SignalCraft
PrivacyTermsSign in

SignalCraft Strategies, LLC

Privacy Policy

Last updated July 3, 2026

This Privacy Policy explains how SignalCraft Strategies, LLC(“SignalCraft,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the SignalCraft client portal and the growth and lead-generation services we provide through it (together, the “Services”).

1. Who this policy covers

SignalCraft provides an invite-only portal that our consulting clients use to view their growth data, documents, invoices, requests, and the sales leads we develop for them. This policy applies to three groups of people whose information we handle differently:

  • Portal users — the client staff we invite to sign in and use the portal.
  • Client-supplied contacts — people whose information a client gives us to load into their workspace (for example, their existing customer or contact list).
  • Prospects we research — people and businesses we identify from public and third-party sources as potential leads for a client.

Because our role differs across these groups, Section 3 sets out who is responsible for each category before the rest of the policy describes what we do.

2. Information we collect

From portal users

  • Account & identity data — name, email address, and organization membership, handled through our authentication provider, Clerk. Clerk manages your login credentials; we do not store your password.
  • Content you provide — documents and files you upload, support and service requests you submit and their attachments, poll and survey responses, and messages you send us through the portal.
  • Billing records — invoices, amounts, and payment status we make available to you. We do not collect or store full payment-card numbers in the portal.
  • Usage & device data — how you interact with the portal (pages viewed, features used), plus technical data such as IP address, browser, and device type, collected through analytics and server logs.

About client-supplied contacts and prospects

For the sales leads that appear in a client’s CRM, we collect business-contact information such as company name, contact name, email address, phone number, firmographic details (industry, size, location, and similar), and sales-process metadata we generate (lifecycle stage, score, source, and activity history).

3. Our role — and who controls which data

Data-protection law distinguishes the party that decides why and howpersonal information is processed (a “business” or “controller”) from a party that merely processes it on someone else’s instructions (a “service provider” or “processor”). Our role changes with the data:

  • Portal user data — we are the business/controller. We decide how account, content, and usage data is used to run the portal, and this policy governs it.
  • Client-supplied contacts — we are the service provider. When a client gives us their own contact list to load into their workspace, the client is the controller of that data. We process it only to provide the Services to that client, under our agreement with them, and we do not use it for our own purposes. Requests from those individuals are generally directed to the client (see Section 8).
  • Prospects we research — we are the business/controller. Most leads in the portal are ones we identify ourselves, on our own initiative, to meet our contractual obligations to a client. Because we decide to collect that information and how, we are responsible for it, and this policy governs it. We then make those leads available to the relevant client for their use.

4. Where prospect information comes from

When we research prospects for a client, we collect business-contact and firmographic information from sources other than the individual, including:

  • LocalProspect and similar third-party business-data and lead-generation providers;
  • Google Search and Google Maps and other publicly accessible business listings and directories;
  • Automated research (“AI-agent”) collection of general business information that is publicly available online, such as company websites and public profiles.

We focus on business and professional contact information used for legitimate business-to- business outreach on a client’s behalf. We do not knowingly collect sensitive personal information for this purpose.

5. How we use information

  • Operate, secure, and maintain the portal and provide the Services;
  • Authenticate users and keep accounts and tenant data separated;
  • Develop, qualify, and deliver sales leads to the relevant client;
  • Respond to requests, provide support, and communicate with you about the Services;
  • Prepare and share invoices and manage billing;
  • Measure and improve how the portal is used through analytics;
  • Detect, prevent, and investigate fraud, abuse, and security incidents; and
  • Comply with legal obligations and enforce our agreements.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

6. Cookies & analytics

We use a limited set of cookies and similar technologies:

  • Essential cookies — set by Clerk to sign you in and keep your session secure. The portal cannot function without these.
  • Analytics — we use privacy-conscious product analytics (such as Vercel Analytics) to understand aggregate usage and improve the portal. We also store your theme preference in your browser.

You can control cookies through your browser settings, but disabling essential cookies will prevent you from signing in.

7. How we share information

We disclose personal information only as described here:

RecipientPurpose
ClientsWe make each client’s workspace — including the leads we develop for them — available to that client.
ClerkAuthentication and user-account management.
SupabaseDatabase and file storage that hosts portal data.
VercelApplication hosting and product analytics.
AirtableA temporary read bridge used while we migrate certain data into the portal.
Data & lead-generation sourcesProviders such as LocalProspect and Google from whom we obtain prospect information (Section 4).
Professional advisors & authoritiesWhere required to comply with law, respond to lawful requests, or protect our rights and users.
A successorIn connection with a merger, financing, or sale of assets, subject to this policy.

These providers are bound by contract to protect the information and use it only to provide services to us.

8. Your privacy rights

Depending on where you live — including under the California Consumer Privacy Act, as amended by the CPRA — you may have the right to know what personal information we hold about you, to request access or a copy, to correct it, to request deletion, and to be free from discrimination for exercising these rights. Because we do not sell personal information or use it for cross-context behavioral advertising, there is nothing to opt out of in that respect.

To exercise your rights:

  • Portal users and prospects we researched: email info@signalcraftstrategies.com and tell us what you would like to do. We will verify your request and respond as required by law.
  • Client-supplied contacts: because the client controls that data, please contact the relevant company directly. If you reach us instead, we will forward your request to them and assist as their service provider.

You may use an authorized agent to submit a request on your behalf where the law allows.

9. Data retention

We keep personal information for as long as needed to provide the Services, maintain your account, meet our legal and contractual obligations, and resolve disputes. When a client relationship ends, we delete or return client-controlled data in line with our agreement with that client, and we delete or de-identify other information when it is no longer needed.

10. Security

We use technical and organizational safeguards designed to protect personal information, including encryption in transit, access controls, and database-level tenant isolation so that one client cannot access another client’s data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Data location

We and our providers process and store information in the United States. If you access the Services from outside the United States, you understand that your information will be processed there.

12. Children

The Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, take additional steps as required by law. Your continued use of the Services after an update means you accept the revised policy.

14. Contact us

SignalCraft Strategies, LLC
Email: info@signalcraftstrategies.com

Questions? Email info@signalcraftstrategies.com.

© 2026 SignalCraft Strategies, LLC. All rights reserved.