
Data processing
Last updated 26 September 2026.
What this page is, and what it is not. When a business sends documents through SignSealer, the business decides what happens to the people it sends them to — it is the controller — and we handle their information for it, as its processor. This page says what we do in that role, as far as the product and our own records make it true today.
It is not a signed data processing agreement. Ours is drafted and waiting on legal review. Until one is signed with you, our terms of service are the agreement, and this page describes how we meet them. To ask for a signed DPA, email privacy@signsealer.com.
Who is who
SignSealer is operated by Mashdun LLC. For the documents a business sends and everything its signers give us, the business is the controller and we are its processor: we handle that information on the business's instructions and for no purpose of our own. We do not sell it, and we do not train models on it. That is what the terms say, and this page adds nothing to them.
We are the controller of a smaller set: the account details of the business's own staff, and what we hold about visitors to this website. Those are covered by the privacy policy, not here.
What we handle for a business
About the people a business sends documents to, and only what the business's documents and settings ask for:
- their name, and the email address or mobile number the document went to;
- the document, and their answers to its questions;
- their signature — typed, drawn or uploaded — and their consent to sign electronically;
- when they opened, consented, signed or declined, the network address they did it from, and their browser's description of itself;
- if the business asks for them: photographs as answers, a photograph of an ID and of the person, and the location they chose to share;
- whether they agreed to be texted and the exact words they agreed to, and the messages sent to them.
We use it to deliver the document, take the signature, send the signed copy, and keep the record that proves who signed what and when — certificate included. We do not ask signers for anything else, and the terms say a business may not send us card numbers, or health records it handles under a business associate agreement we have not signed.
Where it is
Stored and processed in the United States. The database is at Supabase, in its US West (Oregon) region, and our servers run at Railway, in its US East (Virginia) region. The companies that send email and texts for us, and the one that receives our error reports, are in the United States too. The one part that is not in one place is Vercel, which serves this website and passes the signing pages and the app through to our servers from whichever point of its network is nearest the visitor.
A business in the EU, the UK or Switzerland that sends us a signer's information is transferring it to the United States. The Standard Contractual Clauses that cover that transfer belong in a signed DPA, so if that is you, ask for one before you rely on this page.
Who else handles it
A short list of companies — the database, the servers, the website, email, texts, payments, error reports — each named, with what it is handed and where it is, in our subprocessor list. A new one that would see customer data is added there before it starts to, and takes on the same obligations we have to you. A notice period you can hold us to, and a way to object, come with a signed DPA.
How it is protected
What is built and tested, from our security documents:
- One business cannot reach another's data. The rule is in the database itself, as row-level security on every table that holds customer data, and our tests try every way round it from a second business's session.
- Credentials are never stored as themselves. Keys, signing links and sign-in codes are kept as hashes; secrets we have to replay, and photographs, are encrypted with keys that are not in the database.
- The evidence cannot be edited. The record of each signature is append-only and chained, so a change after the fact is detectable rather than arguable.
- Our own staff tools cannot show document text or signer names, and every look our staff take at a business's account is recorded. Staff access to an account is granted per account, for a set time, and ends by itself.
- In transit, it is encrypted, and every one of our hosts tells the browser never to connect to it unencrypted.
- Logs and error reports are trimmed. Error reports carry no request headers, bodies or cookies, and the worker that sends mail logs an address only as its domain.
And what is not done yet, because a page like this should say: no independent audit (we are preparing for SOC 2, and have not had one), no penetration test, no restore from our database host's own backups, and no rehearsal of the incident procedure.
How long it is kept
- Signed documents are kept for the period the business sets — seven years unless it changes it, never less than one and never more than twenty. When a finished document passes it, the text, the people and their answers and photographs are removed on a sweep we run every hour; the fingerprint of the text, the times and the trail stay, so a certificate still proves what it proved.
- Message bodies — the text of an email or a text — go after thirty days by default, which the business can set from one day to a year.
- A photograph of an ID, and the photo of the person that can go with it, are kept for thirty days, then removed; their fingerprints stay on the record.
- A business can remove the people from a finished document sooner, at a signer's request, from the document's page.
- When a business closes its account it can download everything it holds first, and thirty days after closing its documents are redacted the same way.
- Backups are our database host's, and roll off on its schedule, so a removal reaches them later than it reaches the live record.
The detail, including exactly what is removed and what stays, is on data retention and deletion.
When a signer asks
A signer's rights are against the business that sent them the document, and the business has what it needs to answer: it can export what it holds, and remove a signer from a finished document. If a signer writes to us instead, we pass it to the business rather than act on it ourselves.
If something goes wrong
If we find that a business's data has been reached by somebody who should not have reached it, we tell that business without undue delay, in plain words: what happened, and what we know about what was reached. How we contain and look into an incident is on incident response.
Asking for a signed DPA
Email privacy@signsealer.com with your business's name and the address on your account. We will send you ours when it has been through legal review. If your organisation has its own, send it, and we will tell you what we can agree to. Anything else about how we handle data goes to the same address.
Changes
This page carries the date it last changed. The subprocessor list carries its own.

Ready when the next guest is.
Free for the first 25 agreements a month. No card to start.