Privacy Policy
Version 2.0.0 · Effective 2026-07-07
What we collect
- Account data: your name, email, optional company, and the password you set (hashed; we cannot read it).
- Documents and signatures: the PDFs you upload, the signature fields you place, the email and IP address of each signer, the user agent string, and timestamps for every signing event.
- Workspace data: workspace name, member list, plan tier, and monthly usage counters.
- Billing data: processed by Dodo Payments (our payment processor). We do not store full card numbers on our servers.
- Operational data: server logs (request method, path, status code, response time). Retained for 30 days.
Why we collect it
To operate the service. Specifically: to authenticate you, to send signing requests to the people you name, to produce the audit trail that makes each signature legally defensible, to bill you, to detect abuse, and to comply with legal obligations.
Cookies & consent
The cookie banner that appears on your first visit lets you accept all, reject all, or pick per-category. It gates our browser-side error reporter and any future analytics or marketing cookies we add. Strictly-necessary cookies (auth, CSRF, the consent-cookie storage itself) are always on and never gated. See our full Cookie Policy for the per-cookie breakdown.
You can withdraw or change your cookie consent at any time using the “Manage cookie preferences” link in any page footer, or from your account settings.
Marketing email
We send product updates only if you opt in on the signup form (the checkbox is unchecked by default). You can withdraw consent at any time by clicking “unsubscribe” in any marketing email, or by emailing support@signfile.io. Withdrawing marketing consent does not affect transactional emails (signing requests, completed-doc notifications, password resets) which we send regardless because they are required to operate the service.
Who we share with
- Email provider: to send signing requests, completed-doc notifications, and (if opted in) marketing. Current provider: Google SMTP.
- Payment processor: Dodo Payments for billing on paid plans.
- Hosting: Appwrite Cloud for the database, file storage, authentication, and web app hosting (Cloud Sites, region
fra/ Frankfurt). Cloudflare fronts thesignfile.iodomain with proxy disabled (apex-domain email routing requirement). - Scheduled jobs: cron-job.org sends our /api/cron/* routes on a schedule (document expiry, sign reminders, dunning cadence, stale-lock cleanup). cron-job.org receives only the request URL, a Bearer token, and the user-agent string. No document content, no signer metadata.
- Error reporting: Sentry for server-side and (with your consent) client-side exception reports. The server-side SDK runs regardless of consent. The client-side SDK initializes only after you grant “Analytics & Error reporting” in the cookie banner — see our Cookie Policy for the full gating model. PII (IP, browser type, page URL) is sent; document content is not. We use
sendDefaultPii: falseto suppress cookies and user identifiers. - Law enforcement: if we receive a valid legal order, or to investigate violations of our terms.
We do not sell your data. We do not share your documents or signature data with any party for advertising or model training.
How long we keep it
Account data: until you delete your account. Once you confirm the deletion request, your identity is anonymized within 14 days (90 days for encrypted backups before they expire).
Signed documents and audit-trail hashes you authored are retained for at least 7 years per the U.S. ESIGN Act (15 U.S.C. § 7001), UECA, and EU eIDAS. We rely on the GDPR Art. 17(3)(b) legal-obligation exemption for this category: the retention is mandatory for the signature to remain legally verifiable, and erasing it would defeat the legal purpose of the contract.
Operational logs (server access logs, error reports): 30 days, enforced by an automated sweep. Audit events (signing events, account changes, deletion lifecycle): 24 months by default, then redacted of PII and kept as anonymous summary records for an additional 5 years for fraud analysis.
Billing records: 7 years (tax / accounting requirement).
Lawful basis for processing
GDPR Art. 6(1)(c) requires we name the lawful basis for each purpose. Ours:
- Operating the service, authenticating you, producing the audit trail for signed contracts: Art. 6(1)(b) — performance of a contract you accepted by signing up.
- Billing and tax records: Art. 6(1)(c) — legal obligation (tax / accounting).
- Marketing email (only if you opted in): Art. 6(1)(a) — consent, withdrawable at any time via Settings → Privacy or any email’s unsubscribe link.
- Error reporting to Sentry (server + your consent for client): Art. 6(1)(f) — legitimate interest in keeping the service safe and reliable. Where the legitimate-interest basis applies you can object per GDPR Art. 21 by emailing support@signfile.io; we will action the request within 30 days.
Your rights
EU and UK residents have the rights under GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to the signed-document retention above), restriction (Art. 18), portability (Art. 20), and objection (Art. 21).
Self-service access & portability. Download a JSON bundle of every piece of data we hold about you from Settings → Privacy → Download my data (or directly at /api/me/export). Bundles include your profile, workspaces, documents, signers, audit events, signed documents, contacts, and deletion lifecycle records.
Self-service erasure. Start account deletion from Settings → Account → Delete account. A 14-day grace period begins; you can restore within the window. After 14 days your identity is anonymized while the legally-required signed-document retention remains.
Self-service withdraw consent. Marketing email opt-out lives at Settings → Privacy; the cookie banner has a “Withdraw consent entirely” link in the modal. No login required for the email unsubscribe link in any email footer.
Notification on erasure. Where erasure or restriction is performed (GDPR Art. 19), we notify every sub-processor that holds the affected data so they can action it on their side. The notification list is our sub-processor page.
Right to lodge a complaint with a supervisory authority. EU residents can complain to the supervisory authority of their habitual residence; UK residents to the ICO; California residents can exercise CCPA/CPRA rights (know, delete, opt-out of sale, limit use of sensitive PI, non-discrimination) directly with us or via the California AG. We do not sell data, so the opt-out-of-sale right is moot but the others apply.
For anything not self-service, email support@signfile.io. We respond within 30 days.
Security
TLS 1.2+ for all data in transit. Documents stored in Appwrite Cloud's region-locked buckets (EU: Frankfurt). Rate-limited auth endpoints. Per-signer and per-document signing locks to prevent concurrent-stamp races. Server- derived URLs on all signing links. CSP with strict baseline. Session cookies are HttpOnly + Secure + SameSite.
Incident response & compliance documentation. We maintain an internal incident-response runbook, a records-of-processing register (Art. 30), and a data protection impact assessment covering the signature evidence we hold. These documents define notification timelines (supervisory authorities within 72 hours of awareness of a material breach per GDPR Art. 33; affected users without undue delay per Art. 34) and are available to enterprise customers on request via support@signfile.io.
Children
SIGNFILE is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact support@signfile.io and we will delete the account.
International transfers
Our database and storage live in the EU (Frankfurt). Email and error-reporting providers may process data in the US; we use providers that participate in the EU-US Data Privacy Framework or execute Standard Contractual Clauses.
Changes to this policy
Material changes will be communicated by email and an in-app banner at least 30 days before they take effect. The version stamp at the top of this page lets you compare any two versions side-by-side.
Contact & company details
Controller: Ilxonwat (trade name of the operator of signfile.io; legal entity registration is in progress). Controller contact: support@signfile.io. Replies within 30 days per Art. 12(3) GDPR.
Data Protection Officer: we have determined, per Art. 37(1)(b) GDPR, that our processing activities (B2B e-signature SaaS with a focused, contract-necessity basis) do not require a designated DPO. For all privacy inquiries contact support@signfile.io; we escalate within 30 days.
EU representative: as our hosting and primary operations are based in the EU (Appwrite Cloud, Frankfurt region), we have not appointed a separate Art. 27 EU representative. Privacy questions are handled by support@signfile.io. If the operating company is incorporated outside the EU, we will appoint an EU representative and update this page; the GDPR controls apply to data subjects regardless.