Last updated: September 21, 2026
This Privacy Policy explains how Okiova ("Okiova," "we," "us," or "our") collects, uses, stores, protects, and shares information when you visit okiova.com, use app.okiova.com, request a demo, or use an Okiova account, portal, integration, or related service.
Okiova is software for insurance agencies. Okiova is not an insurance carrier and is not the licensed insurance agency that sells or services a policy. Insurance agencies using Okiova remain responsible for their own insurance activities, customer relationships, legal obligations, and data-entry decisions.
1. Information we collect
Website and demo information
When you request information, a demo, or support, we may collect information such as your name, business or agency name, email address, phone number, role, and the information you choose to submit. Our hosting and security systems may also receive technical information such as IP address, browser type, device information, timestamps, referring pages, and security or error logs.
Agency and platform account information
Agency administrators and staff may provide agency profile information, user names and emails, roles, permissions, locations, branding, subscription settings, workflow settings, connected integrations, and support information.
Customer, policy, partner, and operational information
Agencies may use Okiova to store or process information about customers, prospects, policies, households, businesses, referral partners, service and retention activity, tasks, carrier intake, commissions, claims-related workflow information, documents, messages, e-signature records, marketing activity, automations, and other agency operations. The agency controls why this information is entered and who within that agency is authorized to use it.
Files, identity information, and protected values
Okiova may store documents, images, uploads, signed documents, generated documents, agency media, driver-license or identification information, and other information an agency reasonably needs for insurance operations. Okiova provides protected document storage and a tenant-aware Secure Vault for supported high-risk values so they do not need to be placed in ordinary notes or unprotected CRM fields. Agencies remain responsible for deciding what information is appropriate and lawful to collect and retain.
Usage, security, and audit information
We may collect records of sign-ins, feature usage, changes, support activity, automation runs, integration events, file activity, and other audit or security events in order to operate, secure, support, and improve Okiova.
2. Connected Google accounts
When an agency administrator connects a Gmail or Google Workspace mailbox, Okiova uses Google's OAuth process. The current connection can request basic identity information together with Gmail permissions needed to send, synchronize, mark read/unread, archive, move to spam, and move to trash from inside the agency's Okiova workspace.
Connected-mailbox data is tenant-scoped. Okiova uses the agency's authorized mailbox to ingest business communications into that agency's Communications Center, then separately attempts to associate a message with the correct customer, partner, or other CRM record. A message does not need to match a customer in order to belong to the agency inbox.
OAuth access and refresh tokens are stored as protected tenant-specific secrets and are not displayed back to ordinary agency users. An agency can disconnect its mailbox in Okiova and can also revoke access through its Google account. Google controls OAuth app publishing, verification, and any security-assessment requirements that apply to restricted Gmail scopes.
Okiova's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Okiova does not sell Google user data or use Google user data for advertising.
3. Connected Microsoft accounts and other providers
When an agency connects Microsoft 365, Okiova uses delegated authorization to identify the exact business mailbox and, when granted, send, synchronize, and manage supported mailbox state from inside Okiova. Okiova may also support custom SMTP connections. Credentials and authorization material are stored as tenant-specific protected settings where supported.
OAuth-connected Microsoft and Google mailboxes synchronize directly through the provider APIs. Custom SMTP or other providers may use a separately configured inbound-capture method when direct mailbox synchronization is unavailable.
4. How we use information
- Provide, operate, maintain, secure, and improve Okiova.
- Authenticate users and enforce tenant, role, permission, plan, and feature boundaries.
- Provide CRM, policy, service, retention, commission, document, portal, e-signature, reporting, marketing, education, automation, and communication workflows.
- Send agency-authorized email, portal notifications, document requests, review requests, workflow notices, and other communications.
- Provide support, troubleshoot errors, investigate security issues, and maintain audit records.
- Administer subscriptions, promotions, usage limits, pilot or founding-agency terms, and account status.
- Comply with legal obligations and enforce Okiova agreements and acceptable-use requirements.
5. Tenant separation and access
Okiova is designed as a multi-agency platform. Agency-owned records are associated with an agency or tenant and access is intended to be restricted to authorized users of that tenant. Okiova platform staff may use controlled support or assist-mode tools when needed to support an agency. Support access and sensitive administrative actions may be audited. Platform staff are not permitted to use another agency's data merely because they can administer the Okiova service.
6. When information may be shared
We may share or make information available only as reasonably necessary to provide Okiova, at the direction of the agency or user, with service providers that support hosting, email delivery, authentication, storage, security, or other platform functions, to comply with law or lawful process, to protect users or the service, or in connection with a merger, financing, acquisition, or sale of assets subject to appropriate protections.
We do not sell personal information to advertisers. Customer and agency data is not made available to unrelated advertisers for their own marketing.
7. Communications and marketing
Agencies can configure service, operational, review, and marketing communications. Agencies are responsible for having the permissions, consents, and legal basis required for communications they send. Okiova includes suppression and preference controls in supported workflows, but agencies remain responsible for their own compliance with email, telephone, text-message, privacy, and insurance-marketing laws.
8. Payments and financial information
Okiova may store subscription status, pricing, commissions, fees, payment-status information, accounting records, and links or references used for payment workflows. When an authorized agency chooses to use Okiova Secure Vault, Okiova can store a payment-card number, cardholder name, expiration information, and billing ZIP in encrypted tenant-bound storage that is masked by default and subject to access controls and audit logging. Full payment-card numbers are not intended to be placed in ordinary CRM fields, notes, email, or chat.
Okiova Secure Vault does not provide long-term storage for CVV/card security codes. Okiova may also provide a short-lived encrypted payment handoff for an authorized insurance-binding workflow; that handoff is designed for one-time retrieval and automatic destruction. Agencies that choose to collect or store payment-card data remain responsible for applicable payment-card security and compliance obligations. Where a payment is collected through a third-party payment provider or hosted payment page, that provider's terms and privacy practices apply.
9. Data retention and deletion
We retain information for as long as reasonably needed to provide Okiova, maintain security and audit history, comply with legal or contractual obligations, resolve disputes, and support legitimate business operations. Authorized agency managers may have tools to permanently delete certain customer or lead records and associated Okiova data. Some information may remain for a limited period in backups, logs, audit records, or records that must be retained by law or contract.
Disconnecting a Google or Microsoft account stops Okiova from using that connection for new mailbox operations after the connection is removed or revoked. Agencies may also revoke provider access directly with Google or Microsoft.
10. Security
Okiova uses administrative, technical, and organizational safeguards designed for the service, including tenant-aware authorization, protected file handling, encrypted storage of supported OAuth and integration secrets, role and capability checks, audit logging, and HTTPS in production. No system can guarantee absolute security, and agencies are responsible for protecting their own user accounts, devices, mailbox accounts, and credentials.
11. Children
Okiova is not directed to children for independent account creation or use. Insurance agencies may enter household or dependent information in the ordinary course of servicing customers; the agency is responsible for ensuring that such processing is lawful and appropriate.
12. Privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, or other treatment of personal information. If Okiova processes information on behalf of an insurance agency, the agency may be the appropriate party to contact first. You may also contact Okiova using the address below and we will route or respond to the request as appropriate.
13. Changes to this policy
We may update this Privacy Policy as Okiova changes. We will update the "Last updated" date and, when appropriate, provide additional notice. Material changes to the way Okiova uses Google user data will be reflected in this policy and in relevant in-product disclosures.
14. Contact
Questions about privacy or connected-account data can be sent to admin@okiova.com.