1. Information we collect
- Account data — name, email, password (hashed), workspace details.
- Document & signing data — documents you create or sign, recipient names/emails, field values, signing time, IP address, browser/user-agent, and audit/completion events.
- Payment data — we store payment status and Stripe references (e.g. account, customer, and charge identifiers). We do not collect or store full card numbers; card details are handled by Stripe.
- Usage & device data — log data, approximate location from IP, and cookies needed to run the Service.
2. How we use information
To provide, secure, and improve the Service; to create signing and completion records; to process and reconcile payments through Stripe; to send transactional email (signature requests, reminders, receipts); to prevent fraud and abuse; and to comply with law.
3. How we share information — subprocessors
We do not sell your personal information. We share it with service providers (“subprocessors”) that help us run the Service, each under their own terms:
- Stripe— payment processing (on the Sender’s connected account).
- Supabase — database and authentication.
- Vercel — application hosting.
- Email provider — transactional email delivery.
We may also disclose information to comply with law, enforce our terms, or protect rights and safety, and in connection with a business transfer. If we add or change subprocessors, we will update this list.
4. Retention
We retain personal information for as long as your account is active and thereafter as needed to provide the Service, maintain signing and payment records, resolve disputes, and meet our legal, tax, and accounting obligations, after which we delete or de-identify it. Signing and completion records associated with an executed agreement may be retained longer as evidence of that transaction.
5. Security
We use reasonable administrative and technical measures to protect information, including private signing links and access controls. No method of transmission or storage is perfectly secure. See our security overview.
6. Your choices and rights
Depending on where you live (for example, under U.S. state laws such as the CCPA, or the GDPR), you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To make a request, contact us at legal@smartsigner.io. We will respond as required by applicable law. Signers should note that signing and completion records may need to be retained as evidence of a transaction.
7. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their information.
8. Changes and contact
We may update this Policy; material changes take effect on the “Last updated” date above. Questions or privacy requests: legal@smartsigner.io.