Legal

Privacy Policy

This policy explains what personal information Nead, LLC, doing business as digitalsign.co, collects, why, and the choices and rights you have. It applies to our website at digitalsign.co, the digitalsign.co application, the screen player, our API, and our sales and support conversations.

Last updated October 1, 2026

1. Who we are

digitalsign.co is a digital signage platform operated by Nead, LLC ("digitalsign.co", "we", "us" or "our"). Businesses use digitalsign.co to pair screens, design and schedule content, and manage what their screens show.

Questions about this policy or your personal information can be sent to [email protected].

2. Our two roles

We handle personal information in two different capacities, and this policy treats them separately:

  • As a controller, for information about the people who visit digitalsign.co, sign up for or use digitalsign.co, contact us, or buy from us. We decide how that information is used, and this policy describes it.
  • As a processor (or service provider), for personal information within the content and data our customers put into digitalsign.co ("Customer Data"), such as media, designs and data from their connections. Our customer decides what is collected and why; we process it only on their instructions, under our Data Processing Addendum at app.digitalsign.co/dpa. If a business's screens show information about you, that business is responsible for it, and their privacy notice applies. We will help them respond to your requests.

3. People who see our customers' screens

digitalsign.co screens do not collect personal data about the people who look at them. The player does not use cameras, microphones or audience measurement, and does not detect, count, recognize or track viewers. Screens report information about the screen and device (described below), not about people nearby.

If a business adds its own cameras or sensors near its screens, that is outside our service and governed by that business's own notices.

4. Information we collect as a controller

Information you give us

  • Account information: your email address, name, the organizations you belong to and your role within them. We receive this when you sign up, sign in or accept an invitation. We do not use passwords: we send single-use sign-in links to your email address.
  • Organization information: your business name, industry, locations, timezone, and the users you invite.
  • Billing information: billing contact, company details and tax information. Payment card details are collected and stored by our payment processor, Stripe; we receive only limited details such as the card brand, last four digits and expiry date.
  • Communications: what you send us by email or through our support and sales channels, such as your name, email, company and message.
  • AI prompts: the instructions and content you give our AI features, such as a request to design a menu board or write a promotion.

Information collected automatically

  • Usage information: pages and features used in the application, and actions taken (for example, publishing content, changing schedules and sending commands to screens, which we keep in an audit log), and API requests made with your keys.
  • Device and connection information: browser type, operating system and approximate location derived from your connection. We use IP addresses for security and rate limiting.
  • Cookies: see Cookies below.

Information from screens and players

When a customer pairs a screen, the player sends us information about the screen and device so the customer can manage it. This is Customer Data, processed on the customer's behalf:

  • Screen telemetry: the device's IP address, player version, browser and operating system information, screen resolution and orientation, storage, memory and connection status, and heartbeat and sync times.
  • Screenshots: an image of what a screen is displaying, taken only when a customer's user requests one. Screenshots show the screen's own content, not its surroundings.
  • Playback logs: which content played on which screen, when and for how long (proof of play).

Information from others

  • Invitations: when a member of an organization invites you, they give us your email address and the role they are assigning you.
  • Data connections: when a customer connects a data source (such as a REST or JSON endpoint, RSS feed, CSV file or webhook), we fetch or receive the data they configure, on their behalf. Credentials they enter for these connections are stored encrypted.

5. How we use information

  • To provide, maintain and secure the service, including signing users in, enforcing roles and permissions, delivering content to screens and carrying out remote commands.
  • To process payments, manage subscriptions, screen counts and usage allowances, and prevent fraud and abuse.
  • To provide support and respond to your requests.
  • To send service messages, such as sign-in links, invitations, screens going offline, approvals awaiting you, security notices and billing notices.
  • To send marketing communications about our products, where permitted. You can opt out at any time.
  • To analyze and improve the service, including aggregated and de-identified statistics about how features perform.
  • To comply with law, enforce our terms, and protect the rights and safety of our users and others.

Legal bases (EEA, UK and Switzerland)

Where the GDPR or a similar law applies, we rely on these legal bases: performance of our contract with you (to provide the service); our legitimate interests (to secure, support, improve and market the service, balanced against your rights); your consent (for certain marketing, which you can withdraw at any time); and legal obligation (for tax, accounting and compliance).

6. Artificial intelligence

digitalsign.co uses AI models from third-party providers to design layouts, write text and generate images. When you use these features, the relevant content (such as your prompt, brand kit, and the design or data the request needs) is sent to the provider to produce the result.

  • We use AI providers under their business and API terms, not consumer terms, and they are listed as sub-processors at app.digitalsign.co/subprocessors.
  • We do not use Customer Data to train AI models, and we do not permit our AI providers to use it to train theirs.
  • AI output can be inaccurate. Review it before you publish it to your screens.

7. Weather and location

Weather widgets and weather-based rules use the coordinates of the location a customer sets up. We look up forecasts from Open-Meteo by those coordinates only; no personal information is sent with the request. We do not track the location of users or viewers.

8. How we share information

We share personal information only as follows:

  • Service providers (sub-processors) that host, secure, bill, email and provide AI for the service, under contracts that limit their use of the data. The current list is at app.digitalsign.co/subprocessors.
  • Services you connect. When you direct us to, we exchange data with data sources, webhooks and other services you connect. Their use of that data is governed by their own terms and privacy policies.
  • On screens. Content you publish is displayed on your screens, where anyone nearby can see it.
  • Within your organization. Other members of your organization can see content, screens and activity in your shared workspace, according to their roles.
  • Legal and safety. When required by law or legal process, or to protect the rights, property or safety of our users, the public or us.
  • Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this policy.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

9. Cookies and similar technologies

In the digitalsign.co application. We use a necessary session cookie (__ds_session) to keep you signed in. It lasts up to 30 days, and you can end it at any time by signing out.

In the screen player. The player stores a device token and its downloaded content in the browser's local storage and cache so it can identify itself to the service and keep playing offline. These are necessary for the player to work and do not identify viewers.

We do not use advertising cookies in the application or the player. Most browsers let you block or delete cookies; blocking necessary cookies stops sign-in and the player from working.

10. How long we keep information

  • Account and workspace data: for as long as your organization's account is active.
  • After an organization is deleted: access ends immediately, and its data is permanently deleted 30 days later.
  • Screen telemetry and screenshots: for as long as the account is active, unless the screen or the data is deleted sooner. We may summarize or delete older telemetry on a rolling basis.
  • Playback logs: for as long as the account is active, unless the customer deletes them sooner.
  • Sign-in links: expire after 15 minutes and work once.
  • Billing records: as long as required for tax and accounting, typically seven years.
  • Audit and security logs: for as long as the account is active, to show who published and changed what.
  • Backups: replaced on a rolling schedule and kept for no more than 12 months.

11. Security

We protect personal information with administrative, technical and physical safeguards, including encryption in transit, encryption of stored connection credentials with AES-256-GCM, hashing of sign-in links, session tokens, device tokens and API keys, role-based access control, isolation between customers, and audit logging. No system is perfectly secure; please report suspected vulnerabilities to [email protected].

12. International transfers

We are based in the United States. Our servers and database are hosted in the European Union (Germany), with content delivered through a global edge network, and some of our service providers (including payment, email and AI providers) process information in the United States. When we transfer personal information from the EEA, the UK or Switzerland to countries without an adequacy decision, we use Standard Contractual Clauses (and the UK Addendum where relevant) or another lawful transfer mechanism.

13. Your rights and choices

Depending on where you live, you may have the right to:

  • access the personal information we hold about you, and receive a copy in a portable format;
  • correct inaccurate information;
  • delete your information;
  • object to or restrict certain processing, including direct marketing;
  • withdraw consent where we rely on it, without affecting earlier processing;
  • not be discriminated against for exercising your rights.

To exercise these rights, email [email protected]. We will verify your request and respond within the time the law requires (generally within 30 days, or 45 days under US state laws). An authorized agent may make a request for you with your written permission. If you are in the EEA, the UK or Switzerland, you can also complain to your local data protection authority.

California and other US states. In the last 12 months we have collected the categories of information described above (identifiers, commercial information, internet or device activity, approximate geolocation and professional information) for the business purposes described in this policy. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics.

14. Children

digitalsign.co is a business service. It is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact [email protected] and we will delete it.

15. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new effective date and, for material changes, notify account owners by email or in the application before the change takes effect.

16. Contact us

Nead, LLC (digitalsign.co). Privacy questions and requests: [email protected]. Security reports: [email protected]. Everything else: [email protected].