Legal
Privacy policy
Last updated: May 18, 2026
Effective date: May 18, 2026
Jurisdiction: United States. Governed by the laws of the State of Texas, without regard to its conflict-of-laws rules. Where state privacy laws (including the CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA, and similar) provide additional rights to residents of those states, those rights apply.
Direct Event Insurance ("DEI," "we," "us") operates directeventinsurance.com and the related quote and application platform (the "Services"). This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to visitors, applicants, policyholders, venue partners, and vendors who interact with the Services.
DEI is a licensed insurance producer. The majority of our volume (roughly 80%) is underwritten by AM Best-rated insurance carriers; the remainder is placed with other A rated carriers and program administrators we are appointed with, depending on the event type, venue, jurisdiction, and limits requested. The carriers and program administrators that handle your specific policy act as independent or joint controllers of your information for the processing described below.
1. Information we collect
We collect information you give us, information collected automatically, and information from third parties.
Information you provide
- Contact details: name, email, phone, mailing address, business name.
- Event details: event type, dates, venue, attendance, activities, setup and teardown windows.
- Coverage details: limits requested, additional insureds, prior loss history, vendor rosters.
- Payment details: card, ACH, or bank information collected and processed by the PCI-DSS compliant payment processor designated by the issuing carrier or its program administrator for your policy. DEI does not use Stripe to process payments. We do not store full card numbers on our servers.
- Account credentials when you create a save-and-resume application (email and a hashed password managed by our authentication provider).
- Correspondence you send us, including support messages, claims notices, and uploaded certificates or documents.
Information collected automatically
- Device and connection data: IP address, user agent, device type, referring URL, pages viewed, and timestamps.
- Application telemetry: form step progress, autosave snapshots, and error diagnostics used to keep the quote flow working.
- Cookies and similar technologies (see Section 7).
Information from third parties
- Carriers and rating partners (including AM Best-rated insurance carriers) for underwriting, binding, endorsement, and claims.
- Venue partners who refer you to us or who request certificates on your behalf.
- Payment processors and identity or fraud screening services.
We do not knowingly collect sensitive categories such as government ID numbers, health information, or precise geolocation. Do not send these through the Services.
2. How we use information
- Quote, bind, service, renew, and cancel insurance policies.
- Issue certificates of insurance and share them with the venues and additional insureds you designate.
- Process payments, refunds, and the venue-rejection refund guarantee.
- Communicate with you about your application, quote, documents, policy, claims, and renewals, including transactional and informational email and SMS. Our SMS program is used only for these transactional and informational communications and is never used for marketing, promotions, newsletters, or advertising.
- Operate, secure, debug, and improve the Services, including fraud prevention and abuse detection.
- Comply with legal, regulatory, licensing, and recordkeeping obligations applicable to insurance producers and carriers.
3. Legal bases (EEA, UK, and similar regimes)
Where required, we rely on the following legal bases: performance of a contract (issuing and servicing your policy), legal obligation (insurance and tax law), legitimate interests (securing the Services, preventing fraud, improving the product), and consent (optional marketing, certain cookies). You can withdraw consent at any time without affecting prior processing.
4. How we share information
- Carriers, program administrators, and reinsurers: AM Best-rated insurance carriers (AM Best-rated insurance carriers) handles roughly 80% of our volume; the balance is placed with other A rated carriers and program administrators we are appointed with. Whichever carrier underwrites your policy receives the application, rating, and policy data required to quote, bind, and service coverage, and may share it with their reinsurers.
- Venues and additional insureds: certificates of insurance, which include your name, policy number, limits, and event details, are sent to the venues and additional insureds you list.
- Payment processors: the PCI-DSS compliant payment processor designated by the carrier or program administrator that underwrites your policy processes card, ACH, and bank payments under its own privacy terms. DEI does not use Stripe as a payment processor, and Stripe does not receive your payment data through the Services.
- Service providers: hosting (Cloudflare), database and storage (Supabase / PostgreSQL), email delivery, analytics, error monitoring, customer support, and document signing. These providers act on our instructions under written agreements.
- Professional advisors: auditors, attorneys, and accountants under confidentiality obligations.
- Authorities: regulators, courts, and law enforcement when legally required, including state insurance departments.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. Mobile phone numbers and SMS opt-in data are never shared with third parties for marketing purposes.
4a. SMS / text messaging disclosure
Our SMS program is used only for transactional and informational communications related to a submitted event insurance application or an active policy. Messages may include application status updates, quote status updates, quote delivery notices, document requests, policy-related communications, and customer support responses tied to your insurance request. We do not use SMS for marketing, promotions, newsletters, advertising, future offers, or sales campaigns.
- Message frequency varies based on your application or policy activity.
- Message and data rates may apply depending on your mobile service plan.
- Reply STOP to opt out at any time.
- Reply HELP for assistance.
- SMS consent and mobile phone numbers are not shared, sold, or transferred to third parties or affiliates for marketing or promotional purposes.
- SMS consent is not a condition of purchase.
See our SMS opt-in policy for the full consent language and opt-in form.
5. Data retention
We retain policy and application records for as long as required by insurance law and our recordkeeping obligations, typically the policy period plus seven years, and longer where claims, litigation, or regulatory matters require it. Marketing and analytics data are retained for shorter periods aligned to their purpose. Quote applications that are abandoned without binding may be retained to let you resume them and to support fraud prevention.
6. Security
We protect information using administrative, technical, and physical safeguards designed for the sensitivity of the data, including TLS in transit, encryption at rest for our primary database, role-based access, least-privilege service credentials, row-level security on customer records, audit logging, vendored secrets management, and regular dependency and vulnerability scanning. Payment card data is handled by PCI-DSS compliant processors and is not stored on our servers.
No system is perfectly secure. If we become aware of a breach that affects your information, we will notify you and regulators as required by law.
7. Cookies and tracking
We use a small number of strictly necessary cookies and local storage keys to keep you signed in, preserve your in-progress application (autosave), remember preferences, and secure the site against abuse. Analytics cookies are off by default and only run after you opt in. We do not use third-party advertising cookies and do not share data for cross-context behavioral advertising.
You can review or change your choices at any time using the link in the footer. Withdrawing consent stops future analytics collection; it does not affect strictly necessary cookies required to run the Services.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your information, to object to certain processing, and to withdraw consent. California, Colorado, Virginia, Connecticut, Utah, and other state residents have rights under their respective privacy laws, including the right to appeal a denied request. EEA, UK, and Swiss residents have rights under GDPR and similar laws and may lodge a complaint with their supervisory authority.
To exercise a right, email privacy@directeventinsurance.com. We will verify your request against the information on file. Some information must be retained to meet insurance recordkeeping rules even after a deletion request.
9. Children
The Services are intended for adults. We do not knowingly collect information from children under 16. If you believe a child has provided us information, contact us and we will delete it.
10. International transfers
We are based in the United States, and our service providers may process information in the United States and other countries. Where required, we rely on appropriate transfer mechanisms such as the EU Standard Contractual Clauses and the UK Addendum.
11. Third-party sites
The Services may link to venue, partner, or carrier sites. Their privacy practices are governed by their own policies. We are not responsible for content or practices on third-party sites.
12. Changes to this policy
We may update this policy to reflect changes to the Services or the law. We will update the "Last updated" date above and, for material changes, provide additional notice such as email or an in-product banner.
13. Contact us
Direct Event Insurance
Attn: Privacy
privacy@directeventinsurance.com
See also our Terms of service and Licenses.