Legal
Privacy Policy
Effective 21 July 2026
This policy explains how SignalSend processes personal data when you use our signal-based outbound sales service. SignalSend is the name used for the service. For current operator details or privacy questions, contact privacy@signalsend.ai.
Data we process
We process account and workspace details, authentication and security records, billing status, connected-channel credentials, product usage, prompts and generated content, and the business contact data and opportunity information you ask us to research or store. Contact data may include a person's name, business role, employer, business email, public professional profile URL and profile image URL.
How we obtain contact data
Contact data may come from our customers, public business sources, company websites and specialist data suppliers. We record available source and collection details with enriched contacts. We do not use profile images for facial recognition or to infer sensitive characteristics.
Why we use data
We use data to provide and secure the service, find and assess relevant business opportunities, enrich and verify business contact details, draft and send customer-authorised communications, detect replies and opt-outs, provide support, comply with law and improve service reliability. Customers remain responsible for selecting a valid legal basis and complying with the laws that apply to their outreach.
Google user data
If you connect Gmail, SignalSend requests permission to send messages from your account and read Gmail threads associated with SignalSend outreach. We use that access only to send messages you approve or authorize through your automation settings, detect replies, stop scheduled follow-ups, and maintain the related conversation context. We store the connected email address, encrypted OAuth tokens, Gmail message and thread identifiers, and the message content needed to display and continue those conversations.
We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. We do not transfer it to third parties except service providers acting for us where necessary to provide or secure SignalSend, comply with law, or complete an action you explicitly request. Human access is prohibited except when you give specific support consent, it is necessary for security or abuse investigation, or law requires it. SignalSend's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect Gmail in Integrations at any time. Disconnecting removes the stored OAuth tokens and stops sending and automatic reply detection. Account deletion removes the connected-channel data held by SignalSend, subject to narrowly applicable legal or security retention duties.
Suppliers and international transfers
We use service providers to run SignalSend, including Google for connected Gmail services, Polar for billing, AI model providers for analysis and drafting, hosting and database providers, and Enrich.so for business-contact enrichment and verification. Some processing may occur outside your country, including in the United States and, for Enrich.so, the United Arab Emirates. We use contractual and other appropriate safeguards where required.
Retention
Unused prospect records are scheduled for deletion after 180 days. Records connected to messages, replies, suppression decisions, security, billing or legal obligations may be retained longer where needed to provide the service, honour opt-outs, resolve disputes or meet legal requirements. Suppression records are retained so an opted-out person is not contacted again.
Your choices and rights
You can export or delete your account from Settings. Depending on where you live, you may also have rights to access, correct, erase, restrict or object to processing, and to data portability or to complain to a regulator. Contact us to exercise a right. We may need to verify your identity.
Security and changes
We use access controls, encryption for supported credentials, rate limits and audit records designed to protect data. No service can guarantee absolute security. We may update this policy and will identify the effective date above; material changes will be communicated in the service where appropriate.