Effective Date: May 26, 2026
Privacy Policy
- Company:
- SIGNBONA LLC
- Contact:
- privacy@signbona.com
This Privacy Policy explains how SIGNBONA LLC (“SignBona,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information when you use SignBona’s websites, applications, electronic signature tools, document workflows, billing features, verification pages, support channels, and related services (collectively, the “Services”).
SignBona is intended for users and transactions in the United States. This Privacy Policy is written for our current U.S. launch scope. If we later expand materially into additional jurisdictions, we may update this Privacy Policy and our related legal terms.
By using the Services, creating an account, uploading documents, inviting recipients, signing documents, accessing a signing link, verifying a completed document, contacting support, or otherwise interacting with SignBona, you acknowledge that we process personal information as described in this Privacy Policy.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal information we process in connection with the Services, including information about:
- account holders who create or manage SignBona accounts;
- signers, recipients, carbon-copy recipients, and other people invited to view, receive, or sign documents through SignBona;
- visitors to our website and public verification pages;
- people who contact us for support, billing, privacy, legal, or security matters; and
- people whose information appears in documents, templates, audit trails, certificates of completion, envelopes, or related records submitted to or generated through the Services.
This Privacy Policy does not apply to third-party websites, applications, or services that we do not control, even if they are linked from SignBona. Those third parties are governed by their own privacy policies.
2. Information We Collect
We collect personal information in several ways: information you provide directly, information generated through your use of the Services, information submitted by other users, information from service providers, and information collected automatically through technical tools.
2.1 Account Information
When you create or manage a SignBona account, we may collect:
- name;
- email address;
- password and authentication credentials, processed through our authentication provider;
- account identifiers;
- profile settings;
- avatar or profile image, if you upload one;
- language, time zone, region, date format, time format, and notification preferences;
- multi-factor authentication settings;
- hashed backup codes for account recovery;
- account status, account deletion requests, and account activity records;
- records showing your acceptance of our Terms of Service and Privacy Policy, including version numbers, timestamp, IP address, user-agent, email address, and source of acceptance.
2.2 Document, Envelope, Template, and Signing Information
When you use SignBona to upload, prepare, send, sign, store, or verify documents, we may collect and process:
- document titles and envelope names;
- uploaded PDF files and related document metadata;
- document page counts, file paths, file hashes, and integrity records;
- signature fields, initials fields, text fields, date fields, email fields, checkboxes, and other document fields;
- typed, drawn, uploaded, or otherwise submitted signatures and initials;
- values entered into document fields;
- user-created templates, reusable document setups, recipient roles, field placements, and related template metadata;
- custom messages, subjects, reminders, expiration settings, and workflow settings;
- final signed PDFs, stamped PDFs, certificates of completion, audit records, and verification records;
- document status, including draft, sent, in progress, completed, declined, expired, voided, archived, deleted, or retained status.
You are responsible for the documents, templates, and information that you upload or submit to SignBona. Documents may contain personal information, confidential information, financial information, legal information, business information, or other sensitive content. You should only upload documents and invite recipients when you have the right to do so.
2.3 Signer and Recipient Information
If an account holder invites you to sign, view, receive, or otherwise interact with a document through SignBona, we may process information provided by the account holder or generated during the signing process, including:
- name;
- email address;
- company, title, role, or position, if provided;
- recipient order and signing role;
- signing token and signing request status;
- whether you viewed, opened, signed, declined, or completed a document;
- timestamps of signing-related events;
- IP address and user-agent associated with signing-related events;
- electronic record and signature consent version, consent timestamp, consent locale, IP address, and user-agent;
- one-time passcode verification status, attempts, expiration, and related security metadata, where email verification is enabled;
- decline reason, if you choose to decline signing and provide a reason;
- delivery status information, such as email bounce or delivery-failure information.
2.4 Audit Trail, Security, and Verification Information
To support document integrity, legal evidence, fraud prevention, platform security, and verification, we may collect and generate:
- event logs for document creation, sending, viewing, consent, signing, declining, completion, reminders, voiding, and verification;
- IP addresses and user-agents associated with significant events;
- cryptographic hashes and integrity records;
- chained audit records designed to detect tampering;
- certificate serial numbers, fingerprints, signer certificate metadata, and related public-key infrastructure records;
- RFC 3161 timestamping metadata from our timestamp authority provider;
- public verification page status, such as valid, warning, or tampered indicators;
- security logs, rate-limit events, webhook verification records, and abuse-prevention records.
2.5 Billing and Subscription Information
SignBona offers a Personal plan with a 30-day free trial when a user registers. Payments and subscription billing are processed through Stripe. We may collect or receive:
- Stripe customer identifiers;
- subscription identifiers;
- selected plan;
- trial status;
- subscription status;
- billing period information;
- cancellation status;
- payment method brand and limited payment method details, such as last four digits and expiration information, where made available by Stripe;
- invoice, checkout, payment failure, and billing portal metadata.
We do not store full credit card numbers or full payment credentials on our own servers. Stripe processes payment information according to its own policies and applicable payment security requirements.
2.6 Support, Legal, Privacy, Billing, and Security Communications
If you contact us, we may collect:
- your name and email address;
- the content of your message;
- attachments or screenshots you provide;
- account, billing, document, or technical details needed to respond;
- records of our communications with you.
Please do not send sensitive document contents to support unless necessary for your request.
2.7 Cookies, Local Storage, and Similar Technologies
We may use cookies, local storage, session storage, and similar technologies to operate and improve the Services. These may include:
- authentication cookies used to keep you signed in;
- session and security cookies;
- locale or language preference cookies;
- pre-launch access cookies, where applicable;
- local storage or session storage used for interface preferences, viewer state, signing drafts, field clipboard features, or similar product functionality;
- analytics and performance technologies used to understand site performance and improve reliability.
At this time, SignBona is not designed around third-party behavioral advertising. We do not sell personal information, and we do not use personal information to build third-party advertising profiles.
3. How We Use Personal Information
We use personal information for the following business and operational purposes:
3.1 To Provide the Services
We use information to:
- create and manage accounts;
- authenticate users;
- enable multi-factor authentication;
- upload, prepare, send, sign, complete, archive, and verify documents;
- generate final signed PDFs, certificates of completion, and audit trails;
- enable signer access through secure links;
- deliver email notifications, one-time passcodes, reminders, completed-document notices, and related transactional messages;
- provide billing, subscriptions, trials, cancellation access, and payment-related account status;
- provide support and respond to inquiries.
3.2 To Support Electronic Signature Evidence and Document Integrity
We use information to:
- record consent to electronic records and signatures;
- record intent to sign and signing-related actions;
- generate and preserve audit trails;
- apply electronic seals, PDF signatures, timestamps, and certificates of completion;
- verify the integrity and status of completed documents;
- help parties prove what happened during a signing workflow;
- detect tampering, unauthorized changes, abuse, or technical failures.
3.3 To Secure the Services
We use information to:
- prevent unauthorized access;
- detect suspicious activity;
- enforce rate limits;
- verify webhook signatures;
- investigate potential abuse, fraud, spam, phishing, malware, or misuse;
- maintain logs needed for security and reliability;
- protect users, signers, recipients, SignBona, and third parties.
3.4 To Communicate With You
We use information to:
- send transactional emails;
- send account, security, billing, and service notices;
- respond to support, privacy, legal, billing, and security requests;
- notify you about material changes to the Services or our legal terms;
- provide information about your account, documents, trial, subscription, or cancellation status.
3.5 To Improve and Maintain the Services
We use information to:
- monitor performance and reliability;
- debug errors;
- analyze product usage at a technical and operational level;
- improve workflows, user experience, accessibility, and service stability;
- develop and test new features.
We do not use the contents of your documents to train public artificial intelligence models.
4. How We Share Personal Information
We share personal information only as needed to operate the Services, comply with law, enforce our rights, protect users, and support document workflows.
4.1 With People Involved in a Document Workflow
Information may be shared with account holders, signers, recipients, carbon-copy recipients, and other workflow participants as needed to complete or evidence a transaction. For example:
- a signer may see the document and fields they are asked to complete;
- an account holder may see document status, recipient status, timestamps, and audit information;
- completed-document recipients may receive final signed PDFs or certificates of completion;
- verification pages may show limited document integrity status without exposing unnecessary personal information.
4.2 With Service Providers and Subprocessors
We use third-party providers to host, operate, secure, bill, email, monitor, and timestamp the Services. These providers may process personal information only as needed to provide services to us.
Current providers may include:
- Supabase — authentication, database, storage, and related backend infrastructure;
- Vercel — hosting, deployment, analytics, speed insights, and infrastructure services;
- Stripe — checkout, payment processing, subscription billing, customer portal, invoices, and payment-related webhooks;
- Resend — transactional email delivery, including signing requests, one-time passcodes, reminders, support-related emails, and completed-document notices;
- Sentry — error monitoring, diagnostics, and reliability monitoring;
- DigiCert Timestamp Authority — RFC 3161 timestamping for PDF signing workflows, generally using document hashes rather than document contents.
We may update our providers as the Services evolve. If we make a material change to how we use subprocessors, we may update this Privacy Policy or provide other notice as appropriate.
4.3 Legal, Compliance, Safety, and Enforcement
We may disclose personal information when we believe disclosure is reasonably necessary to:
- comply with applicable law, regulation, subpoena, court order, legal process, or government request;
- enforce our Terms of Service, policies, agreements, or rights;
- investigate fraud, abuse, security incidents, spam, phishing, malware, unauthorized access, or misuse;
- protect the rights, property, safety, or security of SignBona, our users, recipients, signers, or others;
- preserve legal claims, evidence, or audit records;
- respond to privacy, security, or legal requests.
4.4 Business Transfers
If SignBona is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, personal information may be disclosed or transferred as part of that transaction, subject to appropriate confidentiality, legal, and operational protections.
4.5 No Sale of Personal Information
We do not sell personal information. We also do not share personal information for cross-context behavioral advertising as those terms are commonly used under U.S. state privacy laws. If this changes, we will update this Privacy Policy and provide any required notices and choices.
5. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services, comply with legal obligations, preserve document integrity, maintain audit evidence, resolve disputes, enforce agreements, prevent abuse, and protect the rights of users, signers, recipients, and SignBona.
Because SignBona is an electronic signature platform, certain records must be retained to preserve evidence of completed transactions. This means some information may be retained even after an account is deleted.
5.1 Account Data
We generally retain account data while your account is active. If you request account deletion and complete any required confirmation process, we may apply a grace period before final deletion. During this period, you may be able to cancel the deletion request.
After account deletion is finalized, we may delete or de-identify account profile data, preferences, contacts, billing records stored in our system, account consent records, and other account-level data, except where retention is required or permitted for legal, security, billing, fraud-prevention, dispute-resolution, or electronic-signature evidence purposes.
5.2 Drafts and In-Progress Documents
Draft documents may be deleted when an account is deleted or when a user deletes them, subject to system retention, backup, security, or operational limitations.
Documents that have been sent but not completed may be voided or expired if the account holder deletes the account or if a workflow is terminated. We may retain related records needed to show that the workflow was voided, expired, or otherwise not completed.
5.3 Completed Documents and Audit Trails
Completed documents, final signed PDFs, certificates of completion, audit trails, consent records, integrity logs, signing event records, verification records, and related evidence may be retained after account deletion. This retention helps preserve legally relevant evidence for signers, recipients, account holders, and other parties to a transaction.
Completed envelopes may be archived or removed from an account holder’s active view, but they may not be fully deleted from SignBona systems if deletion would compromise auditability, legal evidence, transaction records, or the ability of parties to verify a completed document.
5.4 Billing Records
Billing and subscription records may be retained as required for accounting, tax, fraud-prevention, chargeback, legal, and compliance purposes. Stripe may retain payment and billing information according to its own policies and legal obligations.
5.5 Backups and Logs
Residual copies of information may remain in backups, logs, or disaster-recovery systems for a limited period according to our providers’ retention practices and our operational needs. We may not be able to immediately delete information from backups, but we will handle retained backup information according to this Privacy Policy.
6. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These safeguards may include:
- HTTPS/TLS for data in transit;
- authentication and session controls;
- multi-factor authentication support;
- access controls and authorization checks;
- signed URLs and secure signing tokens;
- rate limiting and abuse-prevention controls;
- hashed one-time passcodes and backup codes;
- encrypted storage for sensitive platform signing key material;
- tamper-evident audit records;
- error monitoring with personal-information reduction controls;
- signed webhook verification for payment and email events.
No online service can guarantee absolute security. You are responsible for protecting your account credentials, using strong passwords, enabling available security features, and limiting access to signing links and downloaded documents.
7. Your Choices and Rights
Depending on where you live and how you interact with the Services, you may have rights to access, correct, delete, or receive information about certain personal information we process.
You may contact us at privacy@signbona.com to request:
- access to personal information associated with you;
- correction of inaccurate account information;
- deletion of account information, subject to retention exceptions;
- information about the categories of personal information we collect, use, and disclose;
- information about our service providers and disclosure practices;
- confirmation that we do not sell personal information.
We may need to verify your identity before processing a request. If you are a signer or recipient and your information was submitted by a SignBona account holder, we may direct you to that account holder or process your request in a way that preserves transaction integrity and the rights of other parties.
We will not discriminate against you for exercising applicable privacy rights.
8. California and U.S. State Privacy Disclosures
Although SignBona is currently designed for a U.S. launch and may not meet the thresholds of every state privacy law, we provide the following disclosures for transparency.
8.1 Categories of Personal Information We May Collect
Depending on your interaction with the Services, we may collect the following categories of personal information:
- identifiers, such as name, email address, account ID, IP address, user-agent, signing token, Stripe customer ID, and similar identifiers;
- customer records information, such as billing-related information and account contact information;
- commercial information, such as subscription status, trial status, plan, invoices, and payment-related metadata;
- internet or electronic network activity information, such as login events, document events, page performance, device/browser metadata, and usage logs;
- geolocation-related information derived from IP address, such as approximate location;
- professional or employment-related information, if included in recipient details, templates, documents, or account profile information;
- audio, electronic, visual, or similar information, such as uploaded avatars, signature images, initials, document images, or PDF contents;
- inferences related to preferences, such as language, time zone, notification preferences, and product settings;
- sensitive personal information if you or another user includes it in documents, templates, fields, support messages, or signing workflows.
We do not intentionally collect sensitive personal information for the purpose of inferring characteristics about you. However, because users control document contents, documents uploaded to SignBona may contain sensitive information.
8.2 Sources of Personal Information
We may collect personal information from:
- you;
- account holders who invite signers or recipients;
- signers and recipients;
- documents, templates, and fields submitted to the Services;
- your browser, device, or network connection;
- payment, hosting, email, authentication, monitoring, and infrastructure providers;
- fraud-prevention, security, and operational systems.
8.3 Business or Commercial Purposes
We collect, use, and disclose personal information for the purposes described in this Privacy Policy, including providing the Services, processing payments, delivering emails, preserving signing evidence, maintaining security, preventing abuse, complying with law, and improving reliability.
8.4 Categories of Third Parties to Whom We Disclose Personal Information
We may disclose personal information to:
- service providers and subprocessors;
- account holders, signers, recipients, and other workflow participants;
- payment processors;
- hosting, authentication, database, storage, email, monitoring, analytics, and timestamping providers;
- legal, compliance, safety, and security recipients where required or appropriate;
- business transaction parties in connection with a merger, acquisition, financing, or similar transaction.
8.5 Sale or Sharing
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
8.6 Retention
We retain each category of personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including electronic signature evidence, document integrity, legal compliance, billing, security, and dispute resolution.
9. Children’s Privacy
The Services are not intended for children. You must be at least 18 years old to create a SignBona account or use the Services as an account holder. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us at privacy@signbona.com and we will take appropriate steps.
10. International Users
SignBona is intended for users and transactions in the United States. If you access the Services from outside the United States, you understand that your information may be processed in the United States and by service providers that support our U.S.-based operations.
We do not currently position SignBona as a European Union, United Kingdom, or eIDAS-qualified electronic signature service. If our international scope changes, we may update this Privacy Policy and related terms.
11. Email Communications
We send transactional emails necessary to operate the Services, such as account emails, signing invitations, one-time passcodes, reminders, completed-document notices, billing notices, support messages, and security notices.
You may be able to manage certain notification preferences in your account settings. However, you may still receive essential transactional, security, legal, or billing messages.
12. Do Not Track and Global Privacy Controls
Some browsers offer “Do Not Track” or similar signals. Because there is no uniform industry standard for these signals, our Services may not respond to all such signals.
Where required by applicable law, we will honor legally recognized opt-out preference signals for activities that qualify as sales or sharing. At this time, we do not sell personal information or share it for cross-context behavioral advertising.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may provide notice through the Services, by email, or by other reasonable means. The “Effective Date” above shows when this Privacy Policy was last updated.
Your continued use of the Services after an updated Privacy Policy becomes effective means you acknowledge the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
SIGNBONA LLC
- Privacy: privacy@signbona.com
- Support: support@signbona.com
- Legal: legal@signbona.com
- Security: security@signbona.com
- Billing: billing@signbona.com
15. Spanish Translation Notice
SignBona may provide Spanish translations of this Privacy Policy for convenience. The English version is the official version. If there is any conflict between the English version and a translated version, the English version controls to the fullest extent permitted by law.