Privacy Policy
Last Update: June 25, 2026
- Privacy Commitment
At Smart Tech Insurance (“STI”, “Smart Tech Insurance,” “Company,” “we,” “our,” or “us”), protecting the privacy, confidentiality, and security of the information entrusted to us is fundamental to how we conduct business.
We proudly serve a diverse customer base that includes individual consumers, parents and guardians, K–12 school districts, higher education institutions, government agencies, nonprofit organizations, and commercial businesses throughout the United States. Whether purchasing a single device through our Parent Purchase Program or partnering with us for enterprise technology solutions, our customers trust us to responsibly handle their information.
This Privacy Policy explains how Smart Tech collects, uses, stores, shares, protects, and retains information obtained through our websites, products, services, customer support, repair operations, warranty services, logistics, procurement activities, IT Asset Disposition (ITAD) services, Coverage Purchase Programs, and other business operations.
Our privacy program is designed to support compliance with applicable federal and state privacy laws and recognized industry best practices, including, where applicable:
- Federal Trade Commission Act (FTC Act)
- Children’s Online Privacy Protection Act (COPPA)
- Family Educational Rights and Privacy Act (FERPA)
- Children’s Internet Protection Act (CIPA) as it relates to services provided to educational institutions
- CAN-SPAM Act
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Texas Data Privacy and Security Act (TDPSA)
- Other applicable federal, state, and local privacy laws and regulations
While STI strives to maintain policies and procedures consistent with these legal frameworks, nothing in this Privacy Policy expands or modifies our legal obligations beyond those required by applicable law or contractual agreement.
Our commitment extends beyond legal compliance. We continuously evaluate our privacy and information security practices to safeguard the confidentiality, integrity, and availability of the information entrusted to us while maintaining transparency regarding how information is collected and used.
By accessing or using our website or services, you acknowledge that you have read and understand this Privacy Policy.
- Scope & Applicability
This Privacy Policy applies to information collected by STI through:
- Our public websites and affiliated domains
- Customer portals and support portals
- Online quote requests
- Contact forms
- Product purchases
- Parent Purchase Program transactions
- Device repair and warranty requests
- IT Asset Disposition (ITAD) and buyback services
- Customer support interactions
- Email communications
- Telephone communications
- Live chat and messaging services
- Marketing communications
- Events, webinars, and trade shows
- Employment applications
- Social media interactions where information is voluntarily provided
- Any other interaction in which STI collects information in connection with providing products or services
This Privacy Policy applies to information collected from:
- Individual consumers
- Parents and legal guardians
- Students, where information is provided by a parent, guardian, or educational institution
- Website visitors
- K–12 school districts
- Public, private, and charter schools
- Higher education institutions
- Government agencies
- Commercial businesses
- Nonprofit organizations
- Vendors
- Business partners
- Authorized representatives of organizations
This Privacy Policy does not apply to:
- Third-party websites linked from our website.
- Products or services offered solely by third parties.
- Information collected independently by manufacturers or software providers.
- Information processed exclusively on behalf of customers under separate contractual agreements where Smart Tech acts solely as a service provider.
If a separate written agreement governs the handling of information—including a Master Services Agreement (MSA), Data Processing Agreement (DPA), Student Data Privacy Agreement (SDPA), procurement contract, warranty agreement, or other contractual document—that agreement shall govern to the extent it conflicts with this Privacy Policy.
- Definitions
For purposes of this Privacy Policy, the following definitions apply:
“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual.
“Sensitive Personal Information” means information that receives enhanced protection under applicable privacy laws, including government-issued identifiers, financial account information, authentication credentials, precise geolocation data, and other categories designated by applicable law.
“Consumer” means an individual who purchases products or services directly from STI for personal, family, or household use, including purchases made through the Coverage Purchase Program.
“Customer Data” means information provided to or collected by STI in connection with providing products or services to customers.
“Student Data” means information relating to an identified or identifiable student that is provided by or on behalf of an educational institution or parent in connection with educational technology products or services.
“Educational Institution” means any public school district, charter school, private school, college, university, educational cooperative, or similar organization.
“Coverage Purchase Program” means STI’s direct-to-consumer or school purchasing program through which schools, parents or legal guardians may purchase technology products and related services directly from STI.
“Processing” means any operation performed on information, whether automated or manual, including collection, recording, organization, storage, use, analysis, disclosure, transmission, modification, deletion, or destruction.
“Service Provider” means a third party engaged by STI to perform services on our behalf under contractual obligations requiring appropriate confidentiality and security safeguards.
“Website” means STI‘s public websites, affiliated domains, customer portals, web applications, mobile experiences, and any online services owned or operated by STI.
- Privacy Principles
Smart Tech Insurance is committed to the following core privacy principles:
- We collect only the information reasonably necessary to provide our products and services.
- We use information only for legitimate business, operational, contractual, and legal purposes.
- We maintain administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction.
- We are transparent about our data collection and information handling practices.
- We respect applicable privacy rights and respond to lawful privacy requests in accordance with applicable law.
- We continuously review and improve our privacy and information security program to address evolving legal requirements, cybersecurity risks, and industry best practices.
These principles guide our privacy program and our ongoing commitment to earning and maintaining the trust of our customers, partners, employees, and website visitors.
- Information We Collect
STI collects information that is reasonably necessary to provide our products, services, customer support, and website functionality. The information we collect depends on how you interact with us, the products or services you request, and your relationship with STI.
We collect information directly from you, automatically through our websites and systems, and, where appropriate, from trusted third-party sources.
5.1 Information You Provide Directly
You may voluntarily provide information to STI when you:
- Purchase products or services
- Participate in the Parent Purchase Program
- Request a quote
- Submit a repair or warranty claim
- Contact Customer Support
- Create an online account
- Subscribe to marketing communications
- Register products
- Complete online forms
- Participate in surveys
- Apply for employment
- Communicate with us through email, chat, phone, or social media
Depending on the interaction, information you provide may include:
- First and last name
- Company or organization name
- Parent or guardian name
- School or school district
- Job title
- Email address
- Telephone number
- Billing address
- Shipping address
- Purchase history
- Warranty registration information
- Device information
- Repair requests
- Customer support communications
- Employment information (where applicable)
Providing personal information is voluntary; however, certain information may be required in order to process transactions, fulfill service requests, or provide customer support.
5.2 Consumer Information
When individual consumers, organizations, students or parents purchase products or services directly from STI, including purchases made through our Coverage Purchase Program, we may collect information necessary to:
- Process orders
- Ship products
- Register warranties
- Process repairs
- Verify ownership
- Provide technical support
- Process returns
- Respond to customer inquiries
Consumer information may include:
- Name
- Email address
- Telephone number
- Billing address
- Shipping address
- Product purchases
- Device serial numbers
- Warranty information
- Order history
- Customer service records
Payment card information is processed through secure third-party payment processors. Unless specifically disclosed, STI does not store complete payment card numbers on its systems.
5.3 Business, Government & Educational Customer Information
STI provides technology products and services to educational institutions, government agencies, nonprofit organizations, and commercial businesses.
To support these relationships, we may collect:
- Organization name
- Department
- Purchasing contacts
- Administrative contacts
- Information Technology contacts
- Procurement documentation
- Purchase orders
- Contract information
- Cooperative purchasing documentation
- Tax exemption certificates
- Asset inventory information
- Deployment information
- Shipping information
- Service history
- Warranty information
This information is used solely for legitimate business operations, contractual performance, procurement, customer support, logistics, and warranty administration.
5.4 Device Information
When devices are submitted for repair, diagnostics, refurbishment, warranty service, buyback, or IT Asset Disposition (ITAD), STI may collect technical information necessary to identify, evaluate, service, or process those devices.
Examples include:
- Manufacturer
- Product family
- Model number
- Serial number
- Service tag
- Asset tag
- Hardware configuration
- Warranty status
- Diagnostic information
- Repair history
- Installed replacement parts
- Device condition
- Photographs documenting physical condition
- Shipping and tracking information
STI collects only the information reasonably necessary to complete requested services.
5.5 Customer Device Data
Customers remain responsible for maintaining backups of their data before submitting devices for repair or service.
Unless specifically authorized by the customer or required to diagnose a reported issue, STI personnel do not intentionally access, review, copy, or disclose personal files stored on customer devices.
Customers are strongly encouraged to:
- Remove confidential information whenever practical
- Back up important files
- Remove personal accounts
- Disable device activation locks when appropriate
- Follow any pre-service instructions provided by Smart Tech
Additional information regarding customer data handling is available in our Data Security Policy.
5.6 Automatically Collected Information
When you visit our website, we automatically collect certain technical information, which may include:
- Internet Protocol (IP) address
- Browser type
- Browser version
- Device type
- Operating system
- Screen resolution
- Language settings
- Internet service provider
- Referring website
- Exit pages
- Pages viewed
- Time spent on pages
- Clickstream information
- Search queries
- Date and time of access
- General geographic location derived from IP address
This information is primarily used to:
- Improve website performance
- Diagnose technical issues
- Enhance website security
- Understand visitor behavior
- Measure website effectiveness
- Improve user experience
5.7 Cookies and Similar Technologies
STI uses cookies, pixels, web beacons, local storage, and similar technologies to improve website functionality and measure website performance.
These technologies help us:
- Remember user preferences
- Authenticate users
- Maintain secure sessions
- Analyze website traffic
- Improve website performance
- Prevent fraud
- Deliver personalized content
- Measure advertising effectiveness
Additional information is available in our Cookie Policy.
5.8 Communications
STI maintains records of customer communications for business, quality assurance, training, security, and legal purposes.
These records may include:
- Email correspondence
- Telephone communications
- Chat sessions
- Customer support tickets
- Repair notes
- Service records
- Survey responses
- Customer satisfaction feedback
Where permitted by law, telephone calls may be monitored or recorded for quality assurance, employee training, fraud prevention, and security purposes.
5.9 Marketing Information
If you voluntarily subscribe to STI communications or request information regarding our products or services, we may collect information relating to your communication preferences.
Examples include:
- Newsletter subscriptions
- Webinar registrations
- Event attendance
- Product interests
- Download history
- Marketing preferences
- Email engagement
You may opt out of marketing communications at any time by using the unsubscribe link contained in our emails or by contacting us directly.
5.10 Employment Information
Individuals applying for employment with STI may voluntarily provide information including:
- Resume
- Employment history
- Education
- Professional certifications
- References
- Contact information
- Other information voluntarily submitted during the hiring process
Employment-related information is used solely for recruiting, hiring, onboarding, and other lawful employment purposes.
5.11 Information Obtained from Third Parties
STI may receive limited information from trusted third-party sources, including:
- Manufacturers
- Authorized distributors
- Cooperative purchasing organizations
- Business partners
- Shipping providers
- Credit verification providers
- Government procurement portals
- Public business directories
We use such information only for legitimate business purposes consistent with this Privacy Policy.
5.12 Information We Do Not Intentionally Collect
Except where specifically required to provide requested services or comply with applicable law, STI does not intentionally request or collect:
- Social Security Numbers
- Driver’s license numbers
- Passport information
- Medical records
- Health information
- Biometric identifiers
- Payment card PINs
- Personal banking credentials
- Personal tax information
- Passwords to personal accounts
Customers should avoid storing unnecessary confidential information on devices submitted for repair or service whenever practical.
If STI inadvertently receives sensitive information not necessary to provide requested services, we will make reasonable efforts to protect such information, restrict access to authorized personnel, and securely delete or destroy it when no longer required.
- Sensitive Personal Information
STI recognizes that certain categories of information receive enhanced protection under applicable privacy laws.
We do not intentionally collect Sensitive Personal Information unless it is reasonably necessary to:
- Complete a customer transaction
- Verify identity where legally required
- Fulfill contractual obligations
- Process employment applications
- Comply with applicable laws or regulations
Where Sensitive Personal Information is collected, STI implements reasonable administrative, technical, and physical safeguards designed to protect such information from unauthorized access, disclosure, alteration, or misuse.
STI does not use Sensitive Personal Information to infer characteristics about individuals or for purposes unrelated to providing requested products or services.
Where required by applicable law, individuals may exercise rights regarding the collection, use, correction, or deletion of Sensitive Personal Information by contacting STI using the contact information provided in this Privacy Policy.
- How We Use Information
STI collects and processes information only for legitimate business purposes and only to the extent reasonably necessary to provide our products, services, and customer support. We do not use personal information for purposes that are incompatible with those described in this Privacy Policy unless required or permitted by applicable law.
Depending on your relationship with STI, we may use information for one or more of the following purposes.
7.1 Providing Products and Services
We use information to:
- Process orders and purchases
- Fulfill product shipments
- Coordinate logistics and deliveries
- Register warranties
- Process warranty claims
- Provide repair services
- Perform diagnostics
- Process IT Asset Disposition (ITAD) and buyback transactions
- Configure and deploy devices
- Maintain customer accounts
- Respond to customer inquiries
- Provide technical support
7.2 Customer Service and Support
Information may be used to:
- Respond to support requests
- Troubleshoot technical issues
- Verify customer identity
- Process returns and exchanges
- Schedule repairs
- Provide repair updates
- Respond to warranty inquiries
- Improve customer service quality
- Resolve disputes
- Document service history
Maintaining accurate service records allows STI to provide consistent, efficient customer support throughout the lifecycle of a product or service.
7.3 Coverage Purchase Program
For purchases made through the Coverage Purchase Program, we use information to:
- Process online orders
- Verify payment authorization
- Ship purchased products
- Register warranties
- Provide customer support
- Facilitate returns or exchanges
- Process repair requests
- Communicate order status
- Prevent fraudulent transactions
Information collected through the Coverage Purchase Program is used solely to administer purchases and provide related customer support unless you separately consent to receive marketing communications.
7.4 Business Operations
We use information to support our daily business operations, including:
- Contract administration
- Procurement
- Inventory management
- Asset tracking
- Quality assurance
- Financial reporting
- Accounting
- Auditing
- Internal reporting
- Business planning
- Risk management
7.5 Website Operations
Information collected through our website helps us:
- Operate our website
- Improve website functionality
- Optimize website performance
- Troubleshoot technical issues
- Monitor website security
- Analyze website traffic
- Improve navigation
- Enhance user experience
- Develop new website features
7.6 Communications
We may use information to communicate with you regarding:
- Orders
- Quotes
- Repairs
- Warranty claims
- Shipping updates
- Technical support
- Service notifications
- Product recalls
- Contract renewals
- Customer satisfaction surveys
- Requested information
These communications are generally considered transactional or service-related and may be sent regardless of marketing preferences where permitted by law.
7.7 Marketing
With your consent where required, or as otherwise permitted by law, STI may use information to:
- Send newsletters
- Announce new products
- Share service updates
- Promote special offers
- Invite customers to webinars or events
- Share educational resources
- Inform customers of new technology solutions
You may opt out of marketing communications at any time by selecting the “unsubscribe” link included in marketing emails or by contacting STI directly.
Opting out of marketing communications will not affect essential transactional communications relating to your purchases or services.
7.8 Security and Fraud Prevention
Protecting our customers, employees, and systems is a critical business function.
We may use information to:
- Detect fraudulent activity
- Prevent unauthorized transactions
- Investigate suspicious activity
- Authenticate users
- Protect customer accounts
- Monitor cybersecurity threats
- Prevent abuse of our services
- Enforce our Terms of Use
- Protect the rights, property, and safety of Smart Tech and our customers
7.9 Legal and Regulatory Compliance
We may process information as necessary to:
- Comply with applicable laws
- Respond to lawful governmental requests
- Satisfy tax obligations
- Maintain business records
- Comply with court orders
- Respond to subpoenas
- Enforce contractual rights
- Resolve legal disputes
- Protect against legal claims
7.10 Research and Improvement
Information may be analyzed in aggregate or de-identified form to:
- Improve customer service
- Evaluate product performance
- Improve repair processes
- Measure operational efficiency
- Develop new products and services
- Improve website usability
- Improve cybersecurity practices
Where reasonably possible, STI uses aggregated or de-identified information that cannot reasonably identify an individual.
7.11 Artificial Intelligence and Automation
STI may use automated tools, including artificial intelligence (“AI”) technologies, to support internal business operations such as customer service, website improvements, document processing, analytics, fraud detection, and operational efficiency.
Where AI-assisted technologies are used, STI maintains human oversight over material business decisions and does not use automated processing as the sole basis for decisions that produce legal or similarly significant effects on individuals unless permitted by applicable law.
Any AI technologies used by STI are intended to assist—not replace—human judgment and are subject to our internal privacy, security, and governance practices.
- Legal Bases for Processing and Lawful Disclosure
Depending on the nature of our relationship with you and applicable law, STI processes information under one or more of the following legal bases:
Contract Performance
Processing necessary to fulfill contracts, purchase orders, warranty obligations, repair services, or other requested products and services.
Examples include:
- Processing purchases
- Completing repairs
- Shipping products
- Providing customer support
- Managing warranties
Legitimate Business Interests
Processing necessary for STI’s legitimate business interests, provided those interests are not overridden by applicable privacy rights.
Examples include:
- Improving services
- Preventing fraud
- Maintaining cybersecurity
- Internal reporting
- Quality assurance
- Website analytics
- Business planning
Legal Obligations
Processing necessary to comply with:
- Applicable federal laws
- State laws
- Court orders
- Regulatory requirements
- Tax obligations
- Government investigations
- Law enforcement requests
Consent
Where required by applicable law, STI relies on your consent for activities such as:
- Marketing communications
- Optional cookies
- Certain promotional activities
- Other situations where consent is legally required
You may withdraw consent at any time where applicable. Withdrawal of consent does not affect processing that occurred before consent was withdrawn.
Protection of Rights and Safety
STI may process information when reasonably necessary to:
- Protect customers
- Protect employees
- Protect business operations
- Protect property
- Investigate fraud
- Detect cybersecurity threats
- Enforce legal rights
- Prevent unlawful activity
8.1 No Sale of Personal Information
STI does not sell personal information as that term is generally defined under applicable U.S. privacy laws.
We do not exchange customer information for monetary compensation.
We also do not knowingly sell or share the personal information of minors under the age of 16.
8.2 No Targeted Advertising Based on Student Information
STI does not use student information obtained through educational services to build advertising profiles, engage in targeted advertising, or sell student information to third parties.
Where STI provides services to educational institutions, student information is processed only as necessary to provide contracted services and in accordance with applicable agreements and laws.
8.3 Data Minimization
STI follows the principle of data minimization.
We strive to collect, use, retain, and disclose only the information reasonably necessary to:
- Provide requested services
- Fulfill contractual obligations
- Maintain business operations
- Comply with applicable law
We periodically review our information collection and retention practices to help ensure that unnecessary information is not retained longer than required.
8.4 Purpose Limitation
STI uses information only for the purposes described in this Privacy Policy or for other compatible purposes permitted by applicable law.
Should STI determine that information needs to be used for a materially different purpose, we will provide notice or obtain consent where required by law before proceeding.
- Information Sharing and Disclosure
STI values the trust our customers place in us and limits the sharing of information to circumstances necessary to operate our business, fulfill contractual obligations, provide requested products and services, comply with applicable laws, or protect the rights and safety of our customers and Company.
Except as described in this Privacy Policy, STI does not sell, rent, or lease personal information to third parties for their independent marketing purposes.
9.1 Service Providers
STI may share information with carefully selected third-party service providers that perform services on our behalf.
These providers may include:
- Payment processing providers
- Shipping and logistics companies
- Cloud hosting providers
- Customer relationship management (CRM) platforms
- Help desk and customer support providers
- Email and communication providers
- Website hosting providers
- Data backup providers
- Cybersecurity service providers
- Website analytics providers
- Marketing service providers
- Equipment manufacturers for warranty administration
These service providers receive only the information reasonably necessary to perform the services requested and are contractually required to maintain appropriate confidentiality and security safeguards.
9.2 Manufacturers and Warranty Partners
When necessary to process warranty claims, verify warranty eligibility, or obtain manufacturer-authorized repair services, STI may share limited information with equipment manufacturers or authorized warranty providers.
Information shared may include:
- Customer name
- Organization name
- Device serial number
- Model information
- Warranty status
- Repair documentation
- Service history
- Shipping information
Information is shared solely for warranty administration and related service purposes.
9.3 Business Partners
STI may work with authorized partners, subcontractors, consultants, distributors, cooperative purchasing organizations, and technology providers to deliver products and services.
Information shared with these partners is limited to what is reasonably necessary to fulfill contractual obligations or complete requested services.
9.4 Educational Institutions
When STI provides services under contract with an educational institution, STI processes information only as directed by the institution and in accordance with applicable agreements and laws.
STI does not use student information obtained through educational services for advertising, profiling, or unrelated commercial purposes.
Ownership of student records remains with the educational institution or the individual otherwise entitled to such information under applicable law.
9.5 Parent Purchase Program
For purchases made directly through the Coverage Purchase Program, STI may share limited information with third parties necessary to complete customer transactions, including:
- Payment processors
- Shipping carriers
- Warranty providers
- Customer support providers
- Fraud prevention services
Information shared is limited to what is reasonably necessary to process orders, deliver products, administer warranties, and provide customer support.
9.6 Corporate Transactions
If STI is involved in a merger, acquisition, financing, asset sale, restructuring, reorganization, bankruptcy, or similar corporate transaction, customer information may be transferred as part of that transaction, subject to applicable confidentiality obligations and legal requirements.
Should such a transaction occur, STI will make reasonable efforts to provide notice where required by applicable law.
9.7 Legal Requirements
STI may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable laws or regulations
- Respond to subpoenas or court orders
- Cooperate with law enforcement
- Respond to lawful governmental requests
- Protect against fraud
- Investigate suspected illegal activity
- Protect the rights, property, or safety of Smart Tech, our customers, employees, or the public
- Enforce our contractual agreements or Terms of Use
We review requests for information and disclose only the information reasonably necessary to satisfy applicable legal obligations.
9.8 Professional Advisors
STI may disclose information to our professional advisors, including:
- Attorneys
- Accountants
- Auditors
- Insurance providers
- Financial advisors
Such disclosures are limited to legitimate business purposes and are subject to appropriate confidentiality obligations.
9.9 Aggregated and De-Identified Information
STI may create aggregated, anonymized, or de-identified information that cannot reasonably be used to identify an individual.
This information may be used to:
- Analyze trends
- Improve products and services
- Measure website performance
- Evaluate operational efficiency
- Conduct internal research
- Develop new service offerings
Aggregated and de-identified information may be shared with business partners, manufacturers, or other third parties for legitimate business purposes.
9.10 Information We Do Not Share
Unless required by law or specifically authorized by you, STI does not:
- Sell personal information for monetary compensation.
- Rent customer information to third parties.
- Share customer lists with unrelated organizations.
- Share payment card information except as necessary to process transactions.
- Share student information for advertising purposes.
- Use customer information to build advertising profiles.
- Provide customer information to data brokers.
- Data Retention
STI retains information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, satisfy contractual obligations, comply with applicable legal requirements, resolve disputes, enforce agreements, and support legitimate business operations.
Retention periods vary depending on the nature of the information and the purpose for which it was collected.
Examples include:
| Information Type | Typical Retention Purpose |
| Customer account information | Customer relationship management |
| Order history | Accounting, warranty, and support |
| Repair records | Warranty administration and service history |
| Shipping records | Logistics and accounting |
| Customer communications | Customer support and dispute resolution |
| Employment applications | Hiring and legal compliance |
| Website analytics | Performance analysis and security |
| Financial records | Tax and accounting requirements |
When information is no longer required, STI securely deletes, destroys, anonymizes, or de-identifies the information using commercially reasonable administrative and technical safeguards appropriate to the sensitivity of the information.
Where devices are processed through STI‘s IT Asset Disposition (ITAD) services, data sanitization and destruction procedures are performed in accordance with our internal security standards and applicable customer agreements.
Certain information may be retained longer where required by law, contractual obligations, litigation holds, government investigations, insurance requirements, or other legitimate legal purposes.
- Information Security and Data Protection
STI recognizes that protecting customer information is fundamental to maintaining the trust of our customers, partners, educational institutions, government agencies, and the individuals we serve.
We maintain a comprehensive information security program designed to protect the confidentiality, integrity, and availability of information throughout its lifecycle. Our security program incorporates administrative, technical, and physical safeguards that are appropriate to the nature of our business, the sensitivity of the information we process, and applicable legal and contractual requirements.
Information security is an ongoing process. STI regularly evaluates and improves its security practices to address evolving cybersecurity threats, emerging technologies, regulatory requirements, and industry best practices.
11.1 Security Program
Our information security program is designed to:
- Protect customer information from unauthorized access, disclosure, alteration, or destruction.
- Reduce cybersecurity risks.
- Protect Smart Tech systems and infrastructure.
- Support business continuity.
- Meet applicable contractual and legal obligations.
- Promote responsible information governance.
Security measures are periodically reviewed and updated based on operational needs, risk assessments, technological developments, and changes in applicable laws.
11.2 Administrative Safeguards
STI maintains administrative controls designed to promote responsible information handling throughout the organization.
These safeguards may include:
- Information security policies and procedures
- Employee confidentiality obligations
- Role-based access management
- Acceptable Use Policies
- Employee cybersecurity awareness training
- Privacy awareness training
- Vendor management procedures
- Risk assessments
- Change management practices
- Incident response planning
- Business continuity planning
- Secure information disposal procedures
Access to customer information is limited to authorized personnel with a legitimate business need.
11.3 Technical Safeguards
STI employs commercially reasonable technical safeguards designed to protect information and technology systems.
Depending on operational requirements, these safeguards may include:
- Multi-factor authentication (MFA)
- Role-based access controls
- Password management requirements
- Encryption of sensitive information during transmission using industry-standard protocols
- Firewalls
- Endpoint protection
- Anti-malware technologies
- Email security protections
- Security monitoring
- System logging
- Vulnerability management
- Network segmentation where appropriate
- Secure remote access controls
- Backup and recovery systems
Security technologies are periodically reviewed and updated to address emerging threats.
11.4 Physical Security
STI maintains physical safeguards designed to protect facilities, equipment, inventory, and customer information.
Physical protections may include:
- Controlled facility access
- Visitor management procedures
- Secure storage areas
- Video surveillance where appropriate
- Equipment inventory controls
- Shipping and receiving controls
- Environmental protections for critical equipment
- Secure disposal of documents and media
Access to restricted areas is limited to authorized personnel.
11.5 Access Control
STI follows the principle of least privilege.
Access to systems, applications, and customer information is granted only to personnel whose job responsibilities require such access.
Access permissions are reviewed periodically and modified or revoked when no longer required.
Authentication mechanisms are designed to reduce unauthorized access while supporting efficient business operations.
11.6 Device Repair and Customer Data
STI understands that devices submitted for repair may contain personal, confidential, proprietary, or educational information.
Unless necessary to diagnose a reported issue or specifically authorized by the customer, STI personnel do not intentionally access, review, copy, or disclose customer files stored on submitted devices.
Customers remain responsible for:
- Backing up important data
- Removing confidential information where practical
- Removing personal accounts where appropriate
- Disabling activation locks when instructed
- Following pre-service preparation instructions
While STI exercises reasonable care when servicing customer equipment, we cannot guarantee preservation of data during hardware repairs, software reinstallation, firmware updates, diagnostics, or replacement of storage components.
11.7 IT Asset Disposition (ITAD)
For customers utilizing STI‘s IT Asset Disposition (ITAD) services, information security remains a critical component of our processing procedures.
Where applicable and requested by contract, STI performs data sanitization using recognized industry methods designed to render customer information inaccessible prior to device resale, recycling, or disposal.
Data sanitization procedures may include:
- Secure data erasure
- Cryptographic erase (where supported)
- Physical destruction of storage media when required
- Verification procedures
- Chain-of-custody documentation where applicable
Specific sanitization methods may vary based on customer requirements, media type, contractual obligations, and applicable regulations.
11.8 Third-Party Service Providers
STI carefully evaluates third-party service providers that process information on our behalf.
When appropriate, STI seeks to work with providers that maintain reasonable administrative, technical, and physical safeguards designed to protect customer information.
Service providers are expected to use customer information only for authorized business purposes and in accordance with applicable contractual obligations.
11.9 Incident Response
Despite reasonable safeguards, no organization can eliminate all cybersecurity risk.
STI maintains procedures designed to:
- Detect security incidents
- Investigate suspected unauthorized activity
- Contain potential threats
- Restore affected systems
- Mitigate future risk
- Comply with applicable notification requirements
If STI determines that a security incident involving personal information requires notification under applicable law or contractual obligations, affected individuals or organizations will be notified as required.
11.10 Business Continuity
STI maintains business continuity and operational recovery procedures designed to support continued operations during unexpected events.
These procedures may include:
- Secure data backups
- Disaster recovery planning
- Infrastructure redundancy where appropriate
- Recovery testing
- Emergency communication procedures
Business continuity planning is periodically reviewed and updated.
11.11 Customer Responsibilities
Information security is a shared responsibility.
Customers can help protect their information by:
- Using strong passwords
- Enabling multi-factor authentication where available
- Maintaining current antivirus software
- Installing security updates promptly
- Backing up important data regularly
- Protecting account credentials
- Following Smart Tech’s device preparation instructions before submitting equipment for service
STI encourages customers to report suspected security incidents promptly.
11.12 Security Limitations
Although STI employs commercially reasonable safeguards designed to protect information, no method of transmitting information over the Internet, storing electronic information, or securing physical systems can be guaranteed to be completely secure.
Accordingly, STI cannot guarantee absolute security.
Customers acknowledge that the transmission of information over the Internet and the use of electronic systems involve inherent risks beyond the control of any organization.
STI continually evaluates and enhances its information security program in an effort to reduce those risks while maintaining operational effectiveness.
- Your Privacy Rights
STI is committed to respecting the privacy rights of our customers and website visitors. Depending on your state of residence and applicable law, you may have certain rights regarding the personal information we collect about you.
These rights may vary based on applicable legal requirements and the nature of your relationship with Smart Tech.
Nothing in this section limits any rights provided under applicable law.
12.1 Right to Know
You may have the right to request information regarding the personal information Smart Tech has collected about you.
Where required by applicable law, you may request:
- Categories of personal information collected
- Sources from which information was collected
- Business purposes for collecting information
- Categories of third parties with whom information has been shared
- Categories of personal information disclosed
- Categories of information retained
- Information regarding your applicable privacy rights
12.2 Right to Access
Subject to applicable law, you may request access to personal information maintained by STI.
Where appropriate, we may provide:
- A copy of your personal information
- Information regarding how your information has been used
- Information regarding disclosures made to third parties
- Information regarding retention practices
Requests may be subject to identity verification and applicable legal exceptions.
12.3 Right to Correct
If you believe personal information maintained by STI is inaccurate or incomplete, you may request that we correct or update the information.
We may request documentation reasonably necessary to verify the requested correction.
12.4 Right to Delete
Subject to applicable law and certain legal exceptions, you may request deletion of personal information maintained by STI.
Deletion requests may be denied when retention is necessary to:
- Complete transactions
- Provide requested services
- Honor warranties
- Fulfill contractual obligations
- Maintain accounting records
- Comply with tax obligations
- Detect fraud
- Exercise legal claims
- Protect the security of our systems
- Comply with applicable law
Where deletion is approved, STI will take commercially reasonable steps to securely delete or de-identify applicable information.
12.5 Right to Data Portability
Where required by applicable law, you may request a portable copy of certain personal information that you previously provided to STI.
Where technically feasible, information may be provided in a commonly used electronic format.
12.6 Right to Opt Out
Depending upon applicable law, you may have the right to opt out of certain activities, including:
- Marketing communications
- Targeted advertising
- Certain profiling activities
- Sale or sharing of personal information where applicable
STI does not sell personal information for monetary compensation.
Marketing communications may be discontinued at any time by selecting the unsubscribe link contained within our emails or by contacting Smart Tech directly.
12.7 Right to Non-Discrimination
STI will not discriminate against individuals for exercising applicable privacy rights.
Unless permitted by law, exercising your privacy rights will not result in:
- Denial of services
- Different pricing
- Reduced service quality
- Different levels of customer support
However, certain services may require the use of personal information in order to function properly.
12.8 Identity Verification
Before responding to certain privacy requests, STI may require reasonable verification of your identity.
Verification procedures help protect customer information from unauthorized disclosure.
Verification methods may include:
- Confirming account information
- Confirming recent transactions
- Email verification
- Telephone verification
- Additional documentation where appropriate
If STI cannot reasonably verify your identity, we may decline to fulfill the request to protect customer privacy.
12.9 Authorized Agents
Where permitted by applicable law, you may designate an authorized agent to submit privacy requests on your behalf.
STI may require:
- Written authorization
- Proof of agency
- Identity verification
- Additional documentation reasonably necessary to protect customer information
12.10 Response Time
STI will acknowledge and respond to verified privacy requests within the timeframes required by applicable law.
Where permitted, response periods may be extended when requests are unusually complex or numerous.
If additional time is required, STI will notify the requesting individual as required by applicable law.
12.11 Exercising Your Rights
Privacy requests may be submitted by:
Email: info@smarttechins.com
Mail:
Privacy Officer
Smart Tech Insurance
255 Primera Blvd Ste 160 Lake Mary, FL 32746
Website:
Telephone:
(877) 307-6777
STI may request additional information necessary to verify your identity before processing your request.
- U.S. State Privacy Notices
Residents of certain states may have additional privacy rights under applicable state privacy laws.
Where applicable, STI honors privacy rights provided under laws including, but not limited to:
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Utah Consumer Privacy Act (UCPA)
- Texas Data Privacy and Security Act (TDPSA)
- Oregon Consumer Privacy Act (OCPA)
- Delaware Personal Data Privacy Act (DPDPA)
- Iowa Consumer Data Protection Act (ICDPA)
- Montana Consumer Data Privacy Act (MTCDPA)
- Nebraska Data Privacy Act (NDPA)
- New Hampshire Privacy Law
- New Jersey Data Privacy Act
- Any subsequently enacted state privacy legislation applicable to Smart Tech
13.1 California Residents
California residents may have additional rights, including the right to:
- Know what personal information has been collected
- Request deletion of personal information
- Correct inaccurate personal information
- Obtain a copy of personal information
- Limit the use of Sensitive Personal Information where applicable
- Opt out of the sale or sharing of personal information, if applicable
STI does not sell personal information for monetary compensation.
13.2 Do Not Track Signals
Some web browsers offer a “Do Not Track” (“DNT”) preference.
Because there is currently no universally accepted standard governing DNT signals, STI does not currently respond differently to browser-based Do Not Track requests.
Users may control cookies and certain tracking technologies through browser settings and our Cookie Policy.
13.3 Shine the Light (California Civil Code §1798.83)
California residents may request certain information regarding disclosure of personal information to third parties for direct marketing purposes.
STI does not disclose personal information to third parties for their independent direct marketing purposes.
13.4 Appeal Rights
Where applicable state law provides a right to appeal a denied privacy request, Smart Tech will provide information regarding the appeal process in its response.
Appeals will be reviewed by personnel not involved in the original determination whenever reasonably practicable.
- Educational Privacy and Student Information
STI provides technology products and services to educational institutions throughout the United States, including K–12 school districts, charter schools, private schools, higher education institutions, and educational cooperatives.
We recognize the unique privacy obligations associated with educational environments and are committed to handling student-related information responsibly.
14.1 Student Information
STI does not intentionally collect student personal information unless necessary to provide contracted products or services or where information is voluntarily provided by a parent or legal guardian through a direct consumer transaction, such as the Parent Purchase Program.
Where STI processes student information on behalf of an educational institution, we do so only as directed by the institution and in accordance with applicable contractual obligations and laws.
14.2 FERPA
Where applicable, STI supports educational institutions in meeting their obligations under the Family Educational Rights and Privacy Act (FERPA).
STI does not claim ownership of educational records and processes student information solely for the purposes authorized by the educational institution or applicable agreement.
14.3 COPPA
STI does not knowingly collect personal information directly from children under the age of 13 through its public website.
Where products or services involve children under 13, Smart Tech relies upon schools or parents, as applicable, to obtain any legally required authorizations under the Children’s Online Privacy Protection Act (COPPA).
14.4 CIPA
STI recognizes that many of our educational customers are subject to the Children’s Internet Protection Act (CIPA).
Although CIPA applies primarily to schools and libraries, STI designs its products and services to support customers’ efforts to maintain secure technology environments consistent with their legal and policy obligations.
14.5 Parent Purchase Program
The Coverage Purchase Program is a direct-to-consumer purchasing program operated by STI.
Purchases made through this program establish a direct relationship between STI and the purchasing parent or legal guardian.
Information collected through the Coverage Purchase Program is used to:
- Process orders
- Deliver products
- Register warranties
- Provide technical support
- Process repairs
- Respond to customer inquiries
Except where otherwise authorized, participation in the Coverage Purchase Program does not provide Smart Tech access to educational records maintained by a student’s school.
14.6 Data Ownership
Except as otherwise provided by law or contract:
- Parents retain ownership of information they provide directly to STI.
- Educational institutions retain ownership of student information provided under educational service agreements.
- STI does not acquire ownership rights in customer or student information solely by providing products or services.
14.7 Student Data Privacy Statement
Additional information regarding STI‘s handling of student information is available in our separate Student Data Privacy Statement, which should be read together with this Privacy Policy.
- International Visitors
STI is headquartered in the United States and primarily provides products and services to customers located within the United States.
If you access our website or provide information to STI from outside the United States, you understand that your information may be transferred to, stored, and processed within the United States or other jurisdictions in which our authorized service providers operate.
By using our website or submitting information to STI, you acknowledge that your information may be subject to the laws of the United States, which may differ from the laws of your country of residence.
Where applicable, STI will take commercially reasonable measures to protect personal information transferred across jurisdictions in accordance with applicable legal requirements.
- Cookies and Tracking Technologies
STI uses cookies and similar technologies to improve the functionality, performance, and security of our website.
Cookies are small text files stored on your device that help websites recognize returning visitors, remember preferences, and improve the user experience.
Depending on how you interact with our website, we may use:
Essential Cookies
Essential cookies enable core website functionality such as page navigation, account authentication, security, and access to protected areas of the website.
These cookies are necessary for the website to function properly.
Functional Cookies
Functional cookies allow the website to remember user preferences, language selections, and other customized settings to enhance your browsing experience.
Performance and Analytics Cookies
Performance cookies help us understand how visitors interact with our website by collecting information such as:
- Pages visited
- Time spent on pages
- Navigation paths
- Error messages
- Website performance metrics
This information is generally aggregated and used to improve website functionality and user experience.
Marketing Cookies
Where permitted by applicable law, STI or authorized third-party providers may use marketing cookies to measure the effectiveness of advertising campaigns, understand customer interests, and improve marketing communications.
Marketing cookies may be disabled through your browser settings or our cookie consent tools where available.
Managing Cookies
Most web browsers allow users to:
- View stored cookies
- Delete cookies
- Block cookies
- Configure cookie preferences
- Receive notifications when cookies are placed
Disabling certain cookies may affect the functionality of portions of the Smart Tech website.
Additional information regarding our use of cookies is available in our separate Cookie Policy, which forms part of this Privacy Policy.
- Third-Party Websites and Services
Our website may contain links to websites, applications, products, or services operated by third parties.
These third-party websites are provided for your convenience and informational purposes only.
Smart Tech does not control the privacy practices, security measures, or content of third-party websites and is not responsible for their policies or practices.
We encourage visitors to review the privacy policies of any third-party website before providing personal information.
The inclusion of a third-party link does not constitute an endorsement, recommendation, or guarantee by STI unless expressly stated.
- Children’s Privacy
STI‘s public website is intended for adults, including consumers, parents, educators, school administrators, government representatives, business professionals, and other authorized users.
We do not knowingly solicit or collect personal information directly from children under the age of 13 through our public website.
Where STI provides products or services used in educational settings, we process student information only as authorized by educational institutions, parents, or applicable law.
If STI becomes aware that personal information has been collected directly from a child under the age of 13 without appropriate authorization, we will take reasonable steps to delete such information in accordance with applicable law.
Parents or legal guardians who believe a child has provided personal information directly to STI may contact us using the information provided below.
- Changes to This Privacy Policy
Technology, privacy laws, cybersecurity practices, and business operations continue to evolve.
Accordingly, STI may update this Privacy Policy from time to time to reflect changes in our products, services, legal obligations, operational practices, or information handling procedures.
When material changes are made, STI will revise the “Last Updated” date appearing at the beginning of this Privacy Policy.
Where required by applicable law, additional notice may be provided through our website or by other appropriate means.
Your continued use of the STI website or services following the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Privacy Policy to the extent permitted by applicable law.
- Contact Information
Privacy requests submitted under applicable law should include sufficient information to enable STI to verify the identity of the requesting individual and process the request efficiently.
- Policy Administration
This Privacy Policy is maintained by STI and is reviewed periodically to ensure continued alignment with applicable legal requirements, business operations, and industry best practices.
The most current version of this Privacy Policy will always be available on the STI website.
Previous versions may be retained internally for recordkeeping, legal compliance, and auditing purposes.
- Questions or Concerns
STI values transparency and encourages customers, website visitors, educational institutions, parents, business partners, and government agencies to contact us with any questions regarding our privacy practices.
We are committed to responding to inquiries in a timely, respectful, and professional manner and to working in good faith to address privacy-related concerns.