FastTrack ACA

Privacy Policy

Last updated September 8, 2026

The short version. This policy covers insurance agents and agencies who visit this site, apply, and buy a funnel from us. We collect what we need to decide whether we can serve you, to bill you, and to build and run your funnel. We never see your card number. We do not sell anything about you. And the consumers who come through your funnel are your contacts, not ours — we hold their information on your behalf and under your instructions.

Who we are

This site is operated by Volt Digital, LLC dba FastTrack ACA. We are a marketing agency. We do not sell insurance, we are not an insurance agency, and we are not affiliated with HealthCare.gov, the Centers for Medicare & Medicaid Services, HealthSherpa, Meta or any government agency.

Questions about anything here go to support@fasttrackaca.com.

Who this policy covers, and who it doesn't

It covers you — a licensed agent or agency, or someone at one — when you browse this site, ask us about the service, apply, pay, onboard, or sign in to your account.

It does not cover the consumers who use your funnel. Your funnel is published under your agency name and your National Producer Number, and it carries its own privacy policy naming you as the operator. You decide what happens to those people's information; we hold and process it for you. If you are a consumer who filled in an agent's quote form and you are reading this by accident, the policy you want is the one on that agent's own site.

What we collect about you

When you browse. Your IP address, browser and the pages you view, plus the Meta advertising pixel described below. We use a small number of cookies, listed further down.

When you ask about the service. If you complete the qualifying quiz on our landing page or book a call, we collect your name, email address, phone number and your answers, together with your consent to be contacted. That form is hosted by GoHighLevel and the calendar by Calendly.

When you apply. Your agency name, your name, email address, phone number, National Producer Number, the states you are licensed in, whether you hold current Marketplace certification, whether you already have a Facebook page and advertising account, and the market you want to advertise in. We also record which version of our services agreement you accepted, when, and the IP address you accepted it from — that record is the evidence of the agreement, so we keep it for as long as the agreement could matter.

When you pay. Payment is taken by Stripe. We never receive your card number — it goes from your browser to Stripe and we are given only an identifier for your customer record and your subscription, plus whether payments are succeeding.

When you set up your funnel. Your business mailing address, and optionally your legal entity name, EIN, time zone and preferred web address. Your logo and brand colors. Your Meta pixel identifier if you have one. And two credentials, handled differently from everything else:

  • Your HealthSherpa API key, if you give it to us. It is encrypted the moment it arrives, is never written to a log, and is deleted from our database once a live deployment has confirmed it works. After that it exists only inside your own funnel's environment.
  • Your CRM integration token, which reaches us only when we are building your funnel and is deleted the same way once installed.

When you sign in. Your email address, a single-use sign-in link that expires after 30 minutes, and a session cookie. We do not store a password because we do not ask for one.

When you contact us. Whatever you write, plus your account details so we know who is asking.

Your consumers' information

People who complete your funnel give it their household details, income estimate, contact details, consent records and — because the Marketplace application requires one — a Social Security number for each person seeking coverage. Those are your contacts. You are the agent of record and the controller of that information; we process it only to operate the funnel for you and under this agreement.

Social Security numbers are written only to your CRM. They are never stored in our own database, never sent to any third party other than the enrolment platform you have connected, and never written to a log. That restriction is enforced in code and covered by automated tests.

We do not sell your consumers' information, do not share it with another client, and do not resell your leads. If you leave, you may request a full export of your contact data; see how long we keep things, below.

How we use it

  • To decide whether we can lawfully and practically serve you.
  • To take payment and manage your subscription.
  • To build, deploy and run your funnel and your CRM sub-account.
  • To create and manage advertising campaigns on your behalf.
  • To send you service messages — your setup link, your funnel going live, something that needs your attention.
  • To answer you when you contact us.
  • To keep records we are required to keep, including your acceptance of our agreement.

We do not use your information to train advertising audiences, and we do not use one client's data to benefit another.

Who we share it with

We share what each of these needs to do its job, and nothing more. We do not sell your information to anyone, and none of these is permitted to use it for their own marketing.

  • Vercel — hosting for this site and your funnel.
  • Supabase — the database behind both.
  • Stripe — payments. Your card details go to Stripe directly and are governed by Stripe's own privacy policy.
  • Resend — the service that delivers our emails to you.
  • GoHighLevel — your CRM sub-account, and the form on our landing page.
  • Meta — advertising. See the section below.
  • HealthSherpa — plan pricing and enrolment, using the key issued to you.
  • Calendly — if you book a call with us.

We may also disclose information if the law requires it, or to establish or defend a legal claim. If our business is sold, customer records may transfer as part of it; a buyer would be bound by this policy or would have to give you notice before changing it.

Advertising and the Meta pixel

This site runs the Meta advertising pixel, which reports page views and a small number of events — that you enquired, that you booked a call — back to Meta so we can measure which of our own advertisements work. It sets Meta's cookies in your browser and Meta may use what it collects under its own policies.

Advertising we run for you is a separate matter: it runs on your own Meta advertising account, billed to your own payment method, and the pixel on your funnel is yours rather than ours.

Cookies

  • A session cookie once you sign in to your account, so you stay signed in. It is encrypted, readable only by us, and lasts 30 days.
  • Meta's advertising cookies, described above.

We do not use cookies to build a profile of you across other websites, beyond what the Meta pixel does.

How long we keep it

  • Applications that never became customers — kept so we can tell an enquiry from a duplicate, and so we can answer you if you come back.
  • Your account and business records — for as long as you are a customer, and afterwards for as long as we may need them for tax, accounting or a legal claim.
  • Your acceptance of our agreement — for as long as that agreement could be relevant, because it is the record of what you agreed to.
  • Credentials you give us — deleted as soon as they are installed, as described above.
  • Your consumers' information — held while you are a customer. After you cancel you may request an export; requests made within 30 days will be fulfilled, and after that we may delete it.

How we protect it

Everything travels over encrypted connections. Credentials you give us are encrypted at rest with a key held outside the database, so a copy of the database alone does not yield them. Access to production systems is limited to people who need it. Your sign-in links are single-use and short-lived.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your information we will tell you.

Your choices and rights

You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. Some of it we have to keep — a record of your agreement, and anything tax law requires — and we will tell you plainly which is which.

You can cancel at any time from your account, and you can stop receiving non-essential email from us at any time. We will still send you service messages about your own account while it is active.

Depending on where you live you may have additional rights under your state's privacy law. Write to support@fasttrackaca.com and we will handle your request.

Children

This is a service sold to licensed insurance professionals. It is not directed at children and we do not knowingly collect information from anyone under 18 through this site.

Changes to this policy

If we change it we will update the date at the top, and if the change is significant we will tell customers by email rather than relying on you to notice.

Contact us

Volt Digital, LLC dba FastTrack ACAsupport@fasttrackaca.com