Signal Sparrow

Legal

Data Subject Requests & Opt-Out

Effective date: 7 July 2026  |  Last updated: 7 July 2026

1. About this page

This page explains how to submit a request about personal data that Signal Sparrow LTD ("Signal Sparrow," "we," "us"), may process — including access, correction, deletion, and California's opt-out of sale/sharing right — and how we verify and respond to such requests. It supplements our Privacy Policy.

This page is provided for informational purposes and does not constitute legal advice. If you have questions about your specific rights or obligations, please consult a qualified attorney.

2. Our two roles: controller and processor

Which process applies to your request depends on whose data is involved and what role we play, as described in Section 2 of our Privacy Policy:

  • We are a controller for our own customers' account, billing, and support data — the people who sign up, log in, and pay for the Service.
  • We are a processor for the data our customers collect from their own website visitors using our tracking SDK (visitor identifiers, click IDs, hashed emails, hashed IP addresses). Our customer is the controller of that data.

3. If you are a visitor or end-user of a Signal Sparrow customer

If you interacted with a website or app that uses the Signal Sparrow tracking SDK, the operator of that website — our customer — is the controller responsible for your data and is your primary point of contact. They decide what is collected, for what purpose, and under what consent settings.

  1. Submit your request directly to the website owner or business whose site you visited — not to Signal Sparrow.
  2. If that business determines Signal Sparrow holds data relevant to your request, they can ask us to locate, export, or delete it. The Service includes tools that let our customers export or delete an individual visitor’s data themselves.
  3. If you contact us directly about end-user data, we will identify the responsible customer where we can and refer you to them; we will not act on the request ourselves without instruction from the controller, except where required by law.

4. If you are a Signal Sparrow account holder or business contact

If you have a Signal Sparrow account, or you are a business contact whose data we hold directly (for example, billing contact information or a support conversation), email [email protected] with the subject line "Data Subject Request." Please include:

  • Your full name.
  • The email address associated with your Signal Sparrow account or your correspondence with us.
  • Your organization name, if applicable.
  • A clear description of the request (access, rectification, erasure, restriction, portability, or objection).
  • Your country or state of residence, so we can apply the correct legal framework.

5. Rights you may have

Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, and comparable privacy laws), and as described more fully in Sections 10 and 11 of our Privacy Policy, you may have the right to:

  1. Access — request a copy of the personal data we hold about you.
  2. Rectification / correction — ask us to correct inaccurate or incomplete data.
  3. Erasure / deletion — ask us to delete your personal data, subject to certain legal exceptions.
  4. Restriction — ask us to limit how we use your data.
  5. Data portability — receive your data in a structured, commonly used format.
  6. Objection — object to processing based on legitimate interests or direct marketing.
  7. Withdraw consent — where we rely on consent, withdraw it at any time.
  8. Opt out of sale or sharing — see Section 6; we do not currently sell or share personal information, so there is nothing to opt out of, but we honor the mechanism below.

6. California: opt-out of sale/sharing and other CPRA rights

We do not sell or share personal information (as those terms are defined by the CPRA) and we do not engage in cross-context behavioral advertising. Because no sale or sharing occurs, there is no "Do Not Sell or Share My Personal Information" toggle to activate — but if you would like written confirmation that your information has not been sold or shared, or wish to exercise any other CPRA right (know, delete, correct, limit use of sensitive personal information), email [email protected] with the subject line "California Privacy Request."

You may designate an authorized agent to submit a request on your behalf; the agent must provide signed written authorization, and we may still contact you directly to confirm the request.

If we decline a California request, you may appeal by emailing us within one month of our decision. Full detail on the categories of personal information we collect, our purposes, and your CPRA rights is in Section 11 of our Privacy Policy.

7. Verification and timeline

Before acting on a request, we may ask you for additional information to verify your identity, or to verify your authority to act on someone else's behalf. This protects against fraudulent requests made in another person's name.

We aim to respond to a verified, complete request within one month (30 days) of receiving it. If a request is complex or we receive a high volume of requests, we may extend this by up to two further months; if so, we will tell you within the first month and explain why.

8. How we handle a request

  1. Reception — we confirm whether the request falls within our role as processor or controller for the data involved, using Section 2 above.
  2. Referral where applicable — if you are an end-user of a customer’s site, we identify the responsible customer and refer you to them where we are not able to act directly.
  3. Identification — for requests within our scope, we search our systems (account records, billing records, support logs, and, where instructed by a customer, tracked event data) for responsive records.
  4. Compilation and review — we compile responsive data and confirm, where we act as a processor, that fulfilling the request is consistent with our contractual obligations to the relevant customer.
  5. Response — we provide the requested information (typically as CSV or JSON), confirm correction, or confirm deletion/anonymization, subject to the exceptions in Section 9.

9. Exceptions and limitations

  • We may deny or limit a request where fulfilling it would infringe on another person’s rights, violate a legal obligation, or where the request is manifestly unfounded or excessive.
  • Some data must be retained to meet legal, tax, accounting, security, or dispute-resolution obligations even after an erasure request. Our standard retention periods are set out in Section 9 of our Privacy Policy — for example, billing and tax records are kept 7 years, and security logs 24 months.
  • Where we act as a processor for a customer, we may need that customer’s instruction before deleting or exporting end-user data, and we will tell you if that is the case.

10. Supervisory authorities

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO); in the EU, you may contact the data-protection authority in your country of residence or habitual work; in California, you may contact the California Privacy Protection Agency.

11. Related pages

  • Privacy Policy — full detail on what we collect, our legal bases, retention periods, and your rights.
  • Cookie Policy — cookies used on our site, in the app, and by our tracking SDK.
  • Data Processing Agreement — how we process Customer Personal Data as a processor.

12. Contact us

For DSAR inquiries, verification steps, or any question about this process:

We are not currently required to appoint a Data Protection Officer (DPO) under the GDPR. Privacy requests are handled directly by the business owner.

13. Disclaimer

This page does not constitute legal advice. It is intended to explain how Signal Sparrow handles data subject requests and opt-out requests. If you have questions about your legal rights or obligations, please consult an attorney experienced in data protection law.