This Privacy Policy explains how D & F Research, LLC, a Florida limited liability company (the “Company,” “we,” or “us”), handles information across the two services it operates: FiduciarySignal (retirement-plan research, at fiduciarysignal.com) and Benefit Signals (group-insurance renewal prospecting, at benefit-signals.com). We refer to them together as the “Services.” The two are separate products with separate subscriptions, but they are operated by the same company and follow the same data practices, so this one policy covers both. You are reading it on FiduciarySignal.
We do not collect precise location or your device’s address book. The only third-party advertising technology we use is Meta’s, described in sections 3 and 3a: a consent-gated pixel, server measurement events, and hashed-list audience matching — and you can opt out of all advertising data sharing at any time (section 3a).
We do not sell, rent, or trade your account information, and we do not share it with data brokers. The advertising-related exceptions are the Meta measurement sharing and hashed-list audience matching described in sections 3 and 3a — the browser pixel runs only if you accept it, and you can stop all of it at any time. We do not sell the business-contact data described in section 5 as a marketing list.
When you sign in, we set a session cookie. It is HttpOnly, Secure, and uses SameSite=Lax, and it expires after 30 days of inactivity or when you sign out.
First-party analytics. We run our own analytics to understand how
the Services are used. This stores a random, pseudonymous visitor identifier in
your browser’s local storage, mirrored to a first-party fs_vid
cookie that lasts up to about 400 days. Tied to that identifier we record the
pages you view, the referring site, campaign codes and advertising click
identifiers present in the page address (for example utm_ parameters
or a fbclid), and coarse device categories (browser family,
device type). If you create an account, this pre-signup history is linked to your
account so we can understand which channels bring us customers. Raw page-level
events are deleted after about 400 days; aggregate counts are kept. This analytics
data stays with us — it is never sold and never shared with third parties.
You may object at any time via “Your privacy choices” (section 3a);
objection stops future collection on that device and deletes our analytics
identifiers there, but does not erase previously collected records, which follow
the retention above.
Consent preferences. Your advertising choice itself is stored in a
first-party fs_consent cookie (and a local-storage copy) for up to 12
months, and an analytics objection in a fs_an_optout cookie —
these exist so we can remember and honor your choices. Our service worker may also
cache the application shell and public reference content on your device to enable
offline use; this cache contains no personal information.
We advertise the Services on Meta platforms and measure that advertising two ways. They work differently, so we state them plainly:
_fbp, and _fbc after an ad
click), and reports your page view and browser information to Meta. If you do
not accept, the pixel never loads — there is nothing to opt out of in your
browser. We configure the pixel to report page views only, with Meta’s
automatic event collection turned off.
_fbc, which identifies the
ad click, and _fbp, which identifies the browser). Unlike the
email and name, those two are sent as they are rather than hashed, because
Meta issued them and already knows their values. These may be sent unless and
until you opt out; the same declines described below (including Global Privacy
Control) stop them.
Audience matching (Custom Audiences). Separately from measurement, we may target our advertising using contact lists we already hold. Where enabled, we upload to Meta one-way hashed contact details (email address and name, and — where we have them — phone number, city, state, and ZIP code) from lists collected directly by us or by businesses under common ownership with ours, such as our founders’ 401(k) appointment-scheduling service, whose clients and prospective clients may be shown FiduciarySignal ads. Meta uses those hashes only to match accounts so our ads can be shown to the people on a list, to exclude people from our ads (for example, existing customers and recent leads), and to build “lookalike” audiences of people with similar characteristics; the readable values are not shared, and Meta processes the uploaded identifiers under its Customer List Custom Audience terms, which restrict how they may be used and shared. If you are on such a list, email support@fiduciarysignal.com — or use the opt-outs below from a signed-in or otherwise identifiable visit — and we will exclude your record from all future uploads and remove it, using Meta’s removal tools, from the customer-list audiences we control. We can act on a choice only when we can connect it to your contact record; an anonymous browser signal alone cannot be matched to a list entry.
Opting out. Declining the banner, using the “Your Privacy Choices” control on our pages, or browsing with the Global Privacy Control signal (which we honor automatically as an opt-out) stops all of the above — including, where your contact record can be identified, inclusion in future audience-list uploads. An opt-out recorded for your account applies across both FiduciarySignal and Benefit Signals — one choice covers the whole company. Opting out stops future sharing; it cannot retract data already transmitted to Meta, whose handling is described in Meta’s privacy policy.
We do not currently share conversion data with any other advertising platform. If we enable similar sharing with another platform (for example LinkedIn), we will update this policy first.
The plan and business information the Services display is compiled from public records and licensed third-party data, not created by us. Our sources include:
The Department of Labor and the Small Business Administration are publishers of the public data we display, not recipients of your information.
To help our users reach the right person at a business, the Services display business-contact details — names, business email addresses, phone numbers, and job titles of professionals associated with the plans and businesses in our data. This information is licensed from a third-party data provider and concerns people in their business capacity; those individuals did not create an account with us. We license this data to display it inside the Services; we do not sell it as a standalone marketing list.
If you are a business professional and want your contact details suppressed from the Services, email support@fiduciarysignal.com and we will act on your request as required by applicable law. Because this data is re-licensed and periodically refreshed from our provider, we cannot guarantee that a record will never reappear from the provider’s source in a later refresh; tell us and we will address it each time you do.
We retain your account information for as long as your account is active, and we retain billing records for as long as required for tax, accounting, and legal purposes. Password-reset links expire 30 minutes after they are issued and can be used only once. You may request deletion of your account at any time (see section 10).
The Services are business-to-business tools intended for professionals — retirement-plan advisors, plan sponsors, and ERISA professionals on FiduciarySignal, and benefits brokers, insurance agents, and group-insurance agents on Benefit Signals. They are not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us and we will delete it.
California residents (CCPA/CPRA). You have the right to know what personal information we have collected about you, to request that we correct or delete it, and to not be discriminated against for exercising these rights. We do not sell personal information. Where our Meta advertising measurement or audience matching is enabled (section 3a), the disclosures to Meta may constitute “sharing” for cross-context behavioral advertising under California law; you can opt out at any time by declining the cookie banner, using the “Your Privacy Choices” control on our pages, or enabling the Global Privacy Control signal in your browser, which we honor automatically. For hashed-list audience matching, we act on requests we can connect to your contact record, as described in section 3a.
EEA, UK, and Swiss residents (GDPR/UK GDPR). You have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. The lawful bases for processing your information are performance of our contract with you (operating your account and any subscription), your consent where applicable, and our legitimate interest in operating, securing, and improving the Services and in providing business-to-business research about businesses and the professionals associated with them.
Manage your advertising choice and the first-party analytics objection for this browser here:
These controls are per browser and per device. For account-level requests (access, correction, deletion), see section 10 below.
To request access to or deletion of your data, to request removal of business-contact details, or for any privacy question, email support@fiduciarysignal.com. We will respond within 30 days.
We use HTTPS for all traffic, hash and sign sign-in tokens with a server-side secret, and apply standard hardening to session cookies. No system is perfectly secure; if we become aware of a breach affecting your information, we will notify you in accordance with applicable law.
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the “Last updated” date above. Continued use of the Services after a change indicates acceptance of the updated policy.