Signal Retail LLC · Public document
Privacy Policy
Signal Retail sells evidence. It would be inconsistent to be vague about our own. This policy names every outside system that can see information from this website, states how long each kind of record is kept, and says plainly where we use AI. Where the honest answer is “we do not do that”, it says so instead of reserving the right.
- Effective
- 23 Aug 2026
- Supersedes
- 25 Jun 2026
- Scope
- signal-retail.com
- Operator
- Signal Retail LLC
- Contact
- [email protected]
Who operates this site
Signal Retail LLC is a retail field intelligence company. It operates this website and decides what information is collected here and what happens to it.
The site was built and is maintained by Ameen Systems, a web studio acting on Signal Retail’s instructions. Their access is listed in the register below. They do not use anything from this site for their own purposes.
This policy covers the public website at signal-retail.com. It does not replace the confidentiality and data handling terms in a signed client services agreement, which govern engagement work. Where the two overlap, the service agreement controls the engagement and this policy controls the website.
Systems register
Every outside system that can see information from this site, what it does, and what it is able to see. Each is contractually limited to providing its service to us.
| System | Function | Visibility |
|---|---|---|
| Namecheap | Web hosting | Everything stored on the site, plus server request logs |
| Delivers mail sent by this site, through the Gmail API on the hello@ address | Recipient address, subject line, and message body of site-generated mail | |
| Google Fonts | Serves the three typefaces this site uses: DM Sans, Inter and JetBrains Mono | Your IP address and browser, when a font file is requested |
| Fluent Forms | Runs the pilot request, general contact and Field Auditor application forms | Whatever you enter into a form. Stored on our own server, not a vendor cloud |
| FluentCRM | Holds the contact list and any follow-up sequence you opted into | Name, business email, and which of our messages you opened |
| Ultimate Member | Runs account and profile functions on the site | Account name, email, and profile fields completed |
| Loginizer | Blocks repeated failed sign in attempts | IP addresses attempting to sign in |
| WPVivid | Takes site backups | A full copy of the site. Backups remain on our own hosting account and are blocked from public download at the web server |
| Ameen Systems | Build and maintenance, over a cryptographically signed connection | The same records a site administrator can reach. Used only for maintenance we have requested |
There is no analytics platform on this site. No Google Analytics, no Meta pixel, no advertising or attribution tag of any kind. A previous version of this policy said we used “standard web analytics tools”. That was inherited boilerplate and it was not true, so it has been removed.
If we add a system that can see personal information, it goes in this table before it goes live.
What we collect, by relationship
Anyone visiting the site
- IP address and the approximate region it indicates
- browser and device type
- pages requested, and when
- the referring site or search
- failed sign in attempts, retained so repeated attacks can be blocked
These are ordinary web server records. We do not build a profile from them and nothing analyses them for behavioural purposes.
Prospective clients
If you request a pilot or send an enquiry: your name, business email, company name, role, store count or footprint if you provide it, and the content of your message. We do not take payment through this website and no card details are entered or stored here.
Field Auditor applicants
If you apply to the auditor network: your name, contact details, location and coverage area, relevant experience, availability, and anything else you enter on the application. This is treated as recruitment information, not marketing data, and it is not added to any mailing list.
Client engagement data
Separate from the website entirely. Covered in clause 04.
Client engagement data
Store visit records, audit findings, severity scoring, photographic evidence, and details of a client’s store network are produced during engagements. They are not collected through this website and they are not stored on it.
Engagement data is confidential under the service agreement covering that work. It is not sold, not shared with other clients, not used to build a benchmarking product, and not used for any purpose beyond the contracted engagement.
Field observations are recorded about store conditions and process execution. Where an individual employee could be identified in a record, that record exists to describe a process outcome, not to evaluate a person, and it is handled under the confidentiality terms of the engagement. Signal Retail makes no legal findings and issues no determinations about individuals.
What we use it for
- answering an enquiry and scoping a possible pilot
- following up where you asked us to
- evaluating Field Auditor applications and running the auditor network
- delivering contracted engagement work and the reporting that comes with it
- sending updates only to people who asked for them
- keeping the site available and defending it against spam and attack
- meeting tax, accounting and contractual record keeping obligations
We do not sell, rent or trade contact information. We do not share it with third parties for their marketing.
When information leaves
Three situations, and no others:
- To the systems in clause 02, only so each can perform its function.
- Where the law requires it, such as a lawfully issued subpoena or court order. Where we are permitted to tell you, we will.
- Where there is a genuine and immediate safety risk to a person.
A client’s engagement data is never disclosed to another client, and never used as a sales reference, without that client’s written agreement.
Where AI is used, and where it is not
A company selling ground truth should be specific about this rather than silent.
Where it is used
- Building this website. It was produced with AI assisted development tooling.
- Drafting site copy, including the Insights articles. Published articles in the Insights section are drafted with AI assistance and reviewed, corrected and approved by a person before publication. They are commentary on retail operations, not field findings from a client engagement.
Where it is not
- No decision about a person is automated. Field Auditor applications are assessed by a person. No scoring model accepts or rejects an applicant.
- Your information is not sent to an AI service. Enquiries, applications and the contents of your messages are not fed into any external AI system.
- The website makes no AI calls. Nothing you type here is passed to a model.
How field intelligence reports are produced, including any use of automated tooling in their preparation, is defined in the client services agreement for that engagement rather than in this website policy. Ask before you sign and you will get a direct answer.
If any of this changes, this clause changes before the change takes effect.
Cookies
This site sets almost none. There is no consent banner here because there is nothing to consent to beyond what is strictly necessary.
- Session and sign in cookies, set only if you have an account and sign in.
- Form state, short lived, so a part completed form is not lost.
There are no advertising cookies, no analytics cookies and no cross site tracking, because none of those tools are installed. Your browser settings can clear or block cookies at any time. Doing so may sign you out and will not otherwise limit the site.
Loading a page does request font files from Google, as listed in clause 02. That request reveals your IP address to Google in the same way as visiting any site that uses their font service.
Retention schedule
| Record | Held for |
|---|---|
| Enquiries and pilot requests | 24 months from last contact, then deleted |
| Field Auditor applications, not progressed | 24 months, then deleted |
| Active auditor network records | Duration of the working relationship, then as tax and contractor rules require |
| Client engagement data | As set by the service agreement. Default is the engagement term plus 12 months, so a report can be reissued |
| Contact list membership | Until you unsubscribe |
| Mail delivery records | A short window for troubleshooting |
| Failed sign in records | A short security window, then discarded |
| Server logs and backups | Rotated, older copies removed as new ones are made |
Security
- The site is served over an encrypted connection throughout.
- Form submissions are stored on our own server rather than a third party form cloud.
- Repeated failed sign in attempts are detected and blocked automatically.
- Backups sit on our own hosting account and are blocked from public download at the web server. They are not uploaded to any outside storage service.
- Remote maintenance runs over cryptographically signed requests, not a shared password.
No site can honestly promise perfect security and this one will not. What we will commit to: if a breach affects your information, we will tell the people affected and any authority we are required to notify, and we will describe what actually happened.
What you can require of us
Regardless of which privacy law applies to you, we will act on all of these:
- Access. A copy of what we hold about you.
- Correction. Tell us what is wrong and we will fix it.
- Deletion. We will delete, unless a contractual or legal duty requires us to keep the record, in which case we will tell you which one.
- Opt out. Every message we send carries a working unsubscribe link.
- An explanation. If you just want to know how a workflow handles your data, ask. It does not have to be a formal request.
Send any of these to [email protected]. We reply within 30 days and usually far sooner. There is no charge.
Changes and contact
This policy is revised when our practices change, when a system that can see personal information is added, or when the law requires it. The effective date in the header always reflects the current version, and the previous version’s date is shown beside it.
- Operator
- Signal Retail LLC
- Privacy
- [email protected]
- General
- [email protected]
- Response
- Within 30 days