Privacy
A plain-English privacy policy for SignalOps.
SignalOps is built to help wireless retail teams track performance, transactions, and accountability. This page explains what we collect, what we do not collect, where data lives today, and how to reach us if you want to exercise your privacy rights.
TL;DR
At a glance
- SignalOps is an operations product, not an ad-tech product. We collect the minimum data needed to run accounts, track work, and secure the service.
- We collect account details, transaction and goal data, session data, and audit or security events when people use the product.
- We do not sell or rent personal data, and we do not run marketing or advertising trackers on the public site.
- Data currently lives on Cloudflare infrastructure only: D1 for core records, R2 for receipt images, and Cloudflare edge services for delivery and logs.
- You can ask for access, correction, deletion, or export by emailing [email protected].
Collected data
What we collect
- Account data, such as name, email where provided, role, and store assignment.
- Operational data, including transactions, line items, goals, and related store performance records.
- Authentication and session data, including the `alliance_session` cookie and its expiry so we can keep signed-in users authenticated.
- Audit and security events, including records written to the `audit_log` and `security_events` tables when sensitive actions or security-relevant events occur.
- Minimal Cloudflare edge logs needed to deliver and protect the service, generated under Cloudflare's platform policy.
Not collected
What we DON'T collect
- We don't sell or rent personal data.
- We do not use marketing or advertising trackers on the public site.
- We do not collect precise location, biometrics, or device contacts.
Purpose
How we use it
- Deliver the service, including account access, store assignment, reporting, and receipt handling.
- Calculate goals, leaderboard inputs, compensation-adjacent metrics, and bonus workflows.
- Detect abuse, prevent fraud, investigate incidents, and enforce product rules.
- Respond to lawful legal requests, disputes, and compliance obligations.
Storage
Where it lives
- Core application records live in Cloudflare D1, with U.S. data centers as the current default.
- Receipt images live in Cloudflare R2.
- Edge request logs and delivery infrastructure run on Cloudflare.
Sub-processors
Cloudflare only: hosting, database, object storage, and DNS.
If we add more, this list updates first.
Retention
Retention and deletion
Our soft default is up to 7 years for transaction-level records so stores can support U.S. federal record-keeping expectations. Session logs and similar security-operational records are kept for shorter periods when possible.
If you make a valid deletion request, we aim to complete it within 30 days unless a legal hold, dispute, or other compliance obligation requires us to keep specific records longer.
Your controls
Your rights
- Access the personal data we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion where we are allowed to delete it.
- Request an export of your data.
- Complain to your regulator if you believe your rights were not handled correctly.
To invoke any of these rights, email [email protected].
Age
Children
SignalOps is not directed at children under 16, and we do not knowingly build the public service to target them.
Transfers
International transfers
SignalOps currently runs on Cloudflare infrastructure in the United States. If you are an EU or UK customer and need transfer paperwork, you can request a DPA at [email protected].
Cookies
Cookies
We use one application cookie after sign-in: the alliance_session cookie. It exists to keep a signed-in session active until its expiry. We do not use marketing cookies on the public site.
Security
Security
For the matching security overview and operating posture, see /security.
Contact
Contact
Email [email protected] for privacy questions, requests, or regulator follow-up.
Versioning
Changes
Last updated: 2026-05-04
We version this policy and will email notice for material changes when the change affects how we use or disclose customer data.