Version 2.0 · Last updated August 31, 2026
Privacy Policy
1. Who we are, and what this policy covers
Sapling Signal is a direct-mail marketing platform operated by Sapling Holding Company, a Delaware corporation (“Sapling Signal,” “Company,” “we,” “us,” or “our”), 611 Gateway Blvd, Suite 120 #1225, South San Francisco, CA 94080. This Privacy Policy describes how we collect, use, disclose, and protect personal information across saplingsignal.com(the “Site”), the Sapling Signal platform (the “Platform”), and the campaign services we operate for our business clients — printed mail, hosted landing and booking pages, tracked phone numbers, and the correction service at saplingsignal.com/fix(together, the “Services”).
It is written for four groups: recipients — homeowners who receive mail prepared through the Platform; respondents — people who visit a landing page, submit a form, book an appointment, call a tracked number, or use the correction form; clients — businesses that use the Platform; and visitors to the Site. By accessing or using the Services you accept the practices described here. This policy is incorporated into and forms part of our Terms of Service. If you do not agree with it, please do not use the Services.
2. Information you provide to us
Responses. When you submit a landing-page form or book an appointment, we collect what you enter: name, address, phone, email, appointment details, and your answers to any questions on the form.
Calls. When you call a tracked number, we log the call (caller number, time, duration, routing) and — after a recording disclosure is played, or where the business has certified that its own phone system provides one — record the call for quality assurance and lead verification.
Corrections. When you use the correction form at saplingsignal.com/fix, we collect the name and address printed on the piece and anything else you tell us. We use this information solely to honor your request — fixing the record or suppressing future mail — never to build a marketing list. Keeping the correction on file is how the request stays honored (see Section 11).
Client accounts. Clients provide account details (email; sign-in credentials are handled by our authentication provider), company and brand information, campaign settings, and business locations. If you save a card or buy credits, payment is processed by Stripe — card numbers go directly to Stripe and never touch our servers. Clients may also upload their own lists (for example, existing-customer or do-not-mail lists used to exclude homes from campaigns); the client is responsible for having the right to share those lists with us.
3. Information we collect automatically
Usage and device data. Standard web logs: IP address, browser and device type, pages viewed, referring URLs, and timestamps — used for security, abuse prevention, and debugging.
Page-visit recordings. The Site and hosted campaign pages use session replay to understand how pages are used (scrolling, clicks, navigation). Anything you type into a form on public pages is masked — keystroke content is not captured in the replay. Replays are deleted automatically after about 30 days. Platform pages may also be session-recorded for support and quality purposes.
Cookies and similar technologies. Public campaign pages set no advertising or cross-site tracking cookies. The Site and Platform set essential cookies only: sign-in sessions and workspace preferences. We do not run third-party analytics or advertising trackers on public pages.
4. Information we receive from other sources
Public records. Campaign audiences begin with public records — chiefly building permits and similar public filings about work done at a property. These are records any member of the public can request from the issuing agency.
Licensed data. We combine public records with property and homeowner data licensed from established, regulated data providers: property characteristics, ownership status, owner name and mailing address, and recent-sale or move indicators tied to an address. This is the same category of licensed data used across the direct- mail industry. We do not purchase or use browsing history, app activity, or social-media data to build audiences.
From clients. Exclusion and suppression lists as described in Section 2, and business contact information for client teams.
5. How we use personal information
In the language of the California Consumer Privacy Act, the categories we collect are: identifiers (name, address, phone, email, IP); commercial information (property records, permits, responses to campaigns); internet activity (page interactions on our Site and hosted pages); audio (recorded calls); professional information (client business contacts); and inferences (an estimate of how well a home fits a given home-services offer). We use them to:
Run campaigns— select the homes a client’s campaign will mail, print and deliver the pieces, and route responses (forms, bookings, calls) to the one business whose campaign you responded to, including confirmations, reminders, and calendar sync for booked appointments.
Measure campaigns — match a response back to the mailed list (attribution) so clients see what worked, and verify recorded calls as genuine leads.
Honor requests — maintain the platform-wide correction and suppression databases so corrections, less-mail, and do-not-mail requests are applied to every future mailing for every business on the Platform, and so the same home is not mailed repeatedly in error.
Improve the Services — compute cross-campaign statistics only over de-identified, aggregated groups. No individual homeowner profile is shared between clients, and we commit to not re-identifying de-identified data.
Protect the Services — secure the Platform, prevent fraud and abuse, enforce our terms, and comply with law.
6. How we disclose personal information
With the business you contacted. Your form submission, booking, or call is shared with — and belongs to — the one business whose campaign you responded to. Their use of it is governed by their own privacy practices.
With service providers processing data on our behalf under contract: Vercel (hosting), Supabase (database, authentication, file storage), Stripe (payments), Twilio (phone numbers, call handling, recordings), Google (calendar sync for booked appointments and address geocoding), Resend (transactional email), our print and mail production partners (recipient name and address only, to print and mail pieces), and our licensed data providers.
Optional ad echo.A client may choose to run a social-media ad alongside a mail campaign so the same households see the same offer online. When a client turns this on, we share hashed (one-way encoded) name, city, state, and ZIP derived from that campaign’s mailing list with the advertising platform, which can match the hashes only against its own users. We never share the underlying list, and we do not do this unless the client runs that feature. To the extent this constitutes “sharing” for cross-context behavioral advertising under California law, you may opt out at any time (Section 9) — a do-not-mail request at saplingsignal.com/fix also removes the household from future ad-echo audiences.
Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, personal information may be transferred as part of that transaction, subject to this policy or one at least as protective.
Legal and safety. We may disclose information when we believe it is required by law, subpoena, or legal process, or necessary to protect the rights, property, or safety of Sapling Signal, our users, or the public.
We do not sell personal information for money, and we never will. Apart from the client-initiated ad echo described above, we do not share personal information for cross-context behavioral advertising.
7. Call recording
Tracked numbers exist so a business can prove which calls its mail generated. Calls are recorded only after a recording disclosure is played to the caller (or where the business has certified its own system provides that disclosure), and recordings are used for lead verification, quality assurance, and dispute resolution. You may request deletion of a recording of your call at any time (Section 9).
8. Google user data
Where a client connects a Google Calendar, our access is limited to creating and updating booked-appointment events and checking free/busy availability. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not transfer it except as needed to provide the calendar-sync feature, for security, or to comply with law.
9. Your privacy rights
The fast lane for mail. To fix a wrong name or address, correct a detail about your home, get less mail, or stop mail entirely, use saplingsignal.com/fix — one minute, no account. Requests apply to every business that mails through Sapling Signal, are applied before every future mailing, and are keyed to the name printed on the piece so a future owner of the home starts fresh. We honor do-not-mail requests from anyone, in any state.
California residents have the right to: know and access the personal information we hold about you (categories, sources, purposes, and specific pieces, in a portable format); correct inaccurate information; delete personal information, subject to legal exceptions; opt out of sale or sharing of personal information (we do not sell; the only sharing is the client-initiated ad echo in Section 6, which you may opt out of); limit use of sensitive personal information (we do not use sensitive personal information to infer characteristics); and non-discrimination — we will never treat you differently for exercising any right. Residents of other states with comprehensive privacy laws have similar rights where those laws apply, including the right to appeal a refusal by writing to the contact below.
Making a request. Email compliance@saplingsignal.com or use /fix. We verify requests by matching the details you provide against our records (for mail records, the printed name and address are usually sufficient — by design, no account is needed). An authorized agent may submit a request on your behalf with proof of authorization. We respond within 45 days, extendable once by a further 45 days with notice. Because our public pages set no advertising cookies and we do not share data through cookies, a Global Privacy Control signal finds nothing additional to switch off; we treat a verified GPC-accompanied request as an opt-out of the Section 6 ad echo.
10. Retention
Session replays: about 30 days. Call recordings: while the related client account is active, and deleted on request. Leads and bookings: retained for the business you contacted until deleted or the account closes. Campaign mailing lists: client access expires 90 days after the campaign; we retain the underlying records to honor suppression and attribution. Correction and do-not-mail records: retained indefinitely, because remembering the request is what keeps it honored — these records are used for suppression only. Public-record and licensed property data: retained while it remains current for the purposes above. Client account data: for the life of the account plus the period needed for legal, tax, and audit obligations.
11. Security
All data is encrypted in transit; each client’s data is isolated at the database layer (row-level security); internal access follows least privilege; payment card data is handled entirely by Stripe. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security — if we learn of a breach affecting your personal information, we will notify you as required by applicable law.
12. Children
The Services are for businesses and homeowners. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
13. Changes to this policy
We may revise this policy from time to time by posting the updated version at this URL with a new “last updated” date, and the updated version is effective when posted. For material changes affecting how we handle homeowner data, we will post the change before it takes effect; for material changes affecting client accounts, we may also notify the email address on the account, and that notice is effective when sent. Your continued use of the Services after the effective date constitutes acceptance of the revised policy.
14. Contact
Privacy questions and requests: compliance@saplingsignal.com — Sapling Holding Company, 611 Gateway Blvd, Suite 120 #1225, South San Francisco, CA 94080.
California residents may also report complaints to the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 North Market Blvd, Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.