SaleSignal
Legal

Privacy Policy

Last updated: September 22, 2026 · Sphere Link Innovations

This describes what SaleSignal (a product of Sphere Link Innovations, “we”, “us”) actually collects about you, why, who else genuinely sees it, and what you can do about it. It covers the marketing site, the free Market Research Request tool, the prospect tour and booking flow, the customer product, and the affiliate program.

1. What we collect

We collect different things depending on how you interact with us:

  • Free market research request (/market-research-request): full name, business email, company website, country, state/province/region, and an optional free-text description of who you’re trying to reach.
  • Prospect tour & booking: if you book a call through our own on-platform calendar, we collect your name, email, an optional message, and the time you booked. If you use the “Book a Call” link instead, that opens Calendly in a new tab — see §3.
  • Customer account: first name, last name, company name, email, and a password (Supabase Auth stores this hashed — we never see or store it in plain text).
  • Affiliate program: name, email, password, and, where you provide them, country and social-media handles for verifying referral activity.
  • Product use: the business information, ideal customer profiles, research inputs, and outreach messages you create in the product, plus operational metadata (login and permission events, workspace membership, IP address on certain actions like referral clicks) used for security and to run the service.

We deliberately do not collect or store the content of replies a prospect sends back to your outreach — only whether a reply happened and when. Your correspondence stays in your own mailbox.

2. Why we collect it

  • To create and secure your account, and to know which workspace and role a request is acting as.
  • To run the market research, prospecting, and outreach features you use the product for.
  • To review free Market Research Requests by hand before any research runs, and to email you when results are ready.
  • To schedule and honor calls you book.
  • To operate the affiliate program: attributing a signup to the affiliate who referred it, and calculating commission.
  • To keep a security audit trail (logins, permission changes, credential connect/disconnect, admin actions) for investigating incidents and for billing/legal record-keeping.

3. Who else processes it

We use a short list of real, named processors — not a vague “service providers” clause:

  • Supabase — our database and authentication provider. Your account, workspace, and product data live in a Supabase-managed Postgres database; Supabase Auth handles password storage and login.
  • SendGrid — sends the transactional emails the platform sends you directly (request-received, research-ready, password reset, account-activated) and, where a workspace runs outreach campaigns, the outbound messages composed in the product. SendGrid also reports whether a sent message was opened.
  • Google (Gemini API) — the AI model that performs our market research: it processes the business and market information a workspace supplies (and, when generating results, uses Gemini’s google_search grounding tool, which sends search queries derived from that information to Google) to produce research output. This is not used to make decisions about you personally — it processes business/market content, not to profile individual users.
  • Stripe — not currently active. Billing is switched off in the product today (see the Terms of Service, §6); no payment data reaches Stripe yet. When billing is turned on, Stripe will process payment details for subscription and credit purchases, and this section will be updated first.
  • Calendly — the “Book a Call” link on our marketing pages opens a Calendly page in a new tab. That booking happens on Calendly’s own site, under Calendly’s own privacy policy; we don’t control or receive a copy of what you submit there beyond Calendly’s own notification to us that a call was booked.
  • Google / Microsoft — only if you choose to connect a Gmail or Outlook mailbox, which we use to detect whether a lead replied (a yes/no signal and a timestamp only — we never read or store the content of that reply). That provider’s own terms and privacy practices apply to the connection itself.

4. Cookies

We use a small number of session and attribution cookies, described in full in the Cookie Policy. We do not currently run any analytics or advertising tracking on the site.

5. Data retention

  • Account and workspace data is kept for as long as your account exists.
  • Free Market Research Request submissions are kept so our team can review and complete the request.
  • If you delete your account (see §6), your workspace’s research data, connections, and credentials are deleted. We retain your workspace’s security audit log (login/permission/credential/admin history) and a minimal billing-reference record — never a soft “deleted” flag on the data itself — because we genuinely need those for security investigation and legal/financial record-keeping.

6. Your rights — what you can actually do today

This matches what’s built in the product right now, not an aspirational list:

  • Export your data: from Settings, you can download a JSON export of everything tied to your workspace — offers, research, connection metadata (never a raw credential), and your security audit log.
  • Delete your account: from the same Settings page, you can permanently delete your workspace’s data and disconnect every integration, subject to the retention described in §5.
  • Contact us (below) to ask what we hold about you, correct it, or ask a question this policy doesn't answer.

7. Security

Data sits in Supabase’s managed Postgres with row-level security, behind authentication that goes through Supabase Auth on every request — nothing trusts a client-supplied user or workspace id. Session tokens are stored as httpOnly cookies (see the Cookie Policy). We never log a raw credential or secret; integration connections are recorded as metadata only (provider, status, timestamps).

8. Children

SaleSignal is a B2B product intended for business use and is not directed at, or knowingly used by, children.

9. Changes to this policy

If what we actually collect or who processes it changes, we’ll update this page and the “Last updated” date above.

10. Contact

Questions about this policy: hello@sale-signal.com. General support: Support@sphere-link-team.com or 587-335-4336.