Privacy Policy
How SSGI Benefits handles information in connection with this website.
Last updated: September 11, 2026
Information We Collect
The contact form collects the business-inquiry information you choose to provide, including your name, work email, company, state, employee-range selection, inquiry topic, preferred contact method, optional telephone number, optional renewal month, optional message, and referral source. If you arrive through a tagged campaign link or an external referring site, the submitted inquiry may also include the landing-page path, the external site's origin, a source value, and standard UTM campaign fields shown in that link. Referrer paths, referrer query strings, and fragments are not retained for this purpose.
The form is intended only for general business and coverage inquiries. It does not request or require health information, medical records, diagnoses, claims details, Social Security numbers, financial-account numbers, insurance member IDs, passwords, or other credentials. Do not include those details in the form, email, or other general-contact channels.
If you contact SSGI using an email or telephone link instead of the form, your message is handled by your own email or telephone provider under that provider's practices before it reaches SSGI.
How We Use Your Information
The website validates and delivers an accepted contact-form inquiry through managed email infrastructure to a fixed SSGI business mailbox. SSGI uses the inquiry to route and respond to your request, understand the source of the inquiry, maintain service and security, and follow up about the topic you selected.
Raw form submissions are not retained in the website backend after processing. The system keeps bounded anti-abuse records derived from hashed or non-content identifiers and privacy-safe aggregate outcome counts; those records are used to limit spam, replay, and excessive submissions and do not contain the message body. A delivered copy is retained in SSGI's business email systems under SSGI's operational, legal, and record-retention practices.
SSGI does not sell personal information. SSGI may use service providers that operate the website, security controls, or managed email delivery, and may disclose information when required by law or reasonably necessary to protect the website and its users.
Cookies and Analytics
This website is U.S.-focused. SSGI uses optional Google Analytics 4 (GA4) to understand which content is useful. GA4 is consent-gated using Google Consent Mode v2 with region-scoped defaults: analytics storage is permitted by regional default only for U.S. traffic unless you disable it, and outside the U.S. it is denied by default unless you choose Allow. All Google advertising-related consent (ad_storage, ad_user_data, and ad_personalization) is denied everywhere. Separately, the production site includes the OpenAI Ads Measurement Pixel for consented advertising attribution and conversion measurement. That pixel does not initialize unless you explicitly choose Allow, and GPC or DNT prevents it from initializing. SSGI uses no Google Tag Manager, consent-management-platform vendor, device fingerprinting, or third-party geolocation or language/timezone inference.
Global Privacy Control (GPC) and Do Not Track (DNT) signals are honored. When GPC or DNT is active, analytics is disabled and no Google tag is initiated, so no GA request or cookie is set. The consent banner no longer auto-opens; you can change your analytics setting at any time through the "Privacy Choices" link in the site footer, which opens an accessible settings modal.
How measurement loads depends on your privacy signals and your saved choice. When GPC or DNT is detected before loading, neither the Google tag nor the OpenAI Ads pixel is initiated. When you have a saved explicit Disable on a new page load, that choice prevents both tags from loading. If measurement was active and you disable it during the session, the application immediately updates Google consent to denied, revokes OpenAI Ads pixel consent, stops future SSGI application measurement events, and clears GA cookies where possible; this does not imply a previously loaded script never loaded. With no saved choice, the production site queues Google Consent Mode v2 defaults: analytics_storage is denied globally and granted only for region ["US"], while ad_storage, ad_user_data, and ad_personalization stay denied everywhere. The OpenAI Ads pixel has no regional-default path and remains off until explicit Allow. For non-U.S. or unresolved regions under the Google regional default, analytics storage remains denied; the official advanced Consent Mode implementation may load the Google tag and send limited cookieless consent-mode and measurement signals, but no analytics cookies are set and full stored analytics is not enabled unless you choose Allow. Preview, staging, localhost, and unknown hosts load neither measurement tag.
When GA4 measurement is active, SSGI's application code sends only sanitized canonical context — the page pathname, page title, and a referrer origin (the validated external origin you arrived from on first page open, or the prior sanitized page_location on in-site navigation) — plus one of sixteen allowlisted interaction types: page_view, generate_lead, click_to_call, click_email, schedule_consultation, famli_assessment_complete, benefits_checkup_complete, ask_ssgi_interaction, contact_form_start, contact_form_step_complete, contact_form_validation_failure, google_review_click, portal_start, coverage_application_start, resource_download_or_print, and planning_tool_complete. The page_location is the site origin https://www.ssgibenefits.com plus the page pathname, with no query string, hash fragment, credentials, or port. The page_referrer is never the raw document.referrer string, a referrer path, a referrer query string, or a referrer fragment. SSGI application code sends no other custom analytics events to GA4. GA4 may automatically derive standard session and engagement events or metadata when measurement is enabled.
When analytics is enabled, GA4 may automatically derive ordinary device and browser information, coarse region, session, and engagement metadata from its standard operation. Enhanced Measurement, Google Signals, advertising personalization, granular location or device collection, and optional Google data sharing are off in this implementation.
Google never receives contact-form fields, names, phone numbers, messages, employee data, health information, FAMLI answers or results, user IDs, full URLs, query strings, or hashes from this implementation. GA4 is not a BAA-covered intake system and is never used as one; SSGI and GA4 are not represented as compliant with HIPAA, nor is a BAA in place. The public contact form remains a HIPAA-compatible, non-BAA general-purpose boundary; do not submit PHI. Analytics records only that an allowlisted interaction occurred.
After explicit Allow, the OpenAI Ads browser pixel may process standard page, referrer, browser, device, and network request metadata for advertising attribution. SSGI sends the fixed event name lead_created only after the server confirms that a contact inquiry was accepted. Advanced matching is disabled: no user object, name, email address, telephone number, form field, message, chat content, health or benefits detail, or other raw customer data is supplied to the pixel. There is no OpenAI Conversions API or server-side customer-data transmission in this implementation.
SSGI does not sell analytics or pixel data. GA4 is used for site measurement, and the OpenAI Ads pixel is used only for consented advertising attribution and aggregate conversion measurement; SSGI does not upload customer lists or implement personal advanced matching in this website.
GA4 and the OpenAI Ads pixel load only on the production hosts www.ssgibenefits.com and ssgibenefits.com under the consent rules above. They do not load on preview domains, staging, localhost, test environments, or unknown hosts.
When a page is opened from a tagged campaign link or an external referring site, the application may keep sanitized campaign slugs, the landing-page path, and the external site's origin in session storage for the current browser tab. It does not keep the external referrer's path, query string, or fragment. Nothing is sent to SSGI merely because the page loads. If you submit the contact form, the session attribution may be included with the inquiry so SSGI can understand which page or campaign led to the request. The record is cleared after an accepted submission and otherwise ends with the tab session.
This policy does not make an absolute claim about hosting, security, or server logs outside what the SSGI application emits. It also does not claim that no cookies are ever set, because that can depend on hosting infrastructure, browser behavior, and any future configuration not currently present.
For more information about how Google handles data collected through Google Analytics, see Google's Privacy Policy.
Third-Party Services
This site links to external BenefitZone portals for employer and employee account access. SSGI does not operate these portals; they are separate third-party platforms with their own privacy practices that govern any information you share with them. BenefitZone is used solely for existing client access to benefits accounts and is not the system of record for any request made through this website.
Website hosting, security, and managed email-delivery infrastructure process contact-form submissions only as needed to operate and protect the service and deliver the inquiry to SSGI. The form recipient is controlled on the server and cannot be selected by the visitor.
Choosing an email or telephone link on this site contacts SSGI through your own email or telephone provider. SSGI is not the provider of those services; your provider's terms and privacy practices apply to the message before it reaches SSGI.
No external insurance-application handoff or appointment scheduler is currently active. The consent-gated OpenAI Ads Measurement Pixel described above is the only advertising-measurement pixel implemented by SSGI application code. Ask SSGI uses the third-party inference service described below; SSGI does not control the provider's retention, logging, or training practices.
Ask SSGI AI Assistant
Ask SSGI is available when its backend status query reports ready. That status query reflects application metadata about the assistant's configured availability; it is not a live probe of the underlying inference provider's health. If the backend cannot be reached, the launcher remains hidden and the rest of the website continues to work.
Ask SSGI is an educational benefits guide powered by a platform-hosted inference provider. The assistant is accessed through the platform's server-side path; the third-party inference service processes inputs to produce a response. The assistant does not browse the open web. It answers only from an approved, curated SSGI knowledge corpus built from this site's published content.
What is transmitted: when you send a message, your message text and your selected role (employer, employee, or individual), plus the prior messages in your current session, are transmitted to the third-party inference service to generate a reply. A session identifier is used at the backend admission controls, not in the model payload. SSGI does not control the provider's retention, logging, or training practices.
Purpose: to provide general educational information about benefits and route you to the right SSGI resource.
Retention: SSGI does not persist the conversation. The assistant keeps the conversation in temporary client memory while the panel is open or minimized. Minimize retains it for reopening. Closing the panel or clicking the "Clear conversation" control wipes it and starts a new session. A response that arrives after clearing is ignored; clearing cannot recall a request already sent for processing. No transcript is stored in backend stable memory, OQL, analytics, or your browser's local or session storage.
Model training and provider retention: the assistant is powered by a platform-hosted inference provider. SSGI does not control the provider's retention, logging, or training practices. Do not enter sensitive information. This policy makes no claim about the provider's retention or training of inputs beyond what implementation and official documentation prove.
Ask SSGI does not self-learn. It does not crawl, scrape, train itself from, or dynamically ingest the public website; it answers only from a curated, versioned, reviewed SSGI knowledge corpus.
Only privacy-safe interaction states are measured: launcher open, role choice, successful or failed result, citation use, and safe handoffs. The prompt, the answer, citation URLs or titles, the session identifier, personal identity, and account data are never measured.
Third-party involvement: a third-party inference provider supplies the model. SSGI does not control the provider's retention, logging, or training practices.
Sensitive data: do not enter health details, Social Security numbers, member IDs, financial information, passwords, or other sensitive information. The public chat is not a secure channel for protected health information. SSGI maintains a HIPAA-compatible, non-BAA posture for this public assistant; it does not operate as a HIPAA-covered intake channel.
How to contact SSGI: use the contact form or the client service page, call 800-440-1045, or email VIP@ssgibenefits.com.
Fail-closed: if the assistant is unavailable, the website remains fully usable. The assistant panel shows an unavailable state with a route-to-human link to client service.
Your Rights
Subject to applicable law and legitimate record-retention obligations, you may ask SSGI to access, correct, or delete personal information you submitted through the contact form or shared directly.
To make a request, contact SSGI using the information below. We may need to verify the request before acting on it.
Data Retention
The website backend validates, formats, sends, and then discards the raw contact-form submission. It retains only bounded anti-abuse records and privacy-safe aggregate outcome counters needed to protect and operate the form. The delivered inquiry is retained in SSGI's business email and related records only as long as reasonably necessary to respond, provide service, meet legal or regulatory obligations, resolve disputes, and protect the business, after which it may be deleted or anonymized.
The browser-tab attribution record described above is temporary session storage, is cleared after an accepted inquiry, and does not persist as a cross-session visitor profile.
Changes to This Policy
We may update this privacy policy as our practices evolve. The date above indicates when this policy was last updated. Material changes will be reflected here before they take effect.
This policy must be updated before any additional analytics or advertising-measurement provider, external insurance-application handoff, scheduler, bot-management provider, or AI provider is activated. When such a feature is enabled, the relevant section will describe what is collected, where it goes, and the service involved before activation.
Contact Us
If you have questions about this privacy policy or how your information is handled, contact SSGI using the information below. Do not include health, claims, Social Security, member ID, financial-account, or credential information in a general privacy inquiry.
Email: VIP@ssgibenefits.com
Phone: 800-440-1045
External Application and AI Tools
Ask SSGI is available only when its backend status query reports ready. That status query reflects application metadata about the assistant's configured availability; it is not a live probe of the underlying inference provider's health. Chat inputs are processed by the third-party inference service as described in the Ask SSGI section above; SSGI does not control the provider's retention, logging, or training practices. External insurance-application handoffs remain disabled.
The public assistant is not a secure channel for sensitive information or protected health information. Use SSGI Client Service for personal, plan-specific, claims, eligibility, or account questions.
SSGI Benefits treats your information with care.