Who we are
This site is operated by WJB Services, Inc. dba Bollinsure Insurance Services, an independent California insurance brokerage, at 3625 E Thousand Oaks Blvd Ste 292, Westlake Village, CA 91362. Our California Department of Insurance agency licence number is 0D94699. Brian Bollinger, Principal Insurance Broker, holds licence 6013787; Aaron Bollinger holds licence 4345268. We are a broker, not an insurance company. We do not underwrite, issue, bind, or pay claims.
We are the business responsible for the personal information described on this page. Reach us at 562-COVWELL (562-268-9355) or reviews@bollinsure.com.
California notice at collection
This is the notice California law requires us to give at or before the point at which we collect personal information. It is linked from the consent block of the indication form itself, immediately above the submit control, so you see it before you send us anything.
- What we collect — identifiers, the business and employment records described below, commercial information, internet and network activity, coarse location inferred from IP address, and inferences drawn from those. The full list is in the next two sections.
- Why we collect it — to produce a preliminary premium indication, to prepare and submit a workers compensation application on your behalf to insurance carriers, and to communicate with you about that submission. Nothing else.
- Sensitive personal information — we ask for a Federal Employer Identification Number, which is a business tax identifier rather than a personal one. We do not ask on this site for a Social Security number, a driver’s licence number, precise geolocation, account log-in credentials, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or the contents of your mail, email or texts. We do not use or disclose sensitive personal information for any purpose other than performing the services you asked for.
- Health information — do not send us injured-worker medical records, claim files containing diagnoses, or any other health documents through this website. We do not need them to shop your account, and this site is not built to receive them. If a carrier later needs medical detail on a specific claim, your broker will arrange a secure route for it.
- Sale and sharing — we do not sell personal information for money. Because this site runs a Google advertising conversion tag, we treat the identifiers that tag makes available as “sharing” for cross-context behavioural advertising and we give you a way to switch it off. See Do Not Sell or Share My Personal Information.
- How long we keep it — see the retention schedule below. Every category has a stated period.
What we collect
Everything below is information you type into this site or that your browser sends automatically. No data broker feeds this form, and it contains exactly one hidden field — the anti-bot honeypot described under what actually runs here, which is invisible to you, collects nothing about you, and only ever holds something if a bot filled it in.
- Business identifiers — legal business name, mailing address, city, state, ZIP, entity type, years in operation, website, and Federal Employer Identification Number.
- Contact details — contact name, job title, email address, and phone number.
- Payroll and classification data — each WCIRB class code you select, its description, the annual payroll assigned to it, the rate used, and your full-time and part-time employee counts for that code.
- Rating and coverage history — your experience modification factor, current carrier, current premium, policy expiration date, and the carrier and policy number on your prior coverage.
- Loss and claims history — claim counts and incurred amounts by policy year, whether claims remain open, your narrative notes about them, and any loss run document you choose to upload.
- Operations answers — your description of operations and the underwriting questions the ACORD 130 application asks: whether you have a written safety programme (IIPP), whether you use subcontractors and require certificates from them, whether coverage has been declined, cancelled or non-renewed, whether employees work from home or travel out of state, tax liens or bankruptcy in the last five years, work above fifteen feet or underground, work on or over water, and seasonal employment. If you tell us your industry, the form also asks a short set of questions specific to it, and those go to the broker too: for construction, CSLB licence status, prevailing-wage or public works, and heavy equipment; for restaurants, W-2 delivery drivers, employees under 18, off-site catering, and alcohol served on premises; for healthcare, home visits, bloodborne-pathogen exposure, patient lifting, and whether PPE is provided; for retail, forklifts, loading docks, and seasonal surges.
- Owner and officer details — name, title, ownership percentage, whether each owner is included in or excluded from coverage, and remuneration.
- Uploaded documents — a declarations page or current policy, and loss runs, if you attach them.
- Electronic signature record — when you sign the ACORD 130 application on this site we capture your typed or drawn signature image, the signer’s name, title and email address, the exact consent wording and its version, the timestamps at which you started the review, generated the preview, and checked the consent box, your browser time zone, your IP address, your browser user-agent string, a hash of the signature image, and hashes of the signed PDF. That record exists so the signature can be proven later.
Where it goes, precisely. Almost all of it is drawn onto an Electronic Signature Audit Certificate that is appended as the final page inside the signed PDF — audit ID, signing timestamp, signer name, title and email, your IP address, your user-agent string, your time zone, the consent version and wording, whether you ticked the calls-and-texts box and the number you gave it for, the hash of your signature image, and the hash of the signed PDF. Because that page is part of the document, it is in the copy emailed to you, in our copy, and in the application as it goes to carriers, wholesalers and surplus line brokers. That is deliberate and it is the point: an audit trail that does not travel with the document it certifies proves nothing, and you should hold exactly the same proof of what you signed that we do. A separate plain-text version of the same record, plus the hash of the finished PDF, is attached to our internal email only. - Optional calls-and-texts consent — if you tick the separate telephone consent box beside the submit button, we record that you ticked it, the exact wording you were shown, its version, the number you consented for, and the timestamp.
- Technical data — IP address, user-agent, requested URL, referrer, and timestamps, from ordinary server logs and from the measurement tools described below. Your IP address is also used to rate-limit the submission endpoints, which is what keeps the form from being abused.
The same list, in the statutory categories
California defines categories of personal information by statute. Mapping our plain-English list onto them:
| Statutory category | Do we collect it? | What it is here |
|---|---|---|
| Identifiers | Yes | Name, business name, postal address, email, phone, IP address, FEIN |
| Customer records (Civ. Code § 1798.80(e)) | Yes | Contact and business records, insurance and claims history, signature |
| Commercial information | Yes | Current and prior insurance policies, premiums, coverage considered and obtained |
| Professional or employment-related information | Yes | Job title, owner and officer roles, employee counts, payroll by class code |
| Internet or other network activity | Yes | Pages viewed, referrer, form-start and submission events, device and browser data |
| Geolocation data | Coarse only | Approximate region inferred from IP address by the analytics tools. We do not request or use precise geolocation — no page on this site calls the browser location API, and every response from this site carries a Permissions-Policy header that switches geolocation off outright, so the page could not ask even if it tried. |
| Inferences | Yes | Our estimate of your risk profile and likely market fit, drawn from what you told us |
| Sensitive personal information | Not on this site | We do not request SSN, driver’s licence number, precise geolocation, log-in credentials, health data, or the other statutory sensitive categories through this website |
| Biometric information | No | A typed or drawn signature image is not a biometric identifier; we do not collect fingerprints, faceprints or voiceprints |
| Audio, electronic, visual or similar information | Documents only | The files you upload. We do not record calls placed from or to this site’s numbers without telling you at the start of the call. |
| Education information | No | — |
Where the information comes from
- You — nearly all of it. The form is the source.
- Your browser and device — the technical data, automatically.
- Documents you upload — your declarations page and loss runs, which are produced by your current carrier or broker.
- Your current or prior insurance carrier and broker — if you ask us to obtain loss runs or policy documents on your behalf, or authorise us as broker of record.
- Rating bureaus and insurance-support organisations — principally the Workers’ Compensation Insurance Rating Bureau of California (WCIRB), whose published class codes, expected loss rates and experience modification data we use, and which holds the official record of your ex-mod. Carriers and insurance-support organisations may report information about your account to a bureau, and information reported to a bureau may be retained by it and disclosed to other insurers.
- Public records — Secretary of State business registrations, contractor licence records, and similar public sources, where we need to confirm an entity name or licence status.
How we use it
We use your information to calculate a preliminary indication, to prepare the ACORD 130 workers compensation application, to submit that application to the carriers whose appetite matches your class codes and loss history, to answer underwriter questions about your account, to send you a copy of what you signed, and to talk to you about the result. We also use technical data to keep the site up and to stop abusive submissions, and aggregate measurement data to understand which pages bring employers here.
A preliminary indication is never a quote, binder, or guarantee of coverage, price, or eligibility. Submitting this form does not apply for insurance in a way that binds any carrier, does not obligate any carrier to offer terms, and does not put coverage in force. Nothing we send back from this website is a policy, a binder, a quote, or an offer to insure.
We do not use your information to train advertising models, we do not build a marketing profile of you for anyone else, and we do not pass your submission to any other insurance agency or lead buyer.
Who receives it
Named, because “service providers” is not a disclosure:
- Insurance carriers and their underwriters — the admitted California workers compensation carriers we are appointed with, and, for risks the admitted market declines, a licensed surplus line broker who accesses excess and surplus lines markets. Bollinsure does not hold surplus line authority itself; that placement goes through a licensed surplus line broker. Once a carrier has your application, that carrier’s own privacy notice governs what it does with it — we do not control and do not represent what any carrier does with information after it is submitted.
- Wholesalers and general agents — where a market is only reachable through one.
- Resend (resend.com) — the email service that transmits your submission and your signed application PDF to our office, and the confirmation copy to you. Your submission passes through Resend’s systems in the course of delivery.
- Vercel (vercel.com) — the hosting provider that serves these pages and runs the two submission endpoints,
/api/submit(which receives your answers, generates the application PDF for preview and for signing, and emails it) and/api/submit-wc(the indication and policy-upload route). Vercel handles every request to this site, including the preview request described under The draft saved in your browser, and keeps standard infrastructure logs. - Google — through Google Tag Manager, Google Analytics 4 and the Google Ads conversion tag, described in the next section.
- Professional advisers, and anyone we are legally compelled to give it to — our errors-and-omissions carrier and counsel where a claim or dispute requires it; the California Department of Insurance, a court, or law enforcement acting under valid legal process.
That is the complete list. We do not sell your information, we do not trade it, and we do not disclose it to anyone else’s marketing.
Cookies, analytics, and advertising — what actually runs here
This is the checkable part, so here is exactly how far the check goes. Two things are literally in this page’s HTML: a one-line script that puts brand_key: 'bestworkerscompensation' into the data layer, and immediately after it the Google Tag Manager loader. Everything else Google-side is configuration inside that container rather than markup on this page — we can change it without editing a line of this site, so the honest way to disclose it is to name what the container is configured to run and to tell you where the boundary is:
- Google Tag Manager, container GTM-5QM55LTJ — in this page’s head, as the second script. It loads the two Google tags below.
- Google Analytics 4, property G-2C0V0NWB3Z — configured in that container. Page views, page paths, referrers, coarse region, device and browser, plus a small number of named events this site’s own script pushes into the data layer:
form_startthe first time you focus any form field on a page,phone_clickon atel:link,email_clickon amailto:link,quote_clickon a link into the quote flow, and, when you complete and sign an application,generate_leadtogether with an equivalent legacy event namedquoteFormSubmitted. Those two lead events fire once per browser session at most, and only on the signed-application path — if you use the “submit without signing” fallback, no lead event is pushed at all. GA4 sets its own cookies on your device. All of this is in/assets/lead-events.js, which is a plain readable file. - Google Ads conversion tag, AW-18196791997 — configured in the same container, keyed to the lead event above, so advertising spend can be measured against results. This is the tag that makes the “sharing” question below live.
- Consent Mode v2 — the Google tags read consent signals rather than ignoring them, and this site pushes a Consent Mode v2 update of its own: when your browser sends Global Privacy Control,
ad_storage,ad_user_dataandad_personalizationare all set to denied. That push is in/assets/lead-events.json every page. - Global Privacy Control — read from your browser and acted on, not merely noted. See the next section for exactly what acting on it does.
- Google Fonts — the typefaces on these pages are requested from fonts.googleapis.com and fonts.gstatic.com, which means Google receives the request for the font file.
- A hidden honeypot field on the application form — invisible to you, filled in only by bots, and both endpoints discard the submission when it arrives filled. It collects nothing about you.
What the conversion event contains. Besides the event name itself, six fields, and this is the whole list: the site key (bestworkerscompensation), the page path, a numeric event value of 1.0, the currency USD, a lead type of workers-comp, and a reference-id field that this site leaves empty. It carries no name, email address, phone number, business name, FEIN, payroll figure, class code, ex-mod, or claims history. None of those ever reach Google from this site.
What this site does not run. No session recorder. No heat-map or mouse-tracking tool. No chat widget. No Meta, LinkedIn, TikTok or X pixel. No advertising network other than Google Ads as described. No Vercel Web Analytics script — other properties in our estate load one; this site does not. No A/B testing tool. No third-party cookie is set by us for anyone else’s advertising.
You can also block all of it at the browser level: Google Tag Manager, Analytics and Ads are the only third-party scripts here besides the font stylesheet, and blocking them does not break the application form.
Do Not Sell or Share My Personal Information
We do not sell personal information for money. We never have.
“Sharing” is a different question and we answer it conservatively. California defines sharing to include disclosing a consumer’s personal information to a third party for cross-context behavioural advertising, whether or not money changes hands. Because this site runs a Google Ads conversion tag, and because the identifiers that tag makes available to Google can in principle be used for advertising audiences, we treat that as sharing and give you a working opt-out rather than arguing about it.
Three ways to opt out, all free, none of which requires an account:
- Turn on Global Privacy Control. If your browser or extension sends the GPC signal, we treat it as a valid request to opt out of sale and sharing for that browser and device. Concretely, and you can verify all three: the Google Ads conversion event is not fired at all for that browser, so no conversion identifier for you reaches Google Ads even if you complete and sign an application; a Consent Mode v2 update setting
ad_storage,ad_user_dataandad_personalizationto denied is pushed instead; and agpc_opt_outrecord is written to the data layer so the opt-out is visible in our own measurement. We process it frictionlessly — no fee, no change to the site you get, no pop-up thrown in response to the signal, and no extra step required from you. Because a browser signal cannot tell us who you are, it applies to that browser and device rather than to you across every device. Ordinary analytics (page views, and the click and form-start events named above) still run: those are measurement of our own site, not cross-context behavioural advertising, and they are not what you opted out of. - Email reviews@bollinsure.com with “Do Not Sell or Share” in the subject line.
- Call 562-COVWELL (562-268-9355) and tell whoever answers. You do not need to explain why.
We do not knowingly sell or share the personal information of consumers under 16 years of age. This is a site for employers buying workers compensation insurance; it is not directed to children.
Opting out of sharing does not stop us working your submission, does not change your price, and does not change the service you get. That is not a courtesy — discriminating against you for exercising a privacy right is illegal.
How long we keep it
Every category has a period. “As long as necessary” is not a retention schedule, so we do not use it.
| Category | How long we keep it | Why that period |
|---|---|---|
| Draft saved in your own browser | Until you submit, until you choose “Start fresh”, or 14 days — whichever comes first | Only long enough to let you finish an application you started |
| Enquiries and indications that never became an application | 24 months from the last contact | Long enough to serve a renewal cycle and answer a follow-up; no longer |
| Submitted applications, signed ACORD 130s, and the e-signature audit record | 7 years from the end of the policy term, or from submission if no policy was issued | Broker transaction recordkeeping, premium-audit disputes, and the period in which a professional-liability claim can be brought |
| Uploaded loss runs and declarations pages | Kept with the application they belong to, on the same 7-year schedule | They are part of the underwriting record |
| Calls-and-texts consent records, and revocations | 7 years from the date of the consent or revocation | The burden of proving consent sits on the caller, and a revocation must outlive the consent |
| Email delivering your submission, in our mailbox | Same schedule as the application it carries | It is the same record in another form |
| Server and rate-limit logs | Vercel’s standard log retention for our plan; the rate-limit counter is in memory only, holds a 60-second window and at most 5,000 addresses, and is lost whenever the function restarts | Security and abuse prevention only |
| Google Analytics 4 user-level and event-level data | No longer than 14 months, the maximum that property setting allows | Measurement, not recordkeeping |
| Google Ads conversion data | Held by Google under its own retention policies, which we do not control | Stated plainly rather than guessed at |
At the end of a period we delete or securely dispose of the record. Where a legal hold, an open claim, or a regulatory request applies, we keep the affected record until that ends, and then dispose of it.
The draft saved in your browser
So you can leave the application and come back, the form saves your answers in your own browser’s local storage under the key wc_wizard_v1. Four things are true about that draft, and about when your answers do leave the device, and all four are worth stating precisely:
- The draft itself never leaves your device. The autosave is written to your browser and nothing else. We cannot read it, and clearing your site data destroys it.
- One button does send your answers before you sign, and you should know which one. On the final step, pressing “Generate my application” posts everything you have entered — business details, FEIN, contact details, class codes and payroll, claims figures, owners, and the calls-and-texts consent record — to our
/api/submitendpoint, because the application PDF is generated server-side and sent back to your browser. That request emails no one, is not written to any database, and is discarded when the response is returned; nothing reaches a broker or a carrier until you adopt a signature and press Sign & Submit. But it is a transmission, and our host logs the request the way it logs every request. If you leave before pressing “Generate my application”, we never receive what you typed at all. - It contains most of what you typed — business and contact details, class codes and payroll, claims figures, and owner details. It deliberately excludes your Federal Employer Identification Number, any file you attached, and the calls-and-texts consent tick; those are never written to local storage, and a consent has to be given by the person in front of the form rather than restored from a draft.
- It expires. It is deleted when you submit and when you choose “Start fresh”, and a draft more than 14 days old is discarded unread the next time the form loads. Clearing your browser’s site data removes it immediately. On a shared or public computer, use “Start fresh” when you are done.
Your California privacy rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA (Civil Code section 1798.100 and following) gives you the rights below. We honour them for personal information we hold about you, and we honour them as written whether or not we are a “business” that meets the statute’s revenue and volume thresholds — we have chosen not to make you argue about that.
- Know — the categories of personal information we collected, the categories of sources, the business purposes, the categories of third parties who received it, and whether it was sold or shared.
- Access the specific pieces — not just categories, but a copy of the actual information we hold about you.
- Portability — that copy in a readily usable, machine-readable format where we provided it electronically.
- Correct — inaccurate personal information. This one matters here: a wrong payroll figure or class code changes your premium.
- Delete — personal information we collected from you, subject to the exceptions the statute allows, including records we must keep as a licensed broker and information needed to complete a transaction you asked for.
- Opt out of sale and sharing — see Do Not Sell or Share My Personal Information.
- Limit the use of sensitive personal information — we do not collect sensitive personal information through this site and do not use any for purposes beyond providing the services you requested, so there is nothing here to limit. If that ever changes, this page changes with it and a limit-use link appears.
- Non-discrimination — we will not deny you service, charge you a different price, or give you a lesser result because you exercised a privacy right.
- Use an authorised agent — you may designate someone to make a request for you. We will ask for written permission signed by you, and we may ask you to confirm directly that you gave it.
How to make a request
Two methods, either is fine:
- Email reviews@bollinsure.com
- Call 562-COVWELL (562-268-9355)
Verification. Before we act on a request to know, access, correct or delete, we verify that you are who you say you are. Normally that means matching two or three data points against what is already in your submission — for instance the business name, the email address the application came from, and the policy or reference number. We will not ask you for a Social Security number or a photograph of an identity document. If we cannot verify you to a reasonable degree of certainty, we will tell you why and, where the request was to know specific pieces, we will provide categories instead.
Timing. We confirm receipt of a request within 10 business days and tell you how we will handle it. We respond substantively within 45 calendar days. If we need more time we will tell you within that 45 days and take no more than a further 45, for 90 days total. Opt-out requests, including a GPC signal, we act on within 15 business days.
Cost. Free. Twice in any 12-month period for requests to know or access.
If we deny a request in whole or in part, we tell you which parts and why.
California Insurance Code notice of information practices
Separately from the CCPA, California’s Insurance Information and Privacy Protection Act (Insurance Code section 791 and following) applies to us as a licensed insurance agent regardless of our size. This is the notice that statute requires.
- Information may be collected about you from persons other than you. In the course of placing or servicing your workers compensation coverage, we may obtain information from your current or prior insurance carrier or broker, from the WCIRB, from insurance-support organisations, and from public records — for example loss runs, an experience modification worksheet, a unit statistical report, or a licence status.
- The types of information collected and the sources and techniques used are described in What we collect and Where the information comes from above. Our techniques are ordinary records requests and document review. We do not conduct surveillance.
- Information collected may in certain circumstances be disclosed to third parties without your authorisation — to insurance carriers, wholesalers and surplus line brokers to obtain or service coverage for you; to insurance-support organisations; to persons performing a business, professional or insurance function for us; to a regulator; and where a court or law requires it. Those disclosures are limited to the purposes the statute permits, and are described in Who receives it.
- Information obtained from a report prepared by an insurance-support organisation may be retained by that organisation and disclosed to other persons. The WCIRB, in particular, holds California workers compensation experience data independently of us, and your experience modification is calculated and published by the WCIRB rather than by any carrier or broker.
- You have a right of access. On written request identifying yourself, you may learn whether we hold recorded personal information about you, see and copy that information, and be told the identity of anyone to whom we disclosed it in the previous two years, or if that record was not kept, the names of persons to whom such information is normally disclosed. We will respond within 30 business days. We may charge reasonable copying costs. Medical-record information, if any exists, is disclosed either directly or through a medical professional you designate, as you choose.
- You have a right to correct, amend or delete. If you tell us in writing that recorded personal information is wrong, we will within 30 business days either correct, amend or delete it, or tell you in writing that we refuse and why, and who at our firm made that decision. If we correct it, we will notify you, the persons to whom we previously disclosed it, and any insurance-support organisation that gave it to us. If we refuse, you may file a concise written statement of what you believe is correct and why — we will file it with the disputed information, give it to anyone reviewing that information from then on, and send it to the same people who would have received a correction.
- Investigative consumer reports. If we or a carrier arrange for an investigative consumer report about you — a premium-audit inspection, a loss-control survey, or a credit-based report where one is permitted — you will be told before it is obtained, and on request you will be told whether one was obtained and given the name and address of the agency that prepared it. You may request that a representative of that agency interview you personally.
- Adverse underwriting decisions. If a carrier declines your application, cancels or non-renews coverage, or offers it only on other than standard terms, you are entitled to a written statement of the specific reasons for that decision and of the specific items of information supporting it, together with notice of the access and correction rights above. Ask us and we will obtain and provide it. A statement of reasons must identify the source of the information — and if the reason involves an insurance-support organisation or another person, you are entitled to be told which.
Where these rights and the CCPA rights overlap, you may use whichever route you prefer; we will not send you back and forth. Note that the Insurance Code rights are yours as an individual — they attach to information about a natural person, not to a corporation’s business records.
Financial privacy — GLBA and California Financial Code
As a licensed insurance producer we are a financial institution under the Gramm-Leach-Bliley Act, and this page also serves as our privacy notice for that purpose. The California Financial Information Privacy Act (Financial Code section 4050 and following) is stricter than federal law and we operate to it.
We disclose nonpublic personal financial information about you only to the carriers, wholesalers, surplus line brokers and service providers necessary to deliver the insurance transaction you asked us to perform, and where a law or a regulator requires it. Those are disclosures the statute permits without separate consent because they are how the thing you asked for actually gets done. We do not disclose your nonpublic personal financial information to any nonaffiliated third party for that party’s own marketing, and we do not sell it. We do not need your opt-in for anything, because we do not do the thing that would require one. If that ever changes, we will send you a separate notice and obtain your written consent before sharing.
We restrict access to your information to those in our firm who need it to serve you, and we maintain physical, electronic and procedural safeguards to protect it.
Calls, texts, and email
When you submit the form you are asking a licensed broker to review your account and respond, so we will contact you about that submission — by phone, text or email — using the details you gave us.
Separately, and only if you tick the optional telephone consent box next to the submit button, you give us express written consent to call and text you at the number you entered, including with an automatic telephone dialing system or an artificial or prerecorded voice. That box is optional. It is not pre-ticked. Nothing about your submission, your indication, or the markets we approach depends on whether you tick it. Message frequency varies, and message and data rates may apply.
- To stop texts — reply STOP to any message. Reply HELP for help.
- To revoke consent generally — tell us by any reasonable means: reply STOP, say so on a call, or email reviews@bollinsure.com. We honour a revocation within 10 business days at the outside, and usually the same day. Revoking for one channel revokes for all of them unless you tell us otherwise.
- Internal do-not-call list — we maintain one, we record your request on it when you make one, and it is available on request.
- Call recording — if a call is ever recorded, you will be told at the start of that call and may decline. California requires the consent of every party to record a call involving a cell or cordless phone, and we treat that as a hard rule.
Security
The site is served over HTTPS with HSTS, and every response carries X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Referrer-Policy: strict-origin-when-cross-origin and a Permissions-Policy that switches off camera, microphone and geolocation. Both submission endpoints rate-limit by IP address — more than 20 requests from one address in any 60-second window are refused — and discard any submission in which the hidden honeypot field has been filled. Signed applications are hashed so that any later alteration is detectable, and the audit certificate carrying those hashes, your IP address and your user-agent is appended to the signed PDF itself, so you receive the same proof of what you signed that we and the carriers hold. Access to submissions is limited to the licensed brokers and staff who work your account. No method of transmission or storage is perfectly secure, and we will not pretend otherwise; if a breach ever affects your information we will notify you as California law requires.
Children
This site is for employers buying commercial insurance. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a minor has given us information, email reviews@bollinsure.com and we will delete it.
If you are not in California
We are a California brokerage and this notice is written to California law, which is among the strictest in the country. If you live in another state with its own consumer privacy statute, contact us at the addresses above and we will handle your request under whichever framework gives you more — yours or California’s. This site is not directed to people outside the United States, and we do not offer services in the European Economic Area or the United Kingdom.
Changes to this page
We review this notice at least once every twelve months. If we change it, we update the date at the top of the page before the change takes effect, not after. Material changes to how we use information you already gave us get an email to the address on your submission — we will not rely on you noticing a new date.
Contact
Bollinsure Insurance Services (WJB Services, Inc.)
3625 E Thousand Oaks Blvd Ste 292, Westlake Village, CA 91362
562-COVWELL (562-268-9355) · reviews@bollinsure.com
CA DOI agency licence #0D94699
You can also complain to the California Department of Insurance at 1-800-927-4357 or the California Privacy Protection Agency. We would rather you called us first, but you do not have to.
Last updated August 1, 2026. This page is a privacy notice, not legal advice, and it does not create rights beyond those the law gives you. A preliminary indication is never a quote, binder, or guarantee of coverage, price, or eligibility. Read our Terms of Service as well.