Product transparency

Privacy overview

This technical overview explains the personal data SignaGenius is designed to process and the controls available to workspace administrators.

Updated 29 July 2026

Data the product can process

SignaGenius stores administrator account details and managed employee identity data needed to build signatures and public profiles. Depending on workspace configuration, this can include names, work email addresses, job details, phone numbers, profile photos, aliases, entity membership, custom attributes, and delegated signature variations.

The product also stores organization branding, templates, campaigns, configuration, audit records, deployment outcomes, connector job history, billing references, and support or notification preferences.

  • Public profile leads are stored only after the visitor submits the form and accepts the displayed consent text.
  • Click, impression, profile, and link events are collected only when the relevant workspace tracking setting allows them; workspaces can respect the browser Do Not Track signal.
  • Connector and webhook credentials are kept in server-side encrypted or hashed stores and are excluded from workspace exports.

Why the data is used

Data is used to administer workspaces, resolve the correct signature, synchronize managed directories, deploy or insert signatures, operate campaigns and public profiles, provide analytics selected by the workspace, enforce access and licensing, deliver requested notifications, and investigate failures or security events.

AI campaign and assistant features are configuration-gated. Their requests are bounded and recorded for the requesting workspace; the assistant is designed around operational snapshots rather than employee message content.

Service providers and connected systems

A deployment can use Supabase for database, authentication, and storage; Stripe for billing; Resend for configured email delivery; Google Workspace or Microsoft 365 for authorized directory and signature workflows; OpenAI for explicitly enabled AI features; and DNS, hosting, wallet, or marketplace providers selected by the deployment owner.

The final production notice must list only the providers actually activated, including their processing locations and contractual role.

Retention and workspace control

Workspace administrators control users, templates, campaigns, public profiles, tracking settings, and configurable analytics retention. Operational and security records can be retained separately where needed for integrity, fraud prevention, recovery, or legal obligations.

The versioned workspace export intentionally omits secrets, sessions, event history, and rebuildable artifacts. Deletion, correction, export, and retention requests must be routed through the organization that controls the relevant workspace unless the production notice states otherwise.

Security and questions

Implemented controls include tenant-scoped authorization, row-level database security, granular permissions, audit events, MFA and SSO policy gates, encrypted connector credentials, hashed API keys, signed webhooks, rate limits, and revocable agent access.

Do not send passwords, recovery codes, private keys, API tokens, signing certificates, or service-account credentials in a privacy or support request. Use the controller contact identified in the production workspace agreement or approved privacy notice.