Legal
Privacy Policy
Effective September 9, 2026
What we collect
Account holders: email address, password hash, organization details, API usage. Signers: name and email supplied by the sender, the values they enter, their signature image, and — for the audit trail — IP address, browser user agent and timestamps of each action.
Why we collect it
To deliver signing requests, to produce completed documents, and to create the legally required record of who signed what, when and from where. Audit data is retained as part of the document’s evidence.
Who sees it
The organization that sent the document sees the signer’s data and audit trail. Signers receive their completed copy. We use Resend to deliver email and AiroBase (Airosofts infrastructure) to store data. We do not sell personal data.
Cookies and storage
The dashboard uses a session token for signed-in users. Signing pages set no tracking cookies; a browser-local key remembers unsaved progress.
Retention
Documents and audit trails are kept until the organization archives or deletes them, subject to our terms. Dedicated instances can set their own retention.
Your rights
You may request access to or deletion of personal data we hold about you. Where a document is part of a completed agreement, deletion may be limited by the sender’s legal retention duties. Contact admin@airosofts.com.
Security
Data is encrypted in transit, stored in private buckets and a row-level-secured database, and API keys are stored only as hashes. See the Security page for more.