Privacy Policy

Our privacy policy and how we use your data

1. Who we are

Signatoro is operated by SecOne Inc., a Delaware C Corporation. We are the data controller for the personal data described in this policy. This policy explains what we collect when you visit signatoro.com or use the Signatoro service, why, and the choices you have.

2. What we collect

  • Account data: your name, email address and password (stored as a hash), and, if you sign in with Google, the profile information Google shares with us.
  • Content you provide: the data, documents and settings you create or upload while using the service.
  • Billing data: plan, invoices and payment status. Card details are collected and stored by Stripe, our payment processor, not by us.
  • Usage and device data: pages visited, actions taken in the service, browser type, approximate location derived from IP address, and error logs.
  • Ad click data: if a link from one of our ads brought you here, its click ID and campaign details (such as the campaign and the search term). With advertising cookies on we keep them in a cookie for 90 days, and when you create a company or pay we store them with your company and your payment record.
  • Communications: emails you send us and transactional emails we send you (sign-up confirmation, password resets, invitations).
  • Cookies: see our Cookie Policy for the exact cookies and how to control them.

3. How we use it, and on what legal basis

  • To provide the service you signed up for, including authentication, storing your content and billing (performance of a contract).
  • To keep the service secure: fraud prevention, abuse detection, logging and backups (legitimate interests).
  • To understand and improve the service through analytics and session replay, only with your consent where consent is required (consent, or legitimate interests where permitted).
  • To measure our advertising: which ads lead to sign-ups and paid plans, and showing our ads to people who visited our site, through the Google Ads tag (consent where consent is required; elsewhere legitimate interests, with a way to opt out - see the Cookie Policy).
  • To communicate with you about your account and changes to the service (performance of a contract / legitimate interests). Marketing email is sent only if you opt in, and every message has an unsubscribe link.
  • To comply with law, including tax and accounting obligations (legal obligation).

4. Who we share it with

We do not sell personal data. We share it only with processors that help us run the service, under contracts that restrict their use of it:

  • Supabase (database, authentication and file storage; hosted in the United States, us-east-1).
  • Vercel (application hosting, DNS and edge network).
  • Stripe (payments and invoicing).
  • Resend (transactional email delivery).
  • Google Analytics and Microsoft Clarity (site analytics and session replay, loaded only after you accept analytics cookies).
  • Google Ads (advertising measurement and ad audiences, only while advertising cookies are on). When you buy a plan, it may also receive your email address as a one-way SHA-256 hash, made in your browser, used only to match the purchase to an ad click.
  • PostHog (product analytics, error reporting and the support chat and support email inbox, hosted in the EU; analytics run without cookies until you accept analytics cookies). Support messages are stored with the pages you visited and errors you ran into, so we can see what went wrong.
  • Google, if you choose to sign in with your Google account.

We may also disclose data when the law requires it, to protect our rights or the safety of users, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to your data.

5. International transfers

Our servers and most of our processors are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States under the processors' Standard Contractual Clauses or an equivalent lawful mechanism, and we take reasonable steps to protect it in line with this policy.

6. How long we keep it

  • Account and content data: for as long as your account exists. When you delete your account, we delete or anonymize it within 30 days, except where we must keep it longer.
  • Billing records: 7 years, to meet tax and accounting rules.
  • Server and security logs: up to 90 days.
  • Analytics data: per the retention settings of the analytics provider, currently up to 14 months for Google Analytics.
  • Ad click data: 90 days in the first-visit cookie; stored with your company and payment records for as long as those are kept.

7. Security

Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to production systems is limited to staff who need it and protected by multi-factor authentication. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as the law requires.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent at any time (which does not affect processing already done). You can change or delete most account data yourself in account settings, and withdraw analytics or advertising consent at any time with Cookie settings (see the Cookie Policy). For anything else, email us at the address below; we respond within 30 days. You also have the right to complain to your local data protection authority. California residents have the rights set out in the CCPA/CPRA, including to know what we collect and to request deletion. We do not sell personal data. While advertising cookies are on, the Google Ads tag shares data about your visit with Google to measure our ads and show them to past visitors, which California law may treat as "sharing" for cross-context behavioural advertising. You can opt out at any time with Cookie settings or by sending a Global Privacy Control signal from your browser.

9. Children

The service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We will post any changes here and update the date below. For material changes we will also notify you through the service or by email before they take effect.

11. Contact

Legal entity: SecOne Inc., a Delaware C Corporation (EIN 39-3563209), incorporated on July 31, 2025. SecOne Inc. owns and operates Signatoro.

Contact: ceo@signatoro.com
Website: signatoro.com
Response time: we aim to answer within two business days.


Last updated: September 27, 2026