Privacy Policy
Last updated: January 2026
1. Introduction
Thank you for your interest in CanUSign. Protecting your personal data is important to us. This privacy policy informs you about the processing of personal data when using our service.
2. Data Controller
3. Data We Collect
We collect the following data:
- Account data: Email address for authentication
- Contract data: Contracts and documents you create
- Signature data: Digital signatures, IP addresses, timestamps
- Usage data: How you use our service
- Payment data: Processed securely via Stripe
4. Purpose of Data Processing
Your data is used to:
- Provide our contract service
- Process digital signatures
- Create audit certificates as proof
- Process payments
- Improve our service
5. Legal Basis
Processing is based on Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(a) GDPR (consent), and Art. 6(1)(f) GDPR (legitimate interest).
6. Data Storage & Security
Your data is encrypted and stored on secure servers in the EU. We use industry-standard security measures. Signed contracts are stored according to legal retention requirements.
7. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right to access your stored data
- Right to rectification of inaccurate data
- Right to deletion of your data
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw your consent
8. Third-Party Services
We use the following third-party services:
- Stripe: Payment processing (USA, Privacy Shield)
- Resend: Email delivery (USA)
- Vercel: Hosting and infrastructure (USA)
- Neon: Database hosting (EU)
9. Cookies
We only use technically necessary cookies for authentication and session management. We do not use tracking or advertising cookies.
10. Contact
For privacy-related questions, contact us at: contact@canusign.com