Privacy Policy - SignFortress
SignFortress

Privacy Policy

Secure. Transparent. Respected.

Effective: February 5, 2026

Back to Home Privacy Policy
🔐
Important Security Notice

SignFortress will never send unsolicited emails or messages asking you to verify your account, provide login details, update billing information, reset passwords, or click on links to access your documents.

If you receive any such communication claiming to be from SignFortress, please treat it as fraudulent and do not click any links or provide any information. Always access your account directly at signfortress.com or contact us through official channels.

1. Introduction

Welcome to Signfortress ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website signfortress.com, use our mobile application, or engage with our electronic signature services (collectively, the "Service"). We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Personal Information Protection Act (PIPA) of British Columbia, Canada, and other relevant regulations.

By using the Service, you consent to the practices described in this Policy. If you do not agree, please do not use the Service. We may update this Policy from time to time; changes will be posted here with the updated effective date.

2. Information We Collect

We collect information necessary to provide and improve the Service, including:

  • Account Information: Name, email address, phone number, company name, and billing details when you register or update your profile.
  • Document & Signature Data: Uploaded documents, electronic signatures, signer details (names, emails), timestamps, IP addresses, and related metadata.
  • Usage Data: How you interact with the Service (pages visited, features used, device type, browser, IP address).
  • Cookies & Similar Technologies: Used for functionality, analytics, and security. You can manage preferences via your browser or our cookie banner.
  • Communication Data: Messages sent through support or in-app features.

We do not intentionally collect sensitive personal information unless explicitly required for a feature and with your consent.

2.1 Signer Photo (Identity Confirmation)

When a sender requests identity confirmation, you may be asked to capture or upload a photo. This photo is encrypted on your device before it is transmitted using modern cryptographic standards. Signfortress cannot view, access, or decrypt your photo at any time. Only the sender who initiated the request can access the decrypted image. Retention and deletion of the photo are determined solely by the sender.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service (e.g., process signatures, send notifications, generate audit trails).
  • Manage subscriptions, process payments, and send receipts.
  • Communicate with you (e.g., signature requests, reminders, support responses; marketing opt-out available).
  • Improve the Service through usage analysis and product development.
  • Ensure security, prevent fraud, and comply with legal obligations.

4. Data Sharing and Disclosure

We do not sell your personal data. We share information only when necessary:

  • Service Providers: With trusted partners (e.g., hosting, payment processors, email delivery) under strict confidentiality agreements.
  • Cloud Storage (Pro & Premium): When you choose to store documents in your personal Microsoft OneDrive, Google Drive, or Dropbox account, files are uploaded directly to your account. These providers act under their own privacy policies and security controls. We only interact transiently to upload content and do not retain copies.
  • Legal Requirements: To comply with law, respond to legal requests, or protect rights and safety.
  • Business Transfers: In the event of merger, acquisition, or sale of assets.

5. Data Security

We implement multiple layers of technical and organizational safeguards to protect your information. These include encryption, access controls, monitoring, and secure development practices. Key protections include:

5.1 End to End Encryption (E2EE)

Certain features of the Service, including secure portal messaging, group chat, and all related file attachments, use true end to end encryption. With E2EE:

  • Messages and attachments are encrypted on the sender's device before transmission using modern cryptographic standards such as AES GCM.
  • Only the intended recipients' devices hold the cryptographic keys required to decrypt the content.
  • We cannot view, access, or decrypt E2EE protected content stored on our servers.
  • Encrypted data is stored only in ciphertext form while at rest.
  • Decryption occurs solely within the user's browser or device. Keys are never transmitted to or stored by Signfortress.

5.2 Encryption at Rest

All documents and data stored on our infrastructure are encrypted at rest. This includes:

  • E2EE content: Portal chat messages, group chat messages, and all associated attachments are stored exactly as encrypted binary data generated on the user's device. We do not possess the keys required to decrypt this content.
  • Server processed documents: Documents used in signing workflows, including uploaded PDFs, generated audit files, and final signed documents, are encrypted server side using AES 256 CBC with a unique per file key.
  • Key protection: Server side encryption keys are themselves encrypted using a site level secret and are accessible only through tightly controlled security mechanisms.

5.3 Temporary File Handling

Files used for signing workflows or validation are processed in memory and automatically purged shortly after completion. Only documents you explicitly save remain stored.

5.4 Signer Photo Encryption & Access Control

Signer photos captured during identity confirmation follow the same end‑to‑end encryption principles described in Section 5.1. Specifically, the photo is encrypted on the signer’s device before transmission, and Signfortress does not possess the keys required to decrypt it. The encrypted file is stored only in ciphertext form and is accessible exclusively to the sender who initiated the request. Signfortress cannot determine how long the sender retains the photo; retention is governed entirely by the sender’s own data management practices. If the sender deletes the photo, the encrypted file is permanently removed from our systems.

5.5 Cloud Storage (Pro & Premium Plans)

When you choose to store documents in your personal Microsoft OneDrive, Google Drive, or Dropbox account, files are uploaded directly to your account and removed from our servers immediately after processing. You retain full control and may revoke access at any time.

While we strive to maintain a high level of security, no system is completely immune to risk. In the event of a security incident, we will notify affected users as required by applicable law.

6. Data Retention and Deletion

We retain data only as necessary:

  • Account Data: Retained while your account is active; deleted within 30 days of closure request.
  • Documents: Free plan: 90 days post-expiration; Pro/Enterprise: indefinite unless deleted by you.
  • Usage Logs: 12 months for security; anonymized thereafter.
  • Backup Data: Retained up to 90 days in encrypted backups.

You can request deletion at any time by emailing Support. We'll comply within legal timelines (e.g., 45 days under CCPA).

6.1 Signer Photo Retention

Signer photos are encrypted end‑to‑end and accessible only to the sender. Signfortress does not control or determine the retention duration for these files and cannot delete them on your behalf. To request deletion of your photo, please contact the sender directly. When the sender deletes the photo, the encrypted file is permanently removed from our systems.

7. Your Privacy Rights

Depending on your location, you have rights under GDPR, CCPA, PIPA (British Columbia, Canada), and similar laws:

  • Access: Request a copy of your data.
  • Rectification: Correct inaccurate information.
  • Erasure ("Right to be Forgotten"): Delete your data (subject to legal holds).
  • Restriction/Objection: Limit processing or object to certain uses (e.g., marketing).
  • Portability: Receive data in a structured format.
  • Withdraw Consent: For consent-based processing.
  • Non-Discrimination: No retaliation for exercising rights (CCPA).
  • Under PIPA (BC, Canada): Access, correction, and withdrawal of consent; contact us for details.

To exercise rights, email Support with verification. We'll respond within 30 days (or 45 for complex requests). Appeals available via the same email.

8. International Data Transfers

Signfortress primarily processes data in Canada via secure Canada-based data centers. For transfers from the EU/UK/Switzerland or Canada (including BC under PIPA), we use:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Binding Corporate Rules (BCRs) for intra-group transfers.
  • Adequacy decisions where applicable.

You can request details on transfer mechanisms via our privacy contact.

9. Children's Privacy

The Service is not directed to individuals under 13 (or 16 in some jurisdictions, including higher ages under certain Canadian provincial laws like BC's PIPA). We do not knowingly collect personal data from children. If we discover such data, we'll delete it promptly. Parents/guardians can contact us to review or remove child data. For verification, provide proof of guardianship.

10. Cookies and Tracking

We use cookies for essential functions (e.g., authentication) and optional analytics/marketing. You can manage preferences via browser settings or our cookie banner. For detailed info, see our Cookie Policy.

11. Changes to This Privacy Policy

We may update this Policy to reflect changes in our practices or laws. Material updates will be notified via email (for registered users), in-app notifications, or prominent website posting at least 30 days in advance. Continued use after changes constitutes acceptance.

12. Contact Us

For questions, rights requests, or concerns, email Support.

Scroll to Top
Scroll to Top