Section 1 — Introduction
This Privacy Policy applies to all information collected through the ValidaSign platform and any related services. By using the Service, you agree to the collection and use of information in accordance with this Policy.
Section 2 — Information We Collect
- Account Information: name, email address, password (hashed), company name (optional).
- Document Data: documents you upload, signer names and email addresses, signature images, signing timestamps, IP addresses of signers.
- Payment Information: processed by Stripe — we do not store credit card numbers. We receive transaction IDs and billing status.
- Usage Data: pages visited, features used, device type, browser, operating system, referring URLs.
- Cookies & Analytics: we use Google Analytics (GA4) and essential cookies for session management. We do not use advertising cookies.
Section 3 — How We Use Your Information
- To provide and maintain the Service.
- To process transactions and send billing communications.
- To send signing requests and notifications to designated signers.
- To generate signature certificates and audit trails.
- To respond to support requests.
- To improve the Service and develop new features.
- To comply with legal obligations.
- To detect and prevent fraud or abuse.
Section 4 — Information Sharing
- With Signers: when you send a document for signature, signers receive the document and your name/email.
- With API Partners: if your documents are dispatched via a partner's API integration, that partner receives status updates per their API agreement.
- Service Providers: we use third-party providers (Stripe for payments, email delivery services) who process data on our behalf under contractual obligations.
- Legal Requirements: we may disclose information if required by law, legal process, or government request.
- Business Transfers: in connection with a merger, acquisition, or sale of assets.
Section 5 — Data Retention
Account data is retained while your account is active plus 12 months after a deletion request. Completed documents are retained for a minimum of 90 days after completion — you may download them during this period. Signature audit trail data (signer IP, timestamp, certificate hash) is retained for 7 years for legal compliance purposes. Usage and analytics data is retained for 26 months. You may request deletion of your data — see Section 7.
Section 6 — Data Security
We implement industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, secure authentication, access controls, and regular security assessments. No system is 100% secure — we cannot guarantee absolute security.
Section 7 — Your Rights (California / CPRA)
If you are a California resident, under the California Privacy Rights Act (CPRA) you have the right to:
- Know what personal information we collect and how it is used.
- Delete your personal information (subject to legal exceptions).
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (we do not sell or share your personal information).
- Non-discrimination for exercising your rights.
To exercise these rights, email privacy@validasign.com. We will verify your identity and respond within 45 days. Authorized agents may submit requests on your behalf with written authorization.
Categories of personal information collected (per CPRA):
- Identifiers (name, email, IP address).
- Commercial information (transaction records, credits purchased).
- Internet/electronic activity (usage data, device info).
- Professional information (company name, job title if provided).
We do NOT use personal information for automated decision-making or profiling. We do NOT sell personal information. We do NOT use or disclose sensitive personal information for purposes beyond those authorized by CPRA §1798.121.
Section 8 — Non-User Data Subjects (Signers)
If you are a signer who received a document via ValidaSign but do not have an account, we collect your name, email, signature, IP address, and signing timestamp as necessary to complete the signature transaction. You may request access to or deletion of this data by emailing privacy@validasign.com.
Section 9 — Children's Privacy
The Service is not intended for anyone under 18. We do not knowingly collect personal information from minors. If we learn we have collected data from a minor, we will delete it promptly.
Section 10 — International Users
The Service is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. By using the Service, you consent to this transfer.
Section 11 — AI & Document Processing
ValidaSign does not use artificial intelligence, machine learning, or automated systems to read, analyze, or train on the content of your documents. Documents are processed solely for rendering and signature placement.
Section 12 — Global Privacy Control (GPC)
We honor GPC signals. If your browser sends a GPC signal, we treat it as a valid opt-out request under CPRA.
Section 13 — Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be communicated via email or in-app notification at least 30 days before the effective date. The "Effective Date" at the top reflects the latest revision.
Section 14 — Contact Us
- Privacy inquiries: privacy@validasign.com
- General inquiries: info@validasign.com
- Address: Rancho Santa Margarita, California, USA
