storage is completely secure, and we will not claim otherwise.
Your California privacy rights
We honor the rights below for California residents. We do so whether or not the statutory revenue and volume thresholds apply to a brokerage of our size, and whether or not a particular record falls inside the financial-institution carve-out that covers much of what an insurance producer collects. We would rather give you the right than argue about whether we owe it to you.
- Know the categories of personal information we collected, the sources, the business purpose, and the categories of third parties we disclosed it to.
- Know the specific pieces of personal information we hold about you — not only the categories.
- Access that information, and receive it in a portable, readily usable format where we hold it electronically.
- Correct inaccurate personal information.
- Delete personal information, subject to the exceptions California law allows — the most common one here is insurance record-keeping and the need to defend or establish a legal claim.
- Opt out of the sale or sharing of personal information — see Do Not Sell or Share My Personal Information.
- Limit the use of sensitive personal information. This site does not collect sensitive personal information as California defines it, and we do not use or disclose any for purposes that would trigger this right. If that ever changes, the control comes with it.
- Non-discrimination — we will never deny you service, charge you a different price, or give you a lesser level of service because you exercised a privacy right.
How to make a request
Two ways, and you may use either:
- Email reviews@bollinsure.com
- Call 562-COVWELL (562-268-9355)
An authorized agent may submit a request for you with your written permission; we will verify the permission and confirm the request with you directly before acting on it.
How we verify you, and how fast we respond
We verify a request by matching what you tell us against the contact details already in your file and by contacting you at the email address or telephone number on that file. For a request to know specific pieces of information we verify to a higher standard, because the consequence of getting it wrong is worse. We will confirm receipt of your request within 10 business days and describe how we will handle it, and we will respond substantively within 45 calendar days. If we need more time we will tell you within that 45 days and take no more than a further 45 days, for 90 days in total.
Notice of insurance information practices
This notice is given under California’s Insurance Information and Privacy Protection Act, at Insurance Code section 791 and following. It applies to us as a licensed insurance agent and broker independently of the California Consumer Privacy Act, and it is not displaced by the financial-institution rules that cover much of what an insurance producer collects. Where it gives you more than the section above, the more generous one governs.
Information may be collected from people other than you
Personal information about you or your business may be collected from persons other than the applicant. That can include an investigative consumer report, a loss-history or claims report, an external security-scanning or vulnerability report about your internet-facing systems, information from a prior or current carrier or wholesale broker, and publicly available business information. Such information may be retained by an insurance-support organization and disclosed by it to other persons.
Before an investigative consumer report is obtained
If we or a carrier order an investigative consumer report about you in connection with your application, you will be told before it is obtained. You may request to be interviewed in connection with the preparation of that report, and you may request a copy of it.
Disclosures we may make without your authorization
The Act permits certain disclosures without separate authorization, and these are the ones that arise here: to a carrier, wholesale broker, or reinsurer in order to obtain or service the insurance you asked us to seek; to a person performing a business, professional, or insurance function for us under contract; to detect or prevent fraud, material misrepresentation, or material non-disclosure; to a regulator, or in response to a lawful subpoena, warrant, or court order; and as otherwise permitted by law.
Your right of access
You may ask us in writing whether we hold recorded personal information about you and to see and copy it. We will tell you within 30 business days of receiving your written request what we hold, where it came from, and to whom we have disclosed it in the preceding two years. We will identify anyone else we know to be holding the information for us. Some information gathered in connection with a claim or a civil or criminal proceeding may be withheld until that matter concludes. If we hold medical-record information, we may arrange for it to be given to you through a medical professional you name.
Your right to correct, amend, or delete
If you believe recorded personal information we hold about you is wrong, write to us and tell us what is wrong and what it should say. Within 30 business days we will either correct, amend, or delete it, or tell you in writing why we will not, who made the decision, and how to seek review.
If we make the correction, we will notify you and, at your written request, notify the people to whom we previously disclosed the information — any person you name who may still hold it, any insurance-support organization whose primary source of information is insurance institutions if it received it in the preceding seven years, and any insurance-support organization that supplied it to us.
If we refuse, you may file a concise statement of dispute setting out what you believe is correct and why. We will keep it with the disputed information, include it in any future disclosure of that information, and on your written request supply it to the same people who would be notified of a correction.
If an application is declined, non-renewed, or rated up
If an adverse underwriting decision is made — a declination, a termination, or an offer of coverage on terms less favourable than you applied for — you are entitled to a written statement of the specific reasons for it and of the specific items of information that supported those reasons, together with the name and address of the source of that information. Ask us and we will provide it, or obtain it from the carrier for you. An adverse underwriting decision will not be based, in whole or in part, on a previous adverse underwriting decision or on the fact that you previously obtained insurance through the residual market, without the underlying facts being independently established.
Calls, texts, and email
When you give us a telephone number on the application, a licensed broker uses it to follow up on the submission you made. That is the transaction you asked for.
Separately, and only if you tick the optional box next to the submit button, you may give express written consent for us to call and text you at that number about your insurance options, including with an automatic telephone dialing system or an artificial or prerecorded voice where we use one. That consent is optional. It is not a condition of purchasing any goods or services, and your application is submitted and worked exactly the same way whether you tick it or not. Message and data rates may apply, message frequency varies, and consent is given only to WJB Services, Inc. dba Bollinsure Insurance Services — we do not sell or pass your number to other sellers or lead buyers.
How to stop. Reply STOP to any text message, reply HELP for help, tell any broker you speak to, or email reviews@bollinsure.com or call 562-COVWELL. We accept a revocation made by any reasonable means, we honor it within ten business days at the latest, and a revocation for one kind of message is treated as a revocation for all of them unless you tell us otherwise. You may also ask to be added to our internal do-not-call list, which we maintain in writing and will describe to you on request. Withdrawing consent does not affect an application already in progress.
If we ever record a telephone call, you will be told at the start of that call.
Children
This site is for business owners and the people who buy insurance for a business. It is not directed to children, we do not knowingly collect personal information from anyone under 16, and we do not sell or share the personal information of anyone under 16. If you believe a child has given us information, email reviews@bollinsure.com and we will delete it.
Changes to this page
If our practices change, we will update this page and the “last updated” date below before the change takes effect, and we will note a material change plainly at the top. We review this page at least once every twelve months whether or not anything has changed.
How to reach us
WJB Services, Inc. dba Bollinsure Insurance Services
3625 E Thousand Oaks Blvd Ste 292, Westlake Village, CA 91362
562-COVWELL (562-268-9355) · reviews@bollinsure.com
California Department of Insurance Agency License #0D94699 · Independent broker
Related: Terms of Service.
Last updated: August 1, 2026.