Privacy Policy
1. Introduction
This Privacy Policy explains how Sigtake, Inc. ("Sigtake", "we", "us") collects, uses and protects personal data when you use the Sigtake platform, website and APIs (the "Service"). It applies to account holders, members of customer organizations, and recipients of notifications configured by our customers.
2. Information we collect
- Account information — name, email address, password (stored hashed), phone number if you enable SMS notifications, and two-factor authentication settings.
- Organization data — organization name, teams, roles, notification channel configurations and recipients (which may include contact details of people outside your organization, entered by your organization).
- Alert and monitoring data — alerts, signal readings, monitor configurations and results, comments, and acknowledgement/resolution activity submitted to the Service by your systems or teammates.
- Usage and log data — IP address, browser/device information, timestamps of requests, and an audit trail of sensitive actions within your organization.
3. How we use information
- To provide the Service: ingest, deduplicate and route alerts, run monitors, and deliver notifications to the channels your organization configures.
- To secure the Service: authentication, two-factor verification, rate limiting, audit logging and abuse prevention.
- To operate and improve the Service: diagnostics, troubleshooting and aggregate usage analysis.
- To communicate with you about the Service, including security or service notices.
We do not sell personal data, and we do not use Customer Data for advertising.
4. Notification delivery and service providers
To deliver notifications and operate the Service we share the minimum necessary data with service providers acting on our behalf, such as:
- Amazon Web Services (SES) — email delivery and cloud infrastructure;
- Twilio — SMS delivery (recipient phone numbers and message content);
- Microsoft — delivery of notifications to Microsoft Teams via webhooks configured by your organization.
These providers process data under their own security and privacy commitments. We may also disclose information if required by law or to protect the rights, safety or security of Sigtake, our users or the public.
5. Cookies and sessions
We use strictly necessary cookies and similar storage to keep you signed in and to secure your session. We do not use third-party advertising or tracking cookies on the Service.
6. Data retention
Alert history is retained according to your plan's retention window. Account and organization data is retained while your account is active. When an account or organization is deleted, associated personal data is deleted or anonymized within a reasonable period, except where retention is required by law (for example, security audit records).
7. Security
We apply technical and organizational measures appropriate to the risk: encrypted transport (HTTPS), hashed passwords, optional two-factor authentication, per-organization data isolation, rate-limited API keys and audit logging. No system is perfectly secure; please report vulnerabilities or incidents to help@sigtake.com.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, restrict or delete your personal data. You can exercise most of these directly in the dashboard (profile and organization settings) or by contacting us at help@sigtake.com. If you receive notifications configured by a Sigtake customer, that organization controls the recipient list — contact them, or us, to be removed.
9. Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material we will notify you (for example by email or an in-app notice) before it takes effect. The effective date above indicates the latest revision.
11. Contact
Privacy questions or requests: help@sigtake.com.