← Back to Raro

Privacy Policy

Effective date: June 5, 2026  ·  Last updated: July 29, 2026

1. Who We Are

Raro (“Raro,” “we,” “us,” or “our”) operates the Raro CRM platform available at tryraro.com. Raro CRM is a multi-tenant sales CRM designed for life insurance representatives and teams.

For questions about this policy, contact us at justin@tryraro.com.

2. Scope and Roles

Raro collects and processes two categories of personal data, and our legal role differs for each:

  • Account data — data about the organizations and individual users (insurance reps and managers) who sign up for Raro. For this data, Raro acts as the data controller: we determine the purposes and means of processing.
  • Customer-uploaded lead data — personal information about third-party contacts (leads) that our customers enter into the platform, including names, phone numbers, email addresses, pipeline notes, and communication logs. For this data, Raro acts as a data processor on behalf of the customer (the controller). Customers are responsible for their own compliance obligations with respect to the leads whose data they upload, including obtaining any required consents.

3. Data We Collect

3.1 Account Data (Controller)

  • Name and email address provided at signup
  • Organization/workspace name and slug
  • User role (rep or manager)
  • Authentication credentials managed via Amazon Cognito (we do not store raw passwords)
  • Subscription and billing information processed via Stripe (we do not store full card numbers)
  • Usage and activity metadata (login timestamps, feature interactions)

3.2 Lead and Contact Data (Processor)

When customers use Raro CRM, they may enter the following information about their leads:

  • First name, last name, phone number, email address
  • Pipeline status and ownership assignment
  • Free-text notes
  • Activity history: call logs (including duration and outcome), SMS message bodies, status changes
  • Calendar event details linked to a lead (appointment title, scheduled time)

Raro does not ask for Social Security numbers, financial account numbers, or government-issued ID numbers from leads. However, free-text notes and dictated call transcripts may contain health-related information that reps record in the course of insurance work (for example, underwriting details). That information is processed to provide the service, is shared with OpenAI for transcription and assistant processing, and is covered by the retention terms in Section 9.

3.3 Technical and Usage Data

  • Browser type, operating system, and device type
  • IP address and approximate geographic location
  • Pages visited and features used within the application
  • Error logs and performance data (via AWS CloudWatch)
  • Product usage analytics and error monitoring (via PostHog): behavioral events and diagnostic data

4. How We Use Data

  • To provide, maintain, and improve the Raro CRM platform
  • To authenticate users and enforce organizational data isolation
  • To process subscription payments and manage billing
  • To facilitate outreach features: click-to-call and SMS messaging via Telnyx on behalf of customers and their authorized users
  • To enable the Google Calendar integration at the user's direction
  • To provide AI assistant features and dictation transcription, which process lead names and statuses, note and call-transcript text, and calendar titles via OpenAI
  • To generate KPI reports and dashboard data for authorized users within an organization
  • To send transactional communications (e.g., email verification, billing receipts)
  • To detect, investigate, and prevent security incidents and fraud
  • To comply with legal obligations

We do not sell personal data to third parties. We do not use customer lead data for any purpose other than providing the contracted services.

5. Legal Bases for Processing

Where applicable law requires a legal basis for processing personal data, we rely on:

  • Contract performance — processing necessary to provide the services you or your organization have subscribed to.
  • Legitimate interests — security monitoring, fraud prevention, product improvement, and internal analytics, where those interests are not overridden by your rights.
  • Legal obligation — where processing is required to comply with applicable law.
  • Consent — where we expressly request consent for a specific use (e.g., optional integrations).

6. SMS, Voice Calls, and TCPA Notice

Raro provides click-to-call (voice) and SMS outreach functionality powered by Telnyx. This functionality is provided as a tool to our customers (the insurance reps and organizations using the platform). The following applies:

  • Customer responsibility for consent. Customers are solely responsible for obtaining all legally required consents from their leads before initiating calls or sending text messages. This includes compliance with the Telephone Consumer Protection Act (TCPA), the FCC's A2P 10DLC (Application-to-Person 10-digit long code) regulations, applicable state telemarketing laws, and any Do-Not-Call (DNC) registry obligations.
  • Opt-out handling. Customers must honor opt-out requests (e.g., STOP replies to SMS) promptly and in accordance with applicable law. Raro does not automatically suppress leads upon receipt of STOP messages on the customer's behalf; customers must implement and maintain their own opt-out compliance procedures.
  • Message and call log storage. The body of outbound SMS messages and call log details (duration, outcome, notes) are stored in Raro's database as part of the lead's activity history. This data is retained for the duration of the subscription and for a reasonable period thereafter, subject to Section 9 below.
  • Telnyx as subprocessor. Voice and SMS traffic is routed through Telnyx, Inc. See Section 7 for details.

7. Subprocessors

We use the following third-party service providers (subprocessors) to deliver the platform. Each is engaged under appropriate data protection terms:

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure: compute (Lambda), database (Aurora PostgreSQL), authentication (Cognito), storage (S3), CDN (CloudFront), messaging (SQS), secrets managementUSA (us-west-2)
Telnyx, Inc.Click-to-call voice and SMS outreachUSA
Stripe, Inc.Payment processing and subscription billingUSA
Google LLCGoogle Calendar API integration (at user direction)USA / global
OpenAI, L.L.C.AI assistant features and dictation transcription — lead and calendar data, note and call-transcript textUSA
PostHog, Inc.Product usage analytics and error monitoring; behavioral events and diagnostic dataUSA

We will update this list as subprocessors are added or removed. Customers who require advance notice of subprocessor changes should contact us at justin@tryraro.com.

8. Data Sharing and Disclosure

We do not sell, rent, or share personal data with third parties except:

  • With the subprocessors listed in Section 7, as necessary to deliver the service
  • Within an organization: managers can view data belonging to reps in the same organization; data is strictly isolated by organization ID and never shared across organizations
  • Where required by law, court order, or regulatory authority
  • In connection with a merger, acquisition, or sale of assets, with notice to affected users
  • To protect the rights, property, or safety of Raro, our users, or the public

9. Data Retention

  • Account and lead data is retained for the life of the account. Upon account closure or a verified deletion request, data is deleted or anonymized within 24 months. You may request a data export before deletion.
  • Activity logs and SMS records are retained for the same period as account data.
  • Billing records may be retained longer as required by applicable tax and financial regulations.
  • Backup copies may persist for a reasonable additional period per our disaster recovery procedures, after which they are securely destroyed.

Customers may request deletion of their organization's data at any time by contacting justin@tryraro.com.

10. Security

We implement technical and organizational measures appropriate to the risk, including:

  • All compute and database infrastructure runs in a private AWS VPC with no public internet exposure
  • Data in transit is encrypted using TLS
  • Data at rest is encrypted using AWS-managed encryption (AES-256)
  • Organization-level data isolation: every database query is scoped by org_id, enforced in application code
  • Authentication via Amazon Cognito with JWT validation on every API request; brute-force protections enabled
  • API Gateway throttling to limit abuse
  • AWS Shield Standard on CloudFront
  • Secrets (API keys, database credentials) stored in AWS Secrets Manager, never in code or environment variables
  • CloudWatch monitoring and alerting for anomalous activity

No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify affected parties as required by applicable law.

11. Cookies and Local Storage

Raro does not use advertising cookies or third-party tracking cookies. We use browser local storage for the following operational purposes:

  • Theme preference (raro-theme) — stores your light/dark mode selection. This is a functional preference stored locally in your browser and never transmitted to our servers.
  • Authentication session — Amazon Amplify/Cognito stores session tokens in local storage to maintain your login state. These are cleared when you sign out.

You can clear local storage at any time through your browser settings, which will sign you out and reset your preferences.

12. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. To exercise any right, contact us at justin@tryraro.com with sufficient information to verify your identity and specify your request. We will respond within the timeframe required by applicable law.

Rights Available to All Users

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate or incomplete data
  • Deletion — request deletion of your personal data, subject to legal retention obligations
  • Portability — receive your data in a structured, machine-readable format where feasible

California Residents (CCPA/CPRA)

California residents have the right to: know what personal information is collected and how it is used; request deletion; opt out of the “sale” or “sharing” of personal information (Raro does not sell or share personal information as defined by the CCPA/CPRA); non-discrimination for exercising your rights; and, for sensitive personal information, the right to limit use. To submit a verifiable consumer request, email justin@tryraro.com with the subject line “CCPA Request.” We will respond within 45 days.

EEA / UK Residents (GDPR / UK GDPR)

Raro is primarily a US-based service. If you are located in the European Economic Area or United Kingdom and your personal data is processed by Raro, you have the rights listed above plus the right to object to processing based on legitimate interests and to lodge a complaint with your local supervisory authority. Because Raro currently stores all data in AWS us-west-2 (USA), international transfer safeguards may apply. Please contact us to discuss applicable transfer mechanisms.

Note for Lead Data

If you are a third-party lead whose data was entered into Raro by one of our customers, please direct rights requests to the organization (insurance agency or rep) that collected your data. That organization is the data controller for your data. Raro will assist that organization in responding to your request as required.

13. Data Location

All Raro data is stored and processed in the United States, in AWS region us-west-2 (Oregon). We do not currently transfer personal data to other countries as part of our standard operations. Subprocessors with global infrastructure (e.g., Google, Stripe) may process limited account-level data in other regions subject to their own privacy policies and applicable transfer safeguards.

14. Children

Raro CRM is a professional business tool intended for adults 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately at justin@tryraro.com and we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or via an in-app notice. Continued use of the platform after changes take effect constitutes your acceptance of the revised policy.

16. Contact

For privacy-related questions, requests, or complaints, contact:

Raro

Email: justin@tryraro.com

Website: tryraro.com