What Data We Collect
We collect information that you provide directly to us, information generated through your use of the Service, and, in limited cases, information from third-party providers.
Account information:
- Registration data: When you create an account, we collect your full name, email address, and company name. You may also add a profile photo and phone number.
- Billing data: If you subscribe to a paid plan, we collect billing information including your billing address and tax identifiers. Payment card details are collected and processed by our payment processor and are not stored by FileSign.
- Team data: If you invite team members, we collect their names and email addresses. You are responsible for ensuring that your team members are aware of how their data is handled.
Document and usage data:
- Documents: We store the documents you upload, including their content, metadata (file name, size, upload date), and any signature fields you place.
- Signature data: We capture signature events, including timestamps, IP addresses, and signer email addresses, to generate audit trails.
- Signer information: When you send a document for signature, we collect the recipient’s email address and may collect their name and IP address when they view or sign the document.
Technical data:
- Log data: We automatically collect information about how you interact with the Service, including IP address, browser type and version, device information, pages viewed, and timestamps.
- Cookies: We use essential cookies for authentication and session management, and optional analytics cookies to understand usage patterns. See the Cookies section below for details.
Why We Collect Data
We collect and process your data for the following purposes:
- To provide the Service: We process documents and signature data to enable you to send, sign, and manage agreements. This is the core purpose of the Service and the legal basis for processing (contractual necessity).
- To communicate with you: We send transactional emails related to your account, documents, and subscription (e.g., signing notifications, password resets, billing invoices).
- To improve the Service: We analyze aggregated usage data to understand how the platform is used, identify issues, and improve features. This data is de-identified where possible.
- To comply with legal obligations: We may process data to comply with applicable laws, regulations, or legal requests. This includes retaining audit trails for evidentiary purposes where required.
We do not sell your personal information to third parties. We do not use your document content for training machine learning models or for any purpose other than providing the Service to you.
How We Use Your Data
Your data is used only for the purposes described in this policy. Specifically:
- Account data is used to manage your account, provide customer support, and send service-related communications.
- Document data is used to enable the signing workflow, generate audit trails, and store completed documents for your access.
- Signer data is used to deliver signing invitations, verify identity through email and IP tracking, and generate audit records.
- Usage data is used in aggregated, de-identified form to monitor platform performance, troubleshoot issues, and inform product decisions.
We will not access your documents or signature data except: (a) to provide customer support at your request, (b) to investigate a reported issue or security incident, or (c) to comply with a valid legal obligation. In all cases, access is logged and limited to what is necessary.
Who Processes Your Data
FileSign engages the following third-party service providers (“subprocessors”) to process data in connection with the Service:
- Vercel Inc.— Cloud hosting and edge delivery. Data processed includes application data and request logs. Data center region: United States.
- Supabase Inc.— Managed PostgreSQL database, authentication, and file storage. Data processed includes account data, document data, and authentication credentials. Data center region: United States.
- Resend Inc.— Transactional email delivery. Data processed includes email addresses and document notification content. Data center region: United States and European Union.
- Cloudflare Inc.— Authenticated DOCX conversion. Data processed includes the DOCX file and the converted PDF needed to complete that request.
These providers process data under their applicable service terms and privacy commitments. This list is updated as FileSign’s production providers change.
Data Retention
We retain your data only for as long as it is needed to provide the Service or comply with legal obligations:
- Account data: Retained for the duration of your account plus 90 days after account closure to allow for data export and transition.
- Document data: Retained according to your account settings and document retention policies. Completed documents and audit trails are retained for the duration specified in your plan or as configured in your settings.
- Log and usage data: Retained for a period of 90 days, after which it is aggregated or deleted.
- Billing data: Retained for the period required by tax and accounting regulations (typically 7 years).
When you delete a document or close your account, data is permanently deleted within 30 days, subject to legal hold obligations. Deleted data may remain in backup systems for up to 90 days but is not accessible through the Service.
Cookies & Analytics
We use cookies and similar tracking technologies to operate and improve the Service:
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled while using the Service.
- Analytics cookies: We may use analytics tools (such as Vercel Analytics) to collect aggregated, anonymized information about page views and usage patterns. This helps us understand how the platform is used and identify areas for improvement.
- Third-party cookies: We do not currently use advertising cookies or marketing trackers. If this changes, we will update this policy and provide notice.
You can control cookie preferences through your browser settings. Disabling essential cookies will prevent the Service from functioning properly.
Payment Providers
Paid checkout is not currently available, and FileSign does not collect payment-card details through the current Free workspace.
Before paid plans become available, this policy and the checkout flow will identify the payment provider, the information it receives, and the billing information retained by FileSign.
AI & Automation
AI Prepare may process an uploaded document through a configured model provider to suggest signature fields and provide requested document intelligence. If a compatible provider is unavailable, FileSign uses a heuristic fallback instead.
You can accept, edit, or dismiss AI suggestions. FileSign records those decisions to improve the product workflow, but does not use customer documents to train a FileSign-owned model. Contact FileSign for the currently configured model provider and its data-handling terms before using AI features with sensitive documents.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to deletion: You can request deletion of your data, subject to legal retention requirements.
- Right to portability: You can request a machine-readable copy of your data for transfer to another service.
- Right to object: You can object to the processing of your data for certain purposes.
- Right to restrict: You can request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, submit a request through our contact page. We will respond to your request within 30 days. If you are in the European Economic Area or the UK, you also have the right to lodge a complaint with your local data protection authority. If you are in California, you have the right to know what personal information we collect and to request deletion under the CCPA. We do not sell your personal information.
Security Measures
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or 1.3.
- Encryption at rest: Document data and account data are encrypted at rest using AES-256 encryption.
- Access controls: Access to production systems and customer data is restricted to authorized personnel on a least-privilege basis.
- Authentication: Supabase Auth sessions for senders and expiring, hashed signing tokens for recipients.
- Event records: Signing events, delivery outcomes, and relevant workflow failures are recorded for review.
While we take these measures seriously, no online service can guarantee absolute security. We encourage you to use strong passwords and protect access to your account.
International Transfers
FileSign is based in the United States. Your data is primarily processed and stored in the United States. If you are located in the European Economic Area, the United Kingdom, or other regions with data protection laws that restrict cross-border data transfers, we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms to ensure your data is protected to an adequate standard.
Our subprocessors (Vercel, Supabase, Resend, and Cloudflare) may process data in jurisdictions including the United States and the European Union. Each provider has certified compliance with applicable cross-border transfer frameworks where available.
Children’s Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe that a child has provided us with personal data, please contact us through our contact page and we will take steps to delete that information.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) and through in-app notification at least 14 days before the changes take effect.
We encourage you to review this policy periodically. Your continued use of the Service after the effective date of changes constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy, want to exercise your data rights, or need to report a privacy concern, please contact: