Privacy Policy
Last updated: 19 August 2026
Simple Signups (“Simple Signups”, “we”, “us”) provides signup forms and campaign-scoped subscriber collection tools at simple-signups.com. This Privacy Policy explains what personal data we process, why we process it, and the rights available to people who use the service, including rights that may apply under the GDPR and the California Consumer Privacy Act as amended by the CPRA.
Who this covers
- Account holders — people who create a Simple Signups account and campaigns.
- End subscribers — people who submit an email address and any optional fields to a campaign endpoint configured by an account holder.
Our role: controller and processor
For account registration, authentication, billing readiness, security, and operation of the Simple Signups website and dashboard, Simple Signups acts as a data controller. For subscriber data that account holders collect through their campaigns, the account holder generally acts as the data controller and Simple Signups acts as a data processor on that account holder’s behalf.
If you are an end subscriber and want to exercise rights relating to a mailing list or campaign, you should normally contact the campaign owner first. You may also contact us at privacy@simple-signups.com, and we will route or support the request as appropriate.
What we collect
- Account data: name, email address, password hash, account plan, email-verification state, profile image if provided, and authentication/session records.
- Campaign configuration: campaign name, public campaign identifier, allow-listed domains, success redirect URL if configured, double opt-in and MX-check settings, tag controls, milestone notification settings, and related timestamps.
- Subscriber data collected through campaigns: email address, optional first name, optional last name, optional metadata supplied by the account holder’s form or integration, tags, subscription status, confirmation token and confirmation timestamps, optional referer URL, and created/updated timestamps.
- Anti-abuse and security data: salted hash of the client IP address, user agent, short-lived rate-limit counters, Turnstile verification signals when enabled, and domain/origin validation data. We do not store raw IP addresses long-term in subscriber records.
- Operational email data: email addresses needed to send account verification, password-reset, and optional subscriber confirmation messages from a verified sending domain.
- Product metrics: aggregate counters such as signups, submission totals, and rejects by error code. We do not use invasive advertising fingerprinting.
- Client-side storage: a first-party session cookie for authenticated users and a sessionStorage entry that stores an example campaign identifier for documentation/demo flows.
Why we process it and our legal bases
- To provide the service, including account access, campaign management, subscriber ingestion, and optional confirmation flows. Our legal basis is performance of a contract or steps taken at your request before entering into a contract.
- To secure the service, including bot mitigation, rate limiting, abuse detection, and domain validation. Our legal basis is our legitimate interests in protecting the service, customers, and end subscribers.
- To communicate with users, including transactional and operational emails such as verification and password-reset messages. Our legal basis is performance of a contract and legitimate interests in running the service.
- To improve reliability and performance using aggregate metrics and optional cookieless web analytics. Our legal basis is our legitimate interests in operating and improving the product.
- For subscriber data processed on behalf of account holders, the account holder determines the lawful basis for collection and use, such as consent or legitimate interests. In that context, Simple Signups processes personal data only on the account holder’s instructions as described by the service.
Cookies and similar technologies
- Authentication cookie: when you sign in, we use a first-party session cookie so the dashboard and account routes can recognize your session.
- sessionStorage: we store an example campaign identifier in browser sessionStorage for documentation/demo flows. This value is not used for advertising.
- Optional analytics: when enabled, we may use Cloudflare Web Analytics, which is designed to operate without cross-site advertising cookies.
How we share data and our service providers
We share personal data only as needed to run the service, comply with the law, protect the platform, or at your direction. Our core service providers are Cloudflare (Workers, D1, KV, Turnstile, Email Sending, and optional Web Analytics) and infrastructure/components used for authentication and account security.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising.
International transfers
Simple Signups runs on globally distributed infrastructure. Depending on where you or your subscribers are located, personal data may be processed outside your country of residence. Where required, we rely on contractual, technical, and organisational safeguards designed to protect personal data during cross-border processing.
Retention
We retain account, campaign, and subscriber data for as long as needed to provide the service, maintain account history, enforce security controls, and meet legal obligations. Subscriber data remains under the campaign owner’s control and is typically retained until the account holder deletes it or closes the relevant account. Short-lived rate-limit counters and MX-validation cache entries are kept for operational periods only, and product metrics are stored in aggregate form where practical.
Security
We use technical and organisational measures designed to protect personal data, including password hashing, salted IP hashing in subscriber records, domain restrictions, bot checks, rate limits, and minimised storage of anti-abuse data. No internet service is completely secure, but we work to reduce risk and limit data exposure.
Your GDPR rights
Subject to applicable law, you may have the right to request access to personal data, rectification, erasure, restriction of processing, portability, and objection to processing, and to withdraw consent where consent is the legal basis. You may also have the right to complain to a supervisory authority.
If you are an account holder or website visitor, contact us at privacy@simple-signups.com. If you are an end subscriber, please contact the campaign owner first because they usually control the list relationship and subscriber-purpose decisions.
Your California privacy rights
If California law applies, you may have rights to know what personal information we collect, access it, request deletion, request correction, and receive equal service without discrimination for exercising your rights. We do not sell personal information and do not share personal information for cross-context behavioural advertising. We also do not use sensitive personal information to infer characteristics about consumers.
California requests may be sent to privacy@simple-signups.com. We may need to verify your identity before completing a request.
Children’s privacy
The service is not directed to children, and we do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data through the service, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in the product, legal requirements, or our processing practices. When we do, we will update the “Last updated” date on this page.
Contact
Privacy questions or rights requests: privacy@simple-signups.com. General support questions: hello@simple-signups.com.