Privacy Policy
Effective Date: May 22, 2026 Last Updated: August 7, 2026
Correction, 5 August 2026. We have corrected Section 2.6. A previous version stated that LinkedIn data was not sent to our AI providers by default. That statement did not accurately describe how the Platform processed LinkedIn Page analytics. LinkedIn Page analytics connected to a workspace have been processed by the AI providers listed in Section 5.1 to generate in-product analysis and recommendations. We do not use LinkedIn data to train any AI or machine learning model, and our written terms with those providers prohibit them from using it to train or improve their products or generally available models. We have corrected the Section 2.6 language and updated the sub-processor descriptions in Section 5.1 to describe this accurately.
This Privacy Policy ("Policy") describes how Reverge LLC ("Reverge," "we," "us," or "our") collects, uses, shares, and protects information in connection with our websites and services, including:
- www.reverge.com — our consulting and advisory practice.
- www.signalandscience.com — the public marketing site for Signal & Science.
- Signal & Science (app.signalandscience.com) — our AI-assisted marketing platform (the "Platform").
- Any related applications, APIs, dashboards, communications, and offline interactions (collectively, the "Services").
The Services are intended for businesses operating in the United States and the people who run, manage, or work for those businesses. The Services are not intended for consumers, individuals under 18, or residents outside the United States. By using the Services, you represent that you are at least 18 years old, are using the Services on behalf of a business, and are accessing them from within the United States.
1. Summary
- We collect information you provide (account, business, payment, support communications), information generated when you use the Services, information from third-party tools you connect, and information about your business that is publicly available online.
- We use that information to operate the Services, diagnose your business's marketing, generate plans and content, execute work you authorize, secure the Services, and run our company.
- We do not sell your personal information. If advertising technologies are enabled on our public marketing site, we may disclose limited website activity to advertising platforms for campaign measurement and retargeting as described in Sections 5.7 and 7. We do not use your business data, including Meta Platform Data, to train third-party AI models.
- You can access, correct, delete, or export your information by contacting us.
2. Information We Collect
2.1 Information You Provide Directly
When you request access, sign up, onboard, use the Platform, or contact us, we may collect:
- Identity and contact: name, email address, phone number, business name, business website, business location, role/title.
- Account credentials: password (stored hashed), session tokens, multi-factor authentication data.
- Business profile: revenue range, vertical/industry, goals, marketing capabilities, brand assets, logos, product or service descriptions, pricing, customer descriptions, internal notes, and any other content you input.
- Payment information: name, billing address, last four digits of payment card, and tax/billing identifiers. Full card numbers are processed and stored by Stripe; we do not store them.
- Communications: support messages, survey responses, sales inquiries, beta-access requests, and any content you submit through forms or email.
2.2 Information We Collect Automatically
When you use the Services, we automatically collect:
- Device and connection data: IP address, approximate geographic location (such as city, region, and country) derived from your IP address, browser type, operating system, device identifiers, language preferences, referring URLs, time stamps.
- Marketing attribution data: when you arrive at our marketing site from a campaign, advertisement, or referral link, we record the campaign parameters in the URL (such as
utm_source,utm_medium, andutm_campaign), the referring domain, and any advertising click identifier the advertising platform appended to the link (such as Google'sgclid, Microsoft'smsclkid, Meta'sfbclid, LinkedIn'sli_fat_id, or OpenAI Ads'oppref). We also generate a first-party session identifier so a visit to our marketing site can be connected to an application later submitted on the Platform. We use this to measure which campaigns produce sign-ups. - Advertising interaction data: if advertising technologies are enabled on our public marketing site, advertising platforms may receive the pages you view, referring URL, campaign and click identifiers, approximate location, IP address, browser and device information, and their own cookie or device identifiers. We use this data to measure advertisements, build audiences of marketing-site visitors, and show relevant advertisements. We do not send Platform account activity, connected-service data, form contents, submitted business URLs, generated briefs, or customer business data to advertising platforms for this purpose.
- Usage data: pages and features accessed, actions taken, content generated, errors encountered, session duration, and similar telemetry. We use Vercel Web Analytics for privacy-focused page-view analytics and may use PostHog to capture product analytics events. We do not enable session replay by default; if session replay is enabled for debugging, sensitive form fields (e.g., passwords, payment fields, API keys, and payment information) are masked.
- Cookies and similar technologies: see Section 7.
- Error and performance logs: captured via Sentry and Vercel for debugging and reliability. These logs may contain limited identifiers and request metadata.
2.3 Information from Third-Party Services You Connect
If you choose to connect a third-party service to the Platform via OAuth or API key, we receive the data you authorize. Currently supported integrations include:
- Google services: Google Business Profile and Google Analytics 4 (connected via OAuth). We also use Google Places and PageSpeed Insights as diagnostic data services (no account connection required).
- Meta: Facebook Pages and Instagram Professional accounts, including read-only insights.
- E-commerce platforms: Shopify, WooCommerce.
- LinkedIn: LinkedIn Company Pages you administer, including read-only Page analytics (follower, page, and share statistics).
- X (Twitter): X accounts you connect, including read-only account and post analytics (followers, impressions, and engagement statistics).
- Other platforms we add over time (disclosed in-product before connection).
We use connected data only to operate features you have requested (for example, pulling your GA4 traffic to analyze performance). These integrations are data sources you authorize; they are not sub-processors acting on our behalf. You may disconnect any integration at any time, which revokes ongoing access; previously synced data may be retained as described in Section 8.
2.4 Meta Platform Data (Facebook and Instagram)
If you connect a Facebook Page or Instagram Professional account, we use Meta Platform Data only to provide read-only marketing analytics inside your private Signal & Science dashboard and related reporting views. Depending on the account and permissions you grant, this may include:
- Facebook Page reach, post engagement, page views, video views, website clicks, and follower counts.
- Instagram reach, views or impressions, profile visits, website clicks, follower growth, account engagement, and total interactions.
- Account and page identifiers needed to keep the integration connected and display the selected account.
For the first Meta integration release, we do not publish content, send messages, read private messages or DMs, manage comments, run ads, manage ad accounts, or modify connected Facebook or Instagram accounts. We do not access your Meta password, private message content, follower content, message inbox content, or ad-account data.
Meta Platform Data is never used to train, fine-tune, or otherwise improve any AI or machine learning model, by us or by any third party. We do not currently send Meta Platform Data to Gemini or any other AI provider, and Meta Platform Data is excluded from external AI assistant connections under Section 4.1. We maintain the current list of AI providers in Section 5.1 and will update this Policy to reflect the practices then in effect.
If an agency or other representative connects a client-owned Facebook Page or Instagram account, that representative is responsible for confirming it has authority from the account owner to connect the account and authorize our processing.
2.5 Shopify and E-commerce Platform Data
If you connect a Shopify or WooCommerce store, we use the merchant's commerce data only to provide aggregated marketing and revenue analytics inside your private Signal & Science dashboard and related reporting views. Specifically, we read from the Shopify Admin API (or WooCommerce REST API) and process the following fields:
- Order ID, total price, currency, financial status, creation timestamp, and the numeric customer ID associated with each order — used in memory during sync to compute daily aggregate metrics (orders, revenue, average order value, distinct customer count), then discarded.
- Total customer count for the store — a single integer.
- Up to five top-selling product titles and IDs.
- Basic shop metadata (shop name and primary domain) used to label the integration.
We do not read or store customer names, customer email addresses, customer phone numbers, billing or shipping addresses, or payment instrument details. We read order line items only in memory to aggregate up to five best-selling product titles, IDs, unit totals, and revenue totals; the raw line items are not persisted.
We persist only the daily aggregated totals (orders, revenue, AOV, distinct customer count) in our database. Individual order responses, customer IDs, and any per-order detail are aggregated in memory during the sync job and discarded within seconds.
We do not sell or transfer Shopify or WooCommerce data to advertisers or data brokers. Our infrastructure sub-processors process the data to host and store the service. Aggregated daily commerce metrics may also be included in prompts sent to the AI providers listed in Section 5.1 so Signal & Science can explain marketing performance and produce weekly recommendations. Raw order objects, customer IDs, and per-order details are never sent to AI providers. We and our AI providers do not use this data to train or improve generally available machine learning models.
We participate in Shopify's mandatory data-protection program. When the merchant, an end customer, or Shopify itself requests data access, customer deletion, or shop deletion, we respond to the corresponding webhook (customers/data_request, customers/redact, shop/redact) within Shopify's required timeframes and maintain an audit record of each such request.
You can disconnect the integration at any time from the Integrations page in the Signal & Science dashboard. For Shopify, disconnection deletes the stored access token, stops further sync, and deletes Shopify-sourced aggregates. If you uninstall the Shopify app, the immediate app/uninstalled webhook deletes the stored credential and stops sync; Shopify's later shop/redact delivery deletes the remaining Shopify-sourced aggregates. See Section 8 for retention timing.
2.6 LinkedIn Page Data
If you connect a LinkedIn Company Page you administer, we use LinkedIn data only to provide read-only marketing analytics inside your private Signal & Science dashboard and related reporting views. Depending on the Page and permissions you grant, this may include:
- Follower statistics (lifetime and time-bound follower counts and follower growth).
- Page statistics (page views and click metrics for the Page).
- Share statistics (impressions and engagement on the Page's posts, aggregated over selected date ranges).
- Organization and Page identifiers needed to keep the integration connected and display the selected Page.
We access only LinkedIn Company Pages that the connecting user administers. The LinkedIn permissions requested for this integration may include r_basicprofile, r_1st_connections_size, r_member_profileAnalytics, r_member_postAnalytics, r_organization_social_feed, and rw_organization_admin, depending on LinkedIn's current approval and consent screen. We use those permissions only to verify the connecting member, confirm Page administrator access, list administered Company Pages, and retrieve read-only Page and post analytics. We do not publish posts, send or read messages, manage comments, run or manage ads, or modify any connected LinkedIn Page or account. We do not access your LinkedIn password, private messages, or ad-account data.
We do not use LinkedIn data to train, fine-tune, or otherwise improve any AI or machine learning model. We use the AI providers listed in Section 5.1 to generate analysis and recommendations from your connected LinkedIn Page analytics inside your workspace. Those providers act as our service providers under written terms that limit their processing to providing the service to us, complying with law, and detecting and preventing abuse, that prohibit them from using your data for any other customer or to train or improve their products or generally available models, and that require deletion when the engagement ends, subject to narrow exceptions for legal holds and abuse investigations. Each provider may retain prompts and outputs for a limited period, currently up to 30 days for OpenAI and up to 55 days for Google, solely to detect and prevent abuse of its services, after which the data is deleted in the ordinary course. If you connect an external AI assistant to your workspace, your LinkedIn Page analytics are made available to that assistant only at your direction, only through the connection you authorize, and only for the purpose stated when you authorize it. You can revoke that connection at any time. See Section 4.1.
If an agency or other representative connects a client-owned LinkedIn Company Page, that representative is responsible for confirming it has authority from the Page owner to connect the Page and authorize our processing.
You can disconnect the integration at any time from the Integrations page in the Signal & Science dashboard. Disconnection deletes the stored access token from Signal & Science and stops further sync; you can also revoke the app grant from LinkedIn. See Section 8 for retention timing.
2.7 Information from Public Sources About Your Business
To diagnose marketing performance and produce recommendations, the Platform collects publicly available information about the business you ask us to analyze and, where relevant, about competitor businesses and the local market. This may include:
- Business listings and profiles (Google Business Profile, Yelp, business directories).
- Public web content (your website, competitor websites).
- Public social media profiles and posts associated with the business.
- Search engine results and on-page SEO signals.
- Page speed and technical performance data.
- Public review content and ratings.
We collect this information using a combination of official APIs (e.g., Google Places, PageSpeed Insights) and authorized public-data-collection infrastructure (including Apify, Bright Data, DataForSEO, Brave Search, and Exa). We collect only public-facing business information and do not attempt to circumvent access controls, paywalls, or login requirements.
2.8 Information About People at the Business
When you onboard a business, we may collect publicly available information about its principals (for example, an owner's name appearing on a Google Business Profile, or a personal profile URL representing a professional services brand). We treat this information as business-context information used to perform the Services you have requested. Removal requests for such information are governed by Section 9.
2.9 Public Client Briefs
Our public Signals & Moves feature lets a visitor submit a business website URL and receive an AI-assisted marketing brief without creating an account. For this feature:
- We process the submitted website URL and publicly available business information associated with that website to identify the business, evaluate visible marketing evidence, and generate a recommendation.
- We may process the submitted URL and public information through the infrastructure and AI sub-processors listed in Section 5.1. We do not request or use login credentials, private client accounts, or connected-account data for a public brief.
- A successful brief may be cached for up to 24 hours so repeated or simultaneous requests for the same website do not purchase or generate duplicate analysis. Expired cache records are deleted automatically.
- We record bounded operational and acquisition information such as completion status, latency, campaign attribution, cache use, and abuse-control outcomes. These funnel events do not include the submitted website URL, evidence excerpts, or generated brief text and are retained for up to 90 days by default.
- A visitor may create an opaque share link for the public brief. The signed public brief is stored in a service-only lookup record for up to 12 months so the link can remain short and usable. Anyone who receives the link can view its contents, so the visitor should review the brief before sharing it.
- Rate limits, bot controls, concurrency limits, caching, and emergency spend controls may be used to protect the Services and prevent abusive or excessive use.
3. How We Use Information
We use the information described above to:
- Provide the Services — create accounts, authenticate users, run diagnostics, generate plans and content, execute campaigns and tasks you authorize, deliver consulting work, and surface results.
- Process payments — bill subscriptions, manage trials and entitlements, prevent payment fraud (via Stripe).
- Communicate with you — send transactional messages (account verification, password reset, billing, security, beta access decisions, product updates), respond to support requests, and — where permitted — send occasional product news. You can opt out of non-transactional emails at any time.
- Improve the Services — analyze aggregated usage, debug errors, run experiments, develop new features, and refine our recommendations.
- Secure the Services — detect, prevent, and respond to fraud, abuse, security incidents, and policy violations.
- Comply with law and enforce our terms — meet legal obligations, respond to lawful requests, defend legal claims, and enforce our Terms of Service.
- Run our business — accounting, tax, audit, and corporate operations.
- Measure and advertise the Services — if advertising technologies are enabled, measure campaign performance, limit repetitive ads, build audiences of visitors to our public marketing site, and show relevant advertisements, subject to the controls in Section 7.
4. AI Processing
The Platform uses artificial intelligence to analyze businesses and generate content, plans, and recommendations. By using the Services, you acknowledge and agree to the following:
- We use Google Gemini as our primary AI provider and OpenAI (GPT models) as a fallback provider, which processes the same business inputs for reliability and continuity of service when the primary provider is unavailable or degraded. We maintain at least one fallback AI provider at all times, and may add, change, or remove AI providers at any time; we will update this Policy and the sub-processor list in Section 5.1 to reflect the AI providers then in use.
- Inputs you submit, and information we collect about your business, may be transmitted to AI providers and processed under those providers' published API or enterprise terms, except that Meta Platform Data is not sent to AI providers unless and until that processing is expressly reviewed, enabled, and disclosed.
- We select AI providers whose published terms restrict use of customer-submitted inputs to train general-purpose models. We do not independently warrant, guarantee, or assume responsibility for any AI provider's data-handling practices, and we are not liable for any AI provider's acts or omissions.
- AI Output can be inaccurate, incomplete, biased, fabricated, or out of date. You are solely responsible for reviewing, fact-checking, and editing any Output before relying on it. Any reliance you place on AI Output is at your own risk.
- The Services are not designed or intended to make legal, employment, credit, housing, healthcare, insurance, or other consequential decisions about individuals. If you choose to use Output for any such purpose, you do so at your own risk and assume all liability arising from that use.
4.1 External AI Assistants You Connect
The AI providers described above are providers we engage to operate the Services. This section describes something different: an AI assistant that you connect, under your own account.
You can connect an external AI assistant, such as Claude or ChatGPT, to your Signal & Science workspace. When you do, that assistant can read the workspace data you have granted it access to, at your direction and under your own agreement with the assistant provider. Those providers are not our sub-processors. They act on your instructions, under the terms you have agreed with them, and their handling of your data is governed by those terms rather than by this Policy.
We record the authorization you give, limit the connection to the workspaces and permissions you approve, and stop making data available as soon as you revoke it. You can review and revoke connections at any time in your workspace settings. Meta Platform Data is excluded from these connections.
Because the assistant provider is your provider and not ours, we cannot direct it to delete data it has received, impose retention limits on it, or audit its handling on your behalf. Requests of that kind go to that provider under your agreement with them.
5. How We Share Information
We do not sell or rent personal information. We share information only as described below:
5.1 Service Providers (Sub-Processors)
We share information with vendors who help us operate the Services, each under contractual confidentiality and security obligations. Current sub-processors include:
| Vendor | Purpose |
|---|---|
| Vercel | Application hosting, edge infrastructure, and privacy-focused page-view analytics |
| Cloudflare | Authorization server and request routing for external AI assistant connections; stores connection authorization records and hashed connection credentials |
| Supabase | Database, authentication, and file storage |
| Stripe | Payment processing and subscription billing |
| Resend | Transactional and product emails |
| Sentry | Error tracking and performance monitoring |
| PostHog | Product analytics and feature usage telemetry; session replay only if separately enabled and disclosed |
| Google (Gemini API) | AI processing for in-product analysis and recommendations (primary provider). Bound by written terms prohibiting use of customer data to train or improve its products or generally available models; limited retention (currently up to 55 days) is used solely for abuse detection and policy enforcement. Meta Platform Data is excluded. |
| OpenAI | AI processing for in-product analysis and recommendations (fallback provider for reliability and continuity). Bound by written terms prohibiting use of customer data to develop or improve its models or services; limited retention (currently up to 30 days) is used solely for abuse detection. Meta Platform Data is excluded. |
| Google (Tag Manager, Ads, Places, GA4, GBP, PageSpeed APIs) | Advertising tag delivery and campaign measurement if enabled; marketing data sources |
| Apify | Public-data collection infrastructure |
| Bright Data (Bright Data Ltd.) | Public-web data collection (search-result fallback for business discovery) |
| DataForSEO (DataForSEO LLC) | Public SEO and Google Business Profile data collection |
| Brave Search (Brave Software, Inc.) | Public web-search data for business and competitor discovery |
| Exa (Exa Labs, Inc.) | Public web-search and content extraction for business and competitor discovery |
We may add or replace sub-processors as the Services evolve. A current list is available on request.
5.2 Third-Party Integrations You Authorize
When you connect a third-party service (e.g., Shopify, Meta), data flows between that service and the Platform as needed to operate the integration. Those services have their own privacy practices, which we do not control.
5.3 Professional Advisors
We may share information with our attorneys, accountants, auditors, and insurers, each under confidentiality obligations.
5.4 Legal and Safety
We may disclose information when we believe in good faith that disclosure is necessary to: (a) comply with applicable law, regulation, subpoena, or other legal process; (b) protect the rights, property, or safety of Reverge, our customers, or others; (c) detect, investigate, or prevent fraud, abuse, or security incidents; or (d) enforce our Terms of Service.
5.5 Business Transfers
If Reverge is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you (by email or in-Service notice) of any such transfer that materially affects your information.
5.6 With Your Direction
We share information when you instruct us to — for example, when you ask us to publish content to a connected social account, or to share a report with a teammate.
5.7 Advertising Platforms
If advertising technologies are enabled on www.signalandscience.com, we may disclose the limited advertising interaction data described in Section 2.2 to Google Ads, Meta, X (Twitter), Reddit, LinkedIn, and OpenAI Ads to measure campaigns and, where supported by the platform, retarget visitors to our public marketing site. We may test additional advertising channels, including connected-TV providers, only after reviewing the provider and updating this Policy where necessary.
Depending on applicable state law, this disclosure may be considered "sharing" for cross-context behavioral advertising or "targeted advertising," even though we do not receive money in exchange for the information. You can opt out through the Your Privacy Choices control on our public marketing site or by sending a Global Privacy Control signal. We do not disclose Platform customer data, connected-service data, form contents, submitted business URLs, generated briefs, or customer business data to advertising platforms for this purpose.
6. Marketing Communications
- Transactional messages (account, security, billing, beta access, service notices) are sent regardless of marketing preferences because they are required to operate the Services.
- Product and marketing emails are sent only where permitted. Every marketing email contains an unsubscribe link. You can also email us at the address in Section 13 to opt out.
- We do not currently send marketing SMS. If we add SMS in the future, we will obtain prior express consent and provide opt-out instructions in compliance with the Telephone Consumer Protection Act (TCPA) and applicable rules.
7. Cookies and Tracking Technologies
We use cookies, local storage, and similar technologies to:
- Strictly necessary: keep you logged in, maintain your session (Supabase auth), provide CSRF protection, rate limiting, and operate core security features.
- Functional: remember preferences such as theme and dismissed notices.
- Analytics: measure how the Services are used so we can improve them. We use Vercel Web Analytics for page views and basic traffic analytics. Vercel Web Analytics does not use cookies and is designed to report aggregated usage without identifying individual visitors across applications or websites. If enabled, we may also use PostHog for product analytics, including event capture (page views, feature usage, button clicks). PostHog cookies and identifiers are first-party where technically feasible.
- Diagnostics: detect and debug errors (Sentry).
- Advertising: if enabled on our public marketing site, measure campaigns, build audiences of marketing-site visitors, and show relevant advertisements through tags managed in Google Tag Manager.
Advertising tags are disabled by default. If we activate them, they are limited to www.signalandscience.com and are not loaded on app.signalandscience.com. The advertising gate permits tags only when the visit resolves to the United States, the browser is not sending GPC, and the browser has not recorded an advertising opt-out. Visits from outside the United States and visits whose country cannot be determined are not eligible for advertising tags.
We record advertising click identifiers that an advertising platform appends to a link when you click one of our advertisements (see Section 2.2). These identifiers arrive in the URL, are collected through our first-party analytics implementation, and are processed by PostHog on our behalf. We use them to measure campaign performance, including which campaigns produce sign-ups. When advertising tags are enabled and you have not opted out, the originating advertising platform may also receive its own click identifier and marketing-site activity for measurement and, where supported by the platform, retargeting.
If the OpenAI Ads Measurement Pixel is enabled, it may store OpenAI's oppref attribution identifier in a first-party __oppref cookie so later eligible page views can be associated with the same ad click.
You can change your advertising preference at any time through Your Privacy Choices on the public marketing site. An opt-out is stored in a first-party cookie for up to one year. Short-lived first-party cookies record whether a visit resolved to the United States and whether the request sent GPC so the site can enforce the gate. Opting out does not disable essential site functions. Clearing browser cookies may clear the stored choice, but a GPC signal continues to override any stored preference.
Session replay. We do not enable session replay by default. If we enable it for debugging or product improvement, it may record in-app interactions (clicks, navigation, scroll, page content). We configure session replay to mask password fields, payment fields, API keys, integration credentials, and other sensitive inputs. Replays are stored on PostHog's infrastructure under our account and are subject to PostHog's retention.
You can control cookies through your browser. Blocking essential cookies will break authentication and core functionality.
We honor "Do Not Track" and Global Privacy Control (GPC) browser signals for analytics. Our marketing site does not initialize analytics at all for browsers that signal GPC, and analytics is disabled for browsers that send Do Not Track. When our application detects GPC, it does not load Vercel Web Analytics for that browser session. Where required by law, we also honor GPC as an opt-out of any "sale" or "sharing" of personal information.
8. Data Retention and Deletion
We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account and business data: retained while your account is active.
- After account closure: retained for up to 90 days to allow recovery, then deleted or anonymized, except where longer retention is required by law. If you make a verified deletion request, we delete active records sooner, as described in Section 9 and at https://app.signalandscience.com/data-deletion.
- Billing and tax records: retained for at least 7 years to meet tax and accounting requirements.
- Beta and access requests: retained for up to 24 months from submission, then deleted.
- Sentry error logs: retained per Sentry's default retention (typically 30–90 days).
- Vercel Web Analytics events: retained in aggregated form per our Vercel plan and Vercel's Web Analytics retention settings.
- PostHog analytics events: retained per our PostHog plan retention (typically 12 months for events; session replays typically 30 days).
- Advertising privacy choices: the advertising preference cookie is retained for up to one year. Region and request-level GPC cookies are retained for up to 24 hours. Advertising platforms retain data under their own policies and the retention settings in our advertising accounts.
- Public Signals & Moves briefs: successful analysis cache records are retained for up to 24 hours, then deleted by an automated retention process. If a visitor creates a share link, the signed public brief is stored in a service-only lookup record for up to 12 months so the link can remain short. Share records are not exposed through a public listing or search API and expire automatically.
- Public Signals & Moves funnel events: bounded completion, latency, campaign, cache, and abuse events are retained for up to 90 days by default. These events exclude the submitted website URL, evidence excerpts, and generated brief text.
- Meta Platform Data: cached while the Meta integration is connected and deleted within 30 days after disconnect or a verified deletion request, except for limited security, legal, or audit records we are required or permitted to retain.
- Shopify and WooCommerce data: aggregated daily metrics retained while the integration is connected. Disconnecting from Signal & Science deletes the stored integration credential and imported aggregates. Shopify app uninstall immediately deletes the stored Shopify credential and stops sync; the later Shopify
shop/redactdelivery deletes remaining Shopify-sourced aggregates. Verified deletion requests also trigger deletion, except for limited security, legal, or audit records we are required or permitted to retain. Individual order responses and customer IDs are never persisted — they exist only in memory during the sync job. - Backups: purged on a rolling basis, generally within 35 days.
We may retain information beyond these periods where necessary to comply with legal obligations, resolve disputes, prevent fraud or abuse, enforce our agreements, or defend legal claims.
You may request deletion of your account and associated data at any time by following the process in Section 9.
9. Your Rights and Choices
Depending on the state in which you reside, you may have the following rights regarding personal information we hold about you:
- Access / Know — request confirmation of, and a copy of, the personal information we hold about you.
- Correct — request correction of inaccurate or incomplete information.
- Delete — request deletion of your information, subject to legal exceptions.
- Portability — request a copy of certain information in a portable format.
- Opt out of "sale," "sharing," or targeted advertising — we do not sell personal information. If advertising technologies are enabled, you may opt out of advertising-platform disclosures through Your Privacy Choices on our public marketing site, by sending a GPC signal, or by contacting us.
- Limit use of sensitive personal information — we do not use sensitive personal information for purposes that would trigger this right.
- Non-discrimination — we will not deny services, charge different prices, or provide a different level of service because you exercised a privacy right.
- Appeal — if we deny a request, you may appeal by replying to our denial.
These rights are recognized under, among others, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and similar laws in other US states. Specific rights vary by state.
How to Exercise Your Rights
Email privacy@reverge.com with the subject line "Privacy Request" and describe your request. You can also review deletion instructions at https://app.signalandscience.com/data-deletion. We will:
- Acknowledge your request promptly.
- Verify your identity (typically by confirming control of the email on your account or other reasonable means).
- Respond within 45 days, or notify you if we need an additional 45 days.
You may designate an authorized agent to make a request on your behalf, subject to verification.
Other Removal Requests
If you believe your publicly available business information has been processed by the Services in error and you want it removed, you may email privacy@reverge.com with the URL or other identifier. We evaluate such requests in our sole discretion and consistent with our customer obligations and applicable law. We do not guarantee that we will honor any particular request, and our decision is final.
10. Security
We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information, consistent with the nature of the Services and the type of information processed. The specific controls we use evolve over time as the Services and the threat landscape evolve.
No system is fully secure, and we do not guarantee the security of any information transmitted to or stored by the Services. You are solely responsible for safeguarding your account credentials and for promptly notifying us at security@reverge.com if you suspect unauthorized access. We are not liable for any unauthorized access, loss, or disclosure caused by your or your authorized users' acts or omissions, by your failure to use available security features (including multi-factor authentication), by your connection of insecure third-party services, or by events outside our reasonable control.
11. Children's Privacy
The Services are not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it. If you believe a minor has provided us information, contact privacy@reverge.com.
12. Geographic Scope
The Services are offered to and intended for use by businesses located in the United States. Information is processed primarily in the United States; certain public-data-collection sub-processors identified in Section 5.1 (and in Annex A of our Data Processing Addendum) may process publicly available business information in the United States or the European Union. We do not target the Services to residents of the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions outside the United States, and we do not undertake to comply with the data protection laws of those jurisdictions. If you access the Services from outside the United States, you do so at your own initiative and are responsible for compliance with local law.
13. Contact Us
For privacy questions, requests, or complaints:
Reverge LLC Mail: 5319 University Dr PMB 9483, Irvine, CA 92612 Email: privacy@reverge.com Web: https://www.reverge.com Platform: https://app.signalandscience.com
For security issues: security@reverge.com
14. Changes to This Policy
We may update this Policy at any time, in our sole discretion. The "Last Updated" date at the top reflects the most recent version. For material changes, we will use reasonable efforts to notify you (for example, by posting on the Services, by email, or by an in-product notice) before the changes take effect. Non-material changes (including clarifications, formatting, and updates to Sub-processor lists) take effect when posted. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy. If you do not agree, your sole remedy is to stop using the Services.
15. Roles Under State Privacy Laws
For purposes of US state privacy laws:
- When you provide your own personal information to use the Services, we act as a business (CCPA) or controller (other state laws) of that information.
- When you upload information about your customers, leads, employees, or contacts to the Platform, you are the business / controller of that information, and we act as a service provider / processor under our Terms of Service and any applicable Data Processing Addendum. We process such information only on your documented instructions and only to provide the Services.
*This Policy is provided for informational purposes and does not constitute legal advice. Reverge recommends that businesses consult independent counsel regarding their own privacy obligations.*