DevilLeads
Homechevron_rightPrivacy Policy

Privacy Policy

Last Updated: August 6, 2026

policyDevilLeads Legal Compliance

1. Information Collection

DevilLeads operates Medicare lead generation campaigns on behalf of licensed insurance agencies, brokers, FMOs, and call centers ("Buyers"). We collect information that consumers voluntarily submit through our campaign landing pages, forms, and phone interactions, including name, contact details, state of residence, age or eligibility information, current coverage status, and plan interest.

Information is collected only after a consumer takes an affirmative action, such as submitting a form or verbally confirming interest during a qualification call, and is accompanied by clear disclosure of how that information will be used and who may contact the consumer as a result.

2. How Lead Data Is Used and Shared

The core service DevilLeads provides is connecting consenting consumers with licensed insurance Buyers who can discuss Medicare Advantage, Medicare Supplement, and Part D plans. When a consumer submits a form or opts in on a call, we disclose that their information will be shared with one or more licensed Buyers for the purpose of contacting them about Medicare plans, consistent with the exclusivity terms (exclusive or shared) of that specific campaign.

  • Exclusive leads are delivered to a single Buyer only and are not shared with any other Buyer or third party.
  • Shared leads are delivered to a limited, capped number of Buyers as disclosed at the point of consent.
  • We do not sell or share consumer information with parties outside the scope of the consumer's consent, and we do not use lead data for purposes unrelated to Medicare plan outreach without separate consent.

We also use aggregated, de-identified campaign data to improve targeting, compliance monitoring, and reporting for our Buyers.

3. Data Security

Security is foundational to our operations. We implement institutional-grade security measures to protect data against unauthorized access, alteration, disclosure, or destruction. Our security framework includes:

  • Encryption for data in transit and at rest using industry-standard protocols.
  • Strict role-based access controls (RBAC) ensuring lead data is only accessible to authorized personnel and the intended Buyer.
  • Continuous security monitoring, intrusion detection systems, and regular vulnerability assessments.
  • Physical security measures at all operational facilities, including access controls and monitoring.

4. TCPA & CMS Compliance

Consent to be contacted is captured in accordance with the Telephone Consumer Protection Act (TCPA), and campaign marketing language is designed to align with CMS Medicare Communications and Marketing Guidelines. Full detail on our consent practices is available on our TCPA & CMS Disclaimer page.

Compliance Note

Consumers may request to opt out of future contact or request removal from our marketing lists at any time using the contact information below.

5. Data Retention & Deletion

We retain lead and consent records for as long as necessary to fulfill delivery obligations to Buyers, support compliance audits, and meet applicable legal retention requirements. Consumers may request deletion of their information, subject to records we are required to retain for compliance purposes.

6. Cookies & Tracking Technologies

Our campaign landing pages use cookies, pixels, and similar tracking technologies to measure campaign performance, attribute form submissions to the correct traffic source, and prevent duplicate lead submissions. These technologies track browsing and campaign-attribution data; they are not used to infer or collect health information on their own. You can control cookies through your browser settings, though disabling them may affect how our landing pages function.

7. Your Privacy Rights

Depending on your state of residence, you may have rights under applicable state privacy laws, including the right to:

  • Know what personal information we have collected about you.
  • Request access to or a copy of that information.
  • Request correction of inaccurate information.
  • Request deletion of your information, subject to the retention obligations described in Section 5.
  • Opt out of the sale or sharing of your information, to the extent our data practices are covered by such laws.

To exercise any of these rights, contact us using the information in Section 11. We will not discriminate against you for exercising any privacy right.

8. Children's Privacy

Our services are directed at Medicare-eligible consumers and are not intended for use by anyone under the age of 18. We do not knowingly collect information from minors. If we learn that we have inadvertently collected information from a minor, we will delete it.

9. Third-Party Links

Our landing pages and marketing materials may reference or link to third-party websites, including insurance carrier or Buyer sites. This Privacy Policy applies only to information collected by DevilLeads; we are not responsible for the privacy practices of third-party sites.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be reflected by an updated "Last Updated" date at the top of this page. Continued use of our campaigns or services after changes are posted constitutes acceptance of the revised policy.

11. Contact Information

For questions or concerns regarding this Privacy Policy, to opt out of future contact, or to request your data, please contact our Data Protection Officer: