Legal
Privacy Policy
Last updated 1 September 2026
This describes what the product does, not what a template says. The short version: your CRM data is read in your browser and is not uploaded, and the only customer data we keep on a server is what an advertising platform needs to match a conversion - hashed identifiers, a timestamp and an amount.
Who we are
ValueBasedBidding is operated by BetterSignals. For questions or requests about your data, write to alon@bettersignals.co.
Where our customer is a business using the product on its own data, that business is the controller of the personal data in its CRM and we are its processor. For our own website and marketing contacts, we are the controller.
What we store on our servers
This is the complete list. There is nothing else.
| What | Why |
|---|---|
| Hashed email addresses (SHA-256) and ad click IDs | The only way an advertising platform can match a conversion to the click that produced it. The hash is one-way; we cannot read the address back out of it. |
| A conversion timestamp, a value and a currency | What is sent to the ad platform, and nothing more. |
| A model identifier, and the rules a saved model contains | So any figure can be traced back to the rule that produced it. The rules are segment-level statistics - a close rate, an average deal size - never an individual record. |
| Encrypted access tokens for a CRM or ad account you connect | Encrypted at rest. Needed to read your leads on a schedule and to send values on your behalf. |
| Workspace and run records - a workspace name, when a sync ran, how many rows it handled, and hashed IP addresses for rate limiting | Operating the service and stopping abuse. |
What we never store
We do not keep CRM records. Specifically, we never write to our servers:
- Names, postal addresses or phone numbers
- Email addresses in readable form, anywhere in the conversion feed
- Individual deal amounts, company names or job titles
- Notes, free text or anything a salesperson typed
This is enforced by the database rather than by policy. The conversion table carries constraints that reject a row whose email field is not a 64-character hash, so a plaintext address cannot be written even by mistake.
One exception, stated plainly: if you give us your email address on our website - to receive a report or to be contacted - we store that address in readable form, because an address we cannot read is an address we cannot write to. That is a marketing contact, kept separate from any customer’s CRM data, and you can ask us to delete it at any time.
Where your CRM data is actually processed
A file you upload never leaves your browser. It is read, mapped and analysed on your own machine. The model is fitted there. Only the finished conversion rows - hashed identifier, time, value, currency - are sent to our server, and only when you choose to publish them.
A connected CRM is read through our server but not written down. When you connect HubSpot, deals pass through our service to your browser, which does the analysis. Those records are held in memory for the length of the request and are not saved.
The one AI call, and what it is not allowed to see
When you describe your business at the start, we make a single call to Anthropic’s Claude API. Its only job is to suggest which column in your file is which, and to note the claims you made about your buyers so the product can test them against your data.
It never receives your rows. It is sent a description of each column: the header name, what kind of value it holds, how often it is filled in, how many distinct values there are, and - only for short category columns like an industry list - a few example labels. It is never sent an email address, a name, a phone number, an address, a click ID, a deal amount, or free text.
It never produces a number. Every value, multiplier and rate in the product comes from arithmetic on your own rows. If the AI call fails, the product carries on without it.
Who else touches the data
We use these providers, and no others, to run the service:
- Vercel - hosting.
- Supabase - the database described above.
- Anthropic - the single column-mapping call, on the column descriptions above and nothing else.
- Google and HubSpot - when you connect them, to send values and read deals respectively, under the permissions you grant.
- Google Analytics - on this marketing website only, to see which pages get visited. Described on its own below.
We do not sell data, and we do not share it for advertising of our own.
Analytics on this website
This site, the pages that explain the product before you sign up, uses Google Analytics to see which pages get visited and how. It sets a cookie in your browser and reports page views and clicks to Google.
It has no route to your CRM data. A file you upload is read and priced in your browser and is never sent anywhere, which is a promise the product keeps regardless of whether this cookie exists - Analytics could not see that file even if it tried. It sees which pages you visited, not what you typed into them.
You can opt out with a browser extension such as Google’s own Analytics opt-out add-on, or by blocking cookies from google-analytics.com and googletagmanager.com.
What we send to Google, and why it is hashed
When you publish, we send Google a conversion for each lead: the click ID if there is one, the hashed email if there is one, the time, the value and the currency. Both identifiers travel together where a lead has both, because Google matches on the click ID and falls back to the email.
The email is hashed before it leaves your browser, in the format Google requires. Google matches the hash against its own hashed records. Neither we nor anyone reading our database can reverse it.
How long we keep it
- Conversion rows: kept while your feed is active, so a platform can collect them and so a republish does not send the same conversion twice. Deleted when you delete the feed, and on request.
- Access tokens: deleted when you disconnect the account.
- Run records: kept for operational history.
- Marketing contacts: until you ask us to remove yours.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to alon@bettersignals.co and we will respond within 30 days.
If you are an individual whose details sat in a customer’s CRM, that customer controls the data and is the right first point of contact. Tell us anyway and we will help them act on it.
Depending on where you live you may also have the right to complain to a data protection authority.
Security
Traffic is encrypted in transit. Access tokens are encrypted at rest. Feed URLs are authorised by a token we store only as a hash, so a copy of our database does not hand anyone a working feed.
No system is perfect. If we discover a breach affecting your data we will tell you promptly and say what happened.
Changes
If we change how the product handles data, this page changes with it and the date at the top moves. Material changes will be told to active customers directly rather than left here to be noticed.
Questions about anything on this page: alon@bettersignals.co