Legal
Privacy Policy
Last updated: July 6, 2026
This Policy explains how Signalify processes information across its website, accounts, review collection pages, imports, widgets, analytics, trials, billing, and related services.
Who this Policy applies to
This Privacy Policy explains how the operator of Signalify processes personal data when you visit signalify.io, create or use a Signalify account, start a trial, purchase a subscription, submit a review, interact with a public review page or widget, or contact us.
For account, billing, security, product-usage, and website data, Signalify generally acts as the data controller. For review and testimonial content processed on behalf of a Signalify customer, the customer generally acts as the controller and Signalify acts as its processor. More detail is available in our Data Processing Agreement.
The legal identity and contact details of the operator are available in Signalify’s Legal Notice. Privacy questions may be sent to hello@signalify.io.
Information we collect
Account and authentication data
Name or display name, email address, account identifiers, authentication records, account preferences, project membership, and security-related account information.
Reviews, testimonials, and customer content
Review or testimonial text, reviewer name or display name, rating, date, optional photo or external image URL, image description, visibility status, tags, project and widget configuration, and related moderation information.
Public review submissions and request activity
Information submitted through public review forms, including optional photos, and limited activity data used to provide review-request statistics, such as review-page visits and completed submissions.
Imported review data
CSV data and manually entered testimonials, import source, source URL, import batch identifier, external image URL, date, tags, and duplicate-detection information. Signalify does not fetch a source URL merely because it is stored.
Billing, subscription, and trial data
Stripe customer and subscription identifiers, selected plan and interval, subscription status, renewal and cancellation dates, trial eligibility and trial-usage records, and whether a payment method is available. Signalify does not store complete card numbers or card security codes.
Technical, security, and usage data
Device and browser information, approximate location derived by infrastructure providers, request and error logs, pages or features used, referral information, and security events. IP addresses may be processed transiently by hosting and security infrastructure to deliver and protect the Service.
Widget and website analytics
Privacy-conscious events such as widget views, form opens, review submissions, last activity, page visits, referrers, and campaign parameters. Powered-by links may include the widget type in UTM parameters, but are not designed to include project IDs, widget keys, reviewer details, or other directly identifying customer data.
Support and communications
Messages, attachments, and contact details you provide when requesting support, reporting a problem, or otherwise communicating with Signalify.
How we use personal data
- Create, authenticate, secure, and administer accounts.
- Provide projects, review collection, imports, widgets, public pages, Smart Display, analytics, and other requested functionality.
- Process subscriptions, invoices, payments, trials, renewals, cancellations, and plan entitlements.
- Prevent duplicate trials, fraud, abuse, unauthorised access, and circumvention of plan limits.
- Provide customer support and respond to requests.
- Monitor reliability, diagnose errors, maintain security, and improve usability and performance.
- Send important service, security, billing, and legal notices.
- Measure how Signalify and its embedded widgets are used, including referrals from “Powered by Signalify” links.
- Comply with legal obligations and establish, exercise, or defend legal claims.
Legal bases under the GDPR
Where the GDPR applies, we rely on one or more lawful bases depending on the activity.
- Contract: to create and operate your account, provide the Service, administer trials, and supply paid features.
- Legitimate interests: to secure and improve Signalify, prevent fraud and duplicate trials, measure product performance, provide support, and understand referrals, where those interests are not overridden by your rights.
- Legal obligation: to keep required tax, accounting, transaction, compliance, and security records.
- Consent: where required for optional communications or technologies that are not strictly necessary. You may withdraw consent at any time without affecting earlier lawful processing.
Customer-controlled review content
Signalify customers decide which reviews and testimonials they collect, import, approve, publish, tag, or display. For this content, the customer is generally responsible for providing privacy notices, establishing a lawful basis, obtaining any required permissions, and responding to reviewer requests.
If your personal data appears in a widget or public review page operated by a Signalify customer, contact that customer first. Signalify will reasonably assist the customer with valid data-subject requests where technically possible.
Reviews marked visible may be publicly accessible through widgets, public pages, or customer websites. Public content may be copied, indexed, or cached by third parties outside Signalify’s control.
Imports and external content
Customers may import reviews from ecommerce tools, testimonial platforms, Google, social platforms, CSV files, or other sources. The customer is responsible for having the right to export, import, store, and republish that content.
Imported image URLs may remain hosted by the original provider. When a visitor loads a widget containing such an image, the third-party host may receive ordinary request information under its own privacy practices.
Source names and icons identify the source selected or supplied during import. They do not mean Signalify independently verified the review, reviewer, or original platform record.
Sharing and service providers
We do not sell personal data. We share information only where reasonably necessary to provide, secure, support, and administer Signalify, or where required by law.
- Supabase: authentication, database, storage, and backend infrastructure.
- Vercel: hosting, deployment, application delivery, performance monitoring, and Web Analytics.
- Stripe: checkout, payment processing, subscriptions, invoices, trials, fraud prevention, and Customer Portal services. Stripe may act as our processor and as an independent controller for certain regulated payment activities.
- Professional advisers, authorities, or counterparties where reasonably necessary for legal compliance, security, corporate transactions, or the protection of rights.
Cookies, local storage, and analytics
Signalify uses essential cookies or similar storage where needed for authentication, security, account sessions, preferences, and core functionality.
We use Vercel Web Analytics and may use Vercel Speed Insights to understand website traffic and performance. Vercel describes Web Analytics as cookieless and based on anonymised data. Signalify also records limited first-party widget events such as views, form opens, and submissions.
We do not use advertising cookies or behavioural advertising tools unless this Policy and any required consent interface are updated first.
Data retention
Account and customer content is generally retained while the account or relevant project remains active and until it is deleted by the customer or through an account-deletion request.
Subscription, invoice, transaction, and tax records may be retained for the periods required by law. Minimal trial-usage records may be retained as reasonably necessary to enforce the one-trial-per-user rule and prevent abuse.
Security logs, analytics, support records, backups, and deleted-content remnants may be retained for limited periods based on operational, security, fraud-prevention, and legal needs.
When retention is no longer required, information is deleted, anonymised, or securely isolated from ordinary use. External images and content hosted by third parties must be removed from the original source separately.
International transfers
Signalify and its providers may process data in countries outside your own, including outside the European Economic Area. Where required, we rely on an adequacy decision, approved Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, or another recognised transfer safeguard.
Information about transfer mechanisms used by our providers is available in their legal and privacy documentation.
Security
We use reasonable technical and organisational measures designed to protect personal data, including managed infrastructure, transport encryption, authentication, access controls, project-level permissions, restricted administrative access, database security policies, and monitoring.
No system can guarantee absolute security. You are responsible for securing your credentials, limiting account access, and configuring public visibility appropriately.
Your privacy rights
Depending on applicable law, you may have rights to access, correct, erase, restrict, or receive a copy of your personal data; object to certain processing; and withdraw consent. You may also have the right to complain to a supervisory authority.
Send requests concerning Signalify-controlled account or operational data to hello@signalify.io. We may need to verify your identity. For review content controlled by a Signalify customer, we may direct the request to that customer.
In Slovenia, complaints may be submitted to the Information Commissioner of the Republic of Slovenia. You may also contact the supervisory authority in the country where you live or work.
Children
Signalify is a business service and is not directed to children. Do not use the Service to knowingly collect children’s personal data unless you have a valid legal basis and all protections required by applicable law.
Changes to this Policy
We may update this Policy to reflect product, legal, security, or operational changes. We will revise the “Last updated” date and provide additional notice where a change is material and applicable law requires it.
Contact
For privacy, deletion, or data-protection questions, contact hello@signalify.io. The operator’s legal identity and business contact details are available in Signalify’s Legal Notice.