SignalSend

Legal

Privacy Policy

Effective 2 August 2026

This policy explains how SignalSend processes personal data through our website and signal-based outbound sales service. SignalSend is operated by TRANSCEND FZCO, at IFZA Business Park, Building A2, Dubai Silicon Oasis, Dubai, United Arab Emirates. For privacy questions or a data request, contact hello@signalsend.app.

Who this policy covers

This policy covers website visitors, prospective and current customers, authorised workspace users, people who contact us, and business professionals whose information may appear in SignalSend as a contact or opportunity.

For account, website, security and service-administration data, SignalSend determines why and how the data is processed. When a customer uploads personal data or instructs SignalSend to process it for the customer's own outreach, the customer generally determines the purpose and means of that processing and SignalSend processes the data to provide the service. Where SignalSend independently determines the sources and purposes used to build or verify professional contact and signal data, SignalSend may have separate responsibilities. The precise role can depend on the feature, data source and applicable law.

Data we collect, why, and the bases we rely on

Accounts and access

We process names, business email addresses, company and workspace details, password hashes, role and permission records, authentication events and support communications to create accounts, administer workspaces, provide support and protect the service. Depending on the context, we rely on performing our contract, our legitimate interests in operating and securing SignalSend, and legal obligations.

Business contacts, companies and intent signals

Contact data may include a professional's name, role, employer, business email, public professional profile URL, profile image URL, source details and public professional or company activity. Opportunity data may include company changes, hiring, funding, technology, market activity and our inferences about relevance or timing. We use this information to identify and assess B2B opportunities, verify business contact details, explain why a company may be relevant and support customer-authorised outreach.

This data may come from our customers, public professional and business sources, company websites, APIs, integrations and specialist enrichment or verification providers. We record available source and collection details with enriched contacts. Public availability does not by itself mean information can be used for every purpose; customers must independently determine whether their intended collection, targeting and communication are lawful. Depending on the processing and the bases recognised by applicable law, processing may rely on consent, contractual necessity, information deliberately made public by the person, a customer's documented instructions, an existing business relationship or legitimate interests in proportionate B2B business development.

Workspace content and generated output

We process customer prompts, strategy inputs, radars, uploaded or saved records, opportunity notes, generated drafts, approval decisions, messages, replies and performance outcomes to provide the requested research, drafting, workflow and reporting features. AI and third-party data can be incomplete or wrong, so customers must review source evidence, recipient selection and generated output before relying on it.

Billing, usage and technical data

We process plan, subscription and billing-reference data needed to provide paid features, administer accounts and meet financial obligations. Our merchant-of-record billing provider processes payment details through hosted checkout; SignalSend does not store complete payment-card details. We also process product usage, device and request information, necessary session cookies, audit events, error records and abuse signals to operate, improve and secure the service.

Submitted company websites

When a visitor submits a company website through a SignalSend landing-page form, we retain the canonical public website URL, the SignalSend page and form placement used, submission timestamps and count, and limited first-touch attribution such as source, medium, campaign and referring hostname. The capture record does not include an email address, visitor account, raw IP address, user agent or full referring URL. We use these records to understand demand, reduce duplicate submissions and evaluate which landing pages and campaigns are useful, relying on our legitimate interests in operating and improving SignalSend.

First-party product analytics

SignalSend records a limited first-party onboarding funnel to understand whether account setup works and where it needs improvement. These operational events contain the account identifier, event type, onboarding step number, an optional step duration and timestamp. We also retain the account's first-touch campaign tags, advertising click identifier where supplied, landing path, and referring hostname so aggregate reports can compare paid, organic, referral and direct cohorts. They do not contain the website entered during setup, company or strategy content, lead or contact details, message content, or payment details. Admin reports expose aggregated counts, rates and average duration. This first-party measurement operates independently of the optional third-party analytics choice below and is used for our legitimate interests in operating and improving the service.

Optional product analytics

We use Google Analytics 4 to understand visits and product usage and Hotjar to understand product experience, such as navigation patterns, so we can improve SignalSend. Google and Hotjar may process device, interaction and approximate-location information for this purpose. During our initial test, visitors identified as being in the EU or EEA, the United Kingdom, or Switzerland are asked for permission before these tools load. Their choice is stored in their browser and can be changed using the preference control below. When a visitor's location cannot be determined, we also require permission. For visitors identified as being outside this region, these tools load automatically. SignalSend does not use them for advertising.

Meta Pixel and advertising

We use the Meta Pixel and, when configured, Meta's server-side Conversions API, subject to the analytics preference described above, to measure visits, verified trial activations and paid subscription conversions, attribute advertising results, create audiences of people who interact with SignalSend, and optimise advertising on Meta technologies such as Facebook and Instagram. Browser and server copies use the same event identifier so Meta can deduplicate them. Meta may receive page, device, browser, IP-address, cookie or advertising-click-identifier information and the limited advertising event recorded. We do not send Meta customer-uploaded contacts, message content, payment-card details, billing-provider customer identifiers, or Google user data through these events.

Meta processes this information under its own terms and privacy policy and may combine it with information associated with a Facebook or Instagram account. Depending on where you live, this activity may be considered targeted advertising, cross-context behavioural advertising, or sharing of personal data. You can change your preference below, manage how Meta uses advertising information through Meta's ad preferences, use browser controls to block or delete cookies, or use applicable industry opt-out tools such as YourAdChoices and Your Online Choices.

Customer responsibilities for contact data and outreach

Customers control their campaigns and are responsible for the contact data, targeting instructions, lawful basis, notices, sender identity, content, timing and automation settings they use. A customer must have the right to provide personal data to SignalSend and instruct us to process it; must not treat a public profile or provider result as automatic permission to contact someone; and must comply with applicable privacy, ePrivacy, direct-marketing, communications, advertising and consumer-protection rules.

Customers must keep their sender and business details accurate, review data and AI output for material errors, honour objections and unsubscribe requests, maintain and import relevant suppression records, and promptly tell us about rights requests or restrictions that affect data processed through their workspace. SignalSend's verification, review, suppression, pacing and audit controls assist customers but do not replace their own assessment. These responsibilities are contractual requirements under our Terms of Service and Acceptable Use Policy.

How we use and disclose data

We use personal data to provide and secure SignalSend, manage accounts and billing, research and score business opportunities, enrich and verify contacts, generate and send customer-authorised communications, detect replies and opt-outs, provide support, comply with law and improve service reliability. We may create aggregated or de-identified statistics that are not intended to identify a person.

We do not sell personal data for money. As described above, our use of the Meta Pixel for advertising may be treated as sharing, targeted advertising, or cross-context behavioural advertising under some laws. We otherwise disclose data only as needed to customers and their authorised workspace users; service providers that host, secure, support or help deliver SignalSend; integrations a customer chooses to connect; professional advisers; a successor in a corporate transaction; or public authorities and other parties where disclosure is legally required or necessary to protect rights and safety. Providers must process data under appropriate contractual and confidentiality restrictions.

Google user data

If you connect Gmail, SignalSend requests permission to send messages from your account and read Gmail threads associated with SignalSend outreach. We use that access only to send messages you approve or authorize through your automation settings, detect replies, stop scheduled follow-ups, and maintain the related conversation context. We store the connected email address, encrypted OAuth tokens, Gmail message and thread identifiers, and the message content needed to display and continue those conversations.

We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. We do not transfer it to third parties except service providers acting for us where necessary to provide or secure SignalSend, comply with law, or complete an action you explicitly request. Human access is prohibited except when you give specific support consent, it is necessary for security or abuse investigation, or law requires it. SignalSend's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

You can disconnect Gmail in Integrations at any time. Disconnecting removes the stored OAuth tokens and stops sending and automatic reply detection. Account deletion removes the connected-channel data held by SignalSend, subject to narrowly applicable legal or security retention duties.

Suppliers and international transfers

We use service providers to run SignalSend, including Google for connected Gmail services, our merchant-of-record provider for billing, AI model providers for analysis and drafting, hosting and database providers, and Enrich.so for business-contact enrichment and verification. Some processing may occur outside your country, including in the United States and, for Enrich.so, the United Arab Emirates. We use contractual and other appropriate safeguards where required.

Retention

Unused prospect records and anonymous company-website submissions are scheduled for deletion after 180 days. First-party onboarding events are scheduled for deletion after 365 days. Records connected to messages, replies, security, billing or legal obligations may be retained longer where needed to provide the service, resolve disputes or meet legal requirements. Account deletion removes the account and workspace records held by SignalSend, including contacts, message threads, analytics, jobs, audit records, connected-channel credentials and local billing references. As a narrow exception, a suppression record containing the suppressed email address or domain, the reason and source, and retention metadata may be retained after account deletion only to preserve prior opt-outs, complaints, hard bounces and do-not-contact choices.

Your choices and rights

You can export or delete your account from Settings. Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal data, correct inaccurate data, request deletion, restrict or object to processing, receive portable data, withdraw consent, opt out of certain sale, sharing or targeted-advertising uses, appeal a rights decision, and complain to a regulator. SignalSend will not discriminate against you for exercising an applicable privacy right.

Use our opt-out and privacy request form to opt out of SignalSend-facilitated outreach or submit a rights request. Requests submitted through the public form require inbox verification before an opt-out or data-rights action is applied. A signed unsubscribe link included in a SignalSend-facilitated message applies a service-wide opt-out immediately. We do not confirm through either path whether a person was already in our data. A limited suppression record may be retained to ensure an opt-out is not reversed by future enrichment.

Security, children and changes

We use access controls, encryption for supported credentials, rate limits, audit records and monitoring designed to protect data. Customers and users are responsible for safeguarding their credentials and promptly reporting suspected compromise. No service can guarantee absolute security. Where applicable law requires it, we will notify affected people or authorities of a qualifying breach.

SignalSend is a business service and is not intended for children. Customers must not use it to research or contact children or to process special-category or similarly sensitive personal data.

We may update this policy and will identify the effective date above. Material changes will be communicated by email, in-product notice or another appropriate channel where required.