Privacy Policy
Effective August 27, 2026
1. The short version
VA Claim Net is run by VA Claim Net LLC ("we," "us") and used by veterans' claims representatives ("Firms") to manage the people they represent ("Clients"). Firms put very sensitive information into the service. We use that information only to run the service for the Firm. We do not sell it, and we do not use it for advertising. We use only essential cookies — no advertising or tracking cookies.
2. Information we hold
- Account information — names, email addresses, and passwords (stored only as secure hashes) for Firm staff and portal Clients.
- Client records the Firm manages — contact details, Social Security numbers, dates of birth, military service details, claim information, documents, messages, signed forms, and claim status, claim history, and benefit information retrieved from VA when a Firm uses the VA integration. The Firm controls this data; we process it on the Firm's behalf.
- Usage and log data — sign-ins, actions taken in the app (kept in an audit trail so firms can see who did what), and technical logs such as IP addresses used for security protections like rate limiting.
- Billing data — handled by our payment processor; we never see full card numbers.
3. How we use information
- To provide, secure, and support the service.
- To send the emails the service generates — invitations, reminders, signing requests, notifications, and receipts.
- To bill Firms for their subscriptions.
- To investigate abuse and keep the platform safe.
We do not sell personal information — including sensitive personal information such as Social Security numbers or health details — and we do not share it for advertising or any similar purpose. We do not use client records for advertising or to train AI models. Where an optional AI feature processes text a Firm provides (for example, drafting an automation rule), it is sent to our AI provider solely to produce the result the Firm asked for. The one event that can move data to another company is a sale or merger of our business itself — and Section 12 describes the protections and notice that come with that.
4. Who can see what
A Firm's data is isolated to that Firm. Within a Firm, owners and administrators control which team members can open which client files. Clients see only their own information through their secure portal. Our operators access customer data only when needed to run or support the service.
5. Service providers we rely on
We use a small set of providers to run the service: Render (application hosting and managed database), Amazon Web Services S3 (encrypted file storage), Postmark (transactional email), Stripe (payments), and OpenAI (AI features, solely to produce the requested result, never for training). Every provider or contractor that handles personal data for us is bound by a written agreement to the same commitments we make to you in this policy: it may use the data only to provide its service to us, may not disclose it except as we direct or the law requires, and must protect it. Sentry (error monitoring) receives only technical crash reports stripped of personal information: no form contents, identities, or links containing access tokens. Electronic signatures are handled by our built-in e-signature system, which we run on our own infrastructure.
When a Firm uses the VA.gov integration, we send the veteran's name, Social Security number, date of birth, address, and related claim information to the U.S. Department of Veterans Affairs (api.va.gov). We do this to retrieve claim status or file forms on the Firm's or representative's behalf, and only with the required consent. We store claim and benefit data returned by VA in the Client's file so the Firm can manage the representation. We do not otherwise share client records unless the law requires it. All customer data is stored in the United States.
6. How we protect it
- Encryption in transit (HTTPS) everywhere.
- Documents are stored in private storage with encryption at rest; Social Security numbers are additionally encrypted in the database and masked in the interface by default.
- Passwords are stored only as secure hashes.
- Sign-in protections including lockouts after repeated failures, and audit logging of sensitive actions (like revealing an SSN).
If we discover a security breach affecting a Firm's client records, we will notify that Firm without undue delay — and in any event within 72 hours of confirming a breach affecting its client records, so the Firm can meet its own notification duties. We will also notify each affected veteran or claimant directly, using the contact information on file, with a plain-language explanation of what happened, what information was involved, and the steps they can take to protect themselves — such as placing a fraud alert or credit freeze with the credit bureaus and watching for suspicious mail, calls, or sign-in alerts.
7. Cookies, Do Not Track, and privacy signals
We use only essential cookies — the ones that sign you in, keep your session secure, and remember small interface choices (like dismissing a setup tour). There are no analytics cookies, no advertising cookies, and no trackers from other companies, and we do not track anyone across other websites.
Because there is nothing to opt out of, our answers to browser privacy signals are simple. We do not respond to Do Not Track signals — there is no tracking to turn off. Where a legally recognized opt-out signal such as Global Privacy Control applies, it is honored automatically, because we never sell or share personal information in the first place.
8. How long we keep it
We retain data while the Firm's account is active. Within 45 days after the account ends, we delete its account information and VA-sourced identifiers. One exception applies: an identifier may stay in a claim or representation record that the Firm keeps under the next list. We also complete verified requests to delete VA-sourced identifiers within 45 days. The Firm controls its client records, so deletion requests go through the controlling Firm.
Dormant accounts are handled the same way. If a Firm's account has no sign-ins and no active subscription for 12 months in a row, we treat it as dormant: we notify the account owner by email, and if no one reactivates the account within 60 days, we close it and the deletion schedule above runs. A veteran's data — including data that did not come from VA — is never kept indefinitely in an account nobody uses.
After the 45-day period, we keep only:
- Claim and representation records. The Firm controls these records. We keep them only for as long as the Firm directs or legal or professional rules require, so the Firm can document its work.
- Billing and tax records. We keep them for seven years, to meet tax and accounting requirements.
- Security and audit logs. We keep them for six years to meet security and compliance duties.
9. If you are a veteran or claimant
Your representative's Firm controls your records in this service. To see, correct, or delete your information, start with your Firm. The Firm checks and routes requests to us when needed. We delete VA-sourced identifiers within 45 days after the request is verified. The only exception is for claim and representation records the Firm keeps under Section 8. You can also use your portal account to review your information and update your contact details at any time.
10. State health-data laws
Some states have consumer-health-data laws — such as Washington's My Health My Data Act or Nevada's similar law — that can apply to health-related records a Firm keeps in the service. Where such a law applies, the Firm is the regulated business, and we act solely as its processor: we handle that data only under our agreement with the Firm and on its instructions. Requests about that data go to the Firm, as Section 9 describes.
11. Children
The service is for adults. We don't knowingly collect information from children under 13, except where a Firm records a dependent's details as part of a claim it manages.
12. Ownership changes or service shutdown
If our company merges, is acquired, or transfers ownership, data remains protected under this policy. We will notify account owners before a successor takes control and give them a choice to export their data and close their accounts. If the service shuts down, we will notify Firms and give them at least 30 days to export their data. After that window closes, we will delete the data as described in Section 8.
13. Changes and contact
If we make a material change to this policy, we'll notify account owners before it takes effect. See also our Terms of Service. Privacy questions: evan@processorteam.com.