πŸ‡ΊπŸ‡Έ Veterans in Business β€” Free 30-Day Trial Full access for VIB members & SDVOSBs. Claim Your Trial β†’
Legal Β· Privacy

SignalGround Privacy Policy

This Privacy Policy explains what information we collect when you use SignalGround, how we use it, and the choices you have. We've structured it to be readable β€” but the legal commitments are binding regardless of how readable a given section is.

Effective: June 1, 2026 Last Updated: May 24, 2026 Version: 2.0 Operator: New Vision Security LLC

01Scope & Operator

This Privacy Policy applies to the SignalGround RF Spectrum Intelligence Platform (the "Service"), including the SignalGround Foundation tier, the thirteen vertical bundles (Public Safety, Legal, Utilities, Railroad, Mining, Healthcare, Marine, Broadcast, Real Estate, Construction, Smart City, Carrier, Satellite), Enterprise All-Access, and the FiveBars private wireless qualifier β€” all operated by New Vision Security LLC ("we," "us," "our"), a Service-Disabled Veteran-Owned Small Business based in College Park, Georgia (UEI NQ7DY8MADL23 Β· CAGE 5AAG0).

It applies to information we receive through signalground.net, signalground.app, fivebars.signalground.app, the SignalGround mobile applications, our REST APIs, and Azure Marketplace transactable offers. It does not apply to third-party services we link to, employer-provided email or device monitoring at customer organizations, or public data we surface from federal sources (FCC ULS, FCC ASR, HIFLD).

02Information We Collect

We collect three categories of information, treated separately:

2.1 Account Information

When you register, we collect: your name, work email address, employer name, role/title, phone number (optional), and authentication credentials (password hash, or SSO assertion via Microsoft Entra ID). Federal and enterprise customers may also provide US citizenship attestation for ITAR-controlled deployments.

2.2 Service Usage Data

When you use the Service, we collect:

  • Scan inputs: Addresses, coordinates, query parameters, radius selections, frequency ranges, vendor selections, and other parameters you supply.
  • Generated outputs: Reports, PDFs, exports, ML predictions, and annotations created from your inputs.
  • API access logs: Endpoint, timestamp, source IP, user-agent, response code, and bytes transferred for every API call.
  • Audit trail: Login events, configuration changes, data exports, and administrative actions.

2.3 Public Reference Data

The Service surfaces public federal data β€” FCC ULS license records, FCC ASR antenna structure registry, HIFLD federal facility data, NOAA terrain data, and CISA sector layers. This data is not personal information about you; we ingest it from federal sources and present it through the Service.

2.4 Billing & Payment Information

For paid subscriptions, billing details (company name, billing address, tax ID) are stored in our systems; payment card or ACH details are processed by Stripe and never stored by SignalGround. Azure Marketplace customers have billing handled entirely through Microsoft β€” we receive only the subscription identifier and metered usage data.

2.5 Information from Microsoft Azure Marketplace

If you subscribe through Microsoft Azure Marketplace, Microsoft shares your subscription identifier, organization name, and primary contact with us per the Microsoft Marketplace Publisher Agreement. We do not receive your credit card or payment details from Microsoft.

03How We Use Information

We use the information described above to:

  • Provide the Service: Run spectrum analyses, generate reports, surface FCC license data, train ML models on aggregated and anonymized usage patterns.
  • Authenticate and authorize: Verify your identity, enforce role-based access controls, prevent unauthorized access.
  • Bill and collect payment: Process subscription payments, send invoices, handle refunds and credits.
  • Communicate: Send transactional emails (login confirmations, report-ready notifications, billing receipts, security alerts) and, with your consent, product announcements and newsletters.
  • Improve the Service: Analyze aggregated usage patterns to identify product improvements. We do not use individual customer scan inputs to train ML models that benefit other customers without explicit consent.
  • Maintain audit trails: Per-bundle audit retention (1 year baseline, 2 years for Public Safety, 5 years for Legal) for compliance, dispute resolution, and incident response.
  • Comply with legal obligations: Respond to lawful requests from government authorities, enforce our Terms of Use, protect against fraud and abuse.
What we don't do: We do not sell personal information. We do not run advertising. We do not share customer scan inputs with other customers. We do not use customer data to train models that compete with our customers' use cases.

04How We Share Information

We share information only as described below:

4.1 Subprocessors

Service providers that process data on our behalf under contract. The current list is published at signalground.net/security#subprocessors and Section 5 below.

4.2 Channel Partners & Resellers

If you purchased SignalGround through a channel partner or VIB Partner reseller, we share your subscription status, usage volume, and renewal date with that partner for the purpose of account management. We do not share scan inputs or generated reports with channel partners without your explicit consent.

4.3 Microsoft Azure Marketplace

For Azure Marketplace transactable subscriptions, Microsoft receives subscription identifier and metered usage. We share what is required by the Microsoft Marketplace Publisher Agreement to enable billing reconciliation.

4.4 Legal Obligations

We will share information when required by law, valid court order, or to respond to a verified government request β€” limited to the minimum necessary to comply. We will challenge overbroad requests where legally permissible and notify affected customers where not prohibited from doing so.

4.5 Business Transfers

In the event of merger, acquisition, asset sale, or bankruptcy, customer information may transfer to the acquiring entity, subject to the protections of this Privacy Policy. We will notify customers in advance of any such transfer.

4.6 Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot reasonably be linked to any individual or organization for research, industry reporting, or product development purposes.

05Subprocessors

The following third parties process customer data on our behalf. Customer data does not leave this list. We notify customers 30 days before adding or replacing a subprocessor.

SubprocessorPurposeData Region
Microsoft Azure
Infrastructure, identity, monitoring
Compute, storage, identity, audit loggingEast US 2 Β· East US Gov
Microsoft Entra ID
Identity provider
SSO, MFA, account directoryUS tenant
Stripe, Inc.
Payment processing
Billing, subscriptions, payment cardsUnited States
Twilio SendGrid
Transactional email
Account emails, receipts, alertsUnited States
Mapbox
Map tile rendering
Anonymous map tile requestsUnited States

Federal and Enterprise customers may request a customer-tenant deployment that eliminates non-Azure subprocessors entirely. Stripe, SendGrid, and Mapbox are not used in Azure Government or air-gap configurations.

06Data Retention

Retention varies by data category and bundle:

CategoryRetention Period
Account informationDuration of subscription + 90 days (or as required by law)
Scan history (Foundation, Real Estate, Marine, Mining, Healthcare, Satellite)1 year baseline
Scan history (Utilities, Railroad, Broadcast, Smart City, Carrier, Construction)Per-bundle (typically 1–2 years)
Scan history (Public Safety & Federal)2 years
Scan history (Legal & Attorney)5 years (litigation support)
Billing records7 years (US tax/accounting requirements)
Audit logsSame as bundle scan history
Marketing communications consentUntil withdrawn + 30 days
Aggregated / anonymized analyticsIndefinite

Customers can request earlier deletion at any time (see Section 7). Deletion requests are processed within 30 days; data backed up in disaster-recovery snapshots is retained for up to 90 additional days but is not accessible for operational use.

07Your Rights

7.1 GDPR Rights (EU/UK Data Subjects)

If you are in the EU, UK, or EEA, you have the rights to:

  • Access: Request a copy of personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
  • Restriction: Limit how we process your data while a dispute is resolved.
  • Portability: Receive your data in a structured, machine-readable format (CSV, JSON).
  • Objection: Object to processing based on legitimate interests, including profiling.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time.

7.2 CCPA/CPRA Rights (California Residents)

If you are a California resident, you have the rights to:

  • Know: What personal information we collect, the source, the purpose, and with whom we share it.
  • Delete: Request deletion of your personal information.
  • Correct: Correct inaccurate personal information.
  • Opt-out of sale: We do not sell personal information, but you have the right to opt out if our practices change.
  • Limit use of sensitive personal information: Restrict use of sensitive categories.
  • Non-discrimination: Exercise rights without being denied service, charged different prices, or receiving lesser quality.

7.3 Other State Privacy Laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights. We honor all valid state-law requests.

7.4 How to Exercise Your Rights

Email privacy@signalground.app with your request. We will verify your identity (typically by asking you to confirm from the email on file) and respond within 30 days (45 for complex requests, with notice). There is no fee for the first request in any 12-month period.

08International Data Transfers

SignalGround operates from the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US.

For data subjects in the EU/UK/EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (2021/914).
  • The Data Privacy Framework (DPF) where applicable, with New Vision Security LLC's self-certification (in process).
  • Customer's own determination of adequate protection where the customer is the controller.

We offer a Data Processing Agreement (DPA) incorporating the SCCs on request β€” email privacy@signalground.app.

09Security Measures

We protect your information using industry-standard security measures including AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls with multi-factor authentication, continuous security monitoring via Azure Sentinel, annual independent penetration testing, and a documented incident response process aligned to NIST SP 800-61.

The full security architecture, control families, and incident response timeline are documented at signalground.net/security.

No system is perfectly secure. In the event of a security incident affecting your personal information, we will notify you within 72 hours of confirmed incident scope, in accordance with GDPR Article 33 and applicable US state law timing requirements.

10Children's Privacy

The Service is intended for business use by spectrum professionals and is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, contact privacy@signalground.app and we will delete it promptly.

11Cookies & Tracking

SignalGround uses cookies and similar technologies for the following purposes only:

  • Essential cookies: Authentication session tokens, CSRF protection, load balancing. Cannot be disabled.
  • Functional cookies: User preferences (theme, default vertical, map preferences). Cleared on logout.
  • Analytics cookies: Aggregated, anonymized page-view analytics via Azure Application Insights. No cross-site tracking. No advertising identifiers.

We do not use advertising cookies, third-party tracking pixels, or session replay tools that capture customer scan inputs.

12Changes to This Policy

We may update this Privacy Policy from time to time. Material changes (changes that materially decrease customer privacy protections or expand our use of personal information) will be notified to all customers at least 30 days before taking effect, by email and by prominent notice on signalground.net. Minor clarifications and corrections will be reflected with an updated "Last Updated" date.

Continued use of the Service after a Privacy Policy change constitutes acceptance of the updated policy. If you do not accept changes, you may cancel your subscription before the effective date.

13Contact Us

Questions, concerns, requests, or complaints about this Privacy Policy or our data practices:

EU/UK data subjects may also lodge a complaint with their local supervisory authority.