Privacy Policy
This Privacy Policy explains how SignOfficial collects, uses, and protects your information when you use our e-signature platform — including what we do and do not do with your documents and signature data.
Are signatures collected through SignOfficial legally binding?
Yes — in most cases. Electronic signatures are recognized as legally binding under several major frameworks, including:
- The U.S. Electronic Signatures in Global and National Commerce Act (ESIGN Act, 2000)
- The Uniform Electronic Transactions Act (UETA), adopted in most U.S. states
- The EU eIDAS Regulation for transactions within the European Union
- Comparable national laws in Canada (PIPEDA), the UK (Electronic Communications Act), Australia, and many others
Under these laws, a signature cannot be denied legal effect solely because it is in electronic form. SignOfficial captures the signer's intent, identity (via email), timestamp, and document fingerprint — the key elements courts and regulators look for.
What SignOfficial is — and is not
SignOfficial is an electronic signature platform. We provide the technology infrastructure for you to send, sign, and manage documents digitally. We are not a law firm, a notary, or a court-recognized official.
What we do
- Deliver documents to specified recipients via email for electronic signature
- Record each signature event with a timestamp, IP address, and the signer's email
- Generate a signed PDF with an audit trail embedded in the document
- Host public signing links for waivers and open-enrollment documents
- Send email notifications to document owners when signatures are completed
What we do not do
- We do not serve as an in-person witness or notary for any document
- We do not provide legal advice on whether a document is valid or enforceable
- We do not verify the true identity of signers beyond their email address
- We do not guarantee that your specific document type is legally sufficient in your jurisdiction
Information we collect
Information you provide
- Your email address when you purchase a plan or send a document
- Recipient email addresses you provide when sending private documents
- The PDF documents you upload for signing
- Template names, field configurations, and settings you create
Information collected during signing
- Signer's email address and the timestamp of each signature event
- IP address of the device used to sign (for audit trail purposes)
- Drawn or typed signature image captured at signing
- Document completion status and any decline or void events
Usage and technical data
- Browser type, device type, and general location (country/region)
- Pages visited, features used, and session duration
- Error logs and performance data used to improve the service
How we use the information we collect
- To deliver documents to recipients and process signature requests
- To generate completed, signed PDFs with embedded audit trails
- To send email notifications about document status (sent, signed, completed)
- To process payments via our payment processor (Stripe)
- To maintain your document history linked to your email address
- To detect and prevent fraud, abuse, and unauthorized access
- To improve the reliability and usability of the platform
How we handle your documents
The documents you upload to SignOfficial are stored securely in encrypted cloud storage (AWS S3). We treat your documents as confidential and do not read, sell, or share the content of your documents with third parties except as described below.
- Documents are encrypted at rest and in transit using industry-standard TLS and AES-256 encryption
- Private documents are only accessible to the sender and specified recipients via secure, time-limited links
- Public document links are accessible to anyone with the link, by design — you control whether to publish or deactivate the link
- Completed signed PDFs are available for download by the document owner for as long as the document is retained
When we share your information
We do not sell your personal data. We share information only in the following limited circumstances:
- With Stripe to process payments — Stripe's privacy policy governs any data shared with them
- With AWS to store and deliver documents — AWS acts as our infrastructure provider
- With email delivery services (AWS SES) to send document notifications and signing invitations
- With legal authorities if required by law, court order, or to protect the rights and safety of users
- With a successor entity in the event of a merger, acquisition, or sale of assets
How long we keep your data
We retain your documents and signing records for as long as your plan covers active storage. Completed documents and their audit trails are kept so you can access legally relevant records when needed.
If you wish to delete your documents or data, you may contact us at [email protected]. Note that deleting signing records may affect the enforceability of completed agreements, and we recommend downloading a copy before requesting deletion.
How we protect your data
We use a combination of technical and organizational measures to protect your information, including:
- HTTPS/TLS encryption for all data in transit
- AES-256 encryption for documents stored at rest in AWS S3
- Time-limited, signed URLs for document access — links expire and cannot be reused indefinitely
- Email-based identity verification before document access is granted
- Serverless infrastructure with automated security patching via AWS Lambda
No system is perfectly secure. While we take security seriously, we cannot guarantee absolute protection against all threats. You are responsible for keeping your email account secure, as it is the primary means of accessing your SignOfficial documents.
Your choices and rights
Depending on where you live, you may have rights over your personal data including:
- Access — request a copy of personal data we hold about you
- Correction — request that inaccurate information be corrected
- Deletion — request removal of your data, subject to legal and operational requirements
- Portability — request your data in a machine-readable format where applicable
- Objection — object to processing in certain circumstances
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity (via email) before acting on your request.
Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the platform, our practices, or legal requirements. When we do, we will update the date at the top of this page.
For significant changes, we will notify active users via email. Continued use of SignOfficial after changes take effect constitutes acceptance of the updated policy.
Get in touch
If you have questions about this Privacy Policy, how we handle your data, or want to exercise your rights, please reach out:
Email: [email protected]
SignOfficial is operated by Modern Deployment LLC.