Last updated: September 4, 2026
Material Model, Inc., doing business as Signals (“Signals”, “we”, “us”, “our”), is committed to protecting privacy and securing personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when we provide customer messaging services for ecommerce brands.
Signals is a business-to-business service. We process information for our business customers and their end customers through iMessage, RCS, SMS, 10DLC SMS, WhatsApp, and related commerce, support, analytics, and messaging systems.
For how we handle messaging consent, marketing sends, opt-outs, and channel-specific compliance controls, see our Messaging Compliance page.
We may process end customer information on behalf of a business customer, including:
We use information to:
Signals uses AI and infrastructure providers to process conversation content, commerce context, and workflow state. These providers may include cloud infrastructure, language model providers, messaging providers, analytics tools, and commerce or support integrations.
Where available, we use strict data protection terms and controls, including zero data retention terms for supported AI processing. AI providers are not permitted to use customer data to train their general models unless a separate agreement expressly allows it.
We do not sell personal information. We may share information:
When a merchant installs Signals through Shopify, we receive store, product, customer, order, fulfillment, return, policy, and staff-account information according to the permissions approved by the merchant. We use that information only to provide the customer messaging, order support, returns, recommendations, analytics, billing, security, and account-administration features described in this policy.
Shopify sends Signals privacy requests when a customer asks to access or erase their data, or when a shop’s data must be erased. We authenticate those requests and process them within Shopify’s required 30-day period. Customer data exports are available only to a freshly verified Shopify account owner, expire no later than 30 days after creation, and use short-lived download links.
When we erase Shopify customer data, we may retain a de-identified suppression record where needed to continue honoring an opt-out. We don’t use identifiable Shopify customer personal data to train general-purpose AI models.
Signals processes opt-outs and suppression requests. Standard STOP-style keywords are handled immediately, and ordinary-language requests to stop future text or customer messages may also block future outreach.
Signals may process marketing consent state, opt-in evidence, opt-out evidence, customer outreach preferences, message channel evidence, order geography, and related compliance metadata. For more detail, see Messaging Compliance.
We implement security measures designed to protect information, including:
For more detail, see our Security page.
We retain information for as long as needed to provide Signals, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.
Typical retention categories include:
You may request deletion of identifiable data by contacting privacy@returnsignals.com. Business customers may submit end customer deletion requests on behalf of their end customers. Deletion requests do not require us to delete aggregated or de-identified data, or records we must retain for legal, security, billing, or compliance purposes.
Depending on your location, you may have rights to:
To exercise these rights, contact privacy@returnsignals.com. We will respond as required by applicable law.
We use cookies and similar technologies to support:
You can control cookies through your browser settings. Disabling certain cookies may limit functionality.
Information may be transferred to and processed in the United States and other countries where we or our providers operate. We use appropriate safeguards for international transfers where required.
Signals is not intended for individuals under 18. We do not knowingly collect personal information from children. If we learn that we collected information from a child, we will take appropriate steps to delete it.
California residents may have additional rights, including the right to know what personal information is collected, used, shared, or sold; the right to delete personal information; the right to opt out of sale or sharing where applicable; and the right not to be discriminated against for exercising privacy rights.
We do not sell personal information. To make a California privacy request, email privacy@returnsignals.com.
Signals is currently offered to businesses located in the United States. If European privacy laws apply to particular processing, we will process information under an appropriate legal basis, such as contract performance, legitimate interests, consent, or legal obligation.
Signals may connect to third-party websites, platforms, and services. We are not responsible for the privacy practices of those third parties. Business customers should review the privacy and compliance terms of their connected systems.
We may update this Privacy Policy periodically. We will post the updated policy with a new “Last Updated” date. When required, we will provide additional notice.
Continued use of Signals after changes become effective constitutes acceptance of the updated policy.
For privacy-related questions, requests, or concerns, contact us:
Material Model, Inc. (d/b/a Signals)
2261 Market Street STE 85311, San Francisco, CA 94114
Email: privacy@returnsignals.com
Website: www.returnsignals.com
For general inquiries, contact hello@returnsignals.com.