Privacy Policy
Last updated August 4, 2026
HighSign Pro is built and run by MacappDevelops LLC. This policy explains what we collect, why, who else touches it, and what you can ask us to do with it. It is written to be read, not to be skimmed past.
The short version. We collect what the product needs to work and nothing else. We do not sell your data. We do not use your business records to train anything or to advertise to you. Your data belongs to you, you can export it whenever you like, and you can ask us to delete it.
Who we are
MacappDevelops LLC ("we", "us") operates HighSign Pro at highsignpro.com. For anything in this policy, write to [email protected] and a person will answer.
Two kinds of information
It matters which is which, because our role is different for each.
1. Your account
Information about you as our customer: your name, email address, password (stored only as a salted scrypt hash — we never see it), business name, chosen plan, and the security settings on your account such as two-factor enrolment and trusted devices. We also keep a record of sign-ins, plan changes and similar account activity.
2. The records you put in
The working data of billboard and out-of-home advertising operators: advertising faces and units, advertisers, campaigns, land leases, invoices and proof-of-posting photos. We hold this on your behalf. It is yours. We access it only to run the service, to fix a fault, or when you ask us to — and each business's records are isolated from every other business on the platform.
If your own records include personal information about other people — your customers, your staff, or anyone else you deal with — you are the one who decides what to collect and why. We process it on your instructions.
Technical information we collect automatically
- Your IP address and browser user-agent, used to keep your session, apply rate limits and spot abuse.
- Server logs of requests, kept short-term for debugging and security.
- A small number of strictly necessary cookies — your session, and the optional 30-day "remember this computer" token that lets you skip a two-factor code. We do not use advertising cookies and we do not run third-party analytics or tracking scripts on the app.
Payments
Subscription payments are handled by Stripe. Card numbers go straight to Stripe and never reach our servers — we store only a customer reference, the plan, and the invoice history we need for billing. Stripe's own privacy notice governs what it does with payment data.
Who else handles your data
We keep this list short on purpose.
| Who | What for |
|---|---|
| Hetzner Online GmbH | Hosting. The servers and the database live in a data centre in Ashburn, Virginia, USA. |
| Cloudflare | DNS, TLS and protection against attacks and abusive traffic. |
| Stripe | Subscription payments. |
| Our email provider | Delivering the messages the product sends — sign-in codes, password resets, notifications and anything you choose to send from the app. |
Where the product reaches an outside service to do its job, that happens too:
- OpenStreetMap (map tiles), used when you open the map view
We do not sell your personal information, and we do not share it with anyone for advertising.
Where your data is
On servers in the United States. If you are outside the US, using HighSign Pro means your information is transferred there and handled under this policy.
How long we keep it
- While your account is open: for as long as you keep it, so the product works.
- Backups: the system takes automatic snapshots every few minutes and keeps roughly the last hour of them, so a mistake can be undone. Deleted data can survive briefly in those snapshots before it rolls off.
- After you close your account: tell us and we will delete your records. We keep only what we are legally required to keep, such as billing and tax records.
How we protect it
- Everything travels over HTTPS.
- Passwords are salted and hashed with scrypt — they are never stored in a readable form.
- Two-factor authentication by email or an authenticator app, plus one-time backup codes.
- Repeated failed sign-ins lock the account temporarily and email you about it.
- Each business's data is isolated from every other business.
- Automatic backups, so a bad day is recoverable.
No system is perfect. If we ever discover a breach affecting your data, we will tell you promptly and plainly.
Your choices and rights
- See it or take it with you. Your records are exportable from inside the app, and we will help if something is awkward to get out.
- Correct it. Almost everything is editable directly; ask us about anything that isn't.
- Delete it. Ask and we will delete your account and its records.
- Say no to marketing. Product and security emails are part of the service, but you can turn off notification emails in Settings, and any marketing email has an unsubscribe link.
Depending on where you live, you may have further rights under laws such as the GDPR or the CCPA — including the right to object to processing or to complain to a regulator. Write to us and we will honour them. We will not charge you or treat you differently for exercising a right.
Children
HighSign Pro is a business tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child's information has reached us, tell us and we will remove it.
Changes to this policy
If we change it in a way that matters, we will update the date at the top and tell account owners by email. Continuing to use HighSign Pro after a change means the updated policy applies.
Contact
Questions, requests, or something in here that doesn't look right: [email protected]. You can also reply directly to any email we send you — a real person reads it.