Legal

Privacy Policy

Last updated: May 27, 2026

1. Introduction

Sign Conductor (“we,” “us,” or “our”) is a sign shop management platform operated from St. John’s, Newfoundland, Canada. We are committed to protecting the privacy of the businesses and individuals who use our software.

This Privacy Policy describes what information we collect, how we use it, the third-party services we rely on, and the choices you have with respect to that information.

2. Information We Collect

We collect information in the following categories:

Account and Contact Information

When you register for Sign Conductor, we collect your name, email address, company name, phone number, and billing address. This information is used to create and manage your account and to communicate with you about the service.

Job and Quote Data

Sign Conductor stores the business data you enter into the platform, including customer records, quotes, job details, line items, pricing, materials, change orders, and associated files such as design proofs and photos. This data belongs to you and is used solely to provide the service.

Time Tracking Data

If you use our time tracking features, we collect clock-in and clock-out timestamps, break records, and associated job and staff identifiers. This data is used to generate timesheets and payroll reports within your account.

Usage Data

We automatically collect certain technical information when you use Sign Conductor, including your IP address, browser type, pages visited, application events, performance data, and timestamps. This data helps us diagnose issues, maintain security, improve the product, and understand how the platform is used.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Sign Conductor platform
  • Process payments and manage your subscription
  • Send transactional emails such as quote notifications, invoice reminders, and proof approval requests
  • Send product, account, billing, security, and support notices
  • Respond to support requests and troubleshoot issues
  • Improve the platform through analysis of usage patterns
  • Generate AI-powered suggestions based on your inputs when you use AI features
  • Comply with legal obligations

We do not sell your personal information or your customers’ data to third parties. We do not use your business data to train AI models, and we configure third-party AI services to avoid provider model training where those controls are available.

4. Data Storage and Security

Sign Conductor is hosted on Vercel, a cloud platform with infrastructure located primarily in the United States. Your data is encrypted in transit using TLS and encrypted at rest using industry-standard encryption provided by our hosting and database providers.

Access to your organization’s data is strictly isolated from other tenants. We use session-based authentication with signed tokens and enforce role-based permissions so that only authorized users within your organization can access your data.

While we take reasonable technical and organizational measures to protect your information, no system is completely secure. If you believe your account has been compromised, please contact us immediately at info@signconductor.com.

5. Third-Party Services

Sign Conductor integrates with the following third-party services to deliver its functionality. Each service operates under its own privacy policy:

  • Stripe— Used for payment processing and subscription billing. When you enter payment details, that information is transmitted directly to Stripe and never stored on our servers. Stripe’s privacy practices are governed by the Stripe Privacy Policy.
  • Resend— Used to send transactional emails on your behalf, such as quote delivery, proof approvals, and account notifications. Email content may pass through Resend’s infrastructure to be delivered.
  • Vercel Analytics and Speed Insights — Used to collect aggregate page, performance, and reliability data so we can understand site usage and diagnose production issues.
  • Cloud Storage Integrations — Sign Conductor supports optional integrations with cloud storage providers such as Dropbox, Google Drive, and OneDrive for file management. When you connect a storage provider, files you choose to sync are transmitted to and from that provider under their respective privacy policies.
  • Anthropic and OpenAI — Certain AI-powered features (such as quote assistance and scheduling suggestions) use third-party AI APIs. Inputs sent to these features may be processed by the applicable provider. We limit prompts to the information needed for the specific AI feature and do not use customer prompts or outputs to train our own models.

6. Google User Data (Gmail Integration)

Sign Conductor offers an optional Gmail integration so sign shop staff can read, reply to, and triage customer email inside the app’s shared Inbox. This integration is opt-in and is only activated when an authorized user connects a Google account through Google’s OAuth consent screen.

Scopes we request

  • openid and email — to identify which Google account is connecting and to associate it with the connecting staff member.
  • https://www.googleapis.com/auth/gmail.send — to send quote emails, proof requests, and replies on the connecting user’s behalf.
  • https://www.googleapis.com/auth/gmail.modify — to read, archive, label, mark as read, and otherwise triage the connected mailbox from the in-app Inbox. This scope is only requested for accounts that opt into the shared Inbox feature. A narrower scope (such as gmail.readonly) would not allow the archive/label/mark-read actions that are essential to a shared team inbox workflow.

How we use Google user data

  • Display incoming and outgoing email threads in the Sign Conductor Inbox UI, scoped to the user’s organization.
  • Mirror user-initiated actions (archive, star, label, mark read, reply, send) back to Gmail via the Gmail API.
  • Classify inbound messages as new lead, existing customer, job, vendor, or spam to route them to the correct team folder. Classification uses a rule-based prefilter; only inconclusive inbound messages are sent to a third-party AI provider (Anthropic) for classification, with no message body retained for training.
  • Auto-link threads to existing jobs and customers based on subject and sender matching.

How we do not use Google user data

  • We do not sell or rent Google user data to anyone.
  • We do not transfer Google user data to third parties except as necessary to provide the Inbox feature, to comply with applicable law, or as part of a merger or acquisition.
  • We do not use Google user data to serve advertisements, retarget users, or build advertising profiles.
  • We do not use Google user data to train, fine-tune, or improve generalized or third-party AI/ML models. The AI classification step uses a third-party commercial API only to classify messages for the connected organization’s inbox workflow.
  • We do not allow humans to read Google user data except (a) with your explicit consent, (b) for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.

Storage, retention, and deletion

When you connect a Google account, Sign Conductor stores the data required to operate the Inbox: the connected account’s email address, OAuth tokens, thread and message metadata (subject, sender, recipients, timestamps, Gmail labels), and message bodies needed to display, search, classify, and route email inside your workspace.

You can disconnect a Google account at any time from the in-app Gmail Settings page. On disconnect, we revoke our OAuth tokens with Google and stop background sync for that account. You can also revoke access directly at myaccount.google.com/permissions.

Synced Gmail thread and message records remain in your Sign Conductor workspace after disconnect so your team does not lose customer context unexpectedly. We delete Google user data from active systems within 30 days of a workspace deletion or a deletion request submitted to info@signconductor.com, subject to legal retention requirements. Backups containing Google user data are purged on their normal cycle, usually within 60 days.

Limited Use disclosure

Sign Conductor’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Data Retention

We retain your account data for as long as your subscription is active and as needed to provide the Service. If you delete your account or request deletion, we delete associated data from active systems within 30 days, subject to legal retention requirements and data we must keep for billing, security, dispute resolution, or abuse prevention. Backups are purged on their normal cycle, usually within 60 days.

Some data may be retained longer where required by law or for legitimate business purposes such as resolving disputes or enforcing our agreements. Aggregated, anonymized usage data that cannot be linked to any individual or organization may be retained indefinitely.

8. Your Rights

You have the following rights with respect to your data:

  • Access — You may request a copy of the personal information we hold about you or your organization.
  • Correction — You may update or correct inaccurate information directly within the application, or contact us for assistance.
  • Deletion — You may request that we delete your account and associated data. Deletion requests will be processed within 30 days, subject to any legal retention requirements.
  • Export — You may export your business data (jobs, quotes, customers, and time tracking records) from within the application at any time.
  • Withdraw consent — You may disconnect optional integrations, opt out of non-essential communications, or withdraw consent where applicable.

To exercise any of these rights, please contact us at info@signconductor.com.

9. Cookies

Sign Conductor uses a single session cookie to keep you logged in. This cookie is httpOnly and Secure, meaning it cannot be accessed by JavaScript and is only transmitted over encrypted connections. We do not use advertising cookies or third-party tracking cookies.

You can disable cookies in your browser settings, but doing so will prevent you from logging in to Sign Conductor.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify account owners by email and update the “Last updated” date at the top of this page. Your continued use of Sign Conductor after any changes take effect constitutes your acceptance of the revised policy. If a change would materially expand how we use optional integration data, we will ask affected users for consent before using that data in the new way.

11. Contact Us

If you have questions or concerns about this Privacy Policy or how your data is handled, please contact us:

Sign Conductor

St. John’s, Newfoundland, Canada

info@signconductor.com

This policy applies to Sign Conductor and all services provided under the signconductor.com domain.