IPSON INVESTMENTS

Privacy notice

What we collect, and what we do with it.

Written to describe what this site actually does — in plain language, page by page.

Last updated 3 September 2026 · Hipson Investments LLC, 2000 S Dairy Ashford, Ste 360, Houston, TX 77077

This notice covers hipsoninvestments.com and the tools on it. It is written to describe what the site actually does, in plain language. If anything here does not match your experience, tell us and we will fix the notice or the site.

What we collect, page by page

The plan-review form (/flyer). If you complete it we store what you enter: your name, company, work email, phone number if you give one, and your four answers about employee count, plan funding, renewal timing and what you need help with. We also record which link brought you and your browser's user-agent string. This is stored in a Google Firestore database that only Hipson staff can read.

The plan review form on the home page (and the same form on /contact). Three questions. If you finish it we store what you enter: the topic you picked, your name, work email, company if you give one, and your note. Your contact details are saved at step two rather than at the end, so that if something interrupts you an advisor can still reply — the note joins them when you press send. It goes into the same Google Firestore database as the forms below, readable only by Hipson staff. Enquiries about the 401(k) and retirement side are securities business and reach Michael at his Ameritas mailbox; everything else reaches the general office mailbox. Corrected 3 September 2026: this page did not previously describe this form at all, and the form's own fine print said nothing was stored. Both were wrong, and both were fixed in the same change.

The individual health call-back (/health). Four tap-only questions, then a request for a call. If you send it we store your name, phone number, the best time to call, and your four answers, so a licensed advisor can call you back knowing your situation. No email address is asked for and none is stored. Corrected 3 September 2026: this form previously tried to open an email in your own mail app and stored nothing — which meant it usually did nothing at all. It now saves the request properly, and this notice says so.

The ACA review (/aca-review). This one does collect and store. Before the questions begin we ask for your name, company, work email and phone number, and we keep them along with your seven answers so we can send your results and follow up once. It is stored in the same Google Firestore database as the plan-review form, readable only by Hipson staff. If our system is unreachable when you finish, nothing is stored at all — the page instead opens an email in your own mail app, and you can see exactly what is being sent before you send it.

The ACA chat assistant. Several pages carry a voice-and-text assistant that answers general ACA questions. It is an AI, clearly labeled as one, and it is built not to ask for personal information — if you want a human, it gives you the office number. Conversations with it are processed and may be recorded by ElevenLabs, the service that runs it, under their own terms shown in the widget. Don’t put personal or company financial details into the chat; the review is the right place for those.

The ABA coverage review (/quote) — read this one carefully, because it is the only form on this site that asks about a child's health. If you use it, we store: your name and contact details; your ZIP code, household size and an income band; the names of the ABA clinic, doctors and prescriptions you want us to check; your child's age and the age at which their autism diagnosis was made; and the therapy hours that were prescribed or recommended. We ask you to tick a box agreeing to this before anything clinical is saved, because health information about a child should never be collected on implied consent. Your contact details are saved as soon as you finish the first step, so that if the form is interrupted an advisor can still call you — the rest is saved only when you press send. It goes into the same Google Firestore database as the other forms, readable only by Hipson staff, and it cannot be deleted or altered from a browser by anyone, including us. If our system is unreachable, nothing is stored: the page opens an email in your own mail app instead, and you see exactly what is being sent.

The ABA coverage check (/aba). The check itself stores nothing and sends nothing — the questions about your household and your child are answered in your browser and stay there, which is why the page needs no email to run. If you then ask us to email your results, we store your name, email and phone so we can send the guide and follow up once, together with a copy of the read-out the page showed you — the figures, the ranked list of programmes to ask about, and the household size, child's age and therapy hours those figures were worked out from. We store that copy for one reason: it is what we email back to you, and it cannot be emailed to you without leaving your browser. It is your own result returning to your own address. Whether an advisor also sees your answers is a separate question, and it is what the tick box decides — therapy hours and a disability determination are health information about a child, and we do not put those in front of a person on implied consent. Untick it and the advisor gets your contact details alone. Both the copy and your details go into the same Google Firestore database as the other forms, readable only by Hipson staff, and neither can be deleted or altered from a browser. If our system is unreachable, nothing is stored — the page opens an email in your own mail app instead, and you see exactly what is being sent.

The client portal (/portal). The "sample account" stores and sends nothing — it is demo data drawn in your browser. If you sign in and submit a question or a member-change request, we store what you typed, together with the name and email on the account you signed in with, so the request can be tracked through to done. These records go into the same Google Firestore database, readable only by Hipson staff and by you while signed in, and they cannot be deleted or altered from a browser.

The referral program (/referrals). If you join, we store the name and email on the Google account you sign in with, your points balance, and every referral and redemption you submit. For each person you refer we store what you enter about them — their name, company, email, phone and your note — and we use it for exactly one thing: making the introduction you said they agreed to. We tell them you sent us. Referred people can ask us to delete their details at any time at information@hipson.com, and so can you. Gift-card claim codes are stored on your redemption record, readable only by you while signed in and by Hipson staff.

The ratings page (/reviews). If you rate us, we store the star rating, the role you select, and — only if you type them — your comment, name and email. These go to Michael and Justin, not onto the internet: nothing you enter there is published anywhere. The links on that page to Google, Yelp, Facebook and other review platforms take you to those services, where anything you write is governed by their terms, not ours.

The life-insurance call-back form (/personal/life-insurance). If you ask us to call, we store your name, your phone number or email, and who the coverage is for, so a licensed advisor can call you back. It goes into the same staff-only database. If our system is unreachable, nothing is stored — the page tells you plainly that it did not send, and gives you our phone number and an email link you can use instead. Corrected 3 September 2026: a mismatch between this form and our database rules meant every submission was in fact being refused and quietly turned into an email draft. It saves properly now.

What we do with it. A licensed advisor uses those answers to look your clinic, doctors and prescriptions up in the federal Marketplace's public plan data and to work out what coverage would cost you. The names you give us are sent to that federal service as identifiers so it can tell us which plans include them; your name, your child's age, your diagnosis details and your income are not. We do not sell any of it, we do not share it with insurers unless you ask us to place coverage for you, and you can ask us to delete the whole record at any time by writing to information@hipson.com.

Every page. Firebase Hosting, which serves this site, keeps standard server logs including IP addresses, for security and reliability. We do not use Google Analytics, advertising pixels, or any cross-site tracking, and we do not set our own cookies.

Third parties that see something

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have never done so.

Why we keep it

To reply to you, to prepare the review or assessment you asked for, and to keep a record of advice given — which, as a licensed insurance and securities practice, we are expected to retain. We do not send marketing email to people who only used a free tool; if you want the newsletter you subscribe to it separately.

How long

Enquiries that do not become client relationships: up to 24 months, then deleted. Client records: retained as long as required under insurance and securities recordkeeping rules, which is generally at least six years after the relationship ends.

Your choices

Texas residents have rights under the Texas Data Privacy and Security Act, and residents of other states may have similar rights. Whoever you are and wherever you live, you can ask us to:

Email information@hipson.com with "Privacy request" in the subject, or call 281.493.6862. We respond within 45 days. There is no charge, and asking costs you nothing else — we will not treat you differently for it. If we decline, we will say why and how to appeal.

Security, honestly stated

The database is locked down so that the public can only submit an enquiry — it cannot read anything, and nothing can be deleted from a browser. Staff access requires a Google account on a named allowlist. That said, no website is perfectly secure, and we will not pretend otherwise. Please do not send policy numbers, Social Security numbers, medical details or account numbers through this website; if we need those, we will arrange a secure route.

Children

This site is meant for adults arranging coverage for a business or a household. We do not knowingly collect information from anyone under 13. Where a family's cover involves a child, the information comes from the parent or guardian and is handled with the same care as the rest of the file.

Changes

If this notice changes materially we will update the date at the top and, where it affects information we already hold, tell affected people directly.

Questions about your information? A person answers — same business day.

Email us

This notice describes the website. Insurance and securities business conducted through Ameritas Investment Company, LLC (AIC) and Ameritas Advisory Services (AAS) is additionally covered by their own privacy notices, which are provided to clients at account opening and annually thereafter.