Privacy Policy

Effective date: 31 August 2026

[COMPANY LEGAL NAME] ("we", "us", "our"), registered in England and Wales under company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS], operates Signalpost. We are the data controller for personal data processed through the Service, under UK GDPR and the Data Protection Act 2018.

1. What we collect

Account data: name, email, password (hashed), business name.

LinkedIn connection data: the access token issued by LinkedIn's OAuth flow (encrypted at rest), your LinkedIn account identifier, and the posts we publish on your behalf.

Billing data: handled by Paddle, our payment provider and Merchant of Record. We do not store your card details.

Usage data: log-in activity, generated post history, settings, and support communications.

Demo tool data: if you use our free instant demo, the website URL you enter and the content generated from it.

2. How we use it

To provide the Service: generating and publishing content, running your schedule, showing you your dashboard.

To bill you, via Paddle.

To notify you of failures, expired connections, or account issues.

To improve the Service and its compliance guardrails.

We do not sell your personal data.

3. Who we share it with (our sub-processors)

Supabase (database and authentication hosting).

Lovable (application hosting).

Paddle.com Market Limited (payment processing, billing, VAT and tax handling).

LinkedIn (to publish content to your connected account, via LinkedIn's own API and subject to LinkedIn's privacy policy).

OpenRouter (AI content generation; your niche, topics and settings are sent to generate post drafts).

We only share what each of these providers needs to perform their function, under contract.

4. International transfers

Some of the above providers may process data outside the UK and EEA. Where they do, we rely on their standard contractual clauses or equivalent safeguards.

5. How long we keep it

We keep your account and post data for as long as your account is active, and for a reasonable period after cancellation to handle billing disputes and legal obligations, after which it is deleted or anonymised.

6. Your rights

Under UK GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise any of these, contact [SUPPORT EMAIL]. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you believe we have not handled your data properly.

7. Security

LinkedIn access tokens are encrypted at rest. We use industry-standard access controls and encryption in transit. No system is completely secure, and we cannot guarantee absolute security.

8. Cookies

We use essential cookies to run the Service (authentication, session management) and, where enabled, analytics cookies to understand product usage. You can control non-essential cookies via our cookie banner.

9. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app notice.

10. Contact

Data protection queries: [SUPPORT EMAIL].