SignalStream Privacy Policy
Privacy Policy — SignalStream Server-Side Tracking
Effective date: July 9, 2026
Last updated: July 9, 2026
This Privacy Policy applies to the SignalStream service, operated by Harper Agency (“we”, “us”, “our”), accessible at harper.agency and through the SignalStream platform plugins (woo-sst and future platform plugins).
1. Who This Policy Covers
This policy covers two groups:
- **Merchants** — businesses that subscribe to SignalStream and install the plugin on their store
- **End-customers** — shoppers who purchase from a merchant store that uses SignalStream
If you are a merchant, you are also a data controller for your customers’ data. SignalStream acts as a data processor on your behalf. You are responsible for ensuring your own privacy policy discloses server-side tracking to your customers.
2. What Data the Plugin Collects
When an order event occurs on a merchant’s store, the SignalStream plugin collects and transmits the following data to the SignalStream API (`ss-api.harperservice.tech`):
Order data:
- Order ID
- Currency and order value
- Product names, IDs, quantities, and prices
Customer identifiers (hashed before transmission):
- Email address — SHA-256 hashed
- Phone number — SHA-256 hashed, E.164 format
- Customer account ID — SHA-256 hashed
Browser/session data (transmitted raw — not hashed):
- IP address
- User agent string
- Page URL at time of event
- Facebook click ID (`_fbc` cookie value) — SHA-256 hashed
- Facebook browser ID (`_fbp` cookie value) — SHA-256 hashed
No passwords, payment card numbers, or full PII are ever transmitted. All personal identifiers are one-way hashed (SHA-256) and cannot be reversed by SignalStream or any third party.
3. How We Use This Data
The SignalStream API receives event data and forwards it to the advertising platforms configured by the merchant:
- **Google Analytics 4** via the GA4 Measurement Protocol — [Google Privacy Policy](https://policies.google.com/privacy)
- **Meta (Facebook/Instagram)** via the Conversions API — [Meta Privacy Policy](https://www.facebook.com/privacy/policy/)
- **TikTok** via the TikTok Events API — [TikTok Privacy Policy](https://www.tiktok.com/legal/page/us/privacy-policy/)
We transmit data to only the platforms the merchant has configured. If a merchant has not connected TikTok, for example, no data is sent to TikTok.
We use event data to:
- Forward conversion signals to the merchant’s configured ad platforms
- Track plan usage (order count against subscription limit)
- Log delivery outcomes for the merchant’s dashboard
- Detect and prevent duplicate events
We do not use end-customer data for advertising, profiling, or sale to third parties.
4. Data Retention
| Data | Retention |
|---|---|
| Event log (delivery outcomes) | 90 days, then automatically purged |
| Deduplication records | 30 days |
| Hashed identifiers in event log | Purged with event log |
| Subscription and licence data | Retained for the life of the merchant’s account |
Raw order data is not persistently stored. The API processes events in memory and forwards them; only delivery outcomes (success/failure status) are logged.
5. Cookies
The SignalStream plugin reads (but does not set) the following cookies on the end-customer’s browser:
| Cookie | Set by | Purpose |
|---|---|---|
| `_fbp` | Meta Pixel | Facebook browser identifier |
| `_fbc` | Meta Pixel | Facebook click ID |
These cookies are set by the merchant’s own Meta Pixel (if installed) and are read by the plugin solely to improve attribution accuracy when forwarding to Meta CAPI. Both values are SHA-256 hashed before transmission.
6. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, our legal basis for processing end-customer data is:
- **Legitimate interest** — conversion tracking is a legitimate interest of merchants operating advertising campaigns, balanced against minimal data exposure (hashing all identifiers)
- **Consent** — where the merchant’s store implements a consent mechanism and passes consent status to the plugin, we only forward events for customers who have consented
Merchants are responsible for collecting appropriate consent from their customers under GDPR and any applicable local law.
7. Your Rights
If you are an end-customer of a merchant store using SignalStream, you may have rights under GDPR or CCPA including:
- The right to know what data was collected
- The right to deletion
Because SignalStream only stores hashed identifiers (not reversible to your identity), deletion requests should be directed to the merchant whose store you purchased from. We can delete event log records associated with a specific order ID upon verified request.
To submit a request, email: [email protected]
8. Data Transfers
SignalStream’s API is hosted in Canada. Data forwarded to Google, Meta, and TikTok is subject to those companies’ data transfer mechanisms and privacy policies.
9. Security
All data is transmitted over HTTPS. Personal identifiers are hashed before leaving the merchant’s server. The SignalStream API enforces licence key authentication on all endpoints. We apply rate limiting and connection limits at the network level.
10. Merchant Responsibilities
By using SignalStream, merchants agree to:
- Disclose server-side tracking in their own privacy policy
- Obtain any consent required by applicable law before enabling tracking
- Not use SignalStream to track individuals without a lawful basis
- Configure only platforms they are authorised to send data to
11. Changes to This Policy
We will update this page when material changes are made and update the “Last updated” date above. Continued use of SignalStream after changes constitutes acceptance of the revised policy.
12. Contact
Harper Agency
Ontario, Canada
harper.agency



