Terms of Service

Effective Date: August 2025

IMPORTANT: These Terms of Service ("Terms") govern your access to and use of Spa Signals' services. By accessing or using the Services, you agree to be bound by these terms.

1. Definitions

  • Client, you: The spa resort, wellness center, medical spa, or agency using the Services.
  • Services: Spa Signals' premium audience targeting, lead generation, exclusivity enforcement, analytics, and related software, including the SignalsID™ Pixel.
  • SignalsID™ Pixel: Spa Signals' identity and event tracking script (and associated APIs/SDKs) that performs authenticated, deterministic user resolution and event capture.
  • Audience Sync Data: Platform-ready hashed audiences (e.g., SHA-256) and platform IDs for activation and retargeting.
  • Qualified Lead: Consented, contactable prospect record (PII) captured via Client landing pages, forms, quizzes, tracked calls, or SMS opt-ins.
  • Engagement Lock / Lead Lock: Time-boxed exclusivity periods applied at the individual ID level as defined in Schedule E.
  • Claims Ledger: Spa Signals' system of record that records claimed IDs and enforces global suppression.
  • Global Suppression: Exclusion of claimed IDs from exports and campaigns for all other clients during an active lock.

2. Service Overview

Spa Signals provides:

  • Intent-based audience building and segmentation
  • Audience Sync Data (hashed uploads and/or platform audiences)
  • Qualified Leads with verified consent
  • Daily refresh, claims & suppression management, and analytics
  • ID-level exclusivity via Engagement and Lead Locks (Schedule E)
  • Optional event feeds, CRM/CAPI integrations, dashboards, and APIs

3. Account & Eligibility

Client must: (i) be a legitimate business; (ii) provide accurate registration information; (iii) maintain credential confidentiality; (iv) be authorized to bind the organization; and (v) promptly notify Spa Signals of unauthorized access. Spa Signals may refuse or suspend access for fraud, risk, or Terms violations.

4. Implementation & SignalsID™ Pixel

4.1 License

Spa Signals grants a limited, non-exclusive, non-transferable license to implement and use the SignalsID™ Pixel solely to enable the Services.

4.2 Identity Resolution

SignalsID™ performs a deterministic chain: Cookie/MAID → HEM (SHA-256 email, authentication-only) → UID → Profile. No IP→HEM inference is used.

4.3 Events

Supported events include (without limitation): page_view, dwell thresholds, exit_intent, video_engagement, file_downloads, form_submissions, quiz_start/complete. High-volume events (e.g., all_clicks) should be enabled only as needed.

4.4 Client Duties

Client will (i) deploy the Pixel on authorized domains; (ii) pass normalized email at authentication where applicable; (iii) avoid artificially generating traffic or events; (iv) comply with platform policies and laws.

4.5 Data Flow

Engagement and lead events that meet lock criteria are written to the Claims Ledger and trigger Global Suppression (details in Schedule E).

4.6 Integrations

Supported integrations may include GA4, Clarity, Meta CAPI, Google Enhanced Conversions, webhooks, and server-to-server endpoints as documented.

5. Data Rights, Privacy & Compliance

5.1 Ownership

Client retains rights to its first-party content, creatives, and Qualified Leads collected on Client properties. Spa Signals retains rights to its models, methodologies, software, identity graph, derived datasets, and aggregated/anonymous insights.

5.2 Use Limits

Client may use Audience Sync Data and Qualified Leads solely to market Client's services and may not resell, sublicense, redistribute, or combine with purchased lists.

5.3 PII & Consent

Qualified Leads require valid consent. Client is responsible for honoring opt-outs and deletion requests in Client systems.

5.4 Compliance

Each party will comply with applicable laws (e.g., GDPR, CCPA/CPRA, CAN-SPAM, TCPA) and platform rules. A Data Processing Addendum is available upon request and, if executed, forms part of these Terms.

5.5 Security

Spa Signals uses commercially reasonable administrative, technical, and organizational measures (see Schedule S – Security Summary).

5.6 Verification

For exclusivity verification, Spa Signals may provide hashed lists, suppression proofs, and reports as set out in Schedule E.

6. Acceptable Use

Client will not: (i) use the Services for non-spa offerings; (ii) reverse-engineer identifiers; (iii) artificially inflate events to trigger locks; (iv) misuse platform IDs; (v) share or resell supplied data; (vi) violate platform terms; or (vii) circumvent security controls. Spa Signals may suspend access for suspected abuse.

7. Service Plans & Billing

7.1 Plans

Services are offered in plans that describe included features, usage limits, retention windows, and lock durations (e.g., Growth, Elite, Dominance). Plan specifics appear on the Order Form or Client dashboard.

7.2 Subscription; Overage

Services renew monthly (or as stated on the Order Form). Usage beyond included limits is billed as overage.

7.3 Invoicing; Taxes; Late Payment

Invoices are due as stated. Client is responsible for applicable taxes. Spa Signals may suspend or limit Services for delinquency.

7.4 Changes

Plan features and limits may be updated on notice; Client may change plans by mutual agreement or via dashboard where available.

8. Service Levels & Support

Spa Signals targets commercially reasonable SLAs, including platform uptime, daily refresh windows, lead delivery timelines, support response targets, and monthly exclusivity reporting. Service credits (if any) are the sole remedy for SLA shortfalls and are detailed in the documentation or Order Form.

9. Third-Party Platforms

Activation requires third-party platforms (e.g., Meta, Google). Spa Signals is not responsible for platform outages, policy changes, or enforcement actions. Client remains responsible for its accounts and compliance with platform rules.

10. Intellectual Property

The Services, software, models, identity graph, documentation, and trademarks (including Spa Signals and SignalsID™) are owned by Spa Signals or its licensors. Except for the limited licenses expressly granted, no rights are transferred.

11. Confidentiality & Publicity

Each party will protect the other's Confidential Information and use it only to perform under these Terms. With Client consent, Spa Signals may reference Client name and marks for marketing; consent may be withdrawn on reasonable notice.

12. Warranties; Disclaimers

Spa Signals will provide the Services in a professional manner consistent with industry standards.EXCEPT AS EXPRESSLY STATED, THE SERVICES ARE PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY.

13. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW: (a) NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, COVER, OR PUNITIVE DAMAGES; and (b) A PARTY'S AGGREGATE LIABILITY UNDER THESE TERMS SHALL NOT EXCEED THE FEES PAID BY CLIENT FOR THE THREE (3) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THESE LIMITS DO NOT APPLY TO CLIENT'S PAYMENT OBLIGATIONS OR VIOLATIONS OF SECTION 6 (ACCEPTABLE USE).

14. Term; Termination; Effect

Either party may terminate for convenience with 30 days' written notice, or immediately for material breach (after cure period where applicable). Upon termination: (i) access to Services ceases; (ii) active locks continue until natural expiration; (iii) Client may continue to use previously downloaded Qualified Leads per consent and law; (iv) Spa Signals will provide available exports of Client's Qualified Leads and hashed locked IDs; and (v) Spa Signals will delete Client data according to retention schedules and law.

15. Dispute Resolution; Governing Law

Disputes will be resolved by binding arbitration under the rules of the American Arbitration Association. Class action waiver: claims must be brought individually. Either party may seek injunctive relief in court for misuse of IP or Confidential Information. These Terms are governed by the laws of Florida, excluding its conflicts rules.

16. Changes to Terms

Spa Signals may update these Terms from time to time. Material changes will be communicated with reasonable notice. Continued use after the effective date constitutes acceptance. If Client objects to material changes, Client may terminate before the changes take effect.

17. General

These Terms (including Schedules and any Order Form/DPA) are the entire agreement; severability applies; neither party's failure to enforce is a waiver; neither party may assign without consent (except to an affiliate or in connection with a reorganization/transfer of business); Spa Signals may use subcontractors; force majeure excused; notices will be sent to the registered addresses.

Schedule E — Exclusivity Policy (Binding)

E1. Principle: People, Not Territories

Exclusivity applies at the individual ID level, not to geographic areas. Spa Signals enforces exclusivity by recording claims in the Claims Ledger and applying Global Suppression across all other clients' exports and campaigns during the lock period.

E2. Lock Types & Triggers

Engagement Lock (30 days, default):

Triggered by the first qualifying engagement attributable to Client (any one): dwell ≥15s on Client landing page, quiz start, booking widget open, brochure/menu download, or video engagement ≥15s.

Lead Lock (90–180 days):

Triggered by first valid consented lead event (any one): form submission, quiz completion with email, tracked call match, SMS opt-in.

Booking Extension:

If Client confirms a booking, lock extends to service date + 30 days (or longer where stated in the Client's Plan/Order Form).

Notes: (i) Locks are time-boxed; (ii) if two engagements occur, the earliest qualifying timestamp wins; (iii) locks are applied per person (hashed ID) and relevant context as determined by Spa Signals' systems.

E3. Enforcement & Suppression

Upon trigger, Spa Signals records the claim in the Claims Ledger and updates Global Suppression at least daily (hourly for higher tiers). Suppression prevents claimed IDs from being delivered, exported, or activated for other clients during the lock.

E4. Verification & Reporting

Client receives: (i) a monthly exclusivity report (new locks, active locks, expirations, suppression counts, conversion funnel); (ii) dashboard indicators; and (iii) on reasonable request, hashed lists and suppression proofs for sampling or audit.

E5. Disputes

If Client believes a lock was misapplied, Client must submit a dispute within 7 days of notice or report. Spa Signals will review within 48 hours; disputed IDs may be temporarily frozen. First qualifying timestamp controls absent contrary evidence.

E6. Fair Use & Activity

To maintain exclusivity privileges, Client agrees to: (i) maintain active campaigns a majority of the month; (ii) avoid artificial/bot traffic; and (iii) respond to leads within commercially reasonable SLAs. Spa Signals may suspend locks for abuse or prolonged inactivity.

Schedule P-1 — SignalsID™ Pixel License & Data Processing (Binding)

P-1.1 Scope & Methodology

SignalsID™ collects authenticated events and performs deterministic identity resolution (Cookie/MAID → HEM (auth-only) → UID → Profile). No IP→HEM inference is used. Bot/proxy/TOR filtering and known cloud list filtering are applied.

P-1.2 Data Categories

  • Event Metadata: timestamps, page URL/title, referrer, dwell, scroll, video interactions, file downloads, form submissions, quiz interactions, booking widget events.
  • Identity Elements: HEM (SHA-256 of normalized email captured at authentication), UID, Profile (hashed); device and session traits.
  • PII: Only when a user submits PII to Client (e.g., form, quiz, call, SMS).
  • Enrichment: Where applicable, lawful and deterministic enrichments tied to authenticated profiles.

P-1.3 Client Responsibilities

Deploy the Pixel on authorized domains; configure event toggles thoughtfully (avoid unnecessary high-volume capture); pass authentication email for hashing when available; honor user consent signals, opt-outs, and deletion requests within Client systems.

P-1.4 Retention & Access

Event and ID data are retained per Client plan and Order Form (e.g., nominally 90/180/12 months). Exports/feeds and APIs are provided as specified in documentation. Client may request deletion of Client-specific data as permitted by law and technical feasibility.

P-1.5 Security & Compliance

Spa Signals maintains commercially reasonable security measures and complies with applicable privacy laws. A DPA is available upon request. The Claims Ledger stores hashed identifiers only.

P-1.6 Exclusivity Hooks

Qualifying SignalsID™ events write to the Claims Ledger and trigger Engagement or Lead Locks per Schedule E. Global Suppression is executed at least daily (hourly for higher tiers).

Schedule S — Security Summary (Informational)

  • Logical separation of Client data; least-privilege access
  • Encryption in transit and at rest; hashed identifiers
  • Audit logging; anomaly/bot detection; known cloud and TOR filtering
  • Regular backups and disaster recovery controls
  • Vendor risk assessment for sub-processors
  • Incident response with commercially reasonable notification timelines

For questions about these Terms of Service, please contact us at legal@spasignals.com

Schedule Demo