SignTulip

Privacy Policy

Effective: 2026-10-01

SignTulip (“we”) respects your privacy. This policy explains what personal data we process and why.

1. Data we process

  • Account holders: name, email, password (hashed), company (optional), saved signature (optional).
  • Signers: name, email, signature images and information entered while signing.
  • Collected automatically: IP address, browser/device information, view and signing timestamps (audit trail), cookies.

2. Purposes

  • Providing the Service (sending, signing, delivering completed documents), maintaining an audit trail that proves authenticity and integrity, customer support and improving the Service.

3. Retention

  • Account data is kept until you delete your account. Documents and audit records are kept until the document owner deletes them or closes their account, unless the law requires longer retention.

4. Processors and international transfers

  • We use Supabase Inc. (database, storage, authentication), Vercel Inc. (hosting), Resend (email delivery) and payment providers (Toss Payments, Paddle). Data may be stored outside your country with appropriate safeguards.

5. Sharing

  • We do not sell personal data or share it with third parties except with your consent or where required by law. Senders and signers can see each other's names and emails as needed to process a document.

6. Your rights

  • You can access, correct or delete your data at any time. Profile editing and account deletion are available in Settings.

7. Security

  • TLS in transit, encryption at rest, private storage with row-level access control, unguessable signing tokens and hashed passwords.

8. Cookies

  • We only use essential cookies for sign-in, language and time zone. We do not use advertising cookies.

9. Contact

  • Privacy contact: hello@signtulip.com