What this host stores
- Sessions. A session record holds an email and an expiry. The record and the cookie are set to expire after 12 hours. That timer is in the code.
- A CSRF cookie lives in the browser for 1 hour. It is not a dossier.
- Contact notes. After a note is mailed, this host keeps a copy: name, email, phone, seat, and the note. That copy is set to expire after 30 days. The mailbox copy is outside that timer.
- If a send fails, a short error note is kept for 1 hour.
- An activation link is kept for 48 hours.
- Approved seats: name, email, role, agency name, a password hash, and whether the seat is active. These records have no expiry timer.
- Analytics outcomes: a kind, an agency name, a broker name, a broker email, a short label, who recorded it, and when. These records have no expiry timer. A person in charge can remove one. The label is refused if it looks like an email or a long number.
- Public pages load a Meta Pixel, id 3752929798220720, and send a PageView only. They do not send email or phone. This page does not load that pixel. The signed-in desk and analytics do not load it either. How long Facebook keeps a PageView is not set here.
A destruction schedule for seats and analytics outcomes is not automated yet. Plan Shop at form.s2olutions.com is a separate page. This host does not store that form.
The privacy page describes the request-access form on s2olutions.com: name, email, the product you want, and an optional note. That form is not an insurance application.