Miftah Digital

Privacy notice

Last updated: 9 October 2026.

Miftah Digital Ltd operates Signaldesk and the Miftah Digital starter software workspaces. Privacy contact: support contact. Business address: 56 Chipstead Avenue, London, CR7 7DG, United Kingdom.

Information used to provide the service

Email verification creates an account identifier linked to your email address. Verification codes expire after ten minutes; only protected code hashes are stored. Session tokens are stored as hashes, expire after fourteen days and are removed on sign-out. Email/IP rate limits help prevent abuse; IP addresses are processed into keyed hashes rather than stored directly. We store the website details, audit reports, review decisions, drafts and aggregate CSV data you choose to add. Billing records contain provider identifiers, subscription and one-off purchase status, payment-verification records and audit usage. Stripe processes payments; Miftah Digital applications do not store full card details.

We use this information to provide your account and subscription, save your work, enforce usage limits, respond to support requests and prevent abuse. Service delivery is based on the contract with you; security and abuse prevention rely on legitimate interests. Legal obligations may require retention of billing records.

Sources and providers

Audits retrieve publicly accessible website content. Search performance and outcome data in this release come from exports you upload. Do not upload customer names, individual contact records, payment-card details or sensitive personal information in CSV files. Cloudflare provides application hosting; IONOS delivers requested verification, purchase-confirmation and report emails; Stripe provides payment and subscription management. Providers may process information internationally under their applicable data-protection arrangements.

Business software workspaces and customer requests

Each purchased product stores its business configuration, enquiries, bookings, quote requests, prospects or opportunities privately for the purchasing account. Records can contain the names, contact details, vehicle or flight details and notes you or your customers submit. Public request pages display the business name, description, contact email and configured services. Public forms store requests in that business’s private workspace and do not automatically send marketing messages. The business using the workspace is responsible for its customer information and must provide any business-specific privacy information required for its services. Contact that business about a service request, and contact software support for account, access, export or deletion assistance. Avoid sensitive information in notes. You can remove stored records and export your workspace.

Optional WordPress automation

When activated and authorised by you, the connector shares up to 20 published, unprotected pages or posts, their URLs, plain content samples and SEO metadata with Signaldesk. WordPress passwords and draft content are excluded. The server stores only a hash of the connection token; the token remains in your WordPress settings. Automation policies, planned changes, delivery receipts and verification history are stored privately for your account. If you separately enable AI article generation, the checked business facts, selected topics and website address you provide are sent to OpenAI to prepare content. Do not include customer personal information or sensitive information in these facts. Pause or disconnect automation from your account; local WordPress rollback remains available independently. Live automation and article generation are disabled during launch verification.

Storage and marketing

Information is stored to support your account and saved work. This launch version does not load a Meta advertising pixel or marketing cookies. Essential, secure cookies keep you signed in and bind verification to the browser where you requested it. These cookies do not track marketing activity. Payment services may use their own necessary session mechanisms. Marketing tracking will require a separate consent-controlled implementation before it is enabled.

Free diagnostics and business outreach

A free diagnostic saves a five-page sample and website findings privately to your verified email account. When you request email delivery, IONOS sends the requested findings and private report link; the delivery record prevents duplicate sending. SMTP acceptance means the mail server accepted the message; it does not confirm inbox delivery. No marketing subscription is created. It does not measure Google rankings or AI recommendations. The owner prospecting workspace records public business websites, discovery sources, published contact details, diagnostic findings and opt-outs to assess relevant business enquiries and prevent repeated contact. Legitimate interests support this limited business research; a public email address does not by itself provide marketing consent. Unsolicited outreach is not sent by this application. Contact us to object, correct a record or request deletion. We retain opt-out identifiers to honour objections.

Your choices and rights

Contact us to request access, correction, export or deletion of your personal information, or to object to relevant processing. We may retain information needed for legal obligations or active disputes and explain this when responding. You can complain to the UK Information Commissioner's Office if you believe your information has been mishandled.