Privacy
Privacy Policy
This policy explains what PactStamp collects and how it is used to provide agreement records, signatures, verification, support, and billing.
Last updated: July 18, 2026
1. Information we collect
- Account information, such as email address and optional display name.
- Agreement information, such as party names, emails, addresses, terms, prices, dates, notes, signatures, and optional photos.
- Technical and audit information, such as IP address, user agent, timestamps, document hashes, signature hashes, share-token metadata, and verification events.
- Limited first-party operational analytics using fixed fields and pseudonymous HMAC-derived references, not raw account or agreement IDs.
- Billing information handled by Stripe, such as customer ID, subscription status, invoices, and payment-method metadata. PactStamp does not store full card numbers.
- Support messages you send to us.
2. How we use information
- To create, sign, store, verify, display, and export agreement records.
- To generate sealed PDFs and evidence bundles for paid plans.
- To send magic links, agreement links, support replies, and service notices.
- To operate billing, subscriptions, cancellation, invoices, and customer-portal access through Stripe.
- To prevent abuse, debug errors, improve reliability, and protect signed-record integrity.
3. Operational analytics
PactStamp uses limited first-party operational analytics stored in its own database. It is not sent to a third-party advertising analytics provider.
Product-event rows do not contain agreement or clause content, filled fields, names, email addresses, phone numbers, signatures, photos, IP addresses, user-agent strings, page URLs, signing or share links, access tokens, or token digests. HMAC-derived references are pseudonymous, not anonymous.
Pilot participation begins only after explicit acceptance. New pilot attribution stops when enrollment ends. Account deletion removes pilot enrollment and product events linkable to the account or its agreements; unlinked aggregate reliability events may remain.
4. Sharing and processors
We share information only as needed to operate the service, comply with law, protect the service, or complete a user-requested action.
- Stripe processes payments and subscription management.
- Resend sends transactional email such as magic links and agreement notifications.
- Hosting, database, backup, and security providers store or process data needed to run PactStamp.
- When an explicitly enabled AI feature is used, the configured AI provider processes only the submitted material needed for that request. Do not submit sensitive or regulated information.
- Other parties to an agreement can see the agreement information and evidence they are authorized to access.
5. Retention and signed records
PactStamp keeps records according to their status, account relationship, operational need, security needs, legal obligations, disputes, and backup-recovery cycles. Signed evidence may be retained longer than unsigned drafts because the parties rely on the exact historical record.
PactStamp does not treat tamper-evidence as permission for unlimited retention. Deletion may be delayed or limited when a record must be preserved for another party, a legal obligation, security, fraud prevention, a dispute, or a documented legal hold.
6. Cookies, local storage, and tracking
PactStamp uses first-party cookies and browser storage for sessions, owner and party access, locale, PWA preferences, security, and reliable product operation. Private agreement pages and artifacts are excluded from the service-worker cache.
PactStamp does not use advertising pixels or sell agreement data. Browser Do Not Track signals are not a universal legal standard; PactStamp does not use cross-site advertising tracking regardless of that signal.
7. Your choices and requests
PactStamp handles privacy requests for service data through [email protected]. Submit a request without creating a new account and describe the access, correction, deletion, or portable-copy right you want to exercise. PactStamp may request information reasonably necessary to authenticate the request and protect another party’s record.
For an authenticated Texas request covered by the Texas Data Privacy and Security Act, PactStamp will respond without undue delay and ordinarily within 45 days. If reasonably necessary, PactStamp may extend once for up to 45 additional days and will explain the extension during the initial period. Covered requests are provided without charge up to twice annually unless a request is manifestly unfounded, excessive, or repetitive.
PactStamp does not sell personal data, use targeted advertising, or profile people to make decisions that produce legal or similarly significant effects. You may still submit an opt-out request for those uses, and PactStamp will treat the request as applying if those practices change.
If PactStamp declines a request, the response will explain the decision and how to appeal. Appeal by replying to the decision or emailing [email protected] with “Privacy appeal” and the request reference. PactStamp will respond to a covered appeal within 60 days. If a covered appeal is denied, the response will explain how to submit a complaint to the Texas Attorney General.
- Decline or leave a product pilot from the Dashboard.
- Choose not to upload optional photos or optional fields.
- A copy already retained by another agreement party is outside your account and may not be removed by deleting your account.
8. Security
PactStamp uses HTTPS, signed links, server-side access checks, audit hashes, and operational backups. No online service can guarantee perfect security, so keep account links and email access secure.
9. Adults only and prohibited sensitive data
PactStamp is for adults age 18 or older. Do not enter information about a child or upload medical or health information, government identifiers, financial credentials, biometric identifiers, or intimate images.
10. Changes and contact
Material policy changes will be posted with a new effective date and, when appropriate, an in-product or email notice. For privacy questions or rights requests, email [email protected].