Skip to content
Signedup
  • What it is

    • How it worksThree steps, and what each one takes you.
    • Who uses itThe lists people already keep, department by department.
    • See the formsWhat one of your colleagues actually opens.
    • QuestionsStraight answers on sending, importing and leaving.

    See how it works

  • How it compares

    • What is a preference centre?The category explained, without selling anything.
    • A spreadsheetThe most common alternative, and where its one structural weakness is.
    • An Outlook or Microsoft 365 distribution listAccurate about employment, silent on preference.
    • Mailchimp or another marketing email toolSending tools solve the other half. How the two work together.
    • An intranet formAlready approved and already paid for. Why the list still goes stale.
    • A full internal comms platformWhen a full platform is right, and when it is more than the job requires.

    All comparisons

  • Pricing
  • Practical guides

    • Your first listFrom nothing to a link you can share, in about the time it takes to make a cup of tea. What to call it, what to ask, and when to publish.
    • Getting people to actually sign upA form nobody fills in is a spreadsheet with extra steps. Where to put the link, what to say, and how to reach colleagues who pass a notice board more often than they read an inbox.
    • Keeping a list clean without chasing anyoneEvery list falls out of date - people move team, change site, leave. The answer is not to chase harder; it is to stop being the only person who can make a correction.
    • Do you need consent for internal emails?Employment does not make every internal email lawful, and consent is often the wrong basis to claim. Which messages need what, and the record that settles an argument.
    • How to organise your internal mailing listsMost internal lists are organised by who somebody is, because that is what the directory knows. Nearly everything people actually want is organised by interest, and the gap between the two is where the administration comes from.

    All guides

  • Who it is for
  • How it works
  • Pricing
  • Questions
  • Guides

Privacy notice

Last updated 15 September 2026

This notice explains how Signedup collects and uses personal data, and what rights you have over it. Which parts apply to you depends on how you came to us, so it is divided by the situations people are in.

Who we are

Signedup is based in the United Kingdom. For anything about this notice or your personal data, write to privacy@signedup.io. We have not appointed a data protection officer, because the law does not require us to, but that address reaches a person.

The two roles we play

For most of the personal data described here we are the controller: we decide why and how it is used, and this notice is the full account of it. That applies to visitors to our website, people on our early access list, people who use a Signedup account, billing contacts and people who contact us.

For the people on lists that our customers run using Signedup, we are not the controller. The organisation running the list decides what to ask and why, and we process the answers on its behalf as its processor, under our data processing agreement. The organisation's own privacy notice governs that relationship. The section headed "If you are on a list run by an organisation using Signedup" explains our part in it.

If you visit our website

When you visit our website, the page and its files are delivered to your browser by our hosting provider, which necessarily processes your network address and browser information to do so and to protect the site against attack. We use that information only to deliver and secure the website.

If a page fails to work in your browser, we receive an error report containing the address of the page, the nature of the failure and the type of browser. It is configured not to send your network address, anything you have typed into a form, or anything else that identifies you, and nothing is recorded when a page works. We also count visits to our pages using a measurement method that sets no cookie, stores nothing in your browser and does not identify you.

The typefaces on this site are served by us. A site that loads its fonts from a third-party font service sends every visitor's network address to that service, usually without saying so. Ours are copied when the site is built and served from the same place as the pages.

Lawful basis: our legitimate interests in delivering a working and secure website and in understanding, in aggregate, how it is used. Retention: error reports are kept for no longer than 90 days, and operational records containing network addresses are kept only for the short period needed to diagnose faults and investigate abuse.

If you join our early access list

We collect your first and last name and your email address, and, only if you choose to give them, the name of your organisation, its approximate size and the kind of role you hold. We also record the page you joined from, the date and time, and the network address and browser the form was sent from. A security check on the form helps us tell a person from an automated script.

We use your name and email address to tell you when Signedup opens to everyone, relying on our legitimate interest in replying to somebody who has asked to be told. If you also tick the optional box, we send occasional notes about what we are building, relying on your consent, which we record and which you can withdraw at any time; withdrawing it does not affect anything we did before. We use the optional details about your organisation and role, relying on our legitimate interest, to understand who the product is for. We use the network address, browser and the result of the security check to prevent and investigate abuse of the form, relying on our legitimate interest in keeping a public form usable.

We keep your details until we have told you that Signedup is open to everyone, or until you ask us to remove you, whichever comes first. If you agreed to occasional notes, we keep your name and email address for that purpose until you withdraw your consent. If Signedup never opens to everyone, we delete the list.

If you use a Signedup account

This section covers anyone who signs in to Signedup, whether you created your organisation's account or were added to it by a colleague.

What we hold: your email address and, if given, your name; the organisations you belong to and the role you have in each; technical information about your sign-in sessions, such as the browser and network address used; entries in your organisation's audit log recording what you did and when; and information about how you use the Service, such as which features are used and any errors you encounter.

Where it comes from: from you when you sign up or sign in, and from the Service as you use it. If a colleague adds you to their organisation, we receive your email address, and any name they enter, from that colleague.

What we use it for, and our lawful basis for each use:

  • to create your account, sign you in and provide the Service. Where you are the customer, this is necessary to perform our contract with you; where your organisation is the customer, we rely on our legitimate interest, and your organisation's, in providing the Service it has chosen to the people it has authorised;
  • to keep the Service and your organisation's account secure, including recording administrative actions in the audit log, relying on our legitimate interest in security and in your organisation being able to see who did what;
  • to send you messages about your account and the Service, such as sign-in links, notices about your organisation's plan, and notice of changes to our terms or sub-processors, relying on performance of our contract or our legitimate interest in operating the Service;
  • to understand how the Service is used and to improve it, relying on our legitimate interest in developing the product. Where we produce statistics from this, they are aggregated and do not identify you; and
  • to send you occasional news about Signedup, relying on our legitimate interest where the law allows it. Every such email lets you opt out, and you can object at any time.

How long we keep it: audit log entries are kept for as long as your organisation's account exists and are deleted with it. Your sign-in details are kept while you have access to an organisation on Signedup. When you no longer have access to any organisation, we keep them only for as long as is reasonably needed to deal with any follow-up, and we delete them when you ask us to. Information about how the Service is used is kept in a form that identifies you only for as long as it is needed for the purposes above.

If you pay for a plan or are a billing contact

What we hold: the name, email address and billing address of the person or organisation paying, any VAT or tax number, the plan bought, and the history of payments and invoices. Card details are entered directly with our payment provider and are never received by us.

Lawful basis: performance of our contract, and our legal obligation to keep accounting and tax records. Our payment provider also processes some payment information as an independent controller under its own privacy notice, for example to prevent fraud and to meet financial regulation.

Retention: for as long as tax and accounting law requires, which is currently up to six years after the end of the financial year the record relates to.

If you contact us

When you email us, we hold your email address, your name if you give it, and what you write. We use it to respond and to keep a record of what was agreed, relying on our legitimate interest in answering correspondence, or on our legal obligation where you are exercising a data protection right. We normally keep correspondence for up to two years after the matter is closed, and longer only where it is needed for a legal claim or a legal obligation.

Keeping the service secure, and legal matters

Across everything above, we process network addresses, browser information and the results of automated checks to limit the rate of requests, to detect and prevent abuse, and to investigate security incidents, relying on our legitimate interest in keeping the Service and the people who use it safe. We may also use any of the personal data described in this notice where it is needed to establish, exercise or defend legal claims, or to comply with a legal obligation, and keep it for as long as that requires.

If you are on a list run by an organisation using Signedup

An organisation chose to ask you its questions and holds your answers using our service. That organisation is the controller. Its privacy notice tells you what it does with your details and on what lawful basis, and it is the organisation you should contact about how your details are used.

On the organisation's behalf, we store your details and answers and show them to the people the organisation has authorised. We send you the single-use link you ask for when you enter your address, and, if the organisation chooses, a request to check that your details are still correct. We do not send you marketing, we do not build a profile of you, and we never use one organisation's data for another organisation or for ourselves.

Each time you join, change something or unsubscribe, we record what you did, when, which version of the form you were shown, and the network address and browser the action came from. That record lets the organisation show that you agreed rather than merely assert it. If a message to your address bounces or is reported as unwanted, we record that and stop sending to the address.

From the link you used to join, you can change any answer, unsubscribe, download everything held about you, or delete your record, without an account and without asking anybody. If you write to us instead about your details on an organisation's list, we will pass your request or complaint to that organisation, because it is the controller and it decides the response.

How long your details are kept is the organisation's decision, and it can remove them at any time. In addition, our service removes a request to join that is never confirmed after 30 days. If you delete your own record, it is held for 30 days so that an accidental deletion can be reversed and is then removed, together with the history of your consent, and it leaves our backups within a further 35 days. If the organisation stops using Signedup, its lists are deleted 60 days after its account ends.

Who we share personal data with

We do not sell personal data, and we do not share it with advertisers or data brokers. We share it only with:

  • the companies we use to run the Service, such as our hosting, email delivery, error monitoring, payment and mailbox providers. Each acts on our instructions under a written contract and may not use the data for its own purposes. Each is named, with its purpose and the country where it holds data, on our sub-processors page;
  • our professional advisers, such as lawyers, accountants and insurers, under duties of confidence;
  • courts, regulators, tax authorities, law enforcement agencies and other public bodies, where the law requires us to, or where it is necessary to establish, exercise or defend legal claims; and
  • a buyer of, or successor to, all or part of our business, including a company formed to run Signedup, who would be bound by this notice for the data it receives.

Transfers outside the United Kingdom

Personal data at rest is held in the United Kingdom or the European Union. Some of the companies we use are incorporated in the United States, or belong to groups based there, so personal data may be accessed from the United States, for example to provide support, and our payment provider transfers some payment information there. Where the law requires a safeguard for such a transfer, we rely on UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or on the International Data Transfer Agreement or Addendum issued by the Information Commissioner. To ask for a copy of the relevant safeguards, write to privacy@signedup.io.

How we protect personal data

Personal data is encrypted in transit and at rest, there are no passwords anywhere in the Service, each organisation's data is separated from every other's, and access by our own people is limited to operating and supporting the Service. Our security page describes the measures in more detail.

Your rights

Where we are the controller, you have the following rights. To use any of them, write to privacy@signedup.io. If you are on a list run by one of our customers, contact that organisation, or use the link at the bottom of its messages.

  • Access: to be told whether we hold personal data about you and to receive a copy of it. We will make a reasonable and proportionate search, and if we need you to clarify what you are asking for, the time we have to respond pauses until you do.
  • Rectification: to have inaccurate personal data corrected and incomplete data completed.
  • Erasure: to have personal data deleted where there is no longer a lawful reason to keep it.
  • Restriction: to ask us to hold personal data but not otherwise use it while a question about its accuracy or our use of it is resolved.
  • Portability: to receive personal data you gave us, in a machine-readable form, where we process it by automated means on the basis of consent or a contract.
  • Withdrawing consent: where we rely on consent, to withdraw it at any time, as easily as you gave it. This does not affect anything we did before.

We respond within one month of receiving a request, which we may extend by up to two further months where a request is complex or one of several, telling you why. We may need to confirm your identity first. There is normally no charge, but where a request is manifestly unfounded or excessive we may charge a reasonable fee or decline it, and we will explain why.

Your right to object

Where we rely on legitimate interests, you have the right to object at any time, on grounds relating to your situation, to our use of your personal data. We will stop unless we have compelling legitimate grounds that override your interests, or we need the data for legal claims. You have an absolute right to object to our use of your personal data for direct marketing, and if you do, we will stop. To object, write to privacy@signedup.io, or use the unsubscribe link in any marketing email.

How to complain

If you are unhappy with how we have handled your personal data, you can complain to us by writing to privacy@signedup.io. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office, the supervisory authority in the United Kingdom, at any time, whether or not you have complained to us first. Its website is ico.org.uk and its helpline is 0303 123 1113.

Cookies

Our website sets no tracking or advertising cookies. The product uses only the cookies it needs to keep you signed in and to keep a form session secure, together with a security check on our forms. Our cookie notice lists them.

Children

Signedup is a service for organisations and is not directed at anyone under the age of 18. We do not knowingly collect personal data about children for our own purposes. Our terms do not allow customers to use the Service to collect personal data about children without our written agreement.

Automated decision-making

We do not make any decision about you based solely on automated processing that has a legal or similarly significant effect on you, and we do not profile you. The automated processes that run are checks that refuse disposable email addresses and automated abuse at sign-up, and the scheduled deletion of records described in this notice.

Whether you have to give us personal data

Joining the early access list is voluntary, and only your name and email address are needed. Using a Signedup account requires an email address, because that is how you sign in. Paying for a plan requires billing and tax details, because we need them to perform the contract and to meet our obligations to HM Revenue and Customs. For a form run by one of our customers, the organisation decides which questions are required, and its form says so.

Changes to this notice

We update this notice when what we do with personal data changes, and the date at the top shows when it last changed. If a change materially affects how we use personal data we already hold, we will tell the people affected where we have a way to do so before it takes effect. This version was published on 15 September 2026.

Signedup

  • Security
  • Privacy
  • Terms
  • DPA
  • Sub-processors
  • Acceptable use
  • Cookies
  • Contact