EFFECTIVE LEGAL DOCUMENT
This exact source version is active for CoverageCases.
Document status
- coveragecases-platform-v1.8
- Sep 4, 2026, 4:35 PM ET
- Effective
How CoverageCases and its providers collect, use, disclose, retain, and protect information for attorney accounts and marketplace operations.
1. Scope and contact
This Privacy Policy is version coveragecases-platform-v1.8 and has an effective timestamp of 2026-09-04T20:35:00.000Z. It is not effective unless the exact version is activated. CoverageCases LLC is responsible for the CoverageCases processing described here. Privacy questions and verified access, correction, or deletion requests may be sent to admin@coveragecases.com or mailed to CoverageCases LLC at 7402 North 56th Street, Suite 810 PMB 1013, Tampa, Florida 33617.
2. Information CoverageCases collects
CoverageCases collects account and contact data; firm and profile data; canonical Florida Bar number; continuing-certification evidence; standard membership-record entries and import provenance; structured postings, acceptances, cancellations, appearance reports, disputes, and notifications; individual technology-subscription status and provider identifiers; fixed posting-fee quotes, Checkout attempts, charges, refunds, receipts, and immutable accounting facts; legal assent; support, privacy, security, and administrative records; and ordinary device and server data. Structured posting and engagement data includes court and hearing details, proposed attorney compensation, client name, case number, attendance requirement, and waiver status. CoverageCases does not provide or store attorney-to-attorney messages.
Other marketplace users initially receive only limited opportunity information. An eligible attorney who affirmatively starts the conflict-check workflow may receive only the client and case information reasonably necessary to conduct that review; access and certification are audited. After acceptance, the matched attorneys receive the case and contact information needed for the engagement, including each attorney's name, email address, and telephone number. Authorized CoverageCases personnel and service providers may process these records when reasonably needed to operate, secure, support, audit, or comply with law for the service. Communications between attorneys occur outside CoverageCases and are not received, transmitted, or retained by CoverageCases.
3. Stripe Identity data and roles
For Stripe Identity, CoverageCases discloses the account email and opaque session and application references to Stripe. Stripe captures government-ID and face or selfie images, uses facial-recognition technology to create biometric identifiers and compare the face with the ID, extracts or receives information such as name, date of birth, government identification number and address, and collects device, cookie, analytics, security, and fraud signals. Stripe processes Identity data in the United States regardless of where the user is located and may use verification service providers or check information against third-party or government-managed data sources to evaluate the verification. CoverageCases and Stripe each act as independent controllers for certain processing, and Stripe also acts as a service provider to CoverageCases under the applicable agreements.
Stripe and personnel authorized to use CoverageCases's Stripe account can access submitted verification information in Stripe. CoverageCases uses the provider-verified first and last name transiently to compare against the account name and, when official roster data is available, may use it for roster reconciliation. Its application database stores only opaque session and report identifiers, status and timestamps, the configured document-and-selfie check, consent evidence, the user's attestation, any later roster references and match outcome, restricted error codes, and redaction receipts—not copies of the ID or selfie, extracted date of birth, identification number or address, or biometric identifiers.
Stripe's optional use of submitted information to improve its biometric technology is a separate choice in Stripe's hosted flow and is not required by CoverageCases. Stripe's Privacy Policy is available at https://stripe.com/privacy.
4. Official membership dataset and limitation
CoverageCases may import the standard official Florida Bar membership dataset for later reconciliation, including point-in-time Bar number and name information and import provenance. Initial approval does not claim an official roster match. CoverageCases does not obtain additional standing or disciplinary information and does not treat a later record match as current good standing, authorization, or eligibility.
CoverageCases uses the canonical Bar number and normalized name for user attestation, duplicate prevention, later roster reconciliation, audit, security, and operation of the attorney-only marketplace. A later mismatch may be flagged, investigated, or used to suspend or restrict an account. Current eligibility remains the user's continuing certification and independent professional duty.
5. Uses and disclosures
CoverageCases uses information to authenticate users; verify identity; record the user's Bar number and active-attorney attestation; later reconcile official roster data; administer accounts, individual subscriptions, fixed posting-fee quotes and charges, legal assent, postings, acceptances, lifecycle events, notifications, receipts, refunds, history, privacy requests, security, support, and audits; prevent abuse; enforce platform rules; and comply with law.
CoverageCases discloses information to another eligible attorney only as needed for marketplace functions and accepted-engagement contact release. It may disclose information to Stripe, Supabase, Vercel, email and security providers, professional advisers, authorities when required by law, and a documented business successor, limited to the information reasonably needed for those functions. CoverageCases does not sell consumer legal leads and does not use the service to connect prospective clients with lawyers.
CoverageCases does not sell, lease, trade, or otherwise profit from a person's biometric identifiers or biometric information. CoverageCases permits disclosure of Identity information only as described in this Notice, with the person's authorization, to complete a financial transaction requested or authorized by the person, or when otherwise required or permitted by applicable law.
6. CoverageCases retention schedule
CoverageCases retains Identity attempt status and timestamps, Identity consent/version/hash evidence, roster-match references, and redaction receipts for seven years after the later of verification completion or account closure. It retains standard official membership-dataset snapshots, provenance, validation and conflict reports for seven years after the snapshot is superseded. Legal assent, subscription, historical provider-payment, material administrative, contract, dispute, and audit records are retained for at least seven years after the later applicable account closure, final resolution, or transaction. These periods are subject to documented legal holds, security investigations, provider backup-expiry procedures, immutable audit requirements, and obligations that require longer preservation.
Structured marketplace engagement records are retained while an engagement remains active and for at least seven years after the later of final engagement conclusion and closure of the last participating account. Ordinary application security and authentication logs are retained no longer than 90 days unless associated with an incident, fraud review, dispute, legal hold, or other documented need. Other active account records are retained while needed to operate the account. On closure, CoverageCases immediately scrubs ordinary profile and contact fields and disables marketplace use. Supabase Auth may temporarily retain the login email and limited authentication may remain while period-end subscription cancellation, Stripe Identity redaction, and Auth deletion are positively reconciled; during that interval the account holder may request password recovery and reach the Stripe-hosted billing portal, but cannot resume marketplace activity. This interval can last through the current paid period or a provider retry. CoverageCases then deletes the Auth identity and retains a non-login tombstone. The tombstone's opaque identifier, canonical Florida Bar claim, role and creation or closure facts, and billing or provider references needed to preserve retained legal, billing, audit, duplicate-account, fraud-prevention, security, reconciliation, and referential-integrity records have no automatic expiry in the current architecture and may remain beyond seven years, subject to applicable law, verified privacy requests, and legal holds. CoverageCases maintains documented retention controls and deletion receipts; provider and backup copies may remain until the verified expiry process completes.
7. Stripe retention and redaction
As of this version's approval, Stripe states that it generally stores submitted non-biometric Identity information on CoverageCases's behalf for three years after verification and biometric identifiers for up to one year. CoverageCases does not receive or store the ID, selfie, or biometric identifiers in its application database and does not sell, lease, trade, or profit from biometric data. Stripe may separately retain data it processes for its own lawful purposes. CoverageCases will keep the live configuration and this disclosure under review against Stripe's then-current terms.
For an eligible verified closure or deletion request, CoverageCases queues Stripe-session redaction and does not finalize Auth deletion until Stripe positively confirms redaction. Stripe states that redaction may take up to four days and cannot complete while verification is processing. To request deletion of Stripe Identity information held on CoverageCases's behalf, contact CoverageCases at admin@coveragecases.com. To request deletion of information Stripe controls for its own purposes, contact Stripe through the privacy-request process identified in Stripe's Privacy Policy at https://stripe.com/privacy.
8. Access, correction, deletion, and Identity choice
You may request access to or correction of account information and deletion of eligible information by contacting CoverageCases at admin@coveragecases.com. CoverageCases verifies the requester and may limit a request where preservation is required for law, security, fraud prevention, contracts, billing, disputes, professional obligations, legal assent, audit integrity, backup expiry, or a legal hold. Account closure does not cancel duties or agreements between attorneys. A request to CoverageCases does not delete a separate copy that Stripe controls for its own purposes; use Stripe's privacy-request process for that copy.
If you decline the Stripe Identity document, selfie, or biometric processing, exit the hosted flow and contact support to ask whether a legally required non-biometric alternative is available in your jurisdiction. CoverageCases does not promise ordinary manual approval. If no compliant alternative is available, the marketplace may be unavailable to you.
9. Security, incidents, and cookies
CoverageCases uses administrative, technical, and organizational safeguards appropriate to the service and information, but no system is completely secure. Users must protect credentials and promptly report suspected unauthorized access. CoverageCases maintains incident-response and legally required notification procedures.
CoverageCases and its providers use necessary session, authentication, security, fraud-prevention, and preference technologies. CoverageCases does not promise targeted advertising, sale of personal information, or unrelated cross-site profiling. Provider-hosted pages are governed by the provider's own cookie and privacy disclosures.
10. Changes
A material privacy or commercial-data change requires a new immutable version and fresh affirmative assent before affected marketplace use. Prior versions and assent records remain preserved. The document version, effective timestamp, document-set checksum, and package hash identify the exact notice accepted.
11. Affirmative acceptance and transaction evidence
CoverageCases records affirmative account, identity, legal-update, subscription, posting, and assignment acknowledgements. Evidence may include the user's opaque ID and role; the applicable transaction, subscription, posting, or assignment reference; exact document versions, document hashes, package hash, acknowledgement and button language; displayed amount, currency, billing cadence and renewal status; UTC timestamp; IP address and user agent; provider references; receipt or accepted-terms delivery; and cancellation, refund, reassent, and entitlement-change history. These records are used for contract, billing, audit, security, dispute, and compliance purposes, subject to the retention and request procedures in this Privacy Policy. Raw identity documents are not stored in the application merely to prove assent.