Signet

Privacy Policy

What we collect, why we collect it, how we share it, and the rights you have — including the rights given to residents of US states with consumer privacy laws.

Last updated September 2026

Scope

This policy describes how Signet (“Signet”, “we”) collects, uses, discloses and retains personal information through our website, application and signing experience (the “Service”). It applies to visitors, account holders and document recipients in the United States. Where we process personal information on behalf of an account holder (for example, the contents of documents and recipient details), we act as a service provider / processor and handle that information under our customer’s instructions.

Categories of information we collect

  • Identifiers — name, email address, company name, account identifiers and IP address.
  • Commercial information — plan, billing status and transaction records (card details are handled by our payment processor, not stored by us).
  • Customer content — the documents you upload, the fields you place, signature images and any information contained in those files.
  • Signing evidence — signer email, verification method, consent and intent records, timestamps, document hashes, IP address and browser/device string. This is the audit trail and it is the point of the product.
  • Internet activity and device data — log data, error reports, request metadata and essential cookies used to keep you signed in.

We do not intentionally collect Social Security numbers, government ID numbers, precise geolocation, biometric identifiers, health information or other sensitive personal information. If you place such information inside a document you upload, it is customer content and we process it only to deliver the Service.

How we use information

  • To provide the Service: store and render documents, deliver signing links and reminders, and produce a verifiable evidence record.
  • To authenticate users and recipients and to secure accounts.
  • To bill your plan and to provide support.
  • To detect, investigate and prevent fraud, abuse and security incidents.
  • To comply with legal obligations and to establish, exercise or defend legal claims.
  • To improve and troubleshoot the Service using operational and aggregated or de-identified data.

Automated processing and machine learning

We may use software, automated systems and machine-learning or AI features to operate, secure, support and improve the Service — for example document processing, abuse detection, search and support tooling. Where any such processing involves customer content, we do so to deliver the Service and under the terms of our agreement with the account holder. We do not sell your documents. This policy does not make any additional commitment about model training beyond what is stated in your agreement with us.

How we share information

  • With recipients you choose — a document and the sender’s identity are shown to the people you send it to.
  • Service providers — hosting, database and file storage, transactional email, error monitoring and payment processing. They act on our instructions under written contracts.
  • Legal and safety — where required by law, subpoena or other legal process, or to protect the rights, property or safety of Signet, our users or the public.
  • Corporate transactions — in connection with a merger, acquisition, financing or sale of assets, subject to this policy.

We do not sell personal information and we do not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under US state privacy laws. We do not run advertising trackers on the signing experience.

Cookies and tracking

We use cookies and similar technologies that are strictly necessary to sign you in, keep your session secure and remember basic preferences, plus limited first-party analytics to understand product usage. We do not use third-party advertising cookies. Because we do not sell or share personal information for targeted advertising, we treat Global Privacy Control and similar opt-out preference signals as already satisfied; if we ever change that practice, we will honor those signals.

Your US state privacy rights

Depending on your state of residence — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws in force — you may have the right to:

  • know or access the personal information we hold about you and the categories of sources, purposes and recipients;
  • obtain a portable copy of that information;
  • correct inaccurate personal information;
  • request deletion, subject to legal and evidentiary exceptions described below;
  • opt out of sale, targeted advertising or profiling with legal effects (we do not engage in these activities);
  • limit the use of sensitive personal information (we do not use it beyond providing the Service); and
  • not be discriminated or retaliated against for exercising these rights.

To exercise a right, email privacy@signet.app. We will verify your request using information associated with your account and respond within the period required by your state’s law (generally 45 days, with one permitted extension). You may use an authorized agent where your state allows it. If we deny your request, you may appeal by replying to our decision; we will respond to appeals within the statutory period and, where required, tell you how to contact your state attorney general.

California: we have not sold or shared personal information, and have not knowingly collected the personal information of consumers under 16, in the preceding twelve months. California residents may also request the “Shine the Light” disclosure under Civil Code § 1798.83 at the address above. Nevada: we do not sell covered information as defined by NRS 603A; you may still submit an opt-out request. Washington and Nevada consumer health data: we do not collect consumer health data as defined by the My Health My Data Act or NRS 603A.

If your information was submitted to Signet by an account holder (for example, because someone sent you a document), we will refer your request to that account holder, who controls the information, and assist them in responding.

Who can see your documents

Access is scoped to your account and to the recipients you send to. Signing links are private, single-purpose and expiring, and a recipient must prove control of their mailbox with a one-time code before a document is shown. Our personnel access customer content only where necessary to operate the Service, provide support you request, or comply with law.

Retention

We keep documents and their audit trails while your account is active so you can produce evidence later, and afterwards only as long as needed for the purposes described here, to resolve disputes, and to comply with legal, tax and recordkeeping obligations. Audit entries are append-only by design and cannot be edited. When you delete a document we remove the file; the evidence record of a completed transaction may be retained where retention is required or where deletion would impair the integrity of a record another party relies on. Backups are purged on a rolling schedule.

Security

We maintain administrative, technical and physical safeguards designed to protect personal information, including encryption in transit, short-lived signed URLs instead of public file links, row-level access rules that separate accounts, and least- privilege access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach of security affecting your personal information occurs, we will notify you and any regulators as required by applicable state breach-notification law.

Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

Electronic records and communications

By using the Service you consent to receive notices, disclosures, contracts and signature records electronically, consistent with the federal ESIGN Act and state UETA statutes. You may withdraw that consent by closing your account, though doing so means you can no longer use the Service.

Users outside the United States

The Service is operated from and hosted in the United States. If you access it from another country, you understand that your information will be transferred to, processed and stored in the United States, where data protection laws may differ from those of your jurisdiction.

Changes and contact

Material changes are posted here with an updated date and, where required by law, we will provide additional notice. Continuing to use Signet after a change means you accept the revised policy. Questions or requests: privacy@signet.app.

Not legal advice

This policy describes our practices; it is not legal advice, and it is not a substitute for review by counsel licensed in your jurisdiction.