SignalDeskby R To V Marketing← Back

Privacy Policy

Last updated: June 12, 2026

SignalDesk is a proprietary service operated by R To V Marketing ("we", "us", or "our"). This Privacy Policy sets forth the categories of information we collect in connection with your use of the service, the purposes for which such information is processed, the legal bases on which we rely, the limited circumstances under which information may be disclosed to third parties, and the rights and elections available to you with respect to your data. By accessing or otherwise utilizing the service, you acknowledge and consent to the practices described herein.

1. What we collect

  • Account identifiers - the electronic mail address, display name, and authentication credentials (or federated identity assertions, where applicable) necessary to establish and maintain a registered user account.
  • User-furnished brand inputs - descriptive attributes pertaining to the brand(s) you elect to onboard, including but not limited to denomination, web presence, classificatory category, geographic footprint, narrative talking points, substantiating proof points, intended publication targets, and topical exclusions.
  • Service outputs - derived work product generated on your behalf, including opportunity records, signal annotations, draft communications, and associated scoring metadata.
  • Billing metadata - subscription state and references to the corresponding records maintained by our payment processor. Payment instrument data (including primary account numbers) is collected and retained exclusively by such processor and is never transmitted to or stored by us.
  • Operational telemetry - request, diagnostic, and error logs reasonably required for the continued availability, integrity, and security of the service, retained for limited durations and not utilized for marketing purposes.

2. How we use it

  • To operate, maintain, and provide the contracted functionality of the service, including the surveillance of publicly available sources, the generation of opportunities, and the production of draft communications on your behalf.
  • To authenticate you and to administer and enforce the entitlements and limitations associated with your subscription tier.
  • To effectuate the processing of payments through our designated payment processor.
  • To diagnose technical issues, preserve the integrity of the service, and detect, prevent, or otherwise address fraud, abuse, or violations of our governing terms.

We do not sell, rent, or otherwise commercialize your personal data, nor do we permit your brand inputs or service outputs to be used for the training of third-party foundation models.

3. Sub-processors

In the ordinary course of providing the service, we engage a limited number of vetted sub-processors across the following functional categories: managed cloud infrastructure and database hosting; identity and authentication services; large language model and generative AI inference; programmatic retrieval of publicly accessible web content; payment processing and subscription billing; inbound electronic mail ingestion in connection with reporter-query workflows; and edge delivery, content distribution, and network security. Each such sub-processor is bound by contractual obligations substantially commensurate with the commitments set forth in this policy. A current register identifying our active sub-processors is available to enterprise customers and to data-subject requestors upon written request directed to the contact address set forth in Section 11; we otherwise decline to publish a granular vendor inventory for competitive and operational-security reasons.

4. Where your data lives

Your data is maintained within managed, relational database infrastructure operated by our cloud hosting provider and is delivered to end users by way of a globally distributed edge network. All communications between your client and the service are encrypted in transit by means of Transport Layer Security (TLS), and data at rest is encrypted utilizing the cryptographic facilities of the underlying infrastructure provider.

5. Retention

We retain your account data and user-furnished inputs for such period as your account remains active. Upon your initiation of an account deletion request pursuant to Section 7, we shall, within a commercially reasonable timeframe, expunge the records pertaining to your profile, brands, opportunities, reporter queries, role assignments, and subscription metadata, and shall procure the cancellation of any then-active subscription with our payment processor. Residual copies may persist within short-lived backup media for a period not to exceed thirty (30) days prior to routine overwriting.

6. How we protect it

A comprehensive description of our administrative, technical, and organizational safeguards is set forth in our Security overview. Summarily:

  • Row-level access controls are enforced upon every persisted data table, scoped to the authenticated principal.
  • Privileged service credentials are confined to server-side execution environments and are not transmitted to client devices.
  • Administrative operations are conditioned upon an explicit, role-based authorization check independent of mere session validity.
  • Inbound integration endpoints validate cryptographic signatures from issuing providers prior to the persistence of any received payload.
  • User-selected passwords are evaluated against a publicly maintained corpus of compromised credentials at the points of registration and credential modification.

7. Your rights and controls

  • Right of access - the entirety of the personal data maintained by us with respect to you is rendered visible from within your authenticated workspace.
  • Right of rectification - you may at any time amend your profile, brand records, and other user-furnished inputs.
  • Right of erasure - a self-service deletion facility, captioned "Delete account & data," is accessible from Plan & billing → Danger zone and effectuates the permanent removal of your account together with the cancellation of any associated subscription.
  • Right of portability - a machine-readable export of your data may be obtained by written request directed to the address in Section 11.
  • Withdrawal of consent - you may at any time discontinue use of the service and exercise the right of erasure described above.

Residents of the European Economic Area, the United Kingdom, and Switzerland are afforded the rights conferred by the General Data Protection Regulation and corresponding national implementations. Residents of the State of California are afforded the rights conferred by the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We shall honor all such rights to the extent required by applicable law upon receipt of a verifiable request.

8. Cookies

We employ a limited set of strictly necessary cookies and analogous client-side storage mechanisms (including localStorage) for the sole purposes of session persistence and the retention of user interface preferences. We do not deploy, permit, or otherwise integrate third-party advertising identifiers or cross-site tracking technologies.

9. Children

SignalDesk is a commercial offering intended for business use and is not directed to, nor knowingly made available to, any individual under sixteen (16) years of age.

10. Changes

We reserve the right to modify this policy from time to time. Any such modification shall be reflected by an update to the "last updated" date set forth above and, in the case of material changes, shall be communicated to active account holders by electronic mail.

11. Contact

Inquiries, requests, and notices pertaining to this policy may be directed to: privacy@rtovmarketing.com.