Last updated: September 4, 2026
Signals processes customer conversations and commerce data for business customers. This page describes the controls we use to protect that information without making claims about certifications we haven’t obtained.
Signals runs on Google Cloud Platform. Our public web and API endpoints use HTTPS so merchants, Shopify, messaging providers, and other connected services can reach them securely.
Google Cloud managed services provide encryption at rest. Signals also applies application-level encryption to selected sensitive values, including integration credentials, access tokens, and the selectors used to fulfill Shopify privacy requests. Production secrets are stored in Google Secret Manager rather than in source code.
Production and non-production environments use separate runtime configuration and access boundaries. Application queries and authorization checks scope customer data to the relevant organization.
Signals uses authenticated sessions and organization roles to control access to the platform. Embedded Shopify sessions use Shopify App Bridge session tokens that the Signals backend verifies before returning merchant data. Sensitive Shopify privacy exports require a fresh verification from the Shopify account owner for the same store.
Team and service access is limited according to operational need. We use logging and monitoring to investigate service and security events, and our logging utilities are designed to remove common credential and contact-data patterns from error details.
Signals validates credentials and authorization when connecting to commerce, messaging, support, fulfillment, return, and analytics services. For the public Shopify app, Signals validates signed webhook requests before processing them, stores expiring access credentials in encrypted form, and refreshes or invalidates those credentials as required by Shopify.
Shopify’s mandatory customer-data and shop-redaction webhooks are authenticated before their payloads are parsed. Repeated deliveries are handled idempotently so the same request doesn’t create duplicate work.
We retain information only as long as needed to provide and secure Signals, follow customer instructions, meet legal obligations, honor opt-outs, and resolve billing or service disputes. Conversation and media retention can vary based on the customer’s configuration and operational requirements. Aggregated or de-identified data may be retained after it can no longer reasonably identify a business customer or end customer.
Shopify customer-data access and erasure requests are processed within Shopify’s required 30-day period. Shopify customer-data exports expire no later than 30 days after creation and use short-lived download links. When customer data is erased, Signals may retain a de-identified suppression record where needed to continue honoring an opt-out.
For more detail, see our Privacy Policy.
Signals uses cloud infrastructure, AI, messaging, analytics, and integration providers to operate the service. We limit provider access to the data needed for the relevant function and use contractual or technical data-protection controls where available. AI providers aren’t permitted to use customer data to train their general models unless a separate agreement expressly allows it.
To report a suspected vulnerability, email security@returnsignals.com with a description, reproduction steps, and potential impact. Please avoid accessing, changing, or deleting data beyond what’s necessary to demonstrate the issue, and allow us reasonable time to investigate before public disclosure.
Material Model, Inc. (d/b/a Signals)
2261 Market Street STE 85311, San Francisco, CA 94114
Security email: security@returnsignals.com
Website: www.returnsignals.com
For general inquiries, contact hello@returnsignals.com.