← OpenDesk

TurnNet Labs LLC · Privacy

Privacy Policy (OpenDesk)

Effective date: September 17, 2026 · Last updated: September 17, 2026

Draft for review. Not legal advice. Have a qualified attorney review before relying on it for compliance.

1. Who we are

TurnNet Labs LLC (“TurnNet,” “we,” “us”) provides OpenDesk, an agency desk SaaS product. Contact: turnnetprotocol@proton.me.

2. Data we process

Depending on how an agency uses OpenDesk, we may process:

  • Account data: agency name, owner/producer emails, passwords (hashed), MFA secrets, seat roles.
  • Client / applicant data the agency enters: name, contact, address, DOB, notes, household, vehicles/drivers, policy metadata. SSN may be stored by the agency in the desk; we do not use SSN for marketing.
  • Billing: Stripe customer/subscription identifiers; we do not store full card PAN.
  • Technical logs: IP-derived signals for abuse prevention, audit events for security actions.

3. How we use data

  • Provide and secure the OpenDesk service
  • Billing, support, and product communications
  • Optional features the agency enables (email, Medicare Partner, gift cards, cloud sync, rater bridges)

We do not sell personal information. We do not scrape carrier or rater websites.

4. Sharing

We share data with subprocessors needed to run the product (see Trust): Vercel, Supabase, Stripe, Resend, and optional HealthSherpa / Tremendous. When an agency configures Canopy or Zapier outbound, applicant allowlist fields are sent to those destinations under the agency’s control — never SSN or full card PAN via OpenDesk rater exports.

5. Retention & security

Data is retained while the agency account is active and as needed for billing/legal obligations. We use HTTPS, provider encryption at rest, hashed passwords, MFA (TOTP), and aim to notify agencies within 72 hours of a confirmed security incident affecting their Customer Data. Details: Trust & security.

6. Agency responsibility

Agencies are controllers of their client book. They must have a lawful basis to enter client data, manage seats, enable MFA, and configure outbound integrations.

7. Your requests

Contact turnnetprotocol@proton.me for access, correction, or deletion requests. Agency owners can also export or delete data from the desk where the product allows.

8. Related

Product Terms · Trust & security