Privacy Policy
Version 2026-10-07 · preliminary
This Policy explains what personal data Signum Rise handles, why, with whom it is shared, how long it is kept and what rights you have. It applies to the signumrise.com website, the Platform and its public pages (portal, quote links, “Your shipment” and proposals).
1. Who is responsible and in what capacity
White Heart Elite LLC d/b/a Cargo Structure (White Heart Elite LLC, doing business under the registered trade name Cargo Structure; Florida, United States) operates the website and provides Signum Rise, its product. Privacy contact: support@signumrise.com · +1 305-746-4371.
We are the controller of website data, commercial inquiries, subscription billing and User accounts. For Customer Data (the information each subscribing company uploads about its customers, contacts, staff, candidates and shipments), we act as a service provider or processor on the Customer’s behalf: we handle it only to provide the Platform and as instructed by the Customer. If you are a customer, contact or employee of a company that uses Signum Rise, please direct your requests to that company first; we will help route them.
2. Data we collect and why
The table below describes, item by item, what we collect and why. We do not collect biometric data: fingerprint or Face ID unlock happens on your device and never reaches us. We do not sell personal data or share it for cross-context behavioral advertising. We do not use advertising pixels (such as Meta’s), session recording, or tools that log what you type.
| Area | Data | Purpose |
|---|---|---|
| Website | “Request a demo” form: name, company, email, phone, message | Answer the request and schedule the demo (received by Netlify Forms and delivered by email) |
| Website | “Build your plan” form: name, company, email, phone, country, type of operation, plan, modules, users, message | Prepare and send the commercial proposal; keep the contact as a lead |
| Website | Google Analytics 4 (only if you accept cookies): cookie identifier, pages viewed, traffic source, device and browser type, approximate location derived from IP | Measure how many people visit the site and which sections they view. Not used inside the Platform or for advertising |
| Website | Your cookie choice (browser local storage) | Not ask you again |
| Website and Platform | Technical data: IP address, browser, date and time, requested page, security events (Netlify, Cloudflare and Supabase) | Deliver the site, protect the service, limit abuse (per-IP rate limiting) and diagnose failures |
| Website and Platform | Google Fonts typeface (your browser sends its IP to Google when downloading it) | Display text in the brand typeface |
| Proposal and payment | Acceptance of the Subscription Agreement: name, email, company, version accepted, date and time, IP and browser | Record of electronic acceptance (E-SIGN Act and Chapter 668, Florida Statutes) |
| Proposal and payment | Subscription billing: legal name, billing address, tax ID and payment method (collected and stored by Stripe); Signum Rise keeps only each invoice’s number, amount, status and link | Charge the subscription, issue invoices and track billing status. Signum Rise never sees or stores card numbers |
| User account | Name, email, phone (optional), role, permissions, department, site and assigned user guide | Create the account, control who sees and does what, and show the role’s user guide |
| User account | Password (stored by Supabase Auth as a bcrypt hash; nobody can see it) and two-step verification factor (TOTP secret in Supabase Auth) | Secure authentication |
| User account | Sessions (identifier, IP, browser, dates) and failed sign-in attempts (email, IP, browser) | One session per user, server-side sign-out, detection of suspicious access and security alerts |
| User account | Electronic signature (image of the drawn or typed name) with date, time and hash of the signed document | Confirm reading and approval of manuals and documents; evidence for the Customer’s employment records |
| User account | Preferences (language, theme, screen size) and browser-notification subscription (device push endpoint and public keys) | Personalize the Platform and send notifications to the phone or computer if the User turns them on |
| User account | Activity log (who made which change and when) | Security, audit and support; the Customer’s administrator can review it |
| Customer Data | The Customer’s customers and business contacts (name, title, email, phone, business address, business tax ID), opportunities, activities and tasks | Provide the CRM, Pipeline and reports, on the Customer’s behalf |
| Customer Data | Quotes, rates, costs and margins, issued invoices and imported billing (including the assigned salesperson), goals and forecasts | Quote, invoice, track goals and issue sales alerts, on the Customer’s behalf |
| Customer Data | Shipment files and shipping documents (commercial invoice, B/L or AWB, packing list, booking and others) that may include shipper and consignee names and addresses | Store and share shipment documents with the End Customer via link, on the Customer’s behalf |
| Customer Data | Human Resources: staff (name, position, department, site, dates, fit evaluations, onboarding) and candidates (CV, contact details, job opening and indicative CV-reader score). By default no salaries, Social Security numbers or medical data are stored | Position management, recruiting and onboarding, on the Customer’s behalf; the hiring decision always rests with a person |
| Customer Data | Manuals, procedures, read confirmations, quizzes, incidents, risks and internal audits | Document and quality control, on the Customer’s behalf |
| End Customers | Portal responses, quote acceptances, documents uploaded via link and the IP and date of those actions | Allow the End Customer to respond, accept and send documents to the Customer, with a record |
| Emails | Recipient, subject, delivery status and unsubscribe requests for emails sent by the Platform (via Resend) | Send invitations, notices, proposals and reminders, and honor opt-outs |
| Support | Support cases and messages, and a log of every Cargo Structure support access to the account | Handle requests and keep access traceability |
| Artificial intelligence | API key of the AI provider the Customer connects (encrypted in Supabase Vault) and usage log (feature, date, tokens) | Run the Customer’s optional AI features and enforce usage caps |
| Artificial intelligence | Content sent on each use to the AI provider chosen by the Customer (goods description and public tariff text, or images and text of supplier quotes or rate sheets); files the Customer sends for onboarding (Cargo Structure assistant with Anthropic) | Propose charges, rates or tariff codes for human review; prepare the requested setup |
3. How we use data
We use data to: provide, maintain and protect the Platform; authenticate Users; provide support; charge the subscription; send transactional communications; send commercial communications to people who asked us for information (with an unsubscribe link in every email); prevent fraud and abuse; comply with legal obligations; and, in aggregate form without identifying individuals, measure usage to improve the product. We do not use Customer Data to train artificial-intelligence models.
4. Who we share data with
With providers that process data on our behalf (sub-processors), mainly in the United States: Supabase (database, authentication and files; U.S. East region), Netlify (site hosting and demo form), Cloudflare (domain, security and, if enabled, Turnstile CAPTCHA), Stripe (payments and invoices), Resend (email delivery), Google Workspace (corporate email), Google Analytics (public site only, with consent) and Anthropic (Cargo Structure onboarding assistant). When the Customer connects its own AI account, the chosen provider (Anthropic, OpenAI or Google) receives the content of each use on the Customer’s behalf under the Customer’s contract with that provider.
We may also share data with professional advisers bound by confidentiality, in response to a valid legal order or requirement, to protect rights and safety, or in a reorganization, merger or sale of the business, with prior notice where appropriate.
5. International transfers
Signum Rise operates from the United States. If you use the Platform from another country (for example, Venezuela or another Latin American country), your data is transferred to and processed in the United States, with the contractual and technical safeguards described in this Policy [ATTORNEY: validate transfer requirements for Colombia (Law 1581), Mexico (LFPDPPP), Brazil (LGPD) or other countries with customers, and for the EU if applicable].
6. How long we keep data
Account and Customer Data: while the subscription is active; after cancellation, the Customer may request an export within 30 days and we keep a backup for up to 12 months to allow reactivation, unless deletion is requested earlier (per the Subscription Agreement). Website inquiries and leads: [24 months] from last contact. Billing: as long as tax laws require [ATTORNEY/ACCOUNTANT: confirm, e.g. 7 years]. Security events: up to 400 days. Stripe payment events: 90 days. Rate-limit counters: 1 day. Provider technical logs: per their retention periods. Records of Agreement acceptance: for the relationship and [5 years] thereafter.
7. Security
We apply reasonable measures: per-company data isolation with database access rules (Row Level Security), encryption in transit (HTTPS with HSTS), hashed passwords, two-step verification, one session per user with server-side sign-out, rate limits, real-file-type validation and macro rejection, encrypted provider keys, security headers (CSP), activity logging, monitoring with alerts and provider backups. No system is invulnerable; if an incident affects your data, we will notify you as required by law, including the Florida Information Protection Act (Section 501.171, Florida Statutes) [ATTORNEY: validate deadlines and recipients].
8. Your rights
Depending on where you live and applicable law, you may request access, correction, deletion, portability or restriction of your data, object to certain uses, withdraw consent (for example, for cookies) and appeal our response. Email support@signumrise.com with the subject “Privacy”. We will verify your identity and respond within the legal deadline. If your data is in a subscribing company’s account (Customer Data), we will route the request to that company. We will not discriminate against you for exercising your rights [ATTORNEY: validate whether any U.S. state privacy law applies based on revenue or data-volume thresholds].
9. Minors
Signum Rise is a business service and is not directed to people under 18. Using it requires acting on behalf of a business. We do not knowingly collect data from minors and ask Customers not to upload it. If we learn a minor’s data was uploaded without authorization, we will delete it.
10. Automated decisions and artificial intelligence
Signum Rise does not make decisions with legal or similarly significant effects on people solely by automated means. AI features are optional, enabled by the Customer with its own account, and always go through human review (see Section 7 of the Terms of Service). The CV reader assigns an indicative score using explainable rules and no AI; the hiring decision is always made by a person at the Customer.
11. Commercial communications
If you asked us for information or a proposal, we may send you related commercial emails. Each commercial email includes an unsubscribe link and the sender’s postal address; we honor opt-outs within 10 business days. Transactional emails (security, account, billing, support) are sent while you use the service.
12. Cookies
The public site uses Google Analytics only if you accept in the cookie notice. The Platform uses browser local or session storage only to function (session, language, appearance, drafts) and not for advertising. If Cloudflare Turnstile CAPTCHA is enabled, Cloudflare may process technical browser data to tell people from bots. Details in the Cookie Policy in the legal center.
13. Changes and contact
We will post changes to this Policy here with their date and notify material changes by email or within the Platform. Contact: support@signumrise.com · +1 305-746-4371 · White Heart Elite LLC d/b/a Cargo Structure.