Privacy Policy

Last updated: April 2026

1. Data Controller

SaleSignal is operated as a sole-trader business based in the United Kingdom and acts as the Data Controller for personal data processed through this Service. For all data protection enquiries, contact support@salesignal.co.uk. If you are not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

2. What We Collect

We collect: your name and email address when you register; payment information processed securely by Stripe (we never store card details); usage data such as pages visited and features used; cookies for authentication and session management.

3. How We Use Your Data

Your data is used to: provide and improve the Service; send verification and transactional emails; process subscription payments; send product updates and announcements (you can unsubscribe at any time).

4. Legal Basis for Processing (UK GDPR Article 6)

We process your personal data under the following legal bases: (a) Contract — to provide the Service you signed up for, including authentication, billing, and feature access; (b) Legitimate Interests — to improve the Service, prevent fraud, and respond to support requests; (c) Consent — for non-essential analytics cookies (which we obtain via the cookie banner); (d) Legal Obligation — to comply with tax, accounting, and law-enforcement requirements.

5. Data Sharing & Sub-Processors

We do not sell your personal data. We share data only with our sub-processors: Stripe Inc. (payment processing); Resend Inc. (transactional email); Vercel Inc. (hosting and infrastructure); Neon (PostgreSQL database hosting); Anthropic PBC (AI-powered video analysis). All sub-processors are bound by Data Processing Agreements (DPAs) or equivalent contractual safeguards.

6. International Data Transfers

Some of our sub-processors are located outside the UK and EEA, primarily in the United States. Where data is transferred internationally, we rely on the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses (SCCs), or the EU-US Data Privacy Framework where applicable. Specifically: Stripe (US, DPF-certified); Vercel (US, SCCs in place); Anthropic (US, SCCs in place); Resend (US, SCCs in place); Neon (US, SCCs in place).

7. Cookies

We use essential cookies for authentication (ss_auth, ss_plan, ss_email) that are required for the Service to function — these are set under the Contract legal basis and do not require consent. Any non-essential cookies (e.g. analytics) are only set after you provide consent via our cookie banner.

8. Data Retention

We retain your account data for as long as your account is active. After account closure or a deletion request, we delete personal data within 30 days, except where we are required to retain it for tax, legal, or fraud-prevention purposes (typically up to 6 years for billing records, per HMRC requirements).

9. Your Rights (UK GDPR)

If you are in the UK, EU, or EEA, you have the right to: access the personal data we hold about you (Subject Access Request); correct inaccurate data; request deletion of your data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. Contact support@salesignal.co.uk to exercise these rights — we will respond within one calendar month.

10. Security

We use industry-standard security measures including TLS 1.2+ HTTPS encryption, bcrypt-hashed passwords (cost factor 12), HTTP-only secure cookies, server-side rate limiting on authentication endpoints, and signed webhook verification. No method of transmission over the internet is 100% secure, but we take reasonable precautions.

11. Children

SaleSignal is not directed to children under 18 and we do not knowingly collect data from children. If we discover we have collected data from a child, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 14 days before they take effect. Your continued use of the Service after the change constitutes acceptance.

13. Contact

For privacy enquiries, data subject requests, or to lodge a complaint, contact us at support@salesignal.co.uk. UK residents may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.

SaleSignal · support@salesignal.co.uk · salesignal.co.uk