← Signpost

Privacy

Your information, explained plainly.

This notice describes the information Signpost handles, why it is needed and the choices available to page owners and visitors.

Last updated 13 August 2026

Who this covers

Signpost is operated by Smith & Johnson Ltd (company number 12407892), 7 Bell Yard, London, United Kingdom, WC2A 2JR. Signpost provides pages and optional business tools to page owners. People who open a page, follow a link, join a mailing list or make a booking are visitors or customers.

A page owner decides why they collect subscriber and customer details and how they use them outside Signpost. Signpost also uses limited information to operate, secure and improve the platform. The exact legal roles should be confirmed for each paid module before that module launches.

Information Signpost handles

  • Account details, including the email used to sign in.
  • Page content, settings, images, links and publication choices.
  • Subscriber email addresses and the record of when consent was given or withdrawn.
  • Support-form details: your name, email address, selected topic and message. These are relayed to a private monitored inbox through an email provider, rather than stored in the Signpost product database.
  • Booking contact details and appointment information when Bookings is enabled.
  • Privacy-conscious usage information such as page views, link taps, a safe referring host and short-lived hashed rate-limit signals.
  • Security, delivery and operational records needed to prevent abuse and diagnose faults.

Signpost does not ask a visitor to create an account merely to open a page, follow a link or book with a business.

Why it is used

  • To provide, publish and protect Signpost pages.
  • To deliver requested sign-in, consent and booking messages.
  • To show page owners useful totals without selling visitor profiles.
  • To enforce limits, investigate reports and suspend harmful pages.
  • To meet legal, accounting and dispute-handling duties where they apply.

Google Calendar data

A page owner can choose to connect Google Calendar so Signpost can avoid booking clashes and keep a private Signpost booking event in a calendar the owner selects. Signpost asks for access only when the owner selects “Connect Google Calendar”.

  • Calendar-list access lets the owner choose which calendars check clashes and which writable calendar receives Signpost bookings.
  • Free/busy access lets Signpost retrieve only occupied time ranges. Signpost does not request, read or store the titles, descriptions, locations, attendees or notes of the owner's other Google Calendar events.
  • Event access lets Signpost create, move and remove the private “Signpost booking” events it manages in the selected destination calendar. Those events contain the appointment time and a Signpost booking reference, but no customer name, email, telephone number or booking notes.

While the connection is active, OAuth credentials and provider calendar identifiers are stored in Supabase Vault. Short-lived busy-only snapshots are stored separately to make clash checks reliable. Access is limited to Signpost's calendar service and is not exposed to page visitors or other businesses.

Signpost does not sell Google user data, use it for advertising or credit decisions, allow people to read it except where needed for security, legal compliance or support, or use it to train general-purpose artificial-intelligence models. It is shared only with service providers acting for Signpost where necessary to run and secure this feature.

Signpost's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Disconnecting Google Calendar

A signed-in owner can open their page's Booking setup, find Calendar conflicts and choose “Disconnect account”. Signpost immediately stops using that connection and deletes its saved OAuth credentials, provider calendar identifiers and cached busy-time ranges. Irreversible hashes may remain only to prevent an old connection being mistaken for a different account.

Disconnecting does not delete private Signpost booking events already written to Google Calendar. The owner can delete those events in Google Calendar. Encrypted references to those Signpost-created events may remain with the associated booking record for operational integrity, but they cannot be used after the credentials are deleted.

An owner can also remove Signpost from their Google Account permissions. For help with a connection or a deletion request, use the Signpost support form.

Cookies and privacy-safe analytics

Signpost uses essential session cookies for signed-in owners. Public pages may set an HttpOnly visitor identifier so obvious repeat views and taps are not counted repeatedly. Browser scripts cannot read that cookie.

The platform turns the trusted network address and visitor identifier into scoped, rotating hashes before its database sees them. Short-lived limiter records are removed by maintenance jobs. This reduces tracking risk; it does not make every technical record anonymous in every legal sense.

Service providers and international processing

Signpost relies on specialist providers for hosting, database and authentication, security challenges, transactional email and—when enabled—payments. Current architecture includes Vercel, Supabase, Cloudflare Turnstile, Resend and Stripe.

These providers may process information outside the country where a visitor lives. Signpost uses the contractual and security protections made available by each provider and keeps the provider list under review as the product changes.

Retention, sharing and your choices

Information is kept only for the operating, safety, consent, financial and legal periods that apply to it. Authentication limit records are removed after 24 hours, other public abuse-limit records after about 25 hours, and privacy-conscious raw link-click records after 400 days. Subscriber consent and unsubscribe evidence, page reports and account closure requests have no automatic deletion date: they are retained while they remain necessary for consent, safety or closure handling and are reviewed when an account closes.

To protect the support form from abuse, Signpost keeps only a privacy-preserving counter for about 25 hours. It does not store support message or contact content in the product database. Support correspondence stays in the private monitored inbox only while it is needed to resolve the request or for a related safety or legal follow-up, and is managed through that inbox's retention controls.

Signpost does not sell personal information. Information may be shared with the page owner you chose to contact, with service providers acting for Signpost, or where law and safety genuinely require it.

You may ask for access, correction, deletion, restriction, portability or an explanation of a decision where the law gives you that right. Mailing-list messages include an unsubscribe route. Requests must be verified without asking for more information than is reasonably needed.

Signed-in owners can download their account data and request account closure from the dashboard. A closure request immediately takes their pages offline while any required financial, consent or safety retention is reviewed.

Signpost is operated by Smith & Johnson Ltd (company number 12407892), 7 Bell Yard, London, United Kingdom, WC2A 2JR.

Questions or concerns

Contact Signpost support. Please do not include passwords, card details or sensitive identification documents.