Legal

Privacy Policy

Last updated: July 20, 2026

1. Overview

This policy explains what data Soft eSign collects, why, and the controls you have over it. It covers both account data (you, as a customer) and document data (the agreements you send and sign through the platform).

2. Data we collect

Account details you provide (name, email, organization); documents, fields, and recipient information you upload or enter to create an envelope; signing evidence such as IP address, device and browser information, and timestamps, captured to build the audit trail and certificate of completion; and usage data (pages visited, actions taken) used to operate and improve the Service.

3. How we use it

To deliver the Service — routing envelopes, enforcing signing order, generating audit trails and digital signatures, and sending notifications; to secure accounts and detect abuse; and, only where you've enabled it, to power optional AI features (such as field detection or document analysis) and activity digests.

4. Data residency and retention

Organizations can configure a data region for document storage and a retention policy (including auto-archive and auto-delete schedules) under Settings. Deleted data is removed from active storage in line with that policy; backups are retained for a limited period for disaster recovery.

5. Sharing

We don't sell your data. We share it only with the recipients you designate on an envelope, service providers who help us operate the platform (such as email delivery and cloud storage) under confidentiality obligations, and where required by law.

6. Security

Documents are encrypted in transit and at rest. Completed envelopes are protected by a SHA-256 verification hash and an embedded digital signature so tampering after completion is detectable. Access to your organization's data is scoped by role, and administrators can review activity through audit logs.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Account owners can export or delete organization data from Settings; individual signers can request a copy of their signing record via the sender or by contacting us directly.

8. Cookies

We use essential cookies to keep you signed in and remember your preferences (such as theme and language). We don't use third-party advertising cookies. You can clear cookies at any time from your browser settings; doing so will sign you out.

9. Accessibility

We aim to meet WCAG 2.1 AA guidelines across the marketing site and application — sufficient color contrast, keyboard navigation, and screen-reader-friendly labeling. If you encounter an accessibility barrier, please tell us and we'll prioritize a fix.

10. Changes to this policy

We'll update this page when our data practices change and, for material changes, notify account owners by email.

11. Contact

Questions about this policy or requests regarding your data can be sent to privacy@softesign.com.

See also our Terms of Service.