Privacy Policy
Last updated: July 22, 2026
This Privacy Policy explains how Red Gecko LLC (“Red Gecko,” “Gecko Signage,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use the Gecko Signage digital signage platform at geckosignage.com (the “Service”). It also describes how we handle data we access from your Google and Microsoft accounts when you choose to connect them.
1. Information we collect
We collect the following categories of information to operate the Service:
Account information
When you sign up or log in, including through Google Sign-In or Microsoft Sign-In, we receive your name, email address, profile picture (if available), and a unique account identifier from the provider. We use this to create and secure your account and to identify you within your organization.
Organization and content data
When you use the Service, you create and upload content such as organizations, team members, playlists, schedules, media files (images and videos), device names, and widget configurations. This content is stored so we can deliver it to the digital signage devices you manage.
Connected third-party data
If you connect an integration (for example, the Google Calendar widget), we access data from that third-party account so we can display it on your signage screens. See Google user data & API Services for the specifics.
Device and usage data
We collect technical information generated by your use of the Service, including log data, IP address, browser and device type, and the status and activity of the signage devices enrolled in your organization. This helps us operate, secure, and troubleshoot the Service.
2. Google user data & Google API Services
Gecko Signage integrates with Google APIs so you can display Google Calendar events on your signage screens and so you can sign in with your Google Account. We only access Google user data with your explicit authorization through Google’s OAuth consent screen, and only for the purposes described below.
Scopes we request and why
| Google data / scope | Why we access it |
|---|---|
| Basic profile and email (Google Sign-In: name, email address, profile picture, account ID) | To authenticate you and create or access your Gecko Signage account. |
calendar.readonly and calendar.events.readonly | Read-only access to your list of calendars and the events on a calendar you select, so the Google Calendar widget can display upcoming events (title, date and time, and optionally location and description) on your signage screens. We never create, edit, or delete calendars or events. |
How Google user data is used
Calendar data is used solely to render the calendar widget you configured on the signage devices in your organization. We do not use Google user data for advertising, we do not sell it, and we do not use it to build user profiles or for any purpose unrelated to the feature you enabled. We do not use Google user data to train generalized artificial intelligence or machine learning models.
How Google user data is stored
To keep your calendar widget refreshed without asking you to re-authorize every time, we securely store the OAuth access and refresh tokens Google issues, along with your calendar selection, in our Google Cloud Firestore database (encrypted at rest). Calendar event data is fetched on demand to render the widget and is not retained beyond what is needed to display it.
Limited Use disclosure. Gecko Signage’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Microsoft account data
If you sign in with Microsoft, we request the User.Read permission to obtain your basic profile (name and email address) for the sole purpose of authenticating you and creating or accessing your Gecko Signage account. We do not access your Microsoft mail, files, or other data.
4. How we use information
We use the information we collect to:
- Provide, maintain, and secure the Service and your account;
- Deliver the content and widgets you configure to your signage devices;
- Display data from integrations you connect (such as Google Calendar events);
- Authenticate you and enforce organization roles and permissions;
- Communicate with you about your account, billing, security, and support requests;
- Monitor, troubleshoot, and improve the reliability and performance of the Service; and
- Comply with legal obligations and enforce our terms.
5. Protected Health Information (PHI)
Gecko Signage is not designed or configured by default to receive, store, or process Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act (“HIPAA”). Users should not upload or transmit PHI to the Service unless Red Gecko has entered into a Business Associate Agreement (“BAA”) with the applicable organization. See our Terms of Use for additional detail on PHI and BAA requirements.
6. How we store & protect information
The Service runs on established cloud infrastructure. Account and content metadata is stored in Google Cloud Firestore; media files are stored in Amazon Web Services (AWS) S3. Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. OAuth tokens for connected integrations are stored server-side and are never exposed to the signage devices or other organizations.
Access to data is restricted through Firebase Authentication, organization-level access rules, and server-side authorization checks so that members can only access data belonging to their own organization. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard safeguards.
8. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. When you disconnect an integration, we delete the associated OAuth tokens. When you delete content, an integration, or your account, we delete the associated data from our active systems, except where we are required to retain it for legal, accounting, or legitimate business purposes. Backups are purged on a rolling schedule.
9. Your rights & choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise many of these directly in the dashboard, or by contacting us at support@geckosignage.com. We will respond consistent with applicable law.
10. Revoking access & deleting data
You can stop our access to your connected data at any time:
- Disconnect an integration in Gecko Signage. Editing or removing a widget integration deletes the stored OAuth tokens for that connection.
- Revoke access from your Google Account. Visit myaccount.google.com/permissions and remove Gecko Signage to revoke all Google API access.
- Delete your account. Contact us at support@geckosignage.com to request deletion of your account and associated personal data.
11. Children’s privacy
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us so we can delete it.
12. International users
We operate in the United States, and your information may be processed and stored in the United States and other countries where our service providers operate. By using the Service, you understand that your information may be transferred to and processed in jurisdictions that may have different data protection laws than those in your country.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at support@geckosignage.com.
Red Gecko LLC
Columbus, Ohio, United States