Skip to main content

Data Privacy & Retention

Signal Sparrow is built to help you respect your customers' privacy and meet your obligations under laws like GDPR and CCPA. Here's how your data is protected and how long it's kept.

How personal data is protected

  • Emails are hashed. Email addresses are scrambled into an unreadable code before they're ever shared with an ad platform — the raw email is never exposed.
  • IP addresses are minimized. IPs are used only briefly to process a visit, then removed shortly afterward rather than kept around.
  • Stripe is read-only. Signal Sparrow can read your revenue but can never change it.
  • Access is role-based. Read-only teammates can never see personal details or export data.

How long data is kept

Your organization has a data retention setting that controls how long detailed event and session data is stored. Older raw data ages out automatically, while your aggregated reports and totals remain. If you need a specific retention period for compliance, you can set it in your organization settings.

Access, export, and deletion requests

If one of your customers asks to see or delete the data you hold about them (often called a Data Subject Request), Signal Sparrow gives you the tools to respond:

  • Export an individual's data in a portable format.
  • Delete an individual's data from your organization.

Because you are the owner of your customers' data, these actions are in your hands — Signal Sparrow simply provides the controls.

You're the controller

For the data your website collects, you are the data controller and Signal Sparrow acts as your processor. Our full commitments are in the Privacy Policy and Data Processing Agreement on our main site.

Next