Last updated: June 2026
When you submit the contact form on risksignal.io, we collect:
If you pay for monitoring, PayPal collects and processes your payment details directly. RiskSignal does not see or store your card or billing information, that's handled entirely by PayPal.
Form submissions are used to respond to your inquiry, run a check of your client sites, or operate a monitoring subscription. Nothing you submit through the form is used for any other purpose, sold, or shared with third parties beyond what's needed to operate the service.
If you submit a list of client domains, that list is processed by the Ægis engine and the resulting scan data is retained as the history we compare future scans against. It is never shared externally as raw data. We do not collect or use contact data (names, emails, phone numbers, CRM records) as scan input. Submitted domains are used solely to direct scan targeting.
Findings are produced by RiskSignal's own detection methodology applied to publicly observable signals. They reflect what a visitor's browser can see on a passive visit. We can observe that a tracking tag is absent or sending nothing; we cannot observe conversion event values, deduplication, or consent-mode configuration, and we make no claim about those.
Deliverables and scan artifacts from paid engagements are retained for 180 days from delivery, then permanently deleted. Invoice records and engagement metadata are retained separately for accounting purposes.
Contact form submissions that don't result in a paid engagement are retained only as long as needed to respond to the inquiry.
To request a copy of what we hold about you, or to request deletion, email contact@risksignal.io. We'll respond within 30 days.