Privacy Policy
Last updated 21 August 2026
This policy explains what personal data Putmysign ("we", "us") collects when you use Putmysign, why we collect it, how long we keep it, and the choices you have. It covers both account holders who send documents and recipients who are asked to sign them.
1. Data we collect
Account holders. Name, email address and authentication identifiers from the sign-in provider you choose (email/password or Google); the documents, versions and comments you upload or write; billing status, subscription and customer identifiers from our payment provider (we never see your full card number).
Recipients. The name and email address the sender enters; whether and when you opened, commented on, approved or declined a document; and, when you sign, your signature (typed name, drawn or uploaded image), the consent text you agreed to, the time, your IP address and browser user agent, and cryptographic hashes of the signature and document. This is the evidence that makes an electronic signature verifiable.
Technical data. Server logs (IP address, request path, timestamp, user agent) used for security and rate limiting. We do not use advertising cookies or third-party analytics trackers. We use a strictly necessary session cookie to keep you signed in and a local preference for light/dark theme.
2. How we use data
- to provide the Service: store documents, deliver signing links, record approvals and generate the finalised signed PDF;
- to send transactional emails: invitations, reminders, activity notices and completion notices (we do not send marketing email);
- to manage subscriptions and payments through our merchant of record;
- to secure the Service: prevent abuse, enforce rate limits and investigate misuse;
- to comply with legal obligations and enforce our Terms.
Where the GDPR or similar laws apply, our legal bases are performance of a contract (providing the Service), legitimate interests (security, evidence of signatures, service improvement) and legal obligation. Signature evidence is retained because it is necessary to establish the validity of the agreement you signed.
4. Retention
- Uploaded and signed PDFs — 5 days after sending on the Free plan; for the life of the subscription plus a 30-day grace period on Pro. Expired files are deleted from storage by a scheduled job.
- Document metadata and audit log (who did what, when, from which IP) — kept while the account exists, because it evidences the agreement.
- Account data — until you delete your account, after which documents, files and billing mappings are erased; audit logs are anonymised or deleted unless we must keep them to comply with law.
- Server logs — up to 30 days.
5. Security
Files are stored as authenticated assets and served only through authorised, same-origin routes. Signing links use 256-bit random tokens; only hashes are stored for lookup and encrypted copies for the sender. Finalised PDFs include hashes of the original and final files. Access to production systems is restricted and credentials are stored server-side only.
6. Your rights
Depending on where you live you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. Account holders can delete their account from Account settings. Recipients can contact us to ask what we hold; note that signature evidence attached to a completed agreement may be retained by the sender as the lawful record of that agreement.
To exercise any right, email support@putmysign.com. If you are in the EU/UK you may also complain to your local data protection authority.
7. International transfers
Our processors may store data in the United States and the European Union. Where required we rely on standard contractual clauses or equivalent safeguards.
8. Children
The Service is not directed to children under 16 and we do not knowingly collect their data.
9. Changes and contact
We will post any changes to this policy on this page and, for material changes, notify account holders by email. Questions: support@putmysign.com.