Signals Surveys is part of Compass, the AI-first customer intelligence platform. Explore Compass

Legal

Privacy Policy

How Signals Surveys handles merchant data and survey respondent data.

Last updated July 2026.

Signals Surveys ("Signals", "we", "us") is a customer survey product for Shopify and part of the Compass customer intelligence platform. This policy explains what data we process, why we process it, how long we keep it, and the choices available to merchants and their customers.

This policy is provided for transparency. It is not legal advice. Using Signals does not by itself make a merchant compliant with any privacy law. Signals provides features that support a merchant's compliance program — such as consent gating, retention settings, export, and deletion — but the merchant remains responsible for determining what data to collect, on what legal basis, and what notices and consents to present to its own customers.

1. Who does what

Signals serves two groups of people, and our role differs for each.

  • Merchants. When a Shopify merchant installs and uses Signals, we act as a controller for the merchant's own account data — the information needed to create an account, provide support, bill the subscription, and secure the service.
  • Survey respondents. When a merchant's customer answers a survey or a Spark, the merchant is the controller of that response data and Signals is a processor acting on the merchant's documented instructions. Our processing commitments are set out in our Data Processing Addendum.

If you answered a survey powered by Signals and want your data changed or removed, please contact the merchant whose store you were shopping. We will assist that merchant in responding.

2. Data we process

2.1 Merchant data

  • Store identifiers supplied by Shopify, including shop domain, store name, plan, and locale.
  • Account and user details for the people who administer Signals — name, email address, and role.
  • Configuration you create — surveys, Sparks, questions, branching logic, templates, and integration settings.
  • Billing and subscription records. Where a subscription is charged through Shopify, Shopify processes the payment and we receive the resulting charge status.
  • Support correspondence you send us.
  • Security and diagnostic logs, including IP address, request metadata, and error traces.

2.2 Survey respondent data

  • Answers submitted to a survey or Spark, and the time they were submitted.
  • Where a response can be matched to a Shopify customer, the Shopify customer identifier and the commerce context used to make the response useful — order history, purchased products, and customer tags.
  • Consent state recorded at the time of the response, where the merchant has enabled a consent step.
  • Technical delivery metadata such as survey identifier, response status, device type, and coarse locale.
  • Anonymous responses, where the merchant has configured a survey that does not attempt to identify the respondent.

Merchants control the questions asked. We ask merchants not to use Signals to collect special category data, payment card numbers, government identifiers, or health data, and Signals is not designed for those categories.

3. Why we process data

  • To provide the service — creating, publishing, and serving surveys and Sparks, and storing responses.
  • To connect responses to Shopify customers, orders, and products so the merchant can act on them.
  • To send events and profile properties to the destinations the merchant has connected, such as Klaviyo or Compass.
  • To produce analytics for the merchant about their own responses.
  • To bill, support, secure, debug, and improve the service.
  • To meet legal obligations, including Shopify platform requirements.

We do not sell merchant customer data. We do not share one merchant's response data with another merchant, and we do not use response data to build a cross-merchant advertising or identity graph.

4. Shopify data handling

Signals is installed from the Shopify App Store and operates using the API scopes you approve at install time. We request read access to customers, orders, and products, write access to customer metafields and tags, and the storefront extensions required to display surveys. Shopify displays the full scope list before you approve it.

We implement Shopify's mandatory compliance webhooks. When Shopify sends a customer data request, a customer redaction request, or a shop redaction request, we respond by supplying or deleting the corresponding Signals data for that store.

Uninstalling Signals stops all processing for your store. Store data is then deleted according to the retention schedule in section 6.

5. Sub-processors

We use a limited set of vendors to operate the service. Each is bound by contractual confidentiality and data protection obligations, and each is used only to deliver Signals.

  • Cloudflare — hosting, edge delivery, TLS termination, and network protection.
  • Shopify — the commerce platform Signals integrates with, and, where applicable, subscription billing.
  • Klaviyo — only where a merchant connects Klaviyo and instructs Signals to send events and profile properties.
  • Compass — only where a merchant uses Signals with a Compass workspace.
  • Support, email delivery, and error monitoring providers used to operate and support the service.

A current list of sub-processors, including the processing they perform, is maintained with our Data Processing Addendum. We will give merchants notice of a new sub-processor before it begins processing response data.

6. Retention

  • Response data is retained for as long as the merchant's configured retention window allows. Merchants can set a retention period per survey or for the whole store, and can delete responses at any time.
  • Account and configuration data is retained while the account is active.
  • After uninstall or account closure, store data is deleted within 90 days, except where we must keep records to meet a legal or tax obligation.
  • Security and diagnostic logs are retained on a short rolling window and then removed.
  • Backups expire on their own schedule; data removed from live systems is removed from backups as those backups age out.

7. Deletion and export

Merchants can export responses and their linked customer context from the Signals admin, and can delete an individual response, an entire survey, or all data for the store. Deletion requests received through Shopify's redaction webhooks are actioned automatically.

If you need help with an export or deletion that you cannot complete in the admin, contact us at privacy@signals.compass.st.

8. Rights of individuals

Depending on where they live, individuals may have rights to access, correct, delete, port, or restrict the processing of their personal data, and to object to certain processing.

For survey respondents, those rights are exercised against the merchant, who is the controller. We support merchants in responding to such requests, as described in our Data Processing Addendum. For merchant account data, where we are the controller, contact us directly at privacy@signals.compass.st.

9. Cookies and analytics

On this marketing website we use cookies that are strictly necessary to serve the site, and we load privacy-respecting analytics only where consent is required and has been given. You can decline non-essential cookies without losing access to the site.

In the survey experience shown to a merchant's customers, Signals uses only the storage needed to run a survey — for example, remembering that a survey was already answered so it is not shown again. Where a merchant has enabled a consent step, response data is not stored or linked to a customer profile until the respondent has given consent. Signals does not place advertising or cross-site tracking technology in a merchant's storefront.

Merchants remain responsible for their own storefront cookie banner, privacy notice, and consent configuration, and for integrating Signals with the consent mechanism they use.

10. International transfers

Signals is operated on globally distributed infrastructure, and data may be processed in countries other than the one in which it was collected. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, along with the technical measures described on our security page. These terms are incorporated into our Data Processing Addendum.

11. Security

Signals uses tenant isolation, encryption in transit and at rest, least-privilege Shopify permissions, restricted and multi-factor-authenticated production access, and logging of application and deployment activity. The controls are described in detail on our security page.

12. Children

Signals is a business tool and is not directed at children. We do not knowingly collect personal data from children. Merchants are responsible for ensuring that surveys they publish are appropriate for their audience.

13. Changes to this policy

We may update this policy as the product changes or as legal requirements evolve. We will update the date at the top of this page and, for material changes affecting merchants, give notice in the app or by email.

14. Contact

Privacy questions, data requests, and sub-processor notifications: privacy@signals.compass.st.

Related documents: Terms of Service, Data Processing Addendum, Security & Privacy overview, Accessibility. You can also contact us about anything else.