Acceptable Use Policy
Last updated July 28, 2026
This policy is part of the Terms of Service and applies to every SwiftSign account, API key, integration, document, and signing request.
1. Lawful and authorized use
You may not use SwiftSign to:
- violate law, regulation, court order, contract, intellectual property, privacy, publicity, or other rights;
- impersonate a person or organization, forge authority, falsify an audit trail, or misrepresent who sent or signed a document;
- send fraudulent, deceptive, coercive, exploitative, or misleading documents or signing requests;
- sign on another person’s behalf without valid authorization; or
- use electronic execution for a document that applicable law excludes or subjects to unmet signing, consent, witnessing, notarization, delivery, or retention requirements.
2. Recipient protection and messaging
You may not:
- send unsolicited bulk signing requests, spam, phishing, malware, or messages unrelated to a legitimate document workflow;
- harvest, buy, or use recipient data without a lawful basis and appropriate notice;
- use misleading subject lines, sender identities, domains, or document descriptions;
- repeatedly contact a recipient who has objected, declined, or asked not to receive further requests; or
- use the service to threaten, harass, discriminate against, or exploit a person.
3. Sensitive and regulated data
You may not submit protected health information, full payment-card data, government identification numbers, financial-account credentials, biometric identifiers, children’s data, or other regulated or highly sensitive information unless you have confirmed that the service, your plan, and your configuration are appropriate and you have all required agreements, notices, consents, and safeguards.
SwiftSign is not represented as compliant with a specialized regime such as HIPAA, PCI DSS storage requirements, or qualified electronic signatures under eIDAS unless SwiftSign has expressly agreed to that use in writing.
4. System and service integrity
You may not:
- probe, scan, or test the service for vulnerabilities without written authorization;
- disrupt the service, introduce malicious code, or interfere with another user or recipient;
- bypass authentication, confirmation gates, rate limits, quotas, plan restrictions, or safety controls;
- reverse engineer the hosted service except where the restriction is prohibited by law;
- use automated means that impose an unreasonable load or create abusive sending patterns; or
- resell, sublicense, or provide shared access to the service except as permitted by your plan or a written agreement.
5. Enforcement
We may investigate suspected violations and may rate-limit, block, remove, quarantine, or preserve content; revoke credentials; or suspend or terminate access. We consider the severity, recurrence, recipient impact, legal risk, and whether immediate action is needed to protect people or systems. Where appropriate, we will provide notice and an opportunity to respond.
We may report suspected unlawful conduct to affected parties or authorities and preserve relevant information as permitted or required by law.
6. Reporting abuse
Report suspicious signing mail, fraudulent documents, impersonation, or other abuse to abuse@swiftsign.ca. Include the envelope link or message headers when safe to do so. For account-support questions, email support@swiftsign.ca.