Security & data

How we protect your work.

LaunchSign holds unreleased campaigns, creative assets, and client feedback: material you can't afford to leak. Here is exactly how it is stored, encrypted, and kept isolated, in plain terms. No badges we haven't earned.

Where your data lives

Your data is hosted with established cloud providers in the European Union, with data centres in Ireland. We keep hosting in EU regions so campaign data and personal data stay within the European Economic Area.

LaunchSign is a trade name operated by Albert M. Morales Palleja, a sole trader (empresario individual / autónomo) established in Spain and subject to the GDPR and the Spanish LOPDGDD.

Encryption

All traffic to and from LaunchSign is encrypted in transit with TLS 1.2 or higher. Data at rest, including your uploaded files and database records, is encrypted with AES-256 or equivalent.

Tenant isolation

Every account's data is separated at the database layer using row-level security. Access rules are enforced by the database itself on every query, so one account can never read or write another account's workspaces, campaigns, assets, or comments, regardless of application code paths.

Access & authentication

Sign-in is over email and password (passwords are always hashed, never stored in plain text) or Google sign-in. Sessions use HttpOnly, Secure cookies that JavaScript can't read.

Clients review and approve work through guest links: single-purpose, token-based URLs scoped to one review round. A reviewer never needs an account and never gets access to the rest of your workspace.

Payments

Billing runs through Stripe, a certified PCI Service Provider. Card details are entered directly with Stripe and are never stored on our servers: we only keep a subscription reference and the plan status needed to run your account.

Subprocessors

We rely on a small, carefully chosen set of subprocessors to run the service, each bound by a data processing agreement and appropriate safeguards for any transfer of personal data. The current list, with each provider's role and location, is kept in our DPA and Privacy Policy so it stays accurate as it changes.

Your data rights

You own your data. You can export or delete your campaigns at any time, and deleting your account removes your content from our systems. For GDPR requests, including access, rectification, or erasure, email privacy@launchsign.io.

Our full commitments as a data processor, including subprocessors, security measures, and breach notification, are set out in our Data Processing Agreement, alongside the Privacy Policy.

A note on certifications

We're an independent, early-stage business. We don't yet hold formal certifications like SOC 2 or ISO 27001, and we won't claim badges we haven't earned. What we can show you today is the concrete architecture above, and we're happy to answer specific security questions before you commit.

Reporting a vulnerability

Found a security issue? We want to hear about it. Email hello@launchsign.io with the details and we'll respond quickly. Please give us a reasonable window to fix an issue before disclosing it publicly.

Still have questions?

Ask us anything about how your data is handled.

Contact us →