Privacy Policy
Version 2026-07-28 · Last updated July 28, 2026
This policy explains how SwiftSign handles personal information across the website, dashboard, API, MCP server, document-delivery, and signing experiences.
1. Scope and our role
This policy applies when SwiftSign determines why and how personal information is processed, such as account, billing, support, website, and service-security data.
For documents, recipient details, fields, and signing workflows submitted by a customer, the customer generally determines the purpose of processing and SwiftSign processes the information on the customer’s behalf. If you received a signing request, contact the sender first for questions about the document or their use of your information. Our Data Processing Addendum covers that processor relationship.
2. Information we collect
- Account information: name, email address, authentication records, organization details, settings, API-key metadata, and session information.
- Billing information: plan, subscription, invoice, billing-contact, and transaction status. Payment-card details are collected and processed by Stripe rather than stored by SwiftSign.
- Document and workflow information: uploaded files, templates, document URLs, recipient names and email addresses, routing order, fields, field values, messages, and webhook configuration.
- Signing and audit information: consent records, signatures, timestamps, IP address, user agent, approximate location derived from network information, signing method, document hashes, and events used to create the audit trail and Certificate of Completion.
- Usage and device information: API requests, feature use, pages viewed, diagnostic events, request identifiers, browser and device data, and rate-limit or abuse-prevention signals.
- Communications: support requests, feedback, abuse reports, and other correspondence.
3. Sources of information
We collect information directly from account holders and signers, from customers that send documents or use the API, automatically from browsers, devices, and service activity, and from providers involved in authentication, billing, email delivery, hosting, security, and support.
4. How we use information
We use personal information to:
- create and secure accounts, authenticate users, and manage API access;
- prepare, send, display, sign, seal, store, verify, and deliver documents;
- generate signing audit trails and Certificates of Completion;
- process subscriptions, invoices, and account administration;
- send service, security, signing, and transactional communications;
- prevent spam, fraud, credential abuse, and other prohibited activity;
- troubleshoot, monitor reliability, support users, and improve the service; and
- comply with law, enforce agreements, and establish, exercise, or defend legal claims.
Depending on the context and applicable law, we rely on performance of a contract, consent, compliance with legal obligations, and our legitimate interests in operating and securing the service. Where we rely on consent, it may be withdrawn subject to legal and contractual limits.
5. Cookies and similar technology
SwiftSign uses cookies and comparable local-storage or session technologies that are necessary to authenticate users, protect accounts, remember service state, and operate the dashboard and signing flow. We do not use this information to sell personal information or for cross-context behavioural advertising.
You can control cookies through your browser, but blocking necessary cookies may prevent sign-in or other service features from working.
6. How we disclose information
We may disclose information:
- to senders, recipients, account administrators, and other participants as required by the document workflow;
- to service providers that host, store, transmit, bill, secure, monitor, or support SwiftSign, listed on our Subprocessors page;
- when required by law or reasonably necessary to protect rights, safety, users, recipients, or service integrity;
- in connection with a merger, financing, reorganization, or sale, subject to appropriate confidentiality protections; and
- with your direction or consent.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
7. International processing
SwiftSign and its service providers may process information outside your province, state, or country. As a result, information may be subject to the laws and lawful-access requirements of those jurisdictions. Where required, we use contractual and other safeguards for cross-border transfers.
8. Retention and deletion
We retain personal information only as long as reasonably necessary for the purposes described in this policy, including to provide the service, preserve account and signing records, comply with law, resolve disputes, prevent abuse, and enforce agreements. Retention depends on the data, account status, customer instructions, legal requirements, and whether a record forms part of a completed signing audit trail.
Account holders may request deletion by emailing support@swiftsign.ca from their account address. We may retain limited information when required by law or necessary for security, fraud prevention, payment records, legal claims, or the integrity of completed transactions. Backup copies are deleted on their normal rotation schedule.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transport, access controls, credential hashing, audit records, rate-limiting, and service monitoring. No system is completely secure, and we cannot guarantee absolute security.
If you believe an account, API key, signing link, or document has been compromised, contact support@swiftsign.ca promptly.
10. Your privacy choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; withdraw consent; restrict or object to processing; or complain to a privacy regulator. We will not discriminate against you for exercising a privacy right.
Send a request to support@swiftsign.ca. We may need to verify your identity and authority before completing it. If SwiftSign holds the information only for a customer, we may refer the request to that customer. Rights may be limited by law and by the rights of other people.
11. Children
SwiftSign is a business service and is not directed to children. We do not knowingly collect personal information from a child who cannot lawfully consent to the processing. If you believe a child has provided information improperly, contact us.
12. Changes to this policy
We may update this policy as the service or law changes. The version and date above show the latest revision. We will provide additional notice of material changes when required.
13. Contact and complaints
Questions, requests, or complaints may be sent to our privacy contact at support@swiftsign.ca. We will investigate and respond within the time required by applicable law.
You may also have the right to complain to the Office of the Privacy Commissioner of Canada or another privacy authority in your jurisdiction.