SigSagTSigSagT
To dashboard

Legal · v1.0

Privacy Policy

Effective date: 29 June 2026

1. Who We Are

SigSagT ("we", "us", "our") operates the email signature management platform available at sigsagt.app. This Privacy Policy explains how we collect, use, and protect your personal data when you use our Service.

For questions about this policy, contact our privacy team at privacy@sigsagt.app.

2. Data We Collect

We collect the following categories of personal data:

Account data — your name, email address, and organisation details provided when you register or are invited to an account.

Profile and signature data — job title, department, phone number, and any other information you or your administrator enter into your email signature.

Usage data — information about how you interact with the Service, including pages visited, features used, and actions taken, collected through server logs and application telemetry.

Payment data — billing name, address, and payment method details. Card numbers are processed directly by our payment provider (Stripe) and are not stored on our servers.

Technical data — IP address, browser type and version, device type, and operating system, collected automatically when you access the Service.

3. How We Use Your Data

We use your personal data to:

  • Provide, operate, and maintain the Service.
  • Authenticate your identity and manage your account.
  • Process payments and send billing-related communications.
  • Sync email signatures to connected email clients (e.g. Gmail) on your behalf.
  • Send service notifications, security alerts, and support messages.
  • Improve and develop the Service based on usage patterns.
  • Comply with legal obligations.

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:

  • Contract performance — to deliver the Service you have subscribed to.
  • Legitimate interests — to operate, secure, and improve the Service, where these interests are not overridden by your rights.
  • Legal obligation — where processing is necessary to comply with applicable law.
  • Consent — where we have obtained your explicit consent, which you may withdraw at any time.

5. Data Sharing

We share personal data only with trusted third-party service providers who assist us in operating the Service. These include:

  • Supabase — database hosting and authentication infrastructure.
  • Stripe — payment processing.
  • Google — Gmail API integration for signature deployment.
  • Vercel — hosting and edge delivery.

All third-party processors are bound by data processing agreements and are required to handle your data securely and in accordance with applicable law. We do not share your data with any other third parties without your explicit consent, except as required by law.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Upon account deletion or termination:

  • Account and profile data is deleted within 30 days.
  • Billing records are retained for 7 years to comply with financial regulations.
  • Anonymised usage data may be retained indefinitely for analytics purposes.

7. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (TLS), encryption at rest, access controls, and regular security reviews.

No system is completely secure. If you believe your account has been compromised, contact us immediately at privacy@sigsagt.app.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data, subject to legal retention obligations.
  • Restriction — request that we limit how we use your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdrawal of consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at privacy@sigsagt.app. We will respond within 30 days.

9. Cookies

The Service uses strictly necessary cookies to maintain your authenticated session. These cookies are essential for the Service to function and do not require your consent. We do not currently use tracking or analytics cookies.

10. International Transfers

Some of our service providers operate outside the UK and EEA. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the relevant data protection authority.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 14 days before they take effect. The "Effective date" at the top of this page indicates when the policy was last revised.

12. Contact and Complaints

For privacy-related questions or to exercise your rights, contact us at privacy@sigsagt.app.

If you are located in the UK or EEA and believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk).