This policy is intended to provide clear and accurate information about how Signal Scanner handles personal data. It is not legal advice. We recommend that you review this policy with qualified legal counsel, particularly if you operate in the European Economic Area (EEA), the United Kingdom, or other jurisdictions with specific data protection requirements.
01Information We Collect
Account Information
When you create a Signal Scanner account, we collect:
- Email address and password for authentication
- Business information (name, website, industry, location)
- Contact details for billing and support
- Subscription plan and payment information
Business Analysis Data
To provide AI platform visibility analysis, we collect and process:
- Your business name, website URL, and location details
- Industry classification and service descriptions you provide
- Keywords and search terms related to your business
- Google Analytics data (when you connect your GA4 account)
- Website technical information for SEO analysis
AI Platform Analysis Results
Our automated systems collect:
- Responses from AI platforms (ChatGPT, Google AI, Perplexity, Claude, Grok, DeepSeek, etc.)
- Visibility metrics and mention patterns across AI platforms
- Competitor analysis data from public sources
- Citation information from online directories
- Technical SEO metrics and recommendations
02How We Use Your Information
Service Delivery
- Perform AI platform visibility analysis for your business
- Generate comprehensive reports and insights
- Provide optimization recommendations
- Track competitor performance in your market
- Monitor citation accuracy and opportunities
Platform Operations
- Authenticate your account and maintain security
- Process subscription payments and manage billing
- Send service updates and analysis reports
- Provide customer support and technical assistance
- Improve our analysis algorithms and service quality
03Data Protection and Security
Encryption and Storage
We implement enterprise-grade security measures:
- All data transmission is encrypted using TLS/SSL protocols
- Database encryption at rest for all sensitive information
- Secure authentication with password hashing
- Google Analytics tokens are encrypted when stored
Access Controls
- Complete data isolation between user accounts
- Brand-specific data access controls
- Role-based permissions for team accounts
- Regular security audits and monitoring
04Data Sharing and Third Parties
AI Platform Interactions
To provide our core service, we interact with third-party AI platforms. When we query these platforms about your business, we only use publicly available information and industry-standard search terms. We do not share personal account data with AI platforms.
Service Providers
We work with trusted service providers for:
- Payment processing (Square): only billing information
- Database hosting (Neon/PostgreSQL): encrypted application data
- Email communications: contact information only
- Analytics (Google Analytics): when you explicitly connect your account
No Data Sales
We never sell, rent, or trade your personal information or business data to third parties for marketing purposes. Your competitive intelligence and analysis results remain strictly confidential.
05Google Analytics, Google Search Console, and Google User Data
Google Analytics
When you connect your Google Analytics account to Signal Scanner, we request access using the https://www.googleapis.com/auth/analytics.readonly OAuth scope. This is the only Analytics scope we request.
Google Analytics data obtained through this integration is used exclusively to:
- Display your own Google Analytics performance metrics inside your Signal Scanner account
- Combine GA traffic data with AI visibility analysis for your brand's dashboard
Google Search Console
When you connect your Google data to Signal Scanner, we also request read-only access to your Google Search Console data using the https://www.googleapis.com/auth/webmasters.readonly OAuth scope. This scope is requested only when you actively choose to connect your Google data, never at sign-in.
Google Search Console data obtained through this integration is used exclusively to:
- Display your own Search Console metrics (real search queries, clicks, impressions, and average positions) inside your Signal Scanner account
- Inform your brand's organic search visibility measurements alongside AI platform analysis
We do not modify your Google Search Console configuration. Access is strictly read-only.
Signal Scanner's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We make the following commitments regarding all Google user data (Analytics and Search Console):
- Google user data is never sold, never used for advertising, and never shared with third parties.
- Access is limited to read-only data for your own properties; we do not modify your Google Analytics or Google Search Console configuration.
- You can disconnect your Google integrations at any time from your account settings.
- Google access tokens are encrypted at rest using AES-256-GCM encryption.
- Your Google tokens are permanently deleted when you disconnect the integration or delete your account.
06Data Retention and Deletion
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to provide the service you have contracted for, or as required by applicable law.
Account Data
We retain your account information and analysis results as long as your account is active. When you delete your account:
- All personal information is permanently deleted within 30 days
- Business analysis data is anonymized for service improvement
- Google Analytics and Search Console connections are immediately revoked
- Billing information is retained for tax and legal compliance (7 years, as required by law)
Analysis Data
AI platform analysis results are retained to provide historical tracking and trend analysis for as long as your account is active. This data is associated with your account and deleted when your account is closed.
07Your Rights and Controls
All users have the following rights over their data. Users in the European Economic Area (EEA) and the United Kingdom have these rights under the General Data Protection Regulation (GDPR) and UK GDPR respectively. Users in other jurisdictions may have similar rights under applicable local law.
- Right of access (GDPR Art. 15). You may request a copy of the personal data we hold about you.
- Right to rectification (GDPR Art. 16). You may ask us to correct inaccurate or incomplete personal data.
- Right to erasure / right to be forgotten (GDPR Art. 17). You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent and no other lawful basis applies.
- Right to restrict processing (GDPR Art. 18). You may ask us to pause processing of your personal data in certain circumstances, for example while a dispute about accuracy is resolved.
- Right to data portability (GDPR Art. 20). Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible.
- Right to object (GDPR Art. 21). You may object to processing of your personal data where we rely on legitimate interests as the lawful basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Rights related to automated decision-making (GDPR Art. 22). Signal Scanner does not make solely automated decisions that produce legal or similarly significant effects about you. All scoring and recommendations are provided as analysis tools for your review, not as binding automated decisions.
- Right to withdraw consent. Where processing is based on your consent (such as connecting Google Analytics or Search Console), you may withdraw that consent at any time from your account settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint (GDPR Art. 77). If you are in the EEA or UK and believe we are processing your personal data in breach of the GDPR or UK GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK this is the Information Commissioner's Office (ICO). In the EU, the relevant authority is the data protection authority of your country of residence or the country where the alleged breach occurred.
- Opt out of marketing communications. You may unsubscribe from marketing emails at any time using the link in any email we send.
To exercise any of these rights, contact us at privacy@signalscanner.com. We will respond without undue delay and within one month of receiving your request, as required under applicable law. We may ask you to verify your identity before processing a request.
08Cookies and Tracking
Signal Scanner uses cookies and similar technologies to:
- Maintain your login session and account security
- Remember your dashboard preferences and settings
- Measure marketing performance and conversion events through Google Analytics 4 and the Meta (Facebook) Pixel on our public marketing pages
- Provide personalized analysis recommendations
Marketing trackers are only active on the public marketing site (homepage, pricing, signup). Once you are logged into the dashboard, only first-party session and product analytics cookies are used. You can opt out of advertising trackers by enabling "Do Not Track" in your browser or by blocking third-party cookies.
AI Platforms We Query on Your Behalf
To produce your visibility report, Signal Scanner submits queries to the following third-party AI providers using only your business name, website, location, and industry: OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini), Perplexity, DeepSeek, and xAI (Grok). We do not share your account credentials, payment details, or any personally identifying information with these providers.
09International Data Transfers
Signal Scanner operates primarily in the United States. If you access our service from outside the US, your personal data will be transferred to and processed in the United States, which may have different data protection laws than your country.
For transfers of personal data from the European Economic Area (EEA) or the United Kingdom to the United States, we rely on appropriate safeguards as required under Chapter V of the GDPR and UK GDPR. Where applicable, these safeguards include the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) with our data processors.
You may request further information about the specific safeguards applied to transfers of your personal data by contacting us at privacy@signalscanner.com.
10Children's Privacy
Signal Scanner is designed for business use and not intended for individuals under 18. We do not knowingly collect personal information from children under 18. If we discover such information, we will delete it immediately.
11Data Breach Notification
In the event of a personal data breach, we will respond in line with our legal obligations, including Article 33 of the GDPR where applicable (notification to the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms). Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
Specifically, we will:
- Notify affected users via email within 72 hours of discovery where required
- Notify the relevant supervisory authority where required by law
- Provide details about what information was involved
- Explain the steps we are taking to address the breach
- Offer guidance on protecting your account
12Third-Party Links
Our platform may contain links to third-party websites (such as your business website or Google Analytics). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13Changes to Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Significant changes will be communicated via email and through notifications in your Signal Scanner dashboard.
14Compliance and Certifications
Signal Scanner is committed to data protection compliance and follows industry best practices for data security. We regularly audit our systems and practices to ensure ongoing protection of your information.
15Data Controller and Lawful Basis for Processing
Data Controller
The data controller responsible for your personal data is Tridence, the company behind Signal Scanner. For data protection enquiries, contact us at privacy@signalscanner.com.
Lawful Basis for Processing
For users in the EEA and UK, we process personal data under the following lawful bases as required by Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)). Processing your account information, business data, and analysis results is necessary to deliver the service you have signed up for.
- Consent (Art. 6(1)(a)). Connecting your Google Analytics and Google Search Console data is entirely optional. We process that data only on the basis of your explicit consent, given when you choose to connect those integrations. You may withdraw consent at any time from your account settings.
- Legitimate interests (Art. 6(1)(f)). We process certain data to secure the platform, prevent fraud and abuse, and improve service quality. We have assessed that these interests are not overridden by your privacy interests or fundamental rights.
- Legal obligation (Art. 6(1)(c)). We retain billing records for the period required by applicable tax and financial law.
16EU, EEA, and UK Data Protection
If you are located in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR applies to how we process your personal data. The rights described in Section 07 of this policy are your GDPR and UK GDPR rights, including the right to lodge a complaint with your local supervisory authority.
For EEA users, the relevant supervisory authority is the data protection authority in the EU member state where you live, work, or where the alleged infringement occurred. For UK users, the relevant authority is the Information Commissioner's Office (ICO), reachable at ico.org.uk.
We encourage you to contact us first at privacy@signalscanner.com so we have the opportunity to address your concern before you escalate to a supervisory authority.
17Contact Us
If you have any questions about this Privacy Policy, wish to exercise any of your data rights, or have a concern about how we handle your data, please contact us:
- Email: privacy@signalscanner.com
- Support: through your Signal Scanner dashboard
We will respond to data rights requests without undue delay and within one month of receipt, as required under applicable law.