Groppi Consulting

Privacy Policy

Last updated: July 8, 2026

1. Overview

This Privacy Policy describes how Groppi Consulting ("we," "us," or "our") collects, uses, and protects information in connection with Signal, a revenue intelligence dashboard licensed to home services franchise operators ("you" or "the client"). By using Signal, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information to operate Signal:

Operational Data from ServiceTitan: Job records, revenue figures, campaign attribution, customer service representative (CSR) assignments, and employee roster information. This data is pulled via the ServiceTitan API on your behalf.

Advertising Data from Google Ads: Monthly ad spend, impressions, clicks, and conversions at the campaign level. This data is pulled via the Google Ads API using OAuth 2.0 authorization granted by you or your authorized advertising agency.

Account Information: Email address and name used to create your Signal login, managed via Supabase Auth.

Manually Entered Data: Ad spend figures entered directly into Signal by you or your team.

Usage Data: Log data including pages visited, sync events, and error logs used to maintain and improve the service.

3. How We Use Your Information

We use the information we collect solely to:

— Display revenue intelligence dashboards, KPIs, and reports to you as a licensed client — Calculate metrics including booking rate, revenue per lead, cost per lead, and ISR productivity — Sync data automatically on a nightly schedule to keep your dashboard current — Diagnose errors and maintain the reliability of the service — Improve Signal's features and accuracy over time

We do not use your data to train machine learning models, sell advertising, or build profiles for any purpose beyond operating Signal for your account.

4. Google Ads Data

Signal integrates with the Google Ads API to pull campaign-level performance data. We request read-only access to your Google Ads account via OAuth 2.0. We do not create, modify, pause, delete, or otherwise write to your Google Ads account in any way.

OAuth refresh tokens are stored as encrypted secrets in our Supabase database and are never exposed to the client browser or transmitted to any third party. You may revoke Signal's access to your Google Ads account at any time via your Google Account security settings (myaccount.google.com/permissions).

Google Ads data stored by Signal is limited to aggregated monthly totals (spend, impressions, clicks, conversions) at the campaign level. No personally identifiable information from Google Ads users is stored or displayed.

5. Data Sharing

We do not sell, rent, or share your data with third parties for their own purposes. We may share data only in the following limited circumstances:

— Service providers: Supabase (database and authentication), Vercel (hosting), and cron-job.org (scheduled sync triggers) process data on our behalf under confidentiality obligations. — Legal requirements: We may disclose data if required by law, court order, or government authority. — Business transfer: In the event of a merger or acquisition, your data may be transferred to the successor entity under equivalent privacy protections.

6. Data Security

We implement the following security measures to protect your data:

— All data is transmitted over HTTPS/TLS encryption — Row Level Security (RLS) is enforced in our database — each client account can only access its own data — OAuth tokens are stored as encrypted secrets, never in plain text — Access to Signal requires authenticated login — no public endpoints expose your business data — Database backups are maintained by Supabase with point-in-time recovery

7. Data Retention

We retain your data for the duration of your license agreement with Groppi Consulting. Upon termination of your license, we will delete your account data within 30 days upon written request. Historical job and KPI data may be retained in anonymized aggregate form for product improvement purposes.

8. Your Rights

You have the right to:

— Access the data Signal holds about your business — Request correction of inaccurate data — Request deletion of your account and associated data — Revoke Google Ads API access at any time via your Google Account settings — Export your data in CSV format upon request

To exercise any of these rights, contact us at hello@groppiconsulting.com.

9. Cookies

Signal uses session cookies solely to maintain your authenticated login state. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie data is shared with advertising networks.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice within Signal. Continued use of Signal after changes take effect constitutes acceptance of the updated policy.

11. Contact

Questions about this Privacy Policy should be directed to:

Groppi Consulting hello@groppiconsulting.com signal.groppiconsulting.com

Signal by Groppi Consulting · hello@groppiconsulting.com