Privacy Policy
Last updated: August 5, 2026
1. Information We Collect
When you create a ClientSignal account, we collect your email address and agency name. When you connect integrations, we securely store OAuth tokens to access your advertising platform data on your behalf.
2. How We Use Your Information
We use your information to:
- Generate, review, and deliver performance reports to your clients
- Pull advertising and marketing metrics from connected platforms (Google Ads, GA4, Meta Ads, TikTok Ads, HubSpot CRM, Klaviyo, Mailchimp)
- Provide the account, portfolio, engagement, delivery, and connection signals available on your plan
- For explicitly granted ClientSignal Managed and Client Ops Founding Pilot workspaces, evaluate supported account evidence and create manually reviewed internal Attention briefs
- Send report emails via your configured sender address
- Monitor integration health and alert you to connection issues
3. Data Security
All OAuth tokens are encrypted at rest using AES-256-GCM encryption. We use Supabase with row-level security policies to ensure strict data isolation between agencies. All data is transmitted over HTTPS.
4. Third-Party Services
We use the following third-party services to operate ClientSignal:
- Supabase — database and authentication
- Cloudflare — bot and abuse protection
- Vercel — application hosting
- Resend — email delivery
- Vercel AI Gateway and configured AI model providers — AI-assisted report and separately granted Attention-brief generation and quality review
- Google, Meta, TikTok, Slack — advertising, analytics, and notification integrations
- Klaviyo — email marketing integration for eligible Growth and Agency workspaces
- HubSpot, Mailchimp — providers for integrations labeled coming soon; they process workspace data only if and when the integration is released, enabled, and authorized
- Sentry — error monitoring and performance tracking
5. Data Retention
Delivered reports, metrics snapshots, feedback, summaries, alerts, and workspace events are retained for the period selected in Agency Settings: 90, 180, 365, or 730 days. The default is 365 days. A daily retention job permanently removes records older than the selected window. Finalized report-job recovery metadata is retained for 30 days, sample-report requests for 90 days, and unconverted lead and prospect-report records for up to 365 days.
An account-deletion request immediately makes the workspace read-only and starts a durable deletion process. ClientSignal confirms supported provider revocation, active-subscription cancellation, and stored-logo removal before deleting the primary agency graph, then removes the owner's ClientSignal authentication account. Temporary provider failures are retried. A provider that exposes no usable programmatic revocation path is recorded as requiring provider-side action and does not prevent deletion of the ClientSignal account.
ClientSignal attempts provider-side revocation for Google, Meta, TikTok, HubSpot, and Slack connections for which it has a revocable OAuth credential. Mailchimp authorized apps, user-supplied Klaviyo private keys, and historical Slack connections that stored only an incoming-webhook URL must also be removed or disabled in that provider's settings. In every case, ClientSignal permanently removes its stored copy of the credential when the agency graph is deleted.
A credential-free deletion-recovery record is retained for 30 days after completion; pending and manual-review records remain only until deletion can be reconciled. Limited records may remain temporarily in Supabase encrypted backups; Stripe billing, tax, fraud-prevention, or dispute records; Resend delivery, bounce, complaint, or suppression records; Vercel and Sentry security or operational logs; AI-provider safety or abuse records; and connected- platform systems. Those records follow the applicable processor's configured, contractual, legal, security, fraud-prevention, and backup-retention requirements rather than the application database's deletion schedule.
6. Your Rights
You have the right to:
- Download a complete portable export of customer-provided workspace data, generated artifacts, engagement history, and associated operational metadata from Account Settings
- Request deletion of your account and all associated data
- Revoke connected-platform access from the provider's own security or integrations settings; account deletion also attempts supported programmatic revocation and always removes ClientSignal's stored credential
- Update your data retention preferences
- Unsubscribe from report emails at any time via the unsubscribe link included in every report (CAN-SPAM compliant)
7. Client Data
Advertising and marketing metrics pulled from connected platforms are processed to provide the reporting and client-operations capabilities requested by your agency. Depending on your plan and separately granted Attention access, those capabilities may include reports, historical comparisons, portfolio and account signals, alerts, attention evidence, and internal weekly briefs. Metrics snapshots and related operational records may be stored to provide those workflows, support quality review, and preserve relevant history. We do not sell this data, use it for our own advertising, or disclose it except to the processors and integrations needed to provide the service on your behalf.
8. Marketing Analytics
Public marketing pages use Google Consent Mode with advertising storage denied by default. Before you accept, Google Ads may receive limited cookieless measurement and consent signals, and temporary Google linker parameters may pass through same-domain signup URLs to preserve ad attribution. Google Analytics and the optional Meta Pixel remain disabled unless you accept, which also enables advertising and analytics storage. These tools are not mounted in the authenticated product, client portals, shared reports, invitation flows, or other private capability pages. You can withdraw consent by clearing the ClientSignal site data in your browser.
9. Contact
For privacy questions or data requests, contact us at support@clientsignal.io.