Signals Surveys is part of Compass, the AI-first customer intelligence platform. Explore Compass

Trust & privacy

Customer intelligence deserves careful handling.

Signals collects information your customers chose to give you. Every statement on this page describes a control that exists in the product today — not an aspiration.

Controls

What we actually do with your data.

Nine controls, each mapped to something implemented in the product.

Tenant isolation

Every Shopify store is a separate tenant. Survey definitions, responses, and customer properties are scoped to a single store ID, and every read and write is filtered by that scope.

You own the response data

Survey responses collected from your customers belong to you, the merchant. Signals stores and processes them to run the service you configured — nothing else.

Encryption in transit and at rest

All traffic to Signals — merchant admin, survey pages, and API calls — uses HTTPS with TLS. Stored response data and configuration are encrypted at rest.

Configurable data retention

You choose how long response data is retained. When a retention window elapses, the affected responses are removed on the schedule you set.

Least-privilege Shopify permissions

Signals requests only the Shopify scopes it needs to match responses to customers and read order and product context. Scopes are listed on the install screen before you approve them.

Consent support

Surveys can require an explicit consent step before a response is stored or linked to a customer, and consent state is recorded with the response.

Data deletion

You can delete individual responses, a whole survey, or all data for your store. Shopify customer redaction requests are handled through the mandatory app webhooks.

Export support

Responses and their linked customer context can be exported so your data is never locked inside Signals.

Published privacy documentation

Our privacy policy, terms, and data processing addendum are public — not available on request only.

Data ownership

Your customers' answers are your data.

Signals is a processor acting on your instructions. Responses are collected under your brand, stored against your store, and used to run the surveys, properties, and integrations you set up.

Read the data processing addendum
  • We do not sell merchant customer data.
  • We do not share your response data with other merchants.
  • We do not build a cross-merchant advertising or identity graph from your responses.
  • Sub-processors are used only to operate the service, and are listed in our privacy policy.
Shopify permissions

We ask for the minimum, and we tell you why.

Signals requests a specific set of Shopify scopes. Each one maps to a capability you can see in the product.

  • Read customers — to match a response to the right Shopify customer.
  • Read orders — to add purchase context to a response.
  • Read products — so surveys can reference and recommend your catalog.
  • Write customer metafields and tags — to store the properties a survey produces.
  • App proxy and theme app extension — to serve surveys and Sparks on your storefront.

Signals does not request access to Shopify payment, payout, or financial data, and does not read your customers' payment instruments.

Infrastructure

Built and hosted on Cloudflare.

Signals runs on Cloudflare's global network. Surveys are served from the edge so they load quickly for your customers, and production access is limited to the people who operate the service.

  • Hosted on Cloudflare, including edge delivery, TLS termination, and DDoS protection.
  • Survey pages are served from the edge; response data is written to a regional data store.
  • Access to production systems is restricted to named staff and requires multi-factor authentication.
  • Application, integration, and deployment activity is logged.
Merchant controls

You decide what is collected and how long it lives.

Privacy configuration lives in the Signals admin — not in a support ticket.

  • Choose which questions are asked and what is stored.
  • Require a consent step before responses are linked to a customer.
  • Collect anonymous responses when identity is not needed.
  • Set a retention window per survey or for the whole store.
  • Export or delete response data at any time.
  • Uninstall — which triggers deletion of your store data per our retention schedule.

Questions about security? Ask us directly.

We are happy to walk through how Signals handles data before you install it, and to answer security review questions from your team.