✓GetSimpleSign
ProductTerms

GetSimpleSign legal centre

Privacy Policy

How GetSimpleSign proposes to collect, use, disclose, retain, and protect personal information.

Draft date: August 8, 2026
On this page

Use your browser’s find command to locate a topic. Print styles are included for legal review.

Begin document
⚠ Draft for legal review

This is a product-specific privacy draft, not a statement of current production operations. Confirm the legal entity, vendors, locations, retention periods, and Privacy Officer before publication.

1Scope and accountability

This Privacy Policy describes the practices of [LEGAL ENTITY NAME] (“GetSimpleSign,” “we,” “us,” or “our”) for our website, applications, and electronic-signature service. Our designated Privacy Officer is accountable for personal information under our control and may be contacted at [PRIVACY OFFICER EMAIL].

When an organization sends a document through GetSimpleSign, that organization generally decides why the document and signer information are processed. It is responsible for collection and instructions, while GetSimpleSign acts as its service provider. Questions about document contents should normally be directed to the sender first.

2Information we collect

  • Account information: name, work email, organization, membership, role, authentication, and account-security records.
  • Agreement information: documents, templates, recipient names and email addresses, field assignments, signatures, signing intent, consent records, timestamps, status, and completed records.
  • Technical and security information: IP address, browser and device data, session identifiers, request identifiers, authentication attempts, audit events, and security logs.
  • Communications: support requests, feedback, delivery status, bounce information, and correspondence.
  • Billing information: plan, usage, invoices, and transaction identifiers. A payment processor may collect card details directly; GetSimpleSign should not store complete card information.
  • Website information: essential cookies and basic server logs. This draft assumes no advertising cookies or cross-site behavioural advertising.

3Sources

We receive information from account holders and Signers, organizations that send requests, browsers and devices, and service providers such as email-delivery, hosting, security, support, and payment providers.

4Purposes

  • Create and secure accounts and workspaces.
  • Upload, process, route, sign, finalize, store, and retrieve agreements.
  • Send verification, invitation, routing, reminder, completion, support, billing, and security communications.
  • Authenticate users, prevent fraud and abuse, investigate incidents, and protect the Service.
  • Maintain audit, usage, delivery, and completion records.
  • Provide support, diagnose errors, improve reliability, and understand aggregate usage.
  • Meet legal, tax, accounting, regulatory, and dispute-resolution requirements.
  • Carry out another purpose disclosed at collection or authorized by valid consent.

5Consent and choices

We seek meaningful consent where required, considering information sensitivity and reasonable expectations. A Signer must affirmatively agree to use electronic records and signatures before signing. A Signer may decline and contact the sender for an alternative.

You may withdraw consent to optional processing, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate prior lawful processing and may prevent use of some features.

6How we disclose information

We may disclose personal information:

  • To the Customer and authorized workspace users that initiated or administer the transaction.
  • To transaction participants as needed to display, route, complete, and evidence the agreement.
  • To vetted subprocessors providing hosting, object storage, email delivery, malware scanning, monitoring, support, and payments.
  • To professional advisers under confidentiality obligations.
  • To comply with valid legal process, protect rights and safety, investigate abuse, or complete a corporate transaction subject to safeguards.
  • With the individual’s direction or consent.

We do not sell personal information. This draft assumes we do not use document contents or signatures for advertising or train general-purpose artificial-intelligence models on them.

7Processing locations and transfers

The intended production architecture stores agreement PDFs in a private S3 bucket in Canada and stores application records in a protected SQLite deployment selected by the hosting arrangement. Some subprocessors—particularly email, support, monitoring, or payment providers—may process information outside Canada. Information processed elsewhere may be subject to that jurisdiction’s laws. Final locations and subprocessors must be published before launch.

8Retention

We retain information only as long as reasonably required for the stated purposes, documented Customer instructions, and legal obligations. These product defaults are policy settings, not legal advice, and organizations should confirm they fit their obligations.

Completed agreements and audit recordsSeven years by default.
Draft, declined, expired, or cancelled agreementsNinety days by default.
User deletionThirty-day recovery period before purge.
Account closureThirty-day export and reactivation period before the deletion process begins.
Billing, fraud, and legal recordsRetain only what remains necessary for the applicable purpose.

Deletion may be delayed by legal hold, dispute, statutory requirement, investigation, or backup cycle. We securely delete or de-identify information when retention ends.

9Safeguards

Safeguards are designed to be proportionate to sensitivity and include least-privilege workspace authorization, password hashing, single-use signer tokens stored as cryptographic hashes, encryption in transit, private object storage, file validation and scanning, controlled backups, audit events, monitoring, vendor assessment, and staff confidentiality. Final production claims must match deployed controls.

No safeguard eliminates all risk. Account holders must protect credentials, use accurate recipient addresses, and limit unnecessary information.

10Privacy incidents

We maintain a process to investigate, contain, document, and respond to suspected privacy breaches. Where required, we notify affected Customers, individuals, regulators, or other authorities and maintain breach records. Customer contracts should state incident communication responsibilities.

11Access and correction

You may request access to personal information under our control, ask how it has been used or disclosed, and request correction. We may need to verify identity and may refuse or limit access where law permits or requires, such as where disclosure would reveal another person’s information or protected privilege.

For information in an agreement sent by an organization, contact the sender first. You may also contact [PRIVACY OFFICER EMAIL]. We will respond within applicable legal timeframes.

12Cookies and analytics

Essential cookies may maintain sessions, security, language, and accessibility preferences. If optional analytics or marketing technologies are added, this Policy and the consent interface must be updated before activation. Browser controls can limit cookies, but disabling essential cookies may prevent sign-in or signing.

13Children

The Service is intended for organizations and adults. It is not directed to children. A Customer using the Service for a minor must have lawful authority and use an appropriate consent process.

14Changes

We may update this Policy to reflect legal, service, vendor, or security changes. The effective date will be updated and additional notice provided where changes are material or renewed consent is required.

15Questions and complaints

Contact the Privacy Officer at [PRIVACY OFFICER EMAIL] or [BUSINESS ADDRESS, ONTARIO, CANADA]. We will investigate and explain the outcome. You may also have the right to complain to the Office of the Privacy Commissioner of Canada or the applicable provincial authority.

Privacy sources considered

Confirm the current requirements and obtain legal review.

PIPEDA fair information principlesOPC privacy breach guidanceOPC processing across borders guidance
✓GetSimpleSign
PrivacyTerms