Privacy Policy

Effective Date: March 3, 2026

1. Information We Collect

Account Information

  • Name and email address (via Google OAuth or direct registration)
  • Profile information from OAuth providers
  • Billing information (processed securely by payment providers)

Document Information

  • PDF documents you upload to our Service
  • Signature fields and form data you create
  • Electronic signatures and completion data
  • Email addresses of document recipients

Technical Information

  • IP addresses and device information
  • Browser type and version
  • Usage patterns and feature interactions
  • Error logs and performance metrics

2. How We Use Your Information

  • Service Delivery: To provide electronic signature functionality
  • Legal Compliance: To maintain audit trails required by ESIGN Act
  • Account Management: To manage your subscription and billing
  • Communication: To send service updates and notifications
  • Improvement: To analyze usage and improve our Service
  • Security: To detect and prevent fraud or abuse. Documents are scanned automatically when they are sent, and where we have reason to suspect fraud or misuse a member of our staff may open and read the document itself. We record every such review, including who carried it out and why, and you can request that record. We do not notify you at the time, because doing so would undermine the purpose, but we will always tell you if a review leads to action against your account

3. Legal Basis for Processing

We process your personal data based on:

  • Contract: To fulfill our Terms of Service
  • Legal Obligation: To comply with electronic signature laws
  • Legitimate Interest: To improve and secure our Service
  • Consent: When explicitly provided for optional features

4. Data Security and Storage

Enterprise-Grade Security

  • All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Documents stored in secure AWS S3 buckets with restricted access
  • Database hosted on Neon with connection pooling and encryption
  • Regular security audits and vulnerability assessments

Data Retention

  • Active Accounts: Data retained while your account is active
  • Cancelled Subscriptions: Your account stays open on the free plan and your documents remain available to download
  • Closed Accounts: Your documents are kept for 30 days so you can reopen the account by signing in, then everything is erased permanently
  • Immediate Deletion: If you choose Delete permanently, your documents, signatures and audit trails are erased straight away and cannot be recovered. If a document is subject to a legal hold, we will tell you and keep it until the hold is lifted
  • Audit Trails: Kept for the life of the document they belong to
  • Usage Analytics: Google Analytics and Microsoft Clarity data is held by those providers under their own retention policies, not by us
  • Abuse and Security Records: If content you sent was flagged by our moderation checks, we keep the finding after your account is deleted so we can spot repeat abuse. These records are linked to an internal account identifier rather than your name or email, and the document text itself is removed when you delete your account

5. Data Sharing and Disclosure

We do not sell your personal data. We may share information only:

With Your Consent

  • When you explicitly authorize sharing
  • When you send documents to recipients for signing

Service Providers

  • AWS: Cloud hosting and file storage
  • Neon: Database hosting
  • Resend: Email delivery services
  • Stripe: Payment processing (billing data only)
  • Microsoft Clarity: Website usage analytics (session recordings, heatmaps)
  • Google Analytics: Website traffic and usage measurement
  • Vercel: Application hosting and edge delivery

Legal Requirements

  • To comply with valid legal requests or court orders
  • To protect our rights, property, or safety
  • To prevent fraud or abuse

6. Your Privacy Rights

Access and Control

  • Account Access: View and update your profile information
  • Data Export: Download your documents and data
  • Account Deletion: Permanently delete your account
  • Email Preferences: Opt out of non-essential communications

Additional Rights (Where Applicable)

Depending on your location, you may have additional rights under GDPR, CCPA, or other privacy laws:

  • Right to rectification of inaccurate data
  • Right to data portability
  • Right to restrict processing
  • Right to object to processing

7. International Data Transfers

Your data is primarily stored in the United States. If you access our Service from outside the US, your information may be transferred to and stored in the US. We ensure appropriate safeguards are in place.

8. Cookies and Tracking

  • Essential Cookies: Required for login and core functionality
  • Microsoft Clarity: We use Microsoft Clarity to understand how you interact with our website through session recordings and heatmaps. Clarity may collect usage data such as mouse movements, clicks, scrolls, and page views. This data is processed by Microsoft. For more information, see Microsoft's Privacy Statement.
  • Google Analytics: We use Google Analytics (GA4) to measure traffic and usage patterns. Google may set cookies to distinguish users and sessions. For more information, see Google's Privacy Policy.
  • No Third-Party Advertising: We do not sell data or use advertising cookies
  • Control: You can manage cookies through your browser settings or decline non-essential cookies via our consent banner

9. Children's Privacy

SigPen is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware of such collection, we will delete the information immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending email notifications for significant changes
  • Providing in-app notifications when you next log in

11. Contact Us

For privacy-related questions or requests, contact us at:
Email: privacy@sigpen.com

We will respond to privacy requests within 30 days. For urgent security concerns, please contact us immediately.


Last updated: March 3, 2026