← Back to home

Legal

Privacy Policy

Last updated: September 2026

1. Who we are

Signal ("we", "us") provides client analytics dashboards for ecommerce agencies at signalanalytics.app. For questions about this policy, contact [email protected].

2. Data we collect

  • Account data — your name, email address and password hash when you sign up, plus workspace and team membership details.
  • Integration credentials — API keys and tokens you paste for client projects (Shopify, TripleWhale, Klaviyo, PostHog, Google Analytics). These are encrypted with AES-256-GCM before storage and are never displayed back in full.
  • Analytics data — metrics fetched on your behalf from connected integrations (orders, revenue, traffic, campaign performance) used solely to render your dashboards and caches.
  • Billing data — plan, subscription status and invoices. Card payments are processed by Stripe; we never see or store full card numbers.
  • Usage data — basic technical logs (pages visited, error diagnostics) to operate and secure the service.

3. How we use it

To provide and maintain your dashboards, authenticate you, process subscriptions, offer support, and improve reliability. We do not sell personal data, and we do not use your client data for advertising.

4. Sharing

We share data only with the processors needed to run Signal: Cloudflare (hosting, database, cache), Stripe (billing), and the integrations you connect. Public share links expose only the dashboard data for that project to anyone holding the link — treat links as sensitive.

5. Retention & deletion

Workspace data is kept while your account is active. Delete a project to remove its credentials, settings and cached reports. Delete your account (contact us) and we remove your personal data within 30 days, except where law requires retention (e.g. invoices).

6. Security

Credentials are encrypted at rest, traffic is TLS-encrypted, and access is gated by workspace roles. No system is impenetrable — report concerns to [email protected].

7. Your rights

Depending on your jurisdiction (including UK GDPR / EU GDPR rights), you may request access, correction, export, or deletion of your personal data, and object to or restrict processing. We respond within one month.

8. Changes

We may update this policy as the product evolves; material changes will be announced in-app or by email. Continued use after changes take effect constitutes acceptance.