About this Policy
This Privacy Policy explains how the Service Administration of onlinesignatures.net (the "Service", "we") processes user data. By using the Service you confirm that you have read this Policy and agree to the processing of data as described. Payments are handled by our payment provider; we do not store bank card details.
What data we process
Account data
When you create an account we process your email, your name (if provided) and an encrypted password. This data is used to give you access to the Service and to keep your account secure.
Usage and technical data
We process data about how you use the Service: created signatures, uploaded documents, shared-document links, operation history and generation logs, as well as technical data such as IP address (which may be stored in an anonymized/hashed form), device and browser type, time zone, language and cookies. We process this data, among other purposes, to secure the Service, prevent fraud and abuse, and resolve disputes.
Cookies
We use strictly necessary, analytics and advertising cookies. Strictly necessary cookies are always on; analytics and advertising cookies are used only with your consent. You can change your choice at any time via the cookie banner or the "Cookie settings" link, and doing so does not affect your access to the Service.
Sharing with third parties
We share data only with trusted processors and only to the extent needed to run the Service: the payment provider (to process payments and refunds), the email provider (to deliver messages), the hosting provider (to host the Service) and analytics/advertising providers (only with your consent). We do not sell your personal data. We may also disclose data to competent authorities, courts or the payment provider where required by law, to prevent fraud and abuse, or to establish, exercise or defend legal claims.
Where files are stored and who processes them
The files you create or upload — signature images, documents for signing, shared-document links, profile photos and logos — are stored in Cloudflare R2 object storage, and part of the processing (rendering the signature image, delivering files through protected links) runs on the Cloudflare Workers network. We engage Cloudflare as a data processor: under the data processing agreement concluded with it, Cloudflare may process the files only on our instructions and in order to provide the services to us. Cloudflare's infrastructure is global, so data may be processed on servers outside your country, including outside the EEA; such transfers are carried out on the basis of Cloudflare's data processing agreement and standard contractual clauses. Links to files are signed and valid for a limited time, and direct access to the storage is closed. Where protection is enabled, Cloudflare may set a technical security cookie (for example __cf_bm). We classify it as strictly necessary and, according to Cloudflare's documentation, it serves to protect the site from automated requests and is not used for advertising profiling. Our other processors are: the payment provider (Paddle), the email provider, the hosting provider and — only with your consent — analytics and advertising services. Processing by our processors is additionally governed by their own privacy policies, the current versions of which are published on their websites; we are not responsible for their own actions outside our instructions.
Data retention
We keep account data while your account exists and for a reasonable period afterwards to resolve disputes and meet legal obligations. Payment and tax records are kept for the periods required by law. Support and download logs are kept for up to 24 months as evidence for disputes; technical logs are kept for a limited period. After these periods data is deleted or anonymized. If an account remains inactive for a long period (by default 12 months), we may first notify you by email and then delete or anonymize the account and its personal data; payment and tax records are retained for the periods required by law.
How long files are kept
A document sent for signing is kept exactly as long as the link you chose — 24 hours, 7, 14 or 30 days (on the Free plan, 24 hours). When that period ends, the document itself, its pages and the small preview copies are deleted automatically, usually within an hour, and the recipient link stops working. Signatures saved in your account are kept until you delete them yourself or for as long as the account exists. Service records of generation jobs and the temporary result files are deleted automatically (by default after 7 days). A signature photographed with the camera is processed right in your browser and is not uploaded to our servers.
Your rights
Depending on the applicable law (including GDPR) you may request access to your data, correct or delete it, restrict processing, withdraw consent and lodge a complaint with a supervisory authority. To exercise these rights, contact us by email. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Data security
We apply reasonable technical and organizational measures (password encryption, access control, protected data transfer). However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children and changes to this Policy
The Service is not intended for persons under 16 (or another age set by local law), and we do not knowingly collect their data. We may update this Policy; material changes are published on the site with the update date, and continued use of the Service means acceptance of the updated Policy.
Access to Accounts for Support and Security
To provide technical support, investigate issues, and keep the Service secure, authorized administrators may access a user's account, including temporarily signing in as the user. Such access is granted only when necessary, limited to what is required, and recorded in an internal audit log (who accessed which account, when the access started and ended, and the IP address). We do not use this access to read or use your content for any purpose other than support, security, and compliance with the law.
API request data
When you use our public API, we record technical data about each request — the IP address, an approximate country derived from it, the client program (e.g. the User-Agent), the API key used and the time. We use this data solely to operate, secure and meter the API and to prevent abuse, on the basis of our legitimate interest. These records are kept for up to 90 days and then automatically deleted.
Account Deletion and Data Retention
You can delete your account at any time in your profile. When you do, we permanently erase your personal data — your name, photo, e-mail, Telegram link and login (IP) history — and it cannot be restored. If you have an active paid subscription, it is cancelled immediately, so your card is not charged again. Only where the law requires it, and for a limited time, we keep payment and invoice records (for tax), any refund or dispute materials, and a minimal non-personal deletion record (a masked e-mail and your account ID) with a small activity snapshot retained for up to 180 days to defend payment disputes; after that the snapshot is deleted automatically. Documents you submitted as legal evidence may be retained where the law requires. Legal basis: GDPR Art. 17(3) — a legal obligation (tax) and the defence of legal claims.
Contact
If you have any questions, comments or requests regarding this Privacy Policy, please contact us through the Contact Us page. Full details of the Service Administration are provided on request.