Privacy Policy
Version 2026-01-01 · Effective 1 January 2026
The short version. We collect what we need to run a marketplace: who you are, what you listed or booked, and what you paid. We do not sell your personal information. We do not run third-party ad trackers. Payment card details never touch our servers. You can export or delete your data from your privacy settings.
1. Who is responsible
Signperch is the data controller for the personal data described here. Contact our privacy team at privacy@signperch.com.
2. What we collect
2.1 Data you give us
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Name, email, password hash | Create and secure your account | Contract |
| Phone, company name, profile photo, bio | Let the other party know who they are dealing with | Contract / legitimate interest |
| Listing address and coordinates | Show the space on the map and enable booking | Contract |
| Booking details, campaign names, creative files | Operate the rental and settle disputes | Contract |
| Messages between users | Deliver the conversation; investigate abuse | Contract / legitimate interest |
| Support correspondence | Answer you and improve the service | Legitimate interest |
2.2 Data collected automatically
- Technical data — IP address, browser and device type, pages viewed, timestamps. Used for security, abuse prevention, and debugging.
- Approximate location — derived from your IP to centre the map, or precise location only if you grant browser or app permission.
- Cookies — see the Cookie Policy. Analytics and marketing cookies are off until you opt in.
2.3 Data we never see
Payment card numbers. Card details go directly from your browser to Stripe. We store only a Stripe customer reference, the last four digits, and the card brand. For Space Owners, identity documents and bank details are collected and held by Stripe under its own privacy policy as part of KYC — we receive only a pass/fail status and payout metadata.
3. How we use it
- Operating the marketplace: listings, search, bookings, payouts, messaging.
- Fraud prevention, moderation, and enforcing our policies.
- Transactional email — booking confirmations, receipts, security alerts. You cannot opt out of these while you hold an account, because they are part of the service.
- Marketing email, only with your consent, with an unsubscribe link in every message.
- Aggregate analytics to decide which cities need more inventory.
- Meeting our legal, tax, and accounting obligations.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
4. Automated decisions
We use automated checks to flag suspected fraud, spam, and prohibited content. These can restrict an account or hide a listing. They never make a final irreversible decision about you on their own — you can request human review by emailing privacy@signperch.com, and we will look at it.
5. Who we share it with
| Recipient | What | Why |
|---|---|---|
| The other party to a booking | Your name, profile, and the booking details. The exact street address of a space is shared with the Advertiser once a booking is confirmed. | To carry out the rental |
| Stripe | Payment and identity data | Processing payments and payouts |
| Supabase | Application database and file storage | Hosting |
| OpenFreeMap | Map tile requests (your IP and the area you are viewing) | Rendering the map. No account, no cookie, no tracking identifier. |
| Email provider | Your email address and message content | Sending transactional email |
| Law enforcement | Only what is legally required | Valid legal process |
If Signperch is acquired or merges, personal data may transfer to the successor. We will notify you before your data becomes subject to a materially different policy.
6. International transfers
Our infrastructure is hosted in Canada and the United States. Where we move personal data out of the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, or an adequacy decision — Canada holds partial adequacy for commercial organisations.
7. How long we keep it
| Data | Retention |
|---|---|
| Account profile | While your account is open, then 30 days |
| Booking and payment records | 7 years — required by tax and accounting law |
| Messages | 3 years after the related booking ends |
| Creative files and proof-of-posting | 2 years after campaign end, as dispute evidence |
| Security and audit logs | 12 months |
| Consent records | 5 years, to evidence your choices |
When you delete your account we anonymise your profile and remove your content, but we keep the financial record of completed bookings for the period above. That record is stripped of everything not needed for accounting.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, port, or restrict your data; to object to processing based on legitimate interests; to withdraw consent; and not to be discriminated against for exercising any of these.
Exercise any of them from your privacy settings, or email privacy@signperch.com. We respond within 30 days and will not charge you for a reasonable request.
You can also complain to your data protection authority — in the UK the ICO, in the EU your national supervisory authority, and in Canada the Office of the Privacy Commissioner. We would rather you told us first.
9. Security
- TLS in transit; encryption at rest for the database and file storage.
- Passwords hashed with bcrypt by Supabase Auth. Nobody at Signperch can read yours.
- Row-level security in the database, so a user’s query is constrained to their own rows by the database itself rather than by application code alone.
- Private storage buckets with short-lived signed URLs for creatives and proofs.
- Least-privilege access for staff, with an audit trail.
No system is perfectly secure. If we suffer a breach affecting your personal data we will notify you and the relevant regulator as required, and within 72 hours where GDPR applies.
10. Children
The Platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email privacy@signperch.com and we will delete it.
11. Changes
We will post any change here and update the version at the top. For material changes we will notify you by email at least 30 days in advance.
Before you launch: confirm the retention periods and the named sub-processors match what you actually run, register with your data protection authority if required, and have counsel review this against GDPR, UK GDPR, PIPEDA, and CCPA/CPRA for your markets.