1. Scope
This Privacy Policy describes how SignalGate("we," "us") handles personal data we collect directly when you visit signalgate.ai, sign up for the dashboard, contact us, or otherwise interact with our marketing and customer-facing surfaces.
It does not cover how we process personal data on behalf of our customers (that is governed by the Data Processing Addendum). If you reached this page after encountering the SignalGate SDK on a third-party site, contact that site directly — they are the data controller in that relationship.
2. What we collect
Account data
When you sign up: name, email address, and password (stored as a salted hash). If you set a workspace name, company name, title, or timezone in your profile, we store those too.
Browser fingerprint signals (dashboard users)
When you sign in or sign up via the dashboard, the SignalGate SDK runs in your browser and collects non-PII device signals — GPU renderer string, screen resolution, user-agent, timezone, and similar attributes — to generate a fraud-risk assessment for the login event itself (the same service we provide to our customers). These signals are encrypted in-browser before transmission and processed solely for fraud prevention.
Contact and newsletter data
Name, email address, and the message body you submit via the contact page. Email address only if you subscribe to our newsletter.
Technical data
IP address, user-agent, referrer URL, and pages visited, recorded in server access logs. Authentication tokens are stored in your browser's localStorage — see our Cookie Policy for details.
Analytics and advertising measurement
We load two third-party tags:
- Google Ads conversion tag (Google LLC), across the whole site — measures whether visits that arrive from our ads lead to sign-ups. It sets
_gcl_*cookies and reads thegclidURL parameter that Google appends to ad clicks. It does not record sessions. - Yandex Metrica (Yandex), on our public pages only — never inside the signed-in dashboard — product analytics, including clickmaps and Webvisor session replay (recordings of page interactions such as scrolling, clicks, and mouse movement). It sets
_ym_uid,_ym_d, and related_ym_*cookies.
See the Cookie Policy for the full list of what each tag stores.
What we do not collect
- No advertising or tracking pixels beyond the Google Ads conversion tag and Yandex Metrica described above — in particular, no Facebook pixel.
- No data purchased from data brokers.
- No payment card numbers — billing is handled by a third-party payment processor, which is subject to its own privacy policy.
3. Why we use it
- Providing the service — creating accounts, authenticating logins, sending transactional emails (verification, password reset), billing, and customer support.
- Fraud prevention on our own platform — using the fingerprint signals collected at login to detect credential stuffing and account takeover attempts on signalgate.ai itself.
- Communication — responding to contact-form submissions and, with your consent, sending the newsletter. You can unsubscribe at any time via the link in any marketing email.
- Analytics and advertising measurement — understanding how visitors use the site (Yandex Metrica, including session replay) and measuring which ad campaigns lead to sign-ups (Google Ads conversion tag).
- Legal and compliance obligations — retaining records required by law (e.g. invoices).
We do not sell your personal data. We measure ad-campaign conversions via a Google Ads tag, and analyse product usage via Yandex Metrica, as described in section 2.
5. Retention
- Account data — kept while your account is active and for a reasonable period after deletion for legal and accounting purposes, then purged.
- Access logs — retained for a short rolling window for security purposes.
- Contact messages — kept until the inquiry is resolved and for a reasonable period afterwards.
- Newsletter list — retained until you unsubscribe.
As a general guide: account and billing records are kept for up to 12 months after your account closes; access and event logs for up to 12 months; and contact messages for up to 24 months. We may keep limited records longer where the law requires it.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, or to restrict or object to certain processing. To exercise any of these rights, email [email protected]. We will respond within the timeframe required by applicable law.
You may also lodge a complaint with your local data-protection authority. EU residents can find their authority at edpb.europa.eu.
7. Security
We use TLS in transit, encryption at rest, hashed passwords, and least-privilege access controls. See our Security Overview for details. No system is perfectly secure; in the event of a personal-data breach we will notify affected users and relevant authorities without undue delay as required by law.
8. Children
SignalGate is a B2B service not directed at children under 16 (or the lower age set by local law). We do not knowingly collect personal data from children. If you believe a child has submitted data, contact us and we will delete it promptly.
9. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the current edition. Material changes will be communicated to active customers by email before they take effect.
10. Contact
Privacy questions or rights requests: [email protected].
For written correspondence, email us first at the address above and we will provide a postal address on request.
If a local law requires SignalGate to designate an EU or UK representative, their details will be published here.