FiduciarySignal
← Back to app

Privacy Policy

Last updated: July 8, 2026

This Privacy Policy explains how D & F Research, LLC, a Florida limited liability company that operates FiduciarySignal (the “Service,” “we,” or “us”), handles your information. The Service is made available at www.fiduciarysignal.com.

1. Information we collect

  • Account information. When you create an account we collect a username, your email address, and a password. Passwords are stored only as a salted cryptographic hash — we cannot see or recover your actual password.
  • Authentication metadata. When you sign in, we record session timestamps to maintain your signed-in session.
  • Billing information. If you subscribe or make a purchase, our payment processor (Stripe) collects and processes your payment details directly. We do not store full card numbers; we retain a processor customer and subscription identifier, your plan and billing status, and a record of downloads and delivered items used to apply plan limits and per-item charges.
  • Professional identifiers. For certain features you may provide a FINRA Central Registration Depository (CRD) number to confirm eligibility. A CRD number is public professional-registration information.
  • Public filings data. The Service displays Form 5500 ERISA filings and related public records about employer-sponsored plans and their service providers. This data concerns plans and businesses, not you personally.

We do not collect precise location, contacts, or advertising identifiers, and we do not use third-party advertising or cross-site tracking SDKs.

2. How we use your information

  • To create and maintain your account and your signed-in session.
  • To send account emails, such as password-reset links you request.
  • To process subscriptions and purchases, apply plan limits, and charge for pay-as-you-go items.
  • To respond to support requests you send to us.

We do not sell, rent, or trade your information. We do not share it with advertisers or data brokers.

3. Cookies and local storage

We set a single session cookie when you sign in. It is HttpOnly, Secure, and uses SameSite=Lax. The cookie expires after 30 days of inactivity or when you sign out. Our service worker may cache the application shell and public reference content on your device to enable offline use; this cache contains no personal information.

4. Third-party services

  • Stripe (privacy policy) — processes subscription and one-time payments and handles your card details directly.
  • Resend (privacy policy) — delivers account emails such as password-reset links.
  • Render (privacy policy) — hosts the Service.
  • Sentry (privacy policy) — collects error and diagnostic data to keep the Service reliable.
  • U.S. Department of Labor EFAST2 — source of public Form 5500 filings displayed by the Service. The DOL is the publisher of this data, not a recipient of your information.

5. Data retention

We retain your account information for as long as your account is active, and we retain billing records for as long as required for tax, accounting, and legal purposes. Password-reset links expire 30 minutes after they are issued and can be used only once. You may request deletion of your account at any time (see section 8).

6. Children

The Service is intended for retirement plan professionals and is not directed to individuals under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us and we will delete it.

7. Your rights

California residents (CCPA/CPRA). You have the right to know what personal information we have collected about you, to request its deletion, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising.

EEA, UK, and Swiss residents (GDPR/UK GDPR). You have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. The lawful bases for processing your information are performance of our contract with you (operating your account and any subscription), your consent where applicable, and our legitimate interest in securing and improving the Service.

8. How to exercise your rights / contact us

To request access to or deletion of your data, or for any privacy question, email support@fiduciarysignal.com. We will respond within 30 days.

9. Security

We use HTTPS for all traffic, hash and sign sign-in tokens with a server-side secret, and apply standard hardening to session cookies. No system is perfectly secure; if we become aware of a breach affecting your information, we will notify you in accordance with applicable law.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the “Last updated” date above. Continued use of the Service after a change indicates acceptance of the updated policy.

App Terms of Service Contact