Privacy Policy
On this page
At Expedition Insure, we value your trust and are committed to protecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website or use our travel insurance services.
Information We Collect
We collect information that you voluntarily provide to us when you request a quote, purchase a policy, or contact us. This may include:
- Personal Identity Information: Name, address, email address, phone number, and date of birth.
- Trip Details: Destination, travel dates, trip cost, and travel agency information.
- Payment Information: Credit card numbers and billing addresses (processed securely by our payment partners).
- Health Information: Pre-existing medical conditions if required for specific coverage waivers.
How We Use Your Information
We use the information we collect to:
- Generate accurate travel insurance quotes based on your specific needs.
- Process your insurance policy application with our carrier partners.
- Communicate with you regarding your policy, renewals, or claims.
- Improve our website functionality and customer service.
- Comply with legal and regulatory obligations.
Data Security
We implement industry-standard security measures to maintain the safety of your personal information. We use SSL encryption for sensitive data transmission and restrict access to your personal data to authorized personnel only.
Advertising measurement
With your separate advertising permission, we use OpenAI Ads to measure visits, completed quote requests and completed purchases, and match them to advertisements. Measurement can include the page address, browser details, OpenAI attribution cookies, your country, and a SHA-256 hash of your email address. For a purchase we also send the amount paid and which plan you bought. We do not send your raw email address, trip details, or payment information to OpenAI Ads.
Because a policy is usually bought days after the quote, we store OpenAI's two attribution identifiers on your quote so the purchase can be matched to the advertisement that led to it. We store only those two identifiers, and only when you have given advertising permission.
Advertising is off until you choose it. You can change this choice using Privacy choices in the footer. Refusing does not affect quotes or support. Withdrawal stops future browser measurement and prevents new quote requests from sending advertising events; it does not retract events already sent. To have the stored attribution identifiers on an existing quote deleted, contact us and we will remove them.
Data Returned to AI Assistants (MCP / ChatGPT App)
When AI assistants such as ChatGPT call our public MCP server (mcp.expedition.insure) or our REST API, the following fields may be returned in tool responses. These are the only categories of user-related data exposed through the AI surface; nothing else is forwarded.
- Trip context (user input): destination, departure date, trip duration in days, total trip cost in USD, currency, number of travelers, traveler ages, country of residence, US state (if applicable), tour operator name (optional), deposit-paid date (optional), email address (optional, for follow-up).
- Quote / estimation output: quote ID, quote number, plan name, carrier name, plan tier, estimated premium, premium per traveler, confidence level, medical limit, evacuation coverage, trip cancellation limit, deductible, recommended-plan flag, plan highlights, notes.
- Plan catalog: plan ID, plan name, carrier brand and short name, tier, evacuation coverage, medical limit, trip cancellation limit, deductible, eligibility (residence type, min/max age, max trip duration, max travelers), policy terms URL, plan highlights, base price, list of features.
- Destination catalog: destination name, slug, description, region.
- Coverage gap analysis: credit card name (if provided), card benefits compared, identified gaps and severity, recommendation.
- Checkout link: checkout URL, expiration timestamp, plan and quote summary, optional buyer email and guest names if you provided them.
- ACP purchase session: session ID, session status, line items, totals, buyer email and name (if you provided them), order ID and permalink upon completion.
- Server metadata: server version, environment, supported destinations, capability list, disclaimers (no user data).
The MCP server does not return account passwords, payment card details, government IDs, or stored conversation transcripts. Stripe payment data is collected directly by Stripe, not by our AI surface. Conversation transcripts with third-party AI platforms (e.g. ChatGPT) are governed by that platform's own privacy policy.
Contact Us
If you have questions or comments about this Privacy Policy, please contact us at: