This Privacy Policy explains what information we collect when you use SignalGround, how we use it, and the choices you have. We've structured it to be readable β but the legal commitments are binding regardless of how readable a given section is.
This Privacy Policy applies to the SignalGround RF Spectrum Intelligence Platform (the "Service"), including the SignalGround Foundation tier, the thirteen vertical bundles (Public Safety, Legal, Utilities, Railroad, Mining, Healthcare, Marine, Broadcast, Real Estate, Construction, Smart City, Carrier, Satellite), Enterprise All-Access, and the FiveBars private wireless qualifier β all operated by New Vision Security LLC ("we," "us," "our"), a Service-Disabled Veteran-Owned Small Business based in College Park, Georgia (UEI NQ7DY8MADL23 Β· CAGE 5AAG0).
It applies to information we receive through signalground.net, signalground.app, fivebars.signalground.app, the SignalGround mobile applications, our REST APIs, and Azure Marketplace transactable offers. It does not apply to third-party services we link to, employer-provided email or device monitoring at customer organizations, or public data we surface from federal sources (FCC ULS, FCC ASR, HIFLD).
We collect three categories of information, treated separately:
When you register, we collect: your name, work email address, employer name, role/title, phone number (optional), and authentication credentials (password hash, or SSO assertion via Microsoft Entra ID). Federal and enterprise customers may also provide US citizenship attestation for ITAR-controlled deployments.
When you use the Service, we collect:
The Service surfaces public federal data β FCC ULS license records, FCC ASR antenna structure registry, HIFLD federal facility data, NOAA terrain data, and CISA sector layers. This data is not personal information about you; we ingest it from federal sources and present it through the Service.
For paid subscriptions, billing details (company name, billing address, tax ID) are stored in our systems; payment card or ACH details are processed by Stripe and never stored by SignalGround. Azure Marketplace customers have billing handled entirely through Microsoft β we receive only the subscription identifier and metered usage data.
If you subscribe through Microsoft Azure Marketplace, Microsoft shares your subscription identifier, organization name, and primary contact with us per the Microsoft Marketplace Publisher Agreement. We do not receive your credit card or payment details from Microsoft.
We use the information described above to:
We share information only as described below:
Service providers that process data on our behalf under contract. The current list is published at signalground.net/security#subprocessors and Section 5 below.
If you purchased SignalGround through a channel partner or VIB Partner reseller, we share your subscription status, usage volume, and renewal date with that partner for the purpose of account management. We do not share scan inputs or generated reports with channel partners without your explicit consent.
For Azure Marketplace transactable subscriptions, Microsoft receives subscription identifier and metered usage. We share what is required by the Microsoft Marketplace Publisher Agreement to enable billing reconciliation.
We will share information when required by law, valid court order, or to respond to a verified government request β limited to the minimum necessary to comply. We will challenge overbroad requests where legally permissible and notify affected customers where not prohibited from doing so.
In the event of merger, acquisition, asset sale, or bankruptcy, customer information may transfer to the acquiring entity, subject to the protections of this Privacy Policy. We will notify customers in advance of any such transfer.
We may share aggregated, anonymized data that cannot reasonably be linked to any individual or organization for research, industry reporting, or product development purposes.
The following third parties process customer data on our behalf. Customer data does not leave this list. We notify customers 30 days before adding or replacing a subprocessor.
| Subprocessor | Purpose | Data Region |
|---|---|---|
| Microsoft Azure Infrastructure, identity, monitoring | Compute, storage, identity, audit logging | East US 2 Β· East US Gov |
| Microsoft Entra ID Identity provider | SSO, MFA, account directory | US tenant |
| Stripe, Inc. Payment processing | Billing, subscriptions, payment cards | United States |
| Twilio SendGrid Transactional email | Account emails, receipts, alerts | United States |
| Mapbox Map tile rendering | Anonymous map tile requests | United States |
Federal and Enterprise customers may request a customer-tenant deployment that eliminates non-Azure subprocessors entirely. Stripe, SendGrid, and Mapbox are not used in Azure Government or air-gap configurations.
Retention varies by data category and bundle:
| Category | Retention Period |
|---|---|
| Account information | Duration of subscription + 90 days (or as required by law) |
| Scan history (Foundation, Real Estate, Marine, Mining, Healthcare, Satellite) | 1 year baseline |
| Scan history (Utilities, Railroad, Broadcast, Smart City, Carrier, Construction) | Per-bundle (typically 1β2 years) |
| Scan history (Public Safety & Federal) | 2 years |
| Scan history (Legal & Attorney) | 5 years (litigation support) |
| Billing records | 7 years (US tax/accounting requirements) |
| Audit logs | Same as bundle scan history |
| Marketing communications consent | Until withdrawn + 30 days |
| Aggregated / anonymized analytics | Indefinite |
Customers can request earlier deletion at any time (see Section 7). Deletion requests are processed within 30 days; data backed up in disaster-recovery snapshots is retained for up to 90 additional days but is not accessible for operational use.
If you are in the EU, UK, or EEA, you have the rights to:
If you are a California resident, you have the rights to:
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights. We honor all valid state-law requests.
Email privacy@signalground.app with your request. We will verify your identity (typically by asking you to confirm from the email on file) and respond within 30 days (45 for complex requests, with notice). There is no fee for the first request in any 12-month period.
SignalGround operates from the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US.
For data subjects in the EU/UK/EEA, we rely on:
We offer a Data Processing Agreement (DPA) incorporating the SCCs on request β email privacy@signalground.app.
We protect your information using industry-standard security measures including AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls with multi-factor authentication, continuous security monitoring via Azure Sentinel, annual independent penetration testing, and a documented incident response process aligned to NIST SP 800-61.
The full security architecture, control families, and incident response timeline are documented at signalground.net/security.
No system is perfectly secure. In the event of a security incident affecting your personal information, we will notify you within 72 hours of confirmed incident scope, in accordance with GDPR Article 33 and applicable US state law timing requirements.
The Service is intended for business use by spectrum professionals and is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, contact privacy@signalground.app and we will delete it promptly.
We may update this Privacy Policy from time to time. Material changes (changes that materially decrease customer privacy protections or expand our use of personal information) will be notified to all customers at least 30 days before taking effect, by email and by prominent notice on signalground.net. Minor clarifications and corrections will be reflected with an updated "Last Updated" date.
Continued use of the Service after a Privacy Policy change constitutes acceptance of the updated policy. If you do not accept changes, you may cancel your subscription before the effective date.
Questions, concerns, requests, or complaints about this Privacy Policy or our data practices:
EU/UK data subjects may also lodge a complaint with their local supervisory authority.