Privacy Policy
How SignalDraft LLC collects, uses, and protects information across signaldraft.app and studio.signaldraft.app.
Effective date: August 28, 2026
This Privacy Policy explains how SignalDraft LLC ("SignalDraft," "we," "us," or "our") collects, uses, discloses, and protects information in connection with signaldraft.app (this marketing site) and studio.signaldraft.app (the SignalDraft application, together the "Service"). It applies to visitors of this site, and to the organizations and individual users ("you") who access the Service.
This Policy should be read together with our Terms & Conditions. If there is a conflict between the two on a privacy matter, this Policy controls.
1. Scope of This Policy
SignalDraft is a B2B application: organizations we work with (integrators, dealers, and similar businesses) are our customers, and their invited users access the Service on the organization's behalf. Where an organization's users enter information about the organization's own clients or contacts (for example, under Customers or on a proposal), the organization acts as the data controller for that information and SignalDraft acts as a service provider/processor on the organization's behalf. This Policy describes our practices in both roles.
2. Information We Collect
Account and organization information. When you sign up, we set up your organization, or you accept an invitation, we collect your name, email address, and role/permissions within the organization. If your organization enables two-factor authentication, we (via Firebase Authentication) process a TOTP secret or a phone number used solely to deliver SMS verification codes. If you sign in with Google, we receive the basic profile information Google provides for authentication (name, email, account identifier).
Content you or your organization submit. This includes vendor price sheets and the catalog data extracted from them (SKUs, costs, pricing, categories), vendor and customer/client records your organization enters, labor rates, bundles, proposals and their line items, comments left on proposals, and any files or images uploaded to the Service.
Billing information. For paid subscriptions, payment card details are collected and processed directly by our payment processor, Stripe — SignalDraft does not receive or store full card numbers. We do receive limited billing metadata from Stripe (such as subscription status, plan tier, and invoice history) needed to administer your account.
Usage and log data. Like most hosted services, our infrastructure (Google Cloud Run) automatically logs standard technical data such as IP address, browser/device type, timestamps, and request paths, used for security, debugging, and reliability.
Communications. If you contact us by email (for example, for support or other inquiries), we receive whatever you send us in that message, including your email address and its content.
Cookies and analytics. This marketing website (signaldraft.app) uses Google Analytics to understand how visitors use the site — for example, which pages are viewed and how visitors arrived here. Google Analytics uses cookies and collects information such as your IP address, device and browser type, and pages visited. This applies only to this marketing website; the SignalDraft application itself (studio.signaldraft.app) does not use Google Analytics or any similar third-party analytics or advertising tool. This marketing site also sets a strictly-necessary, httpOnly session cookie only when an authorized administrator logs into the content-management panel at /admin — it is not set for ordinary visitors and is not used for tracking or advertising. Fonts are loaded from Google Fonts, which may receive your IP address as an inherent part of serving the font files.
3. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Service, including authenticating users and enforcing organization-level permissions;
- Process vendor price sheets and power features like column classification, catalog management, and proposal building;
- Process subscription billing and communicate about your account (invoices, payment failures, plan changes);
- Provide customer support and respond to inquiries;
- Send administrative and security-related communications (for example, password resets or suspicious-login alerts) via our own transactional email sending (through Resend) — we do not send marketing email without your organization's consent;
- Monitor, secure, and improve the Service, including maintaining the platform-level organization activity log used to audit account changes; and
- Comply with legal obligations and enforce our Terms & Conditions.
We do not use Your Content (Section 7 of the Terms & Conditions) to train models for the benefit of other customers, and we do not sell personal information.
5. Data Retention
We retain account and organization data for as long as your organization maintains an active subscription or account, and for a reasonable period after termination (currently up to 30 days) to allow for data export, after which it is deleted from our active systems, subject to residual copies in routine backups that are purged in the ordinary course. Billing records may be retained longer where necessary to comply with tax, accounting, or other legal obligations. Support and contact emails are retained as long as reasonably needed to resolve the matter and for our records.
6. Data Security
We maintain administrative, technical, and organizational safeguards designed to protect information, including encryption of data in transit, access controls scoped to organization and role, and optional two-factor authentication for user accounts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify affected organizations as required by applicable law.
7. Your Rights and Choices
If you are an individual user invited into an organization's SignalDraft account, many privacy choices (such as what data is entered about your organization's clients, or who has access to it) are controlled by your organization's administrators, since they control the account. Subject to that, you may:
- Ask us to confirm what personal information we hold about you and request a copy of it;
- Ask us to correct inaccurate information (or update it yourself where the Service allows self-service edits);
- Ask us to delete your personal information, subject to our legitimate need to retain certain records (for example, billing history) and our organization-account model described above;
- Object to or ask us to restrict certain processing; and
- Withdraw consent where processing is based on consent, without affecting processing that already occurred.
To exercise any of these rights, contact us at hello@signaldraft.app. We may need to verify your identity and, where the request concerns organizational data, confirm it with your organization's administrator before acting on it.
8. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (as amended) may give you additional rights, including the right to know what personal information we collect, request deletion, correct inaccuracies, and not be discriminated against for exercising these rights. We do not sell or "share" personal information as those terms are defined under California law. You can exercise these rights using the contact details in Section 7 above.
9. European Economic Area, UK, and Swiss Users
SignalDraft primarily serves customers in the United States. If you access the Service from the EEA, UK, or Switzerland, we process personal information on the following legal bases where applicable: performance of a contract (providing the Service to your organization), our legitimate interests (securing and improving the Service), compliance with legal obligations, and consent where we ask for it. You have rights to access, correct, delete, restrict, or port your personal information, and to object to certain processing, as described in Section 7. You also have the right to lodge a complaint with your local data protection authority.
10. International Data Transfers
SignalDraft's infrastructure is hosted in the United States (Google Cloud, us-central1/us-east1 regions). If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home jurisdiction. Where required, we rely on appropriate safeguards for such transfers.
11. Children's Privacy
The Service is a business tool intended for use by adults acting on behalf of a business. It is not directed to, and we do not knowingly collect personal information from, anyone under 18. If we learn we have inadvertently collected information from a child, we will delete it.
12. Third-Party Links
The Service may contain links to third-party websites (for example, a Stripe-hosted billing portal). We are not responsible for the privacy practices of third-party sites, and we encourage you to review their privacy policies before providing information to them.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Service or our practices. We will update the "Effective date" above and, for material changes, provide reasonable advance notice (such as by email to organization admins or an in-app notice) before the change takes effect.
14. Contact Us
Questions about this Privacy Policy, or requests regarding your personal information, can be sent to hello@signaldraft.app.
SignalDraft LLC