SignalPathPrivacy and terms
Privacy

Privacy Policy

SignalPath keeps ordinary working diagrams in your browser. Information is sent to SignalPath only when the owner creates a client workflow or uses a hosted service such as email delivery, agreement signing, or payment-link delivery.

Effective and last updated August 12, 2026

At a glance

  • Diagrams, component libraries, settings, and unpublished document drafts are stored in your browser by default.
  • Published workflows are server-backed so clients can respond, sign agreements, and follow payment status across devices.
  • SignalPath does not sell personal data, run behavioral advertising, or use its own advertising trackers.
  • Client links are high-entropy, unlisted links. Anyone who receives the exact URL may be able to view the published quote or project page; downloading a completed signed agreement also requires verification of the assigned client email.
  • For initial payments, the publisher supplies the external invoice or payment URL when one is required. For a final balance, the publisher may release an embedded Stripe Checkout inside SignalPath with an optional gratuity field. Stripe hosts payment collection and—not SignalPath—collects the payment-card or bank credentials.

Information processed

Local workspace data

Your diagrams, uploaded baseplate images, equipment and port-name libraries, preferences, and unpublished document drafts are stored in browser storage on the device and browser profile you use. SignalPath does not receive that content merely because you edit, export, or locally save it. Clearing browser data may permanently remove local saves.

Published quotes and workflows

When an authorized publisher creates a client workflow, SignalPath stores the selected quote, equipment and pricing, diagram snapshot, client contact details, document versions and fingerprints, agreement and invoice records, workflow status, and an append-only history of important actions. The publisher is responsible for having permission to publish that information and for avoiding unnecessary sensitive information.

Client page views

After a client project page visibly loads in a browser, SignalPath may record the first and latest view time, a limited visit count, IP address, browser information, workflow stage, and the document shown. Repeated loads from the same network within a short period are combined. Automated email-link checks may still occasionally resemble a real visit. Authenticated owner previews are separate and do not count as client views.

Quote responses and email verification

To approve a quote or request changes, a client provides a name and the email address listed on the quote, receives a six-digit verification code, and confirms the requested action. SignalPath stores a one-way hash of the short-lived code rather than the code itself. After successful verification, SignalPath places a secure, browser-only cookie tied to that workflow and client email for up to one year so the same browser does not require another code for later project steps. A different browser, cleared cookies, or a changed client email requires verification again. The response record may include the quote version and fingerprint, response text, confirmation, server timestamp, IP address, browser information, first and latest view times, and an audit identifier. Quote approval is recorded as a verified response, not an electronic signature.

Agreement approvals and signatures

The publisher’s approval records their name, title, confirmation, timestamp, agreement version, and document fingerprint. A client signing an agreement provides the matching client email and adopts either a typed or drawn electronic signature. The previously verified project email remains valid in the same browser; SignalPath requests another code only when that project verification is unavailable or the client email changed. The same verification is required to download a signed agreement from a new browser. SignalPath stores the signature, consent choices, timestamps, IP address, browser information, agreement fingerprint, and audit identifier. It generates retainable, immutable agreement copies with the accepted quote and diagram attached. New quotes and invoices do not collect electronic signatures. Previously signed invoice links and certificates remain retained as historical records.

Email delivery

SignalPath uses Resend to deliver quote and agreement links, verification codes, signed-copy links, invoice notices, and owner alerts. Resend receives the recipient address, sender identity, subject, message content, and ordinary delivery information. The publisher may receive a separate authenticated owner-preview email; it does not contain the client action link and cannot change the client workflow. SignalPath stores provider message identifiers and delivery, bounce, and failure events so the publisher can see whether a message arrived. Resend processes this information under its own privacy terms.

Payment links and payment status

When an initial payment is required, the publisher can attach a secure external invoice or payment link to the owner-approved agreement. For a final payment, the publisher can release a balance through Stripe Checkout embedded in the client project page. The client may leave the optional gratuity at zero or enter an amount before Checkout opens. SignalPath sends the client email, project reference, fixed balance, optional gratuity, and related reconciliation metadata to Stripe. Stripe securely renders the payment form; SignalPath does not receive card or bank credentials.

Stripe may send signed payment-status events back to SignalPath. SignalPath stores the fixed balance, optional gratuity, total, Stripe identifiers, payment result, and closing time. A verified final-payment event can close the workflow automatically. The owner can alternatively record cash, check, wire transfer, another external payment, no balance due, or an owner-only closing override; those actions are retained in the project audit history.

Publisher identity and operational data

The private owner account stores an owner email, a one-way password hash and salt, an encrypted authenticator secret, one-way recovery-code hashes, short-lived session records, and failed-attempt and lockout records. Passwords, authenticator codes, and recovery codes are not stored in readable form. A separate one-time setup code authorizes creation of the first owner account.

Publishing and owner actions require authentication. SignalPath stores the authenticated publisher’s email address and ownership identifiers to prevent other accounts from changing a workflow. Hosting, security, authentication, Resend, and Stripe may process ordinary network and device information such as IP address, request time, browser details, and security logs to deliver and protect the service.

Call operations

When the Just Home Theater call system is activated, callers hear a disclosure before recording begins. SignalPath may store encrypted caller and callback details, project intake, consent events, call and routing metadata, dual-channel audio, raw and normalized transcripts, summaries, approved analysis, model and constrained-tool events, appointments, messages, payment state, route results, and advertising attribution. Caller and project records are kept in SignalPath’s private D1 and R2 environment and are not copied into the public website analytics database.

Plivo processes voice calls and recordings and, when enabled, transactional texts; Retell processes the guarded voice conversation; Deepgram transcribes canonical multichannel audio with provider model-improvement opt-out requested; Google may process route distance, calendar availability, and—with separate caller consent—call conversion details; Stripe hosts consultation checkout. SignalPath does not receive card details. An objection to Google sharing suppresses that call’s conversion upload. An objection to recording stops the automated intake because it depends on transcription and queues captured artifacts for deletion.

How information is used and disclosed

SignalPath uses information to operate the workflow requested by the publisher, verify client email access, preserve document versions and audit evidence, deliver messages, report payment and delivery status, enforce security and abuse limits, troubleshoot failures, and comply with law. Published information is disclosed to people who have the client-link URL and to service providers that host, authenticate, email, store, or process the selected workflow. SignalPath does not sell personal information or disclose it for cross-context behavioral advertising.

Retention and deletion

Local data remains in the browser until the user deletes it or browser/site data is cleared. Unpublished server records may be removed when no longer needed. Published responses, immutable agreements, signatures, payment events, delivery events, and their audit history may be retained for seven years from the relevant agreement or payment, or longer when reasonably required for tax, accounting, dispute, fraud-prevention, or legal obligations. Revoking a client link prevents ordinary future access but may not erase immutable records, backups, or information another party already downloaded.

Call audio, transcripts, summaries, approved analysis, tool events, and related metadata have no automatic expiration in the initial call system. An authenticated owner can preview an individual or date-range purge; bulk execution requires a fresh authenticator check and typed confirmation and is audited. Cloudflare D1 rollback storage may temporarily retain deleted rows. A call conversion already accepted by Google cannot be retracted through SignalPath.

Your choices and requests

A client may request a paper or downloadable copy, decline electronic signing, or ask the publisher to correct contact information before responding. A person named in a workflow should first contact the business that sent the link. For an access, correction, deletion, privacy, or appeal request that cannot be resolved with the publisher, email legal@usesignalpath.com. SignalPath may need to verify the requester’s identity and relationship to the record. Some deletion requests may be limited by recordkeeping, dispute, security, or legal obligations.

Security

SignalPath uses encrypted transport, high-entropy links, owner authentication, short-lived hashed verification codes, attempt and resend limits, same-origin write checks, payload validation, signed provider webhooks, and immutable document fingerprints. No system can guarantee absolute security. Do not place passwords, financial account numbers, government identifiers, health information, or other highly sensitive data in a diagram or client document.

Children

SignalPath is a professional AV planning service and is not directed to children under 13. Do not use the service to collect or publish personal information from a child under 13. If you believe such information has been published, contact SignalPath promptly.

Changes and contact

This policy may be updated as the service changes. Material changes affecting already-collected information will be disclosed where required. Questions, privacy requests, and safety reports may be sent to legal@usesignalpath.com.

SignalPathOperated by Summit Theater Systems LLC, d/b/a Just Home Theater6 Heatherstone Ct., Trophy Club, TX 76262 · info@justhometheaters.com
PrivacyTermsContact