BenefitProof
Version 1.2 — Founding Advisor Beta · Effective September 2, 2026
How Sensible Benefits, LLC, doing business as BenefitProof ("we," "us"), handles personal information in connection with the BenefitProof beta (the "Service"). BenefitProof is a business tool for professional benefits advisors in the United States, and this policy is written for that B2B context.
Data we control (as controller/business): account and billing information about you and your Authorized Users, and usage and technical data. We decide how this is used, as described below.
Data you control (we act as processor/service provider): the Customer Data and Employer Data you submit to the Service. We process it only to provide the Service to you and under your instructions, as set out in the Terms. We do not sell Customer Data, and we do not use it for our own independent purposes, except to create de-identified or aggregated information as permitted by the Terms. As the advisor, you control the employer data you submit and are responsible for it.
Account data: name, business email, company, role, and invitation details.
Billing data: payment method and transaction records, handled by our payment processor; we do not store full card numbers.
Usage and technical data: log data, device and browser information, IP address, and product interactions, used to operate, secure, and improve the Service.
Customer and Employer Data: documents and information you upload. Do not upload data you lack authority to provide, or protected health information without a required Business Associate Agreement.
Cookies: we use only strictly necessary cookies to keep you signed in and to operate the Service. We do not use third-party advertising cookies or cross-site tracking, and we do not use the Service to serve advertising.
To provide, secure, support, and improve the Service; to process enrollment, trials, billing, and renewals; to communicate about your account; to prevent fraud and abuse; and to comply with law. We rely on the performance of our contract with you and our legitimate business interests as bases for processing.
Service providers who help us run the Service — for functions that may include cloud hosting, data storage, authentication, payment processing, email delivery, analytics, and artificial intelligence and automated processing — bound by contract to protect the data and to use it only to provide services to us.
Legal and safety: to comply with law, enforce our terms, or protect rights and safety.
Business transfers: in a merger, financing, or sale, subject to this policy.
We do not "sell" personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under applicable law.
You may access or update account data in-product or by contacting us at privacy@ratemybenefits.com. Depending on your state, individuals may have rights to access, correct, delete, or limit certain data. Because most Customer and Employer Data is controlled by you (or the employer), we will refer individual requests concerning Customer Data to you and support you in responding.
We retain controller-data for as long as needed for the purposes above and to meet legal obligations. Customer Data retention, export, and deletion are governed by the Terms: during the subscription and for thirty (30) days after termination you may request a reasonable export; after that period we delete Customer Data from active systems within thirty (30) days and purge it from routine backups within ninety (90) days, except de-identified or aggregated data and records we must retain by law. De-identified or aggregated information may be retained.
We use reasonable administrative, technical, and physical safeguards appropriate to an early-stage service. No system is perfectly secure, and we cannot guarantee absolute security.
The Service is intended for U.S.-based business users. It is not directed to individuals outside the United States or to consumers, and it is not intended for children.
Benefits data may include sensitive information. We handle it as Customer Data under your control and the Terms. We do not represent that the Service is a HIPAA-compliant environment. You are solely responsible for determining whether your use involves protected health information and for obtaining any necessary Business Associate Agreement, employer authorization, client consent, or other legal authority before uploading or processing such information. Nothing in this policy or the Terms creates a Business Associate Agreement between the parties; any such agreement must be separately negotiated and executed in writing. Protected health information must not be submitted without a required Business Associate Agreement.
We may update this policy and will post the new effective date; material changes will be communicated reasonably. Questions about this policy may be directed to privacy@ratemybenefits.com.