eSign

Privacy notice

[Effective date — not configured] What this signing service collects, why, who receives it, how long it is kept, and how to exercise your rights.

This notice is not finished. The operator of this deployment has not yet supplied their legal name, business address, privacy contact, or an effective date, and counsel has not necessarily reviewed the text. Set PRIVACY_OPERATOR_NAME, PRIVACY_OPERATOR_ADDRESS, PRIVACY_CONTACT_EMAIL, PRIVACY_CONTACT_PHONE (optional) and PRIVACY_EFFECTIVE_DATE before accepting real signers.

Who this notice is from

This electronic signature service is operated by [Operator legal name — not configured] (“we”), at [Business address — not configured].

An important distinction: when you are asked to sign a document, the organization that sent it to you decides what document you receive and what information it asks for. We handle that information on their behalf, under their instructions. If your request concerns a document you were sent, the sending organization is usually the right place to start — but you can always contact us and we will route it.

What we collect, and why

Collected at or before the moment you use each feature — this is the notice at collection.

InformationWhere it comes fromWhy we collect it
Your name and email addressFrom you, or from the person who sent you a document to signTo address the document to you, deliver the signing link, and name you on the executed record
Mobile phone numberFrom the sender, when they require identity verification by textTo send a one-time passcode before you can open the document
Access codeFrom the sender, entered by youTo confirm the link reached the intended person
Your signature — drawn image or typed name and fontFrom you, during signingIt is the signature applied to the document
Anything you type into the document’s fieldsFrom you, during signingIt becomes part of the agreement you are signing
IP address, browser user agent, timestamps of each stepAutomatically from your device as you view, consent, and signRequired evidence that you agreed to sign electronically and that the signature is attributable to you (ESIGN Act / UETA)
The document itselfFrom the sending organizationIt is the record being signed and stored
Account email, name, password (stored hashed), organization nameFrom you, if you create a sender accountTo operate your account
Payment detailsFrom you, only when a document includes a payment fieldTo take the payment the document requires

We do not collect this information for advertising, and we do not build profiles from it. We use it to deliver, execute, and evidence the agreement you were sent, to verify who is signing, to prevent fraud and abuse of the service, and to meet legal and record-keeping obligations.

Who receives your information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose it to the other parties to your document (a signed agreement is, by design, shared with everyone who signs it and with the organization that sent it), and to the service providers this deployment uses:

  • Email deliveryno third party (this deployment does not hand your email to an outside mail provider). Recipient name and email address, the document title, and the signing link.
  • Document storageno third party (files are stored on the operator’s own systems). Uploaded and signed PDFs, and captured signature images.
  • Trusted timestampsFreeTSA. A cryptographic hash of the signed document — not the document, and no personal information.

We may also disclose information when the law requires it (subpoena, court order, lawful government request), to establish or defend legal claims, or as part of a merger or sale of the business. If a sending organization has connected a webhook or its own systems to this service, executed documents and their audit records are delivered there too.

How long we keep it

  • Signed documents. Kept for as long as the sending organization’s retention policy specifies. Executed documents are additionally held for a minimum of 365 days after the envelope closes, so that a mis-set policy cannot destroy a legally significant record. Documents attached to an open deal are not deleted while that deal is open.
  • The audit trail. The tamper-evident log of the signing ceremony (who did what, when, from which IP) is the evidence that makes an electronic signature enforceable under the ESIGN Act and UETA. It is retained even after a deletion request, and it is never rewritten — rewriting it would destroy the very tamper-evidence it exists to provide. What we do on deletion is remove your identifying details from the operational records (see below).
  • Generated data exports. Deleted 7 days after they are produced.
  • Everything past its window is deleted automatically, and each destruction is itself recorded in the audit log — what was destroyed, when, and under which policy.

Your rights, and how to exercise them

Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to have it deleted, and not to be discriminated against for asking. This service supports all of these.

To make a request, email [Privacy contact email — not configured] with the email address the document was sent to. We will verify that the request comes from you (usually by confirming control of that email address) before acting, and we will respond within the time your state’s law allows.

Two honest limits on deletion. First, as above, the signing audit trail is kept as a legal record. Second, if you still have a document out for signature, we will tell you rather than silently deleting your details mid-ceremony — you can either finish or cancel it, or ask us to cancel it as part of the deletion. An authorized agent may make a request on your behalf with written permission we can verify.

How it is protected

Documents are cryptographically signed and every step of the ceremony is written to a hash-chained log, so any later alteration of a document or its history is detectable. Traffic is encrypted in transit, passwords are stored hashed, and access to an organization’s documents is limited to that organization. No system is perfectly secure, and we do not claim to hold any security certification unless we say so explicitly and by name.

Children

This service is for business use and is not directed to children under 13. We do not knowingly collect their information.

Changes to this notice

If we change how we handle personal information, we will update this page and its effective date. Material changes will be communicated to account holders by email.

Contact

[Operator legal name — not configured]
[Business address — not configured]
[Privacy contact email — not configured]

Verify a signed document · Sign in