What this policy covers
This policy explains what data Signa collects, why we collect it, who can see it, and how to ask us to change or delete it. It covers two things: the website at heysigna.com and Signa Ads.
Signa Ads is used by authorized Signa team members to manage advertising accounts with the permission of the account owner. There is no public signup. Advertising is its purpose. Some supporting business data may also be processed when expressly authorized, as described below.
The website
heysigna.com has no login, no forms, and no checkout. The only way to contact us from the site is an email link. If you email work@heysigna.com, we keep the message so we can reply and follow up on the work you asked about.
The site serves its font from our own hosting and runs no analytics script today. Our hosting providers, Vercel and Cloudflare, process ordinary technical data such as IP addresses, browser type, and request logs to serve pages and protect the site. They handle that data under their own policies.
Signa Ads and connected advertising accounts
Signa Ads connects to advertising accounts an authorized person has permission to manage. Each connection goes through the platform's own sign-in and consent screen, which shows the permissions requested. Which platforms can be connected, and what Signa Ads can do on each, depends on that platform's supported interfaces, its approval of our application, and the permissions granted. Permissions are requested for the features that are enabled. Only data relevant to authorized work is processed.
Through a connected advertising account, Signa Ads may read and, where authorized, change:
- Account identity: the business name, account name, and identifiers needed to tell accounts apart.
- Campaign configuration: campaigns, ad groups or ad sets, targeting settings, bids, and budgets.
- Creative assets: ad text, images, video, and landing page links.
- Performance data: impressions, clicks, spend, conversions, and related reporting metrics.
Supporting business data
Signa Ads connects to Google through a single business-services authorization that Signa also uses for separately authorized general business operations. When an authorized person connects a Google account, the consent screen shows the full set of permissions in that combined grant. Advertising is the purpose of Signa Ads, but not every task run under this connection is advertising. Each task, whether advertising or general business work, is authorized by a person before it runs.
Under this authorization, and only when expressly authorized, we may process:
- Business correspondence: email messages and settings, to read briefs, prepare drafts, and send explicitly authorized messages.
- Schedules: calendar events, to plan and update meetings, launches, and reviews.
- Working documents: documents, files, and spreadsheets used to prepare creative, briefs, reports, and other business work.
- Website and search performance data: site traffic and search performance used in reporting.
- Business listing data: listing details, to keep listings current and consistent with advertising.
These purposes are business correspondence, scheduling, working documents, website reporting and listing updates, and advertising support. Data from these sources is processed only for the work a person has authorized, not for unrelated purposes.
Other data Signa Ads holds
- Business contact details for the people who authorize and receive the work, such as name, email address, and role.
- Connection credentials issued by each platform when an account is connected. These let Signa Ads act on the account within the granted permissions.
- Operational logs recording what Signa Ads read or changed, when, and under whose authority, so work can be checked.
How we use this data
Signa Ads uses connected account data to manage the advertising the account owner has authorized: building and adjusting campaigns, preparing creative, monitoring budgets, producing performance reports, and applying authorized changes. Supporting business data is used to inform and prepare that work. It processes the data relevant to those purposes.
We do not:
- sell data received from connected accounts or platforms;
- use the content of private email, documents, calendars, or files as targeting data for personalized advertising or retargeting;
- use connected account data to train or improve generalized AI models;
- transfer it to anyone except as described in this policy.
Managing targeting inside an advertising account, using that account's own settings and the platform's own tools, is the authorized work. It is not the use of private data described above.
Google API Services User Data Policy
Where Signa Ads connects to Google services, it receives data through Google APIs. Signa Ads' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means we use Google user data only to provide or improve user-facing features of Signa Ads. We do not sell it or use it for personalized advertising. People read it only with the user's consent, for security purposes, to comply with law, or as aggregated and anonymized data for internal operations.
You can remove Signa Ads' access to your Google account at myaccount.google.com/permissions.
Other connected platforms
Each advertising platform you connect has its own terms, privacy policy, and permission controls. Those govern what the platform shares with Signa Ads and how you can review or remove that access. We follow the developer and data terms of each platform we connect to, and we apply the limits in this policy to data received from every platform.
Who can see the data
Access is limited to the Signa team members working on the account. Contracted providers may process data on our behalf where a task needs it, including cloud hosting and AI processing services used for specific tasks such as drafting ad copy, summarizing performance, or analyzing results. We use providers for the authorized service and require that their handling of this data follows these limits.
We may also disclose data when the law requires it or to protect the security of our systems.
Oversight and review
People set the scope of Signa Ads' work and approve what it may do. Proposed or consequential work, such as a new campaign, a budget change, or new creative, requires review by a responsible person before it is applied. Recurring tasks may run under standing instructions a person has authorized, without a person checking every individual change. Signa Ads does not increase spend or start new spending without the authority of the account owner. Standing instructions can be changed or withdrawn at any time.
How we protect data
Long-lived connection credentials for Signa Ads are stored in a password manager, 1Password. Short-lived access tokens used during a session are held in memory while the software runs and are not written to shared documents or logs. Access is limited to the people who need it for the work.
No system is perfectly secure, and we do not promise otherwise. We work to keep data safe and to limit what we hold to what the work needs.
How long we keep data
We keep data as long as the work needs it, and then as long as we need it for support, records, or legal reasons. Reports and working files stay with the account they belong to. Operational logs are kept so past changes can be checked. Email to work@heysigna.com is kept as part of our business correspondence. We do not set a fixed deletion schedule today. Ask and we will tell you what we hold and delete what we no longer need.
Your choices
- Access, correction, deletion. Email work@heysigna.com to ask what we hold about you or your accounts, to correct it, or to delete it. We will act on the request unless we need to keep something for legal or record reasons, and we will tell you if that is the case.
- Revoking access. You can remove Signa Ads' access to a connected account through that platform's permission settings. For Google accounts, that is myaccount.google.com/permissions. Revoking access stops Signa Ads from reading or changing anything through that account going forward. It does not automatically remove records we already hold. Email us to request that separately.
Changes to this policy
We may update this policy as Signa Ads changes. The date at the top shows the current version. Changes to how we handle data from connected accounts, including Google user data, will appear here before they take effect.
Contact
Signa. Email work@heysigna.com.