Privacy Policy
Effective date: July 24, 2026
This policy explains how the service collects, uses, stores, and protects information. It is a general operational policy and should be reviewed by qualified counsel before public launch.
Information collected
We may collect account and business information, client and vendor records, invoices, estimates, expenses, payments, uploaded logos and documents, support communications, login and audit activity, IP addresses, device/browser information, and technical logs. Electronic-signature workflows also collect recipient names and email addresses, consent and intent records, signature and initials values, completed field values, invitation delivery and viewing events, optional access-code verification outcomes, timestamps, document fingerprints, IP addresses, browser information, and a tamper-evident activity history.
How information is used
Information is used to provide and secure the service, authenticate users, process requested business workflows, generate reports, maintain audit and electronic-signature evidence, prevent fraud and abuse, troubleshoot problems, communicate service notices, comply with law, and improve reliability.
Customer-controlled data
Account owners control the business data they enter and the access granted to secondary users. For electronic-signature activity, the sending customer determines the document, recipients, purposes, authentication options, disclosures, and retention period and is responsible for having a lawful basis to collect and process that information. Recipients should direct transaction, correction, paper-copy, withdrawal, or document-content requests to the sender identified in the signing request.
Service providers and disclosure
Information may be disclosed to infrastructure, hosting, email, payment, analytics, security, support, and professional-service providers acting under appropriate restrictions; to comply with legal process; to protect rights and safety; or in connection with a merger, financing, acquisition, or sale of assets. We do not sell personal information for money.
Retention
Business records, including completed signature packages and their evidence histories, are retained while an account is active and as reasonably needed for legal, accounting, security, backup, and dispute-resolution purposes. Customers must determine and satisfy the retention period applicable to each signed record and maintain independent copies of critical documents. Signed packages or evidence may be preserved after a deletion request when reasonably necessary for legal obligations, fraud prevention, security, disputes, or establishing, exercising, or defending legal claims. Routine access logs may be deleted after 90 days; authentication and security logs after approximately two years; and material change and financial audit records after approximately seven years, subject to configuration and legal requirements.
Security
We use role-based access controls, tenant isolation, password hashing, session expiration, login throttling, CSRF protection, audit logging, encrypted customer-file storage, restricted database privileges, backups, and transport encryption when HTTPS is enabled. No method of storage or transmission is guaranteed to be completely secure.
Cookies and analytics
The service uses essential session and security cookies, including temporary state needed to verify optional electronic-signature access codes. We use a self-hosted Plausible Analytics service to measure aggregate page visits, referral sources, browsers, devices, and feature usage without advertising cookies. Private route tokens, access references, query-string secrets, and individual customer record identifiers are removed or grouped before an analytics pageview is sent.
Rights and choices
Depending on location, individuals may have rights to access, correct, delete, restrict, or export personal information and to appeal or complain to a regulator. Requests may be limited by identity verification, legal obligations, evidentiary retention requirements, and the rights of others.
Children
The service is intended for businesses and is not directed to children under 13 or the minimum applicable age.
International use
Information may be processed in the United States or other locations where service providers operate, subject to applicable safeguards.
Changes and contact
Material changes will be posted with a revised effective date. Account owners should provide a privacy contact address in the service’s public-facing configuration before launch.
Data deletion
Upon account closure, active data may be deleted after a reasonable export period. Encrypted backups may persist until normal backup rotation completes. A deletion request may be limited where a signed record or evidence history must be retained to establish, exercise, or defend legal claims or satisfy another lawful obligation.
Incident response
If we become aware of a security incident affecting personal information, we will investigate and provide notifications as required by applicable law.
Third-party processors
We may use reputable subprocessors for hosting, email delivery, payment processing, analytics, monitoring, and support. These providers may change over time.