SignQuick
TermsPrivacyES

Privacy Policy

Last updated: May 22, 2026

1. Who we are

SignQuick (“we,” “us,” or “our”) is the data controller for personal data collected through the SignQuick iOS application and the websitesignquickapp.com. If you have any privacy-related questions, you can contact us at privacy@signquickapp.com.

2. Data we collect

2.1 Account data

When you create an account using Google Sign-In, we collect:

  • Email address
  • Public profile name
  • Unique user identifier (UUID generated by Supabase Auth)

2.2 Documents and signatures

To provide the electronic signature service, we process:

  • Files you upload (PDF, PNG, JPEG) to send for signature
  • The PNG image of the signature drawn by the signer on the canvas
  • The names and email addresses of the signers you provide
  • The SHA-256 hash of the signature token (never the token in plain text)

2.3 Technical and audit data

For each signature event, we record:

  • The signer's IP address at the time of signing
  • The User-Agent of the browser used to sign
  • A timestamp for each action (sent, viewed, signed)
  • The SHA-256 hash of the signed file (to verify integrity)

This audit data is necessary to support the legal validity of signatures and cannot be deleted individually without invalidating the signature record.

2.4 Access to photos and documents (iOS app)

The iOS app requests access to your photo library and files on your deviceonly when you actively select a document to upload. We do not access your photo library in the background or collect images without your explicit action.

3. How we use your data

  • Providing the service: Sending documents for signature, generating secure links, and notifying you of request status.
  • Legal traceability: Maintaining an immutable audit trail for each signature to support its validity.
  • Security: Detecting unauthorized access and preventing fraud.
  • Support: Responding to inquiries and resolving issues.

We do not sell your data to third parties or use it for advertising.

4. Data processors

We use the following trusted service providers to operate the service:

Supabase, Inc.

Database infrastructure, authentication, and file storage. Data is stored on servers located in the European Union (Frankfurt, Germany).
Supabase Privacy Policy →

Google LLC (Sign-In)

We use Google OAuth 2.0 to authenticate users. Google acts as an identity provider; we do not store passwords.
Google Privacy Policy →

Netlify, Inc.

Hosting for the signquickapp.com website.
Netlify Privacy Policy →

5. Data retention and deletion

Type of dataRetention period
Account data (email, name)Until you delete your account
Original uploaded documentsUntil you delete them or close your account
Signature images3 years from the date of signature (legal requirement)
Audit records5 years (legal evidentiary value)
Technical logs (IP addresses, timestamps)12 months

You can request the deletion of your account and personal data at any time by emailing privacy@signquickapp.com. Audit records linked to completed signatures may be retained to comply with legal obligations even after you delete your account.

6. International data transfers

Data is primarily stored on Supabase servers located in the European Union (Frankfurt). When data is transferred outside the EEA (for example, to Supabase services in the United States), those transfers are protected by the Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Your rights under the GDPR

If you are in the European Union or European Economic Area, you have the right to:

  • Access: Request a copy of the data we hold about you
  • Rectification: Correct inaccurate data
  • Erasure: Request the deletion of your data (“right to be forgotten”)
  • Portability: Receive your data in a structured, machine-readable format
  • Object: Object to certain processing activities
  • Restriction: Restrict processing in certain circumstances

To exercise any of these rights, email us atprivacy@signquickapp.com. We will respond within 30 days.

8. Security

We implement the following technical and organizational measures to protect your data:

  • Encryption in transit using TLS 1.2+
  • Encryption at rest in Supabase Storage
  • Signature tokens stored only as irreversible SHA-256 hashes
  • Temporary, cryptographically signed document access URLs (valid for 1 hour)
  • Authentication using Google OAuth 2.0 (no password storage)
  • Row Level Security (RLS) in the database

9. Cookies and similar technologies

We use strictly necessary session cookies to keep you signed in. We do not use third-party tracking or advertising cookies. Session cookies are deleted when you close your browser or sign out.

10. Children

SignQuick is not intended for children under 16. We do not knowingly collect data from children. If you become aware that a child has provided personal data, contact us so that we can delete it.

11. Changes to this policy

We may update this policy periodically. We will notify you of material changes by email or through a prominent notice in the application at least 30 days in advance. The “Last updated” date at the top always reflects the current version.

12. Contact

For any questions about this policy or how we process your data: