This Privacy Policy explains how SignMyLetters ("we", "us") handles information when you use our website and services at signmyletters.com (the "Service"). By using the Service you agree to the practices described here.
1. Information we collect
- Account information — your name, email address, and password (stored only as a secure hash).
- Business information — business name, DBA, EIN, owner name, address, and contact details you provide during onboarding.
- Verification documents — government-issued identity documents you upload for business verification (KYC).
- Documents & content — the letters, contracts, letterheads, and related content you create or upload.
- Signature data — typed, drawn, uploaded, or certificate-based signatures, plus signer name, email, and the date/time of signing.
- Payment information — wallet balances and transactions. Card details are handled by our payment processor; we do not store full card numbers.
- Technical & usage data — IP address, device/browser information, and activity logs used for security and audit purposes.
2. How we use information
- To provide the Service — creating documents, routing them for signature, and generating signed PDFs.
- To verify businesses and prevent fraud and abuse.
- To process payments and maintain your wallet.
- To send transactional email (verification, signing requests, reminders, and completion notices).
- To maintain a tamper-evident audit trail of document and account activity.
- To secure, operate, and improve the Service and to comply with legal obligations.
3. How we protect information
Traffic is encrypted in transit with TLS. Sensitive fields — including identity documents, signature images, EINs, and configured secrets — are encrypted at rest using AES-256-GCM. Passwords are hashed with argon2id. Access is role-based and least-privilege. See our Security page for details.
4. When we share information
We do not sell your personal information. We share it only as needed to run the Service:
- Signers you designate receive the documents and signing links you send them.
- Service providers — our payment processor, email/SMTP provider, and hosting/infrastructure providers, acting on our behalf.
- Legal — where required by law, regulation, or valid legal process, or to protect our rights and users.
5. Data retention
We retain your account, documents, and audit records for as long as your account is active and as needed to provide the Service, resolve disputes, and meet legal requirements. Verification documents are retained only as long as necessary for compliance. You may request deletion of your account and associated data, subject to records we are required to keep.
6. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact privacy@signmyletters.com.
7. Cookies
We use only the cookies and local storage necessary to keep you signed in and to operate the Service. We do not use advertising trackers.
8. Children
The Service is intended for businesses and is not directed to individuals under 18.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date, and where appropriate we will notify you.
10. Contact
Questions about privacy? Email privacy@signmyletters.com or visit Contact.