Legal
Privacy Policy
Effective date: 29 June 2026 | Last updated: 29 June 2026
1. Who we are
Signal Sparrow LTD is a conversion-tracking and revenue-attribution platform ("Signal Sparrow," "we," "us"). Our website is signalsparrow.com (the "Service").
For questions about this Privacy Policy or your personal data, contact:
- Email: [email protected]
- Address: 16 Humberstone Close, Luton, England, LU4 9ST
2. Our two roles: controller and processor
Our role under data-protection law (including the EU GDPR, UK GDPR, and comparable laws) depends on whose data is involved.
We are a data controller for personal data of our customers — the account holders who sign up, log in, and pay for the Service. We decide how and why this data is processed.
We are a data processor for the data our customers collect from their own website visitors using our tracking tools (such as visitor identifiers, click IDs, email addresses passed via our SDK, and IP addresses). Our customer is the controller of that data; we process it only on their documented instructions, governed by our Data Processing Agreement (Section 15).
3. Data we process as a controller (our customers)
When you create and use a Signal Sparrow account, we process the following categories of personal data:
- Account data: name, email address, password (hashed), organization details (company name, website, country, company size), and team role.
- Billing data: subscription plan, billing status, invoice history, and payment records. Payments are processed by Stripe, Inc.; we do not store full card numbers.
- Connection data: OAuth tokens, account identifiers, and configuration details for the third-party services you connect (Stripe, Meta, Google Ads, Google Analytics 4, TikTok, LinkedIn), stored encrypted at rest.
- Communication data: emails or messages you send to support, onboarding responses, and product feedback.
- Usage and technical data: IP address, browser/device information, session and activity logs, and how you interact with the Service, used for security, debugging, and product improvement.
4. Legal bases for processing (GDPR / UK GDPR)
We process controller data only where we have a valid legal basis. The table below sets out the main purposes, data involved, and the lawful basis we rely on.
| Purpose | Data | Legal basis |
|---|---|---|
| Provide and manage your account and the Service | Account data, organization details, connection data | Performance of contract |
| Process payments, invoices, and tax records | Billing data, transaction history | Legal obligation and performance of contract |
| Secure the Service, prevent fraud, and enforce terms | IP address, device data, logs, account activity | Legitimate interests (security and fraud prevention) |
| Improve, maintain, and troubleshoot the Service | Usage data, error logs, product feedback | Legitimate interests (product development and reliability) |
| Send product updates, marketing, or newsletters | Email address, name | Consent, where required by law; otherwise legitimate interests with opt-out |
| Comply with legal or regulatory requests | Data required by the request | Legal obligation |
Where we rely on legitimate interests, those interests are maintaining a secure and reliable service, understanding how customers use the Service, and preventing abuse. You may object to processing based on legitimate interests at any time (see Section 12).
5. Data we process as a processor (end-users of our customers' sites)
On behalf of our customers, our tracking technology collects data from visitors to our customers' websites. Depending on the customer's configuration and the visitor's consent settings, this may include:
- Tracking identifiers: an anonymous visitor identifier we generate, stored via first-party cookie or local storage.
- Click and campaign data: advertising click identifiers (such as fbclid, gclid, ttclid, msclkid) and UTM parameters present in the URL.
- Session context: landing page, referrer, coarse device information, and timestamps.
- IP address: processed transiently and immediately transformed into a one-way hash before storage. We do not retain raw IP addresses at rest.
- Identifiers passed by the customer: where the customer's site calls our identify function, an email address or user ID, stored encrypted and matched using a keyed hash.
- Conversion data: revenue event type, amount, currency, and associated identifiers, as provided by the customer's connected Stripe account.
We process this data only on the documented instructions of our customer, except where required by applicable law, in order to provide attribution, conversion tracking, and event-forwarding services. The customer determines what is collected, sets the consent mode, and is responsible for obtaining any required consent from their visitors. If you are an end-user with questions about this data, contact the website operator (our customer) who is the controller; we will assist them in responding.
6. Cookies and similar technologies
Our tracking tool uses a first-party cookie (default name __rpv) and a local-storage fallback to maintain an anonymous visitor identifier. The cookie has a maximum lifetime of approximately 13 months and is refreshed on each tracked interaction where persistence is allowed.
Our customers choose how tracking behaves before a visitor grants consent:
- Anonymous-only mode (default): no cookie or personal data is stored before consent; data is enriched only after consent is granted.
- Hold-until-consent mode: nothing is stored until the customer's consent management platform signals consent.
On signalsparrow.com itself, we do not use advertising or analytics cookies. We use:
- Essential cookies: session and authentication cookies, plus a sidebar-state preference cookie (sidebar_state).
- Font delivery: we load Inter from Google Fonts and General Sans from Fontshare. Those providers may receive your IP address and browser headers when serving font files. Font requests are made directly between your browser and the font provider.
Responsibility for obtaining valid consent for customer-site tracking, and for displaying any required cookie notice, rests with our customer as the controller of their visitors' data.
For a full list of every cookie we and our SDK use, including names, providers, and durations, see our Cookie Policy.
7. How we disclose personal data and our sub-processors
We disclose personal data only with service providers necessary to operate the Service, and with advertising or analytics platforms only when a customer instructs us to forward events. A current list of sub-processors is maintained on our Sub-processors page.
Key parties with whom personal data may be disclosed:
| Provider | Role | Data processed |
|---|---|---|
| Hostinger | Hosting / VPS provider for the Service | All application and database data (encrypted at rest) |
| Stripe, Inc. | Payment processor for Signal Sparrow subscriptions | Customer billing data and payment records |
| Meta Platforms, Inc. | Destination platform (when connected by customer) | Hashed identifiers and forwarded conversion events |
| Google LLC | Destination platform (Google Ads, GA4) and font CDN | Hashed identifiers, forwarded events, and font request data |
| TikTok, LinkedIn | Destination platforms (when connected by customer) | Hashed identifiers and forwarded conversion events |
| Titan / Postmark / Resend / Amazon SES | Transactional and account email delivery (provider depends on active configuration) | Customer name, email address, and message content |
| Fontshare (Indian Type Foundry) | Font CDN for the marketing website | IP address and browser headers |
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
8. International transfers
Our production application and database are currently hosted in Boston, United States. The location of that server is the primary place where customer and end-user data is stored at rest. If you need the current data-center region for a transfer impact assessment, please contact us.
Some of our sub-processors (such as Stripe, Meta, Google, and LinkedIn) are located in the United States or otherwise outside the European Economic Area (EEA) and the UK. Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, including:
- The European Commission's Standard Contractual Clauses (SCCs) and, where relevant, the UK International Data Transfer Addendum.
- Adequacy decisions adopted by the European Commission or UK government, where applicable.
- The participating provider's compliance frameworks and transfer safeguards, as described in their respective privacy policies.
Details of the transfer safeguards applicable to processor-scope data are included in our Data Processing Agreement.
9. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law.
| Data category | Retention period |
|---|---|
| Account and profile data | For the life of your account, plus 2 years afterward (or longer if required by law). |
| Billing and tax records | 7 years after the relevant transaction, to meet accounting and tax obligations. |
| Tracked events, sessions, and conversion data (processor data) | For the retention window configured by the customer; default is 24 months. Aggregated reports may be retained longer. |
| Connection tokens and integration credentials | Until the integration is disconnected or the account is closed. |
| Support emails and communications | 12 months after the ticket or thread is closed. |
| Marketing and newsletter communications | Until you unsubscribe, plus 12 months on a suppression list to honor opt-out requests. |
| Security logs and audit trails | 24 months, unless needed for an active investigation or legal hold. |
| First-party tracking cookie | Up to 13 months from the last tracked interaction, or earlier if the visitor deletes it. |
10. Your data protection rights
Subject to applicable law (GDPR, UK GDPR, and comparable privacy laws), you have the following rights in relation to personal data we hold about you:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data in certain circumstances.
- Restriction — ask us to limit how we use your data.
- Data portability — receive your data in a structured, commonly used format, and transmit it to another controller.
- Objection — object to processing based on legitimate interests or direct marketing.
- Withdraw consent — where we rely on consent, you can withdraw it at any time.
To exercise these rights as a customer, email [email protected]. We will respond within one month and generally do not charge a fee unless requests are manifestly unfounded or excessive. Step-by-step instructions, including how end-users and California residents should submit a request, are on our Data Subject Requests & Opt-Out page.
End-users should contact the website operator (our customer) whose site collected their data; we provide tools enabling our customers to export or delete an individual's data.
You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO); in the EU, you may contact the data-protection authority in your country of residence or habitual work.
11. California privacy rights (CCPA / CPRA)
If you are a California resident, the following information applies to the personal information we collect as a controller.
Categories of personal information collected (last 12 months): identifiers (name, email, IP address, device identifiers); commercial information (subscription and billing records); internet or other electronic network activity information (logs, interactions with the Service); geolocation data derived from IP address; and professional or employment information (if provided).
Sources: directly from you or your device, and (for end-user data) from our customers.
Purposes of use: to provide the Service, process billing, maintain security, provide support, and comply with legal obligations.
Categories of third parties: service providers listed in Section 7, and advertising/analytics destination platforms connected by our customers.
Sale or sharing: We do not sell or share personal information for cross-context behavioral advertising. We do not process sensitive personal information (as defined by the CPRA) except to the limited extent needed to provide the Service.
Retention: as described in Section 9.
Consumer rights: You may request to know/access, delete, or correct your personal information, and to opt out of any sale or sharing (none currently occurring). We will not discriminate against you for exercising these rights.
How to exercise: email [email protected] with the subject line "California Privacy Request." We may need to verify your identity before responding. See our Data Subject Requests & Opt-Out page for the full process.
Authorized agents: You may designate an authorized agent to make a request on your behalf. The agent must provide signed written authorization, and we may contact you to confirm the request.
Appeal: If we decline your request, you may appeal by emailing us within one month. If you remain dissatisfied, you may contact the appropriate California privacy enforcement authority.
Do Not Track / Global Privacy Control: We do not respond to browser Do Not Track signals or Global Privacy Control signals because we do not track users across third-party websites for advertising purposes.
12. Automated decision-making and profiling
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. The attribution models we provide (such as first-click, last-click, linear, and time-decay) are deterministic rules selected and configured by our customers; they are not used by us to evaluate, score, or make decisions about individuals.
13. Security
We protect personal data using a combination of technical and organizational measures, including:
- Encryption in transit using TLS for all Service traffic.
- Encryption at rest for database storage and backups.
- Hashing of personal identifiers (including email addresses) before forwarding to advertising platforms.
- Multi-tenant isolation so one customer's data is not accessible to another.
- Role-based access controls and two-factor authentication for administrative access.
- Audit logging of access and changes to production systems.
- Regular backups and incident-response procedures.
Although we implement reasonable technical and organizational safeguards, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure.
14. Children's privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children under 16. If you believe we have collected data from a child under 16, please contact us and we will delete it promptly.
15. Data Processing Agreement
Where we act as a processor, our processing is governed by a Data Processing Agreement (DPA) that forms part of our customer terms. Customers can access the DPA at signalsparrow.com/dpa. The DPA also incorporates the Standard Contractual Clauses where applicable.
16. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email, and the "Last updated" date at the top of this page will change. We encourage you to review this policy periodically.
17. Contact us
For privacy questions, data subject requests, or sub-processor inquiries, please contact:
- Email: [email protected]
- Address: 16 Humberstone Close, Luton, England, LU4 9ST
We are not currently required to appoint a Data Protection Officer (DPO) under the GDPR. Privacy queries are handled directly by the business owner.