Legal
Privacy Policy
This Privacy Policy explains what personal data SignQA collects, why we process it, how we share it, how long we keep it, and the rights you may have.
Last updated: September 8, 2026
1. Controller and contact
The controller of personal data processed through SignQA (except as noted for payment below) is the operator of the Service at signqa.monster (“SignQA”, “we”, “us”). This Policy applies to SignQA Teams and Classic solo.
Contact: hello@signqa.monster
For terms of use, see our Terms of Service. For cancellations and refunds, see our Refund Policy.
2. Scope and roles
Account and Service data. When you register or use SignQA, we act as controller for account, billing metadata we store, security logs, and Service operations data.
Organization workspace content. For content that organizations create in Teams (stories, evidence, comments, etc.), the organization typically decides purposes and means of processing. In that capacity we act as a processor / service provider for the organization, and the organization’s admin is responsible for a lawful basis to invite users and upload content. We process that content to provide the Service under our agreement with the organization.
Payments. Paid Teams checkouts are handled by Paddle as merchant of record. Paddle processes payment card and tax data as an independent controller (or as described in Paddle’s privacy notice). We receive subscription status, customer identifiers, transaction/invoice references, and related billing metadata needed to unlock plan entitlements—not full payment card numbers.
3. Information we collect
Account and profile. Email address, name, password (stored hashed), email verification status, profile details you provide, and organization membership and roles.
Workspace content (Teams). Organizations, projects, teams, stories, test cases, steps, statuses, comments, mentions, shares, activity/audit events, and uploaded evidence (for example screenshots in object storage).
Billing metadata. Plan selection, subscription and entitlement status, Paddle customer/subscription/transaction identifiers, invoice history we store or retrieve, and usage against plan limits. We do not store full payment card PANs on SignQA servers.
Technical and security data. Session cookies, IP address, user-agent / device information typical of web server logs, and timestamps needed for authentication, abuse prevention, and reliability.
Classic solo. Classic may keep stories and related data in your browser storage and, if you connect one, in your own Postgres database. Connection strings you save may be stored encrypted so we can sync on your behalf. API keys you enter (for example for AI features) are stored to provide features you enable and remain your responsibility.
Communications. Content of transactional emails (verification, password reset, invites, service notices) and messages you send to our support, billing, or privacy addresses.
We do not intentionally collect special-category data. Please do not upload unnecessary sensitive personal data into stories or evidence.
4. How we use information
- Provide, maintain, secure, and improve the Service
- Authenticate users and manage sessions and organization context
- Operate invites, sharing, roles, and access controls
- Process billing entitlements, enforce plan limits, and respond to billing inquiries
- Send transactional email (verify, reset, invites, security)
- Detect abuse, debug issues, prevent fraud, and comply with law
- Generate and deliver exports or shared views you explicitly create
We do not sell your personal information. We do not use Your Content to train third-party foundation models unless you separately opt in to such a feature (none is enabled by default today). We do not send marketing emails unless you opt in; transactional Service emails may still be sent as needed to operate your account.
5. Legal bases (EEA/UK and similar)
Where the GDPR / UK GDPR or similar laws apply, we process personal data on these bases:
- Contract — to provide the Service and account features you request
- Legitimate interests — security, service integrity, product improvement, and preventing abuse, balanced against your rights
- Consent — where we ask for it (for example optional non-essential cookies or marketing, if offered); you may withdraw consent at any time
- Legal obligation — when we must retain or disclose information to comply with law
8. Retention
We retain personal data only as long as needed for the purposes described in this Policy, including:
- Active accounts / organizations — while the account or organization remains active
- After deletion or closure — we delete or anonymize workspace and account data within a reasonable period (typically within 30–90 days), except backups that roll off on a longer cycle
- Billing and security records — retained as needed for disputes, fraud prevention, accounting, and legal compliance (often up to several years where required)
- Classic local / customer DB data — under your control; clearing browser storage or deleting your database removes that copy
9. Security
We use measures appropriate to the nature of the Service, including HTTPS encryption in transit, hashed passwords, session controls, and access checks for organization data. No method of transmission or storage is completely secure. You are responsible for protecting credentials, invite links, share tokens, customer-managed databases, and API keys.
10. International transfers
We may process and store data in countries other than where you live, including where our hosting providers and subprocessors operate (for example regions in Asia, Europe, or the United States). Where required by law, we rely on appropriate safeguards for cross-border transfers (such as standard contractual clauses or equivalent mechanisms used by our providers).
11. Your rights
Depending on your location (including EEA/UK, and certain other jurisdictions), you may have rights to:
- Access a copy of personal data we hold about you
- Correct inaccurate personal data
- Request deletion (subject to legal retention exceptions)
- Export / portability of data you provided, where applicable
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise rights, email hello@signqa.monster. We may need to verify your identity and may ask for information reasonably needed to locate your data. We aim to respond within one month (or the period required by applicable law).
Organization content. If your data appears in an organization’s workspace, contact that organization’s admin as well; we may redirect requests that must be handled by the organization as controller.
California / similar US state laws. We do not sell or “share” personal information for cross-context behavioral advertising as those terms are commonly defined. You may request access, deletion, or correction as described above. We will not discriminate against you for exercising privacy rights.
12. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Plan entitlement checks are rule-based product features, not profiling for credit or similar purposes.
13. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided data, contact hello@signqa.monster and we will take appropriate steps to delete it.
14. Changes
We may update this Privacy Policy from time to time. We will post the new version with an updated “Last updated” date. Material changes may be highlighted in the product or by email when appropriate. Continued use after the effective date means you acknowledge the updated Policy, except where mandatory law requires consent.
15. Contact
Contact: hello@signqa.monster
Website: https://signqa.monster
