Legal

Privacy Policy

How we collect, use, and protect your data.

Last updated: April 2026
Key point: We do not access, read, or store the contents of your signed documents. Your files are processed in memory, signed, and returned — never stored on our servers beyond the signing operation.

1. Information We Collect

Account Information: Name, email address, company name, billing address when you register or purchase our services.

Usage Data: API call counts, signing statistics, error logs, IP addresses, and timestamps for service monitoring and billing.

Technical Data: Hardware ID (for license binding), operating system version, software version.

Payment Data: Processed through third-party payment processors. We do not store credit card numbers.

Social Login: If you register or sign in via Google, Facebook, or GitHub, we receive your name and email address from that provider to create or link your account. We never receive your password from these providers.

2. Information We Do NOT Collect

3. How We Use Your Information

4. Data Storage and Security

Your account data is stored on secure servers in Singapore. We implement industry-standard security measures including:

5. Hardware Token Storage (Optional Cloud Service)

For customers using our optional cloud signing service (available on request) who send USB tokens to our facility:

6. Data Sharing

We do not sell, trade, or rent your personal information. We may share data with:

7. Data Retention

We retain account data for the duration of your account plus 12 months. Signing logs are retained for 90 days. You may request deletion of your data at any time by contacting us.

8. Your Rights

You have the right to:

9. Cookies and Analytics

Our website uses the following cookies and similar technologies:

We do not use third-party advertising cookies.

10. Children's Privacy

Our services are not intended for individuals under 18 years of age.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or platform notification.

12. Contact

For privacy inquiries or data requests, contact our Data Protection Officer at dpo@onesign.sg.