Privacy policy

Effective 14 September 2026. These terms replace the 18 August 2026 version.

Who we are

Big Sky Little Acorn, LLC, doing business as CON Signal (“CON Signal,” “we,” “us”), operates consignal.pro. We are the controller of account data. We are not a consumer reporting agency. We are not a covered entity or business associate under HIPAA.

Privacy and all other requests: support@consignal.pro
Mail: 780 W FM 1626 #1057, Manchaca, TX 78652

Whose data this covers

This policy covers personal data about people who use the site or hold an account (customers, demo users, and people who send the sales form).

The feed itself is compiled from records that state and federal agencies published. Names of applicants, facilities, and state analysts appear because the issuing agency published them. Under the Texas Data Privacy and Security Act, publicly available information is not “personal data.” We do not use those public records to build a dossier on a private individual, and we do not sell them as a contact list.

What we collect, and why

CategoryExamplesSourcePurposeShared with
Account identifiersEmail, password hash, user idYouCreate and secure the accountSupabase (Auth)
ProfileName, company, role, segment, project typesYouRun the account, tailor the feed, supportSupabase
Plan and accessPlan, subscription status, renewal dateYou and StripeDeliver the plan you paid forSupabase, Stripe
Billing identifiersStripe customer and subscription ids. We never receive the full card number.StripeCharge, tax, invoicesStripe
Saved searches and alertsFilters; email; optional Slack or webhook URL you pasteYouSend alerts you asked forResend; any Slack/webhook host you named
Usage and securityIP, user-agent, auth timestamps, request logsAutomaticallyRun, secure, and debug the serviceCloudflare, Supabase
Sales formYour message and a Turnstile tokenYouAnswer you, block botsCloudflare Turnstile
Transactional mailConfirm, receipts, payment notices, alertsYou and usOperate the service. We do not send marketing email.Resend / Amazon SES

We do not collect government ID numbers of subscribers, precise geolocation, biometrics, or health diagnoses of any person. We do not send marketing email. We do not sell personal data. We do not use personal data for profiling that produces a legal or similarly significant effect.

We run X (Twitter) conversion tracking on every page (pixel reizr) so we can measure ads we place on X. X may set cookies or use similar identifiers. That is advertising measurement, not a sale of your data. To opt out of X tailored ads, use X’s own settings or a browser control that blocks third-party trackers.

Cookies

We use first-party session cookies that are httpOnly so you stay logged in. They are necessary. Cloudflare may set a token to run Turnstile on the sales form. The X conversion pixel may set its own cookies as described above.

Who processes data for us

The dated list is on the subprocessors page. Today:

ProcessorRoleRegion
SupabaseDatabase and authenticationUnited States
StripePayments, invoicing, tax calculationUnited States (Stripe’s terms)
Resend / Amazon SESTransactional emailUnited States
CloudflareHosting, CDN, WAF, Turnstile, operational logs and infrastructure analyticsGlobal edge
X (Twitter)Conversion tracking for ads we run on XX’s terms

Each processes data under its own terms as our processor. A Slack workspace or webhook endpoint you paste is yours, not ours. We will update the subprocessors page before we add a processor that sees account data, and we will not add one that sells that data. A data processing addendum is at /dpa. HIPAA: we are not a covered entity or business associate; see /hipaa.

Retention and deletion

Account data is kept for the life of the account. After you ask us to delete, we delete account and profile data within 30 days, except (a) invoices, tax records, and Stripe objects we must keep under tax law, typically seven years; (b) records we must keep to establish our rights (for example a confirmed abuse incident); (c) backups, which rotate out on their ordinary cycle. Saved searches die with the account. Alert content is generated from public filings and is not a file of your personal data.

Your rights

If you are a Texas consumer, or otherwise have rights under a U.S. state privacy law that applies, you may request that we: confirm whether we process your personal data; give you a copy; correct it; delete it; or export it in a portable format. You may appeal a refusal by writing support@consignal.pro with the word “Appeal.” If we deny the appeal we will tell you how to complain to the Texas Attorney General.

Send requests to support@consignal.pro from the email on the account. We will verify it is you and respond within 45 days (or tell you we need 45 more, and why). You will not have to open a new account to ask. We will not retaliate.

These rights apply to personal data we hold about you as a user. They do not require us to alter a public CON filing that a state published.

Security

We use HTTPS, httpOnly session cookies, hashed passwords with a 12-character minimum, row-level security on the database, and access control on production. No method is perfect. Tell us at support@consignal.pro if you think there has been a breach involving your account. We will notify affected customers without unreasonable delay if a breach of personal data happens, and we will notify authorities when the law requires it.

Children; where data lives; changes

The service is not directed at children under 13, and we do not knowingly collect their data.

The service is hosted in the United States and offered to U.S. organizations. If you access it from elsewhere, you understand the data is processed in the United States.

We will post changes to this policy with a new effective date. Material changes will also be emailed to the account owner. We do not send marketing email; that notice is a product notice.