Usign Privacy Policy
Under legal review. Effective 8 September 2026; not yet countersigned by counsel. Please confirm the current version with legal@usign.co before relying on it.
1. Who we are and what this policy covers
Usign is an electronic signature platform operated by Upfluence Inc., 214 Sullivan Street, Suite 3A, New York, NY 10012, United States ("Usign", "we", "us").
This Privacy Policy explains how we handle personal data when you:
- visit our website or marketing pages;
- hold or administer a Usign account (an "Authorized User" of a customer "Organization");
- are asked to review, complete, sign or decline a document through Usign (a "Signer");
- contact us for support, sales or a legal request.
Two very different roles. How we handle personal data — and who you should contact about it — depends on which of these applies:
| We act as | What that means for you | |
|---|---|---|
| Account, billing, website, support and marketing data | Controller | We decide how the data is used. This policy governs it, and you can exercise your rights directly with us (Section 9). |
| Everything inside a customer's Workspace — the documents themselves, the people invited to sign them, field values, signature images and the audit trail | Processor on behalf of our customer | Our customer — the business that sent you the document — decides what is collected, why, and how long it is kept. We process it on their instructions. Your rights are exercised against them; we will help them respond and will pass your request on (Section 10). |
If you received a document to sign and want to know why, or want your data corrected or erased, the fastest route is the business that sent it. If you are not sure who that is, email us at privacy@usign.co and we will identify them and forward your request.
Contact. privacy@usign.co, or by post to the address above, Attn: Privacy.
2. Personal data we handle
2.1 As controller
Account data. Name, email address, password (stored only as a cryptographic hash), profile avatar if you upload one, the Organizations and Workspaces you belong to, your role, invitation status, sign-in method (email and password, or Google sign-in), and timestamps of account events. Where you sign in with Google, we receive your name, email address and Google account identifier from Google — we never receive your Google password.
Organization and billing data. Organization name, billing email, plan terms, metered usage counts, the identifier of your payment record at our payment processor, and the brand, last four digits and status of your payment card. We never receive or store full card numbers, CVC codes or bank credentials — those go directly to Stripe.
Support and communications data. The content of emails and support requests you send us, and our replies.
Website and technical data. IP address, browser and device information, pages requested, referring URL, and request identifiers, collected in server and platform logs; error and diagnostic reports (including a stack trace and the technical context of a failure) generated when something goes wrong; and the strictly necessary cookies described in Section 7.
Marketing data (only if applicable to you). Business contact details you give us and your subscription status for product or marketing emails.
2.2 As processor, on our customers' instructions
Document content. The text, templates, merge-field values and attachments our customer prepares, and everything a Signer types into a fillable field. Document content can contain any category of personal data our customer chooses to put in it — commercial terms, fees, addresses, identifiers and, if our customer includes them, sensitive categories. Our customer decides this; we do not read documents to look for it.
Signer data. Name and email address as supplied by the sender; the field values, initials and signature the Signer provides; a drawn, typed or uploaded signature image; and, where our customer has enabled a stored signature, a signature held on file for reuse in that Workspace.
Signing and audit data. For each meaningful event on a document — sent, opened, viewed, one-time passcode requested and verified, email re-affirmed, signed, declined, voided, expired, downloaded — we record the timestamp, the actor, the IP address, the browser user agent, and an approximate geographic location (country and region) derived from the IP address. These entries form the audit trail, which is append-only and is reproduced as an appendix inside the finished signed PDF so that the file stands on its own as evidence.
Why we collect signing and audit data. Under U.S. and EU electronic-signature law, the evidentiary weight of an electronic signature comes from the record of how it was made. Without it, a signature can be repudiated. This is why the audit trail is retained even where other data is deleted, and why it cannot be edited (see Section 8).
Integration and API data. Where a customer uses our API, the MCP endpoint or an embedded surface, we process the identifiers, references and events that integration sends us, including an external reference the customer supplies to tie a document to a record in their own system.
2.3 One deliberate privacy design choice
A Signer's identity in Usign is scoped to a single Workspace. If the same email address signs documents for two different customers, those are two separate, unlinked records. We do not build a cross-customer profile of a Signer, and one customer cannot discover that a person also signed something for another. We consider this a feature, not an accident.
2.4 What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising or targeted advertising.
- We do not use document content, signer data or audit data to train, fine-tune or improve machine-learning models, and we do not permit our vendors to do so on our behalf.
- We do not use advertising cookies or third-party tracking pixels in the Usign application or on signing pages.
- We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.
- We do not knowingly collect personal data from children. The Service is for business use by people aged 18 or over.
3. Where the data comes from
We obtain personal data (a) directly from you, (b) from the customer who invited you to a Workspace or sent you a document, (c) from an integrator's platform where the Service is embedded, (d) from Google if you choose Google sign-in, (e) from Stripe in relation to payment status, and (f) automatically from your device and browser when you use the Service.
4. Why we use it, and our legal bases
Where the EU or UK GDPR applies and we act as controller, we rely on the following legal bases.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and administer your account; provide the Service to you | Account data | Performance of a contract (Art. 6(1)(b)) |
| Authenticate you and keep your session secure | Account data, technical data, session cookies | Contract; legitimate interests in securing the Service (Art. 6(1)(f)) |
| Send transactional email — invitations, confirmations, password resets, signing requests, one-time passcodes, completed-document copies | Account and Signer data | Contract; legitimate interests in providing a service our customer requested |
| Bill and collect fees, prevent payment fraud | Organization, billing and usage data | Contract; legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Provide support and respond to requests | Support data | Contract; legitimate interests |
| Keep the Service secure, prevent abuse, investigate incidents, enforce our terms | Technical data, audit data, account data | Legitimate interests in protecting the Service, our customers and third parties |
| Monitor errors, debug and improve reliability | Technical and diagnostic data | Legitimate interests in operating a reliable service |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any of the above, as needed | Legal obligation; legitimate interests (Art. 6(1)(f)) |
| Send product or marketing emails to business contacts | Marketing data | Consent (Art. 6(1)(a)) or legitimate interests where permitted for existing business contacts, with an unsubscribe link in every message |
Where we act as processor — document content, signer data and audit data inside a Workspace — the legal basis is determined by our customer, the controller. Typically it will be performance of a contract with the Signer, the controller's legitimate interests in concluding and evidencing an agreement, or a legal obligation to retain executed instruments. Our customer must be able to explain its basis; we cannot do so on its behalf.
You may object to processing based on legitimate interests at any time (Section 9).
6. International transfers
We are established in the United States and our infrastructure is operated in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data will be transferred to and processed in the United States, which is not the subject of a general adequacy decision covering all recipients.
For those transfers we rely on:
- the European Commission's Standard Contractual Clauses (Decision 2021/914) — Module Two (controller to processor) or Module Three (processor to processor), as applicable — incorporated into our Data Processing Addendum and into our agreements with sub-processors;
- the UK International Data Transfer Addendum to those clauses for UK transfers, and the Swiss addendum for Swiss transfers;
- the EU–US and UK–US Data Privacy Framework, where the recipient is certified under it and the transfer falls within its scope; and
- supplementary technical and organizational measures, including encryption in transit and at rest, strict access control, and a commitment to challenge unlawful government access requests and to publish what we lawfully can about them.
Our EU representative (Art. 27 GDPR). Upfluence SAS, 33 quai Arloing, 69009 Lyon, France — our French affiliate. EU data subjects may contact the representative at privacy@usign.co.
The United Kingdom. We do not offer the Service to UK-established customers and have not appointed a UK representative under Article 27 of the UK GDPR. A Signer in the United Kingdom may nonetheless be sent a document at a Sender's direction, in which case we process that Signer's personal data as the Sender's processor and on the Sender's instructions.
You may request a copy of the transfer mechanism relevant to you by emailing privacy@usign.co.
8. How long we keep personal data
| Data | Retention |
|---|---|
| Account data | For as long as the account exists, then deleted or de-identified within 90 days of account closure |
| Documents, templates and signed PDFs | For as long as the customer's Organization exists, unless the customer deletes them. Deleting a document in the Service hides it but retains it as a legal record; permanent deletion is performed on the customer's documented request. After termination, the customer has 30 days to export, and we then delete or de-identify within 90 days |
| Audit trail entries | Retained indefinitely, including after the related document or Workspace is deleted. Entries are append-only and cannot be edited or removed through the Service. Personal data within them (IP address, user agent, approximate location) is redacted on a valid erasure request — see Section 10 |
| Signature images held on file | Until the Authorized User or Signer removes them, or the Workspace is deleted |
| Billing and tax records | As required by applicable tax and accounting law, generally 7 years |
| Email delivery metadata (recipient, subject, delivery status) | Held by our email provider under its own retention period 3 days |
| Webhook delivery logs | 90 days; the last response for a permanently failed delivery, a further 30 days for debugging |
| Application and platform request logs | Up to 30 days |
| Error and diagnostic reports | Up to 90 days 90 days |
| Database point-in-time recovery backups | 7 days |
| Storage object version history | 30 days |
| Support correspondence | 3 years from the last message, unless a longer period is needed for a legal claim |
Backups purge on their own cycle: a deletion request is applied to live systems immediately and works through backups as they expire, within the windows above.
9. Your rights
Depending on where you live, you have some or all of the following rights. Where we are the processor (Section 1), see Section 10 instead.
If you are in the EEA, the UK or Switzerland, you have the right to: access your personal data and receive a copy; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; object to processing based on legitimate interests, and to direct marketing at any time; receive data you provided in a portable format; withdraw consent where processing is based on it; and not be subject to a decision based solely on automated processing with legal or similarly significant effects (we do not make such decisions). You also have the right to lodge a complaint with your local supervisory authority, or with the authority in the country of our EU/UK representative once appointed. We would appreciate the chance to address your concern first.
If you are a California resident, you have the right to know what personal information we collect, use, disclose and — if we did — sell or share; to access a copy in a portable format; to correct inaccurate information; to delete personal information, subject to exceptions; to limit the use of sensitive personal information; and not to be discriminated or retaliated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA/CPRA without offering a limitation right. The categories we collect, the sources, the purposes and the categories of recipients are described in Sections 2, 3, 4 and 5; our retention periods are in Section 8.
If you are in another U.S. state with a comprehensive privacy law — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and others as they take effect — you have broadly equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and certain profiling, together with a right to appeal a refusal. We do not conduct targeted advertising, sale or profiling that would trigger an opt-out.
How to exercise a right. Email privacy@usign.co from the address associated with your data, or write to us at the postal address in Section 1. We will verify your identity in a manner proportionate to the sensitivity of the request — usually by confirming control of the email address, and for a broader request by asking for information matching what we already hold. We do not require an account to make a request.
Authorized agents. You may use an authorized agent where the law allows. We will ask for written authorization and may still verify your identity directly.
Timing and cost. We respond within 30 days (or 45 days for U.S. state-law requests), and may extend once where the request is complex, telling you why. Requests are free unless they are manifestly unfounded or excessive, in which case we will tell you the reason and any fee before proceeding.
Appeals. If we decline your request, we will explain why. Where the applicable law provides an appeal right, you may appeal by replying to our decision with "Appeal" in the subject line; we will respond within the statutory period and, if we again decline, tell you how to contact your regulator.
10. If you were asked to sign a document (Signers)
You did not choose Usign; the business that sent you the document did. That business is the controller of your data inside its Workspace, and we act on its instructions. In practice:
To ask why you received a document, to correct your name or email, or to have your data erased, contact the business that sent it — its identity appears in the email and on the signing page. If you cannot reach them or do not know who they are, email privacy@usign.co and we will identify the sender, forward your request and, where appropriate, help them action it.
What erasure does — and does not — do. Where a valid erasure request is actioned, we redact your identifying data from the document metadata and the audit trail: your email address is removed, your display name is replaced with "Redacted Signer", and the IP address, user agent and approximate location captured during signing are deleted. Your signature is withheld from the live signing page.
What is retained. The signed PDF itself is not altered. It remains as the immutable record of an executed agreement, and it continues to show the name and signature as they were at the time of signing. Field values you entered also remain, because they are agreed terms of the document. This is the standard reconciliation of the right to erasure with the retention of executed instruments: an executed contract is evidence of a legal obligation, and the sender ordinarily has a lawful basis — its own legal obligation or legitimate interests, including the establishment or defence of legal claims — for keeping it. If you disagree that a basis exists in your case, raise it with the sender, and you may complain to your supervisory authority.
Keeping your copy. When a document is fully executed, we email you a link to download the signed PDF. The PDF is not attached to that email, and the download link is valid for a limited period (currently 90 days). Download the PDF and save it — that downloaded file is your durable copy. After the link expires, you can still ask the sender for a copy.
One-time passcodes. In an embedded signing flow we email you a six-digit code to verify that you control the email address. We record that a code was requested and verified, but the code itself is short-lived and single-use.
11. Security
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit — HTTPS only, TLS 1.2 or higher, HTTP rejected at the edge, HSTS on all responses.
- Encryption at rest — for the database, storage objects and backups.
- Tenant isolation at the database layer — row-level security policies enforce that a query cannot return another customer's data even if application code has a bug; every policy combines an authenticated-user check with a workspace-membership check.
- Least-privilege access control — role-based permissions within a Workspace and Organization, and restricted operator access to production.
- Credential hygiene — passwords stored as bcrypt hashes by our authentication provider; API keys stored only as SHA-256 hashes and compared in constant time; session cookies
HttpOnly,Secure,SameSite=Lax. - Signing integrity — a SHA-256 content hash embedded in every signed PDF, cryptographic signing performed server-side only, and an append-only audit log that the application itself cannot rewrite.
- Boundary controls — strict content-security policy on signing pages, iframe embedding restricted to origins a customer has explicitly allow-listed, schema validation of all API input, file-type verification on uploads, and rate limiting including a per-signer limit on passcode requests.
- Secrets management — production secrets held in a restricted store with documented rotation procedures.
- Monitoring and response — application audit logging, authentication event logs, request logging, and a documented incident-response runbook covering suspected breach, signing-key compromise, abuse and infrastructure loss.
What we do not claim. We do not currently hold a SOC 2 or ISO/IEC 27001 attestation, and multi-factor authentication is not yet available for Authorized Users. We would rather tell you that than imply otherwise.
No system is perfectly secure. If you believe you have found a vulnerability, please email security@usign.co with details; we will acknowledge it and will not pursue good-faith security research that respects our users' data.
Breach notification. If a personal data breach occurs, we will notify the affected controller without undue delay, and will notify supervisory authorities and individuals where the law requires it and we are the controller.
12. Changes to this policy
We may update this policy. If a change is material, we will notify account administrators by email or by prominent notice in the Service at least 30 days before it takes effect, unless a shorter period is required by law. The "Last updated" date at the top always reflects the current version, and we keep prior versions available on request.
13. Contact us
Upfluence Inc. (Usign) — Attn: Privacy
214 Sullivan Street, Suite 3A
New York, NY 10012
United States
privacy@usign.co
If you are in the EEA or the UK, you may also contact our Article 27 representative once appointed (Section 6), and you have the right to complain to your local supervisory authority.