Legal
Privacy policy
Last updated 22 July 2026
This policy explains what data Signalpost, a product of Quick Rank Marketing ("Signalpost," "we," "us"), collects and processes, how we use it, and the choices you have. Signalpost is a business-to-business reporting service. We sell to marketing agencies and provide reporting about the local and AI search visibility of those agencies' clients (dental and other local practices). We do not offer the service to consumers. We serve marketing agencies in the United States, the United Kingdom, and the European Union, and the data is stored and processed in the United States.
Who we are and our role
Signalpost is operated by Quick Rank Marketing, established in South Africa. Quick Rank Marketing is the controller responsible for the personal data described in this policy. For the Google account and profile information of the agency staff who log in to Signalpost, we act as a data controller. For the Google Search Console, Google Analytics, and related visibility data we process about an agency's clients, we act as a data processor on the agency's instructions: the agency is responsible for having the right to connect each practice's properties, and we process that data only to produce the agency's reports. A data processing agreement governs that processor relationship and is available to agencies on request.
We never collect patient data or PHI
Signalpost does not connect to dental practice-management systems and does not collect, store, or process any patient data, appointment data, treatment data, or any other protected health information (PHI). This is an architectural boundary, not just a policy: the product has no path to that data and is designed to stay entirely outside the scope of HIPAA.
What we collect and process
Agency account information
- Name and email address of agency staff, provided at sign-up or through "Sign in with Google" (name, email address, and basic profile).
- Authentication and session information needed to keep you signed in securely.
Google Search Console and Google Analytics data
When an agency connects a practice, we request read-only access to that practice's Google Search Console and Google Analytics (GA4) properties. We use this access to read search and traffic metrics, such as impressions, clicks, queries, sessions, and engagement, for the purpose of building that practice's report. We request the minimum, read-only scopes needed (webmasters.readonly and analytics.readonly) and never request write access.
Public Google Places data
- Publicly available business-profile signals for a practice (name, address, phone, category, rating, review count, and hours) retrieved through the Google Places API for context in the report.
Local and AI search-visibility data
- Geo-grid map rankings sampled across public search results using industry-standard SERP APIs.
- Whether a practice is cited in public AI-assistant answers to a set of buying-intent prompts.
Google user data and Limited Use
Signalpost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The Google user data we access is limited to, and used only as described below.
- What we access. Google Search Console search-analytics (search queries, clicks, impressions, and average position) and Google Analytics 4 traffic data (sessions, users, and traffic trends over time). We access this data read-only, through the webmasters.readonly and analytics.readonly scopes, and only after an agency connects the property and consents on behalf of its client.
- How we use it. Solely to generate the agency's white-label client report, the "Search performance" and "Website traffic" sections. That is the only feature it powers; the only other handling of this data is the limited security, legal-compliance, and aggregated internal-operations exceptions described below.
- What we never do. We do not sell this data; we do not use it for advertising or to build advertising profiles; we do not use it to train, develop, or improve any AI or machine-learning models; and we do not transfer or disclose it to third parties except as needed to provide the service (the sub-processors listed below), to comply with applicable law, or in connection with a merger, acquisition, or sale of assets after obtaining explicit prior consent.
- Human access. We do not allow humans to read this data unless we have the agency's affirmative agreement to view specific data; it is necessary for security purposes (for example, investigating a bug or abuse); it is necessary to comply with applicable law; or the data is aggregated and used for internal operations in line with applicable privacy requirements.
We retain this data only while the agency keeps the connection and its account active, and we delete it and the stored Google tokens on disconnection, account termination, or request. See Retention and deletion below.
Tokens and how access is stored
- Google refresh tokens are encrypted at rest and stored server-side only.
- Google access tokens are never persisted, they are requested on demand and discarded.
- All Google API calls are made from our servers. Credentials never reach a browser and never appear in client-side code.
How we use the data
We use the data described above to authenticate agency users, to build and deliver the white-label reports an agency has requested for its clients, and to operate, secure, and support the service. We do not use it to build advertising profiles, and we do not sell it.
Legal bases for UK and EU users
For individuals in the United Kingdom and the European Union, we rely on the following legal bases under the UK GDPR and EU GDPR:
- Legitimate interests (Article 6(1)(f)): providing, securing, and supporting a business reporting service for our agency customers.
- Performance of a contract (Article 6(1)(b)): creating and running the agency's account and delivering the service it has requested.
- Consent (Article 6(1)(a)): where we rely on it, such as the agency's authorization to connect a Google property. The agency can withdraw consent at any time, which does not affect processing already carried out.
Notice at collection
When agency staff sign up or use "Sign in with Google," we present a short notice at the point of collection that links to this policy and states the categories of personal information we collect, the purposes we use it for, that we do not sell or share it, and how long we keep it. That notice is shown on the sign-in screen (at https://signalposthq.com/login) and links here. Because we act as the agency's processor for its clients' data, the agency is responsible for informing its own clients (the practices) about this data collection and for obtaining any consent those clients require, as described in the data processing agreement.
Where it is stored and how it is protected
- Data is stored in the United States (our database and infrastructure run in a US region), even though the controlling entity, Quick Rank Marketing, is established in South Africa.
- Every database table enforces row-level security, and every request is checked for organization membership, so one agency's data is walled off from every other agency's.
- Data is encrypted in transit (HTTPS) and refresh tokens are encrypted at rest.
International data transfers
Because the data is stored and processed in the United States while Quick Rank Marketing is established in South Africa, personal data of UK and EU individuals is transferred out of the UK and the EEA. Where we make such a transfer, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses (SCCs) for transfers from the EU, the UK International Data Transfer Addendum or IDTA for transfers from the UK, and adequacy decisions where they apply. A copy of the relevant safeguards is available on request.
Sub-processors
We use a small number of service providers to run Signalpost:
- Google: Search Console, Analytics, and Places APIs (the source data).
- Supabase: database, authentication, and storage (US region).
- Vercel: application hosting.
- SERP data provider(s): geo-grid ranking data from public search results.
Data sharing
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share data only with the sub-processors above to provide the service, when required by law, or in connection with a merger, acquisition, or sale of assets after obtaining explicit prior consent. Reports we generate are delivered to the agency that connected the practice; we do not share one agency's data with another.
Retention and deletion
We keep each category of data only as long as we need it for the purpose it was collected:
- Agency account information (name, email, authentication and session data): kept while the account is active and for up to 90 days after the account is closed, then deleted, unless a longer period is required by law.
- Google refresh tokens: deleted when the agency disconnects the property or closes the account (access tokens are never stored).
- Connected Search Console and Analytics data: read on demand to build reports and retained only as part of the reports we generate; we do not keep a separate long-term store of raw Google metrics.
- Reports and their PDF files, and visibility data (geo-grid rankings and AI-answer records): kept while the account is active and deleted on account closure or on request.
- Operational and security logs: kept for up to 12 months, then deleted or aggregated.
An agency can disconnect a practice at any time, can revoke Signalpost's Google access directly from its Google Account security settings, and can ask us to delete its account data by emailing the contact below.
Your privacy rights in the UK and EU
If you are in the United Kingdom or the European Union, you have the right to access your personal data, to have it corrected (rectification), to have it deleted (erasure), to restrict or object to our processing, to data portability, and to withdraw consent where we rely on it. To exercise any of these rights, email us at hello@signalposthq.com. You can also lodge a complaint with your local supervisory authority: in the UK, the Information Commissioner's Office (ICO); in the EU, your national data protection authority.
Your privacy rights in California
This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). In the past 12 months we have collected the following statutory categories of personal information, which map to the plain-English items listed above:
- Identifiers: real name, email address, and account or device identifiers of agency staff.
- Internet or other electronic network activity information: authentication and session information, and operational or security logs.
- Professional or employment-related information: the fact that a user is staff of a marketing agency acting for its clients.
We do not collect sensitive personal information as defined by the CPRA. We collect this information from you directly (at sign-up or through "Sign in with Google"), from Google APIs with the agency's consent and on its instructions, and from public sources (business-profile and public search data, which is not personal information about the agency user). We use it for the business purposes of providing, authenticating, securing, and supporting the reporting service. We may disclose it to the categories of third parties listed under Sub-processors above, and, where required, to legal or regulatory authorities or to a successor entity in a merger, acquisition, or sale of assets.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We treat a Global Privacy Control (GPC) browser signal as a valid request to opt out of sale or sharing, even though we do not sell or share personal information.
As a California resident you have the right to:
- Know and access the personal information we have collected about you.
- Delete the personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (we do not sell or share).
- Limit the use of sensitive personal information (we do not collect any).
- Not be discriminated against for exercising any of these rights.
To exercise a California right, email us at hello@signalposthq.com. We will confirm receipt and respond within 45 days; if we need more time, we will tell you and may extend by a further 45 days. We may need to verify your identity before acting on a request. We keep each category of personal information only for the periods described under Retention and deletion above.
Security incidents
We maintain an incident-response process. If a security incident affects personal data, we will investigate promptly, notify affected agencies without undue delay, and notify the relevant regulators within the timeframes required by applicable law (for example, within 72 hours where the UK GDPR or EU GDPR requires it). If a security incident affects Google user data obtained through restricted scopes, we will report it to Google as required by the Google API Services User Data Policy.
Children
Signalpost is a business tool sold to marketing agencies for business use. It is not intended for, or directed to, anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by a new "last updated" date at the top of this page.
Contact and legal entity
Signalpost is a product of Quick Rank Marketing, the controller responsible for the personal data described in this policy. Quick Rank Marketing is established in South Africa; the data is stored and processed in the United States. For any privacy question, or to exercise a right described above, email hello@signalposthq.com.
Governing law
This policy is governed by the laws of the Republic of South Africa, where Quick Rank Marketing is established. This does not remove the protections you have under the law of your own country or state: UK, EU, and California residents keep their statutory rights and may contact their local supervisory or regulatory authority.