Legal

Privacy Policy

Effective September 9, 2026

What we collect

Account holders: email address, password hash, organization details, API usage. Signers: name and email supplied by the sender, the values they enter, their signature image, and — for the audit trail — IP address, browser user agent and timestamps of each action.

Why we collect it

To deliver signing requests, to produce completed documents, and to create the legally required record of who signed what, when and from where. Audit data is retained as part of the document’s evidence.

Who sees it

The organization that sent the document sees the signer’s data and audit trail. Signers receive their completed copy. We use Resend to deliver email and AiroBase (Airosofts infrastructure) to store data. We do not sell personal data.

Cookies and storage

The dashboard uses a session token for signed-in users. Signing pages set no tracking cookies; a browser-local key remembers unsaved progress.

Retention

Documents and audit trails are kept until the organization archives or deletes them, subject to our terms. Dedicated instances can set their own retention.

Your rights

You may request access to or deletion of personal data we hold about you. Where a document is part of a completed agreement, deletion may be limited by the sender’s legal retention duties. Contact admin@airosofts.com.

Security

Data is encrypted in transit, stored in private buckets and a row-level-secured database, and API keys are stored only as hashes. See the Security page for more.