Last Updated: February, 2023
This Privacy Policy and Notice ( “Privacy Notice”) describes how RLI Corp., RLI Insurance Company, Mt. Hawley Insurance Company, Contractors Bonding and Insurance Company, RLI Underwriting Services, Inc., Safe Fleet Insurance Services, Inc., and Data and Staff Service Co. (“RLI” or “we” or “us” ) collect, use, share, retain, and protect information about you when you (1) visit https://www.rlicorp.com/ or one of the pages thereon (the “Website”); (2) communicate with us or the Website via email and other electronic messages; (3) create an account on our Website; (4) submit a claim via our Website; and (5) otherwise interact with us online or offline, such as on the telephone and in written correspondence.
RLI does not control and is not responsible for the content or the privacy policies or practices of any third-parties, third-party websites, or third-party applications, including those that may link to or can be accessible via the Website. This Privacy Notice does not govern third parties’ collection and use of your information, except as specifically described in this Privacy Notice.
Before accessing, using, or interacting with the Website you should carefully review this Privacy Notice and our Terms of Use (https://www.rlicorp.com/terms-use), which are incorporated by reference and also govern use of the Website. We may change our Privacy Notice and Terms of Use from time to time and encourage you to review them whenever you interact with us.
User Consent: By choosing to interact with RLI, including through our Website and by communicating with us via email, telephone or in person, you consent to the collection and use of information as described in this Privacy Notice and you represent that you are at least 18 years old. If you are under the age of 18 or you do not consent to the collection, use and/or disclosure of your personal information as set forth in this Privacy Notice, please exit and do not use our Website or other applications or services.
What Personal Information Does RLI Collect?
For purposes of this Notice, unless noted otherwise, when we use the term “personal information,” we mean information that identifies, relates to, describes, references, is reasonably capable of being associated with or could reasonably be linked, directly or indirectly, with a particular person or household (“personal information”).
We may collect personal information that falls into the following categories:
How Does RLI Collect Information About Me?
We collect and store information that you give us directly. For example, when you:
We also receive and store certain types of information automatically when you interact with us online or with the Website.
RLI uses third-party services to better understand your needs and to optimize your experience, by assessing, for example, how much time you spend on which pages and which links you choose to click. These services use cookies and other technologies to collect data on your behavior and devices. This includes a device’s IP address (collected during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. RLI’s third-party service providers store this information on our behalf in a pseudonymized user profile, and are contractually forbidden from selling the data collected on our behalf. RLI also uses other third-party service providers to collect and store data given to us directly via forms on our website. These service providers are contractually forbidden to sell any of the data collected on our behalf.
For purposes of our insurance policy information, RLI may also learn information indirectly about you, which you make publicly available, such as on a social network or shared with third parties. Please note, any content or information you share with or provide to third parties regarding RLI, your communications with RLI, or using or related to the Website may not be private or confidential and is not the responsibility of RLI.
How Does RLI Use Information About Me?
RLI may use and process information about you, including personal information, for one or more of the legitimate business purposes described in this Privacy Notice. For example, RLI (and/or our Service Providers) may use information about you to:
Does RLI Share the Information It Receives About Me?
RLI does not sell your personal information or share your information for cross context behavioral advertising. We will not sell personal information that we collected without giving you an opportunity to opt-out and unless we first give you notice of our intent to sell and an express opportunity to opt-out of that sale. We do not knowingly sell the personal information of Consumers under 16. Because RLI does not sell your personal information or share your personal information for cross-context behavioral advertising, we are not required to provide a Notice of Right to Opt-out of Sale/Sharing.
We may share your personal information with third-party service providers with whom we have entered into contracts that require personal information be kept confidential and prohibit the retention, use, or disclosure of personal information for any purpose other than the services specified. for the following purposes, which are not a sale: (i) if you direct us to share personal information; (ii) to comply with your requests under the CCPA; (iii) disclosures amongst the entities that constitute Company as defined above, or as part of a merger or asset sale; and (iv) as otherwise required or permitted by applicable law.
RLI may share or disclose information as described below:
How Does RLI Secure Information About Me?
We realize that you trust us to protect your personal information. We take that trust seriously and maintain physical, electronic and procedural safeguards that are consistent with industry standards to help protect the privacy, accuracy, and reliability of personal information and to protect it from loss, misuse, unauthorized access, disclosure, acquisition, exfiltration, alteration and destruction.
We also take commercially reasonable steps to ensure that our third-party service providers reasonably protect and secure your information. If RLI becomes aware that a third-party service provider is using or disclosing information improperly, we will take necessary and immediate steps to end or correct such improper use or disclosure.
While we attempt to protect the information in our possession and account for the protection of information provided to our third-party service providers through us, no security system is perfect and we cannot promise that information about you will remain secure in all circumstances. Please do your part to help us keep your information secure. You are responsible for maintaining the confidentiality of your password(s) and your Account(s), and for all activities that occur under your password or Account(s). RLI specifically reserves the right to terminate your access to your Account(s) and any contract you have with RLI related to the use of the Website in the event it learns or suspects you have disclosed your Account or password information to an unauthorized third party.
What Choices Do I Have?
RLI seeks to ensure that all individuals are provided with the rights mandated by their governing jurisdiction. Not all of the rights discussed herein will apply to everyone and, depending upon your jurisdiction, may not apply to you. For example, the CCPA and CPRA provide California Residents the right, under certain circumstances, to request that RLI disclose, delete or correct their personal information. California Residents can read more here.
To exercise these rights, as described above, please submit a request to us by either:
Communications from RLI
Users may opt-out of receiving certain communications from RLI by following the unsubscribe process described in our communications, changing your account settings, or by contacting us by using the contact information provided below. Please note that such requests may take some time to fulfill and that certain insurance policy and Website-related communications, including but not limited to account verification, changes or updates to Website features, or technical and security notices are non-optional.
Notice to California Residents of Their Rights
The California Consumer Privacy Act (the “CCPA”) and as amended by the California Privacy Rights Act (the “CPRA”), provide California Residents (as defined in the CCPA and CPRA), specific rights regarding their personal information. For purposes of the CCPA, personal information does not include: publicly available information from government records; de-identified or aggregated consumer information; and, information excluded from the CCPA’s scope, including: health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data, certain information covered by sector-specific privacy laws, such as the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA), the California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994 (DPPA). Any terms defined in the CCPA have the same meaning when used in this Notice.
The rights conferred by the CCPA and CPRA apply solely to visitors, users, and others who reside in the State of California. The following sections describe your rights and explains how to exercise those rights.
Right to Request Access to Specific Information and Data Portability Rights
The CCPA grants California Residents the right to ask RLI about its collection and use of the personal information it has collected, used, and disclosed over the past twelve (12) months. Instructions on how a California Resident can submit a verifiable consumer request for access to this information (referred to as a “Request to Know”) are below. Once we receive and confirm that you have made a verifiable consumer Request to Know, we will make an individualized disclosure to you about:
Right to Request Deletion of Your Data
California Residents have the right to request that we delete the personal information that we have collected and retained (“Requests to Delete”). Upon RLI’s receipt of a verifiable request to delete personal information (see below), we will delete—subject to the exceptions explained below— the personal information from our records and will direct our service providers to delete your personal information from their records.
However, please note that RLI may deny your request to delete and need not comply with such a request (and need not ask third-party service providers to comply) if retaining the information is necessary to perform certain functions or commitments, including: completing the transaction for which the personal information was collected; providing a service requested; otherwise performing our contract with you or taking reasonably anticipated actions within the context of our ongoing business relationship with you; detecting security incidents and protecting against malicious, deceptive or otherwise illegal activity or to prosecute those responsible for those activities; complying with a legal obligation or otherwise using the personal information, internally, in a lawful manner; complying with the California Electronic Communications Privacy Act; fulfilling the terms of a written warranty or product recall conducted in accordance with federal law; or, for a purpose otherwise contemplated by Cal. Civ. Code Section 1798.105(c)-(d) or as otherwise amended.
Right to Correct Inaccurate Personal Information
The CPRA provides an additional right for California Residents to request that we correct inaccurate personal information that we maintain about them (the “Right to Correct”). RLI will use commercially reasonable efforts in order to comply with California consumer requests to correct.
Use and Disclosure of Sensitive Personal Information
RLI only uses and discloses sensitive personal information (“SPI”) for the following purposes provided by Section 7027(m) of the CCPA regulations. Specifically, RLI may use or disclose SPI to: provide goods or services reasonably expected by California consumers; to prevent, detect and investigate security incidents; to resist malicious, deceptive, fraudulent or illegal actions directed at RLI; to ensure the physical safety of natural persons; for short-term transient use related to your interaction with RLI; to perform services on behalf of RLI in the insurance industry; to verify or maintain the quality or safety of a product or service; and, to maintain the necessary security and quality control over RLI’s stored information. Since RLI does not use or disclose SPI for purposes other than these exempted purposes, we are not required to post a Notice of Right to Limit or provide a method for submitting a request to limit use or disclosure of SPI.
How to Exercise Your Access, Data Portability, Deletion and Correction Rights
You may make a verifiable request to exercise your right to access or data portability twice within a 12-month period. To exercise the access, data portability, deletion, and correction rights described above, please submit a verifiable consumer request to us by either:
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf may make a verifiable consumer request related to the personal information about you. If the request is made through an agent, we reserve the right to require a signed authorization or verification of the agent’s identify from you in order protect the privacy of the personal information requested. You may also make a verifiable consumer request on behalf of your minor child.
We cannot provide you with the information sought in a Request to Access, or comply with a Request to Delete or Correct, if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. A verifiable request must:
We reserve the right to require additional information from you to verify your request before we respond. Any information provided to us in a verifiable customer request will be used only to verify the requestor’s identity or authority to make the request.
Response Timing and Format
We will acknowledge your request or exercise of the foregoing Rights within ten (10) days of receipt with information regarding how we will process your request. We will endeavor to respond to a verifiable consumer request within forty-five (45) days of receipt. If we require more time to provide a response, we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the twelve (12) month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
As mentioned above, we may collect or process sensitive data as needed or required to deliver services you have requested, to inform you of other products or services, and to contact you via surveys to conduct research about your opinions. You may request that we delete this information, subject to certain exceptions as provided by the CCPA.
Other California Privacy Rights
Under California Civil Code Section 1798.83 (known as the "Shine the Light" law), residents of California may request certain information about our disclosure of personal information during the prior calendar year to third parties for their direct marketing purposes. To make such a request, please write to us at the address below or email privacy@rlicorp.com with "Request for California Privacy Information" on the subject line and in the body of your message. We will comply with your request within thirty (30) days or as otherwise required by the statute. Please be aware that not all information sharing is covered by the "Shine the Light" requirements and only information on covered sharing will be included in our response.
Non-Discrimination
We will not discriminate against you for exercising any of the rights conferred by California statute, including the CCPA. Unless permitted by law, we will not: deny you goods or services; charge you different prices or rates; provide you a different level or quality of goods or services; or suggest that you may receive a different price or rate or a different level or quality of goods or services. We may offer certain financial incentives permitted by the CCPA that can result in different prices, rates or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects.
Changes to Our Privacy Notice
RLI may modify this Privacy Notice from time to time. The most current version of this Privacy Notice will govern our use of your information and will be located at https://www.rlicorp.com/rli-privacy-policy. You may contact us to obtain prior versions. We will notify you of material changes to this policy by posting a notice at the Website or by emailing you at an email address associated with your Website Account, if applicable, and provide an “at a glance” overview of any changes.
Contact for More Information
RLI Corp. is located at 9025 N. Lindbergh Dr., Peoria, IL 61615. Should you have any comments or questions about how we collect and use your personal information, communication can be directed to RLI’s postal address, via email to privacy@rlicorp.com or by telephone to 1-833-473-1468.