Privacy Policy
Last updated: May 2026
SignalIQ (“we”, “us”, or “our”) provides this Privacy Policy to explain how we collect, use, disclose, and safeguard your information when you use our platform at app.getsignaliq.app.
1. Data We Collect
- Account information: name, email address, password (hashed — never stored in plaintext)
- Workspace information: workspace name, team member emails, roles
- Social account OAuth tokens: encrypted at rest using AES-256-GCM; decrypted only when making API calls to connected platforms
- Analytics data: follower counts, engagement metrics, reach, and impressions pulled from your connected social accounts via official APIs
- Usage data: pages viewed, features used, errors encountered (via Sentry and PostHog — anonymised)
- Payment data: subscription status, invoice records; card details are handled entirely by Razorpay and never touch our servers
- Audit logs: login/logout events, account connections, billing events — retained for security and compliance
2. Two-Level Data Chain
SignalIQ operates as a data processor on behalf of our customers (agencies and businesses). Our customers are the data fiduciaries responsible for their end clients’ social media data that flows through SignalIQ. We process social analytics data only under the instructions of the workspace admin who connected the relevant social accounts.
If you are an end client of a SignalIQ customer, please contact that customer directly regarding your personal data.
3. Third-Party Platforms
We connect to the following platforms via their official APIs only:
- Meta (Facebook & Instagram): via Meta Graph API v18+
- LinkedIn (Phase 1), YouTube (Phase 2), TikTok / X (Phase 3) — when available
Data retrieved from these platforms is used solely to display analytics inside your SignalIQ workspace. We do not sell this data, use it for advertising targeting, share it with third parties for commercial purposes, or use it to train AI models.
4. Data Storage
Your data is stored on servers based in the United States and/or EU via:
- Supabase (PostgreSQL database — AWS us-east-1 / eu-west-1)
- Railway (API server — US region)
- Vercel (frontend — global CDN)
- Upstash (Redis — US region)
By using SignalIQ, you consent to your data being transferred to and processed in these jurisdictions under the safeguards described herein.
5. Your Rights under DPDP Act 2023 (India)
As a Data Principal under India’s Digital Personal Data Protection Act 2023, you have the right to:
- Access: obtain a summary of personal data we hold about you
- Correct: update inaccurate or incomplete personal data
- Erase: request deletion of your personal data (subject to legal retention obligations)
- Withdraw consent: revoke consent for data processing where consent is the lawful basis
- Nominate: designate a nominee to exercise rights on your behalf in case of death or incapacity
- Grievance redressal: contact our Grievance Officer (see Section 9)
To exercise these rights, email support@getsignaliq.app or visit our data deletion page.
6. Data Retention
- OAuth tokens: retained until you disconnect the social account; deleted immediately on disconnect
- Analytics data: retained for 90 days after account deletion
- Audit logs: retained for 12 months (required for security and compliance)
- Payment records and invoices: retained for 8 years (required by Indian tax law)
- Account data: deleted within 30 days of account deletion request (except data subject to legal holds)
7. Cookies
We use two categories of cookies:
- Essential cookies: session management and JWT authentication — required for the platform to function; no consent needed
- Analytics cookies: PostHog product analytics — only activated after you give explicit consent via our cookie banner
You can change your cookie preference at any time by clearing your browser storage.
8. Data Deletion
To request deletion of your personal data, email support@getsignaliq.app with subject line “Data Deletion Request”, or use our Meta data deletion page.
We will process your request within 30 days. A 30-day grace period applies before hard deletion to allow data export. Payment records are retained for 8 years as required by law.
9. Grievance Officer
In accordance with the DPDP Act 2023 and the Information Technology (Intermediary Guidelines) Rules, 2011, our Grievance Officer is:
Uma Mahesh Bhamidipati
Founder, SignalIQ
Email: support@getsignaliq.app
Acknowledgment: within 24 hours
Resolution: within 15 days
10. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of India. Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts in Hyderabad, Telangana, India.
11. Contact Us
For questions about this Privacy Policy, contact us at support@getsignaliq.app.