1. Who we are
EsignCenter is an electronic signature service operated by EsignCenter LLC at esigncenter.com. In this policy “we” and “us” mean that company.
This policy explains what we collect, why we have it, who else sees it and what you can do about it. It covers two different kinds of people, and the answers are different for each:
- Account holders — people who sign up for EsignCenter and send documents.
- Signers — people who receive a document through EsignCenter and sign it. If you are a signer, the person who sent you the document decided what to ask you for. We hold your information on their behalf.
You can reach us about anything in this policy at support@aceddev.com.
2. What we collect from account holders
- Your name and email address, and the name you give your account.
- Your password, stored as a one-way hash. A hash cannot be turned back into the password, so we cannot read yours and we cannot recover it for you — only help you set a new one. An account created with “Continue with Google” or “Continue with Apple” is given a random password nobody holds; you can set one of your own later from “Forgot your password?”.
- Your timezone and language, so dates and pages read correctly for you. Your browser tells us these when you sign up.
- Your Google or Apple profile — your email address and your name — if you choose to sign in with Google or Apple. Apple may give us a private relay address that forwards to your real one instead of the address itself; if it does, the relay address is the one we keep and email. We ask Google and Apple for nothing else, and we do not read your Google account or your Apple ID.
- Billing details, held by Stripe. Payments are handled entirely by Stripe. Your card number never reaches our servers and we never see it. What we keep is what Stripe tells us: which plan you are on, how many seats, whether the last payment succeeded, and the invoices.
- Usage counters — how many documents you have completed and sent this month, how many are waiting for signatures, and how much storage you are using. We need these to apply the plan limits and to show you your usage page.
- The network address you signed in from. We keep the IP address of your current sign-in and of the one before it, and when each of them happened, so that we can spot an account being broken into and answer “who did this, and from where?”. We do not keep a longer sign-in history, and we do not record which browser you signed in with. Changing your password, or turning two-factor authentication on or off, creates no record of its own beyond the change itself.
- Your agreement to our published documents. When you accept the Terms of Service and this Privacy Policy — when you sign up, or when you join somebody else's team by invitation — we write down which version of each you were shown, a digest of those exact words, the moment you agreed, and the IP address and browser user agent your browser sent with it. Section 12 explains why the version matters.
- Support session records. When one of our operators opens a support session on your account, we record the start of it — with the written reason they gave — every change they make, and every door they are refused at. Your administrators are emailed the moment a session starts, and Settings lists every session there has ever been. Section 10 sets out exactly how that access works.
- What you write to us when you email support or use our support form.
3. What we collect from signers
When somebody sends you a document through EsignCenter, we hold:
- The name and email address the sender gave us for you. They typed those, not us.
- Everything you enter into the document — the fields the sender put in it, whatever they contain.
- Your signature and initials, as the images you draw, type or upload.
- Any files you attach to the document.
- Your IP address and browser user agent, each time you open or act on the document.
- Your agreement to sign electronically — the moment you gave it, your IP address, and the version and language of the disclosure you were shown.
- What happened to the emails we sent you on the sender's behalf: sent, delivered, bounced, or reported as spam.
- Whether you opened one of those emails, and whether you clicked a link in it — together with the browser or mail client you used and roughly where you were (the country, region, city and postal area our email provider works out from your network address). We record this on every plan, because it is what tells us an account is sending mail to people who do not want it. What changes with the plan is who can see it: the sender is shown opens and clicks only when their plan includes delivery tracking. On every other plan those events exist for abuse protection, and the events themselves are not shown to them — not in the document's event list, not in the audit trail, not over the API and not in an export. One fact drawn from them is. Clicking the link in the email we sent is what tells us the address reached you, so the audit trail that travels with the signed document records that your email address was verified, on every plan. It records that and nothing more: not when you opened the email, not how often, not which link you clicked and not where you were.
Most of this ends up in the document's audit trail, which is the record of who did what and when. That is the point of it: an audit trail that could be edited would not be worth keeping. The sender receives it with the signed document.
4. Why we have it
- To run the service — to show you your documents, deliver them to signers, and produce the signed result.
- To prove a signature happened — the audit trail, the consent record and the verification fingerprint exist so that a signed document can be shown to be the document that was signed.
- To prevent abuse — the rate limits, the bot check on the sign-up and support forms, and the complaint and bounce handling that stop EsignCenter being used to send mail nobody asked for.
- To bill you, if you are on the paid plan.
- To support you when you ask us for help.
- To meet legal obligations — tax and accounting records, and responding to a lawful request we are required to answer.
We do not sell your information, we do not rent it, and we do not use it to advertise to you or to anybody else.
5. Who else sees it
We use a small number of other companies to run EsignCenter. Each of them sees only what it needs, and none of them may use it for anything but working for us:
| Company | What it does | What it sees |
|---|---|---|
| Render | Hosting (United States) | Everything the application handles, because it runs the application |
| Amazon Web Services (S3) | File storage (United States) | Your uploaded and signed documents, and the images in them |
| Postmark (an ActiveCampaign company) | Sending email, and reporting what happened to it | Recipient names and addresses, and the contents of the emails we send |
| Stripe | Payments | Your billing name, email address and card details. Stripe holds the card; we do not |
| Sentry | Error reports | Technical details of a failure, which can include parts of the request that caused it |
| Cloudflare | Bot check on the sign-up and support forms (Turnstile) | Your IP address and the browser signals the check needs |
| “Continue with Google” sign-in | Only what is needed to sign you in, and only if you use that button | |
| Apple | “Continue with Apple” sign-in | Only what is needed to sign you in, and only if you use that button |
| DigiCert | Trusted timestamps on signed documents | A cryptographic hash only. It never receives the document |
The current list is also published on our Sub-processors page. We will update both when it changes.
Beyond that list, we share information only when the law requires it, when we have to in order to protect somebody's safety or our own rights, or as part of a sale of the business — in which case this policy travels with the information and we tell you.
6. Cookies
Every cookie EsignCenter sets does a job. Some are set on an account holder's browser; several are set on a signer's browser, and those are the ones people are least likely to expect, so they are listed here too.
Signing you in (account holders):
- The session cookie. What keeps you signed in while you use the application. It goes when you close the browser or sign out.
- “Remember me”, if you tick it when you sign in, so that browser does not ask again. It lasts up to two years, and signing out ends it.
Remembering how you like things (account holders):
- Your dashboard view and the order your templates are listed in — two small preferences, kept for about twenty years so you are not asked again.
- Which tab you last used when adding recipients. The same kind of preference, kept the same way.
Signing a document (signers):
- A marker of the documents this browser completed, kept encrypted for 12 hours. It is what lets the browser that actually signed a document see the confirmation page again without being asked to prove who it is.
- A reference to a signature you saved, kept encrypted, so the signature or initials you drew once can be offered back to you on the next document instead of making you draw them again.
- A marker that you passed an emailed verification code, kept encrypted, when a sender protects a link with one. Without it you would be asked for a fresh code on every step.
That is the whole list. We set no advertising cookies, and we run no third-party analytics at this time. Nobody is tracking you across the web from our pages.
Do Not Track. Because we do not track you across other websites, and do not let anybody else do so from our pages, there is nothing for a browser's “Do Not Track” or Global Privacy Control signal to turn off. We treat every visitor the same whether or not their browser sends one.
7. How long we keep it
- While your account exists, we keep your documents and their audit trails for as long as you keep them. Deleting a document the ordinary way moves it to your archive: it comes off your lists, and its files still exist and still count towards your storage. Delete permanently is the one that really removes them.
- After you cancel, we keep a canceled paid account's data for at least 1 year. An account nobody uses for 1 year may be deleted after we have warned everybody in it 60, 30 and 7 days beforehand.
- When you delete your account, your documents, templates, audit trails, files, settings and logins are destroyed 90 days later, and you can call it off at any point in between. A short list survives, set out in section 8 of our Terms of Service: the verification record of each signed document (kept permanently), your subscription and payment history, the record of what our payment processor told us with the identity redacted out of it, a stub of the account row itself, our own log of support access to the account, and any stored file that another EsignCenter account is also using.
- Email delivery records — what we sent on your behalf and what happened to it — are kept with the account and deleted with it.
- Verification records are kept permanently. The fingerprint, date and signer count of each signed document outlive the account and are never deleted, because every copy of that document already in the world would otherwise stop verifying. They name nobody and contain nothing from inside the document.
- Backups. Our hosting provider takes automatic database backups and keeps them for a limited time, and our file storage keeps previous versions of files. Something deleted from the live service can therefore persist in a backup for a while before it is gone for good.
8. Your choices
If you have an account:
- Take a copy. Settings gives you a single zip holding your documents, your templates and your audit trails. You do not need a reason and you do not need to ask us.
- Correct it. Your name, your email address, your timezone and your language are all yours to change in Settings.
- Delete it. Settings will delete the whole account, on the 90-day schedule described above.
- Ask us. Write to support@aceddev.com with any question about your information, and we will answer.
If you are a signer:
The person who sent you the document decides what happens to it. They chose what to ask you for, they hold the signed result, and requests about that document — a copy of it, a correction, its deletion — go to them. If you cannot reach them, or you are not sure who they are, write to us at support@aceddev.com and we will help you get to the right person.
If you would rather not sign electronically, tell the sender before you sign. Once a document is completed, its audit trail is part of the record of that signature and we do not edit it.
Section 22 of our Terms of Service sets out the rights we honor for everybody — to know, to have a copy, to correct, to delete and to appeal a refusal — how to use an authorized agent, and our statement that we do not sell personal information or share it for cross-context behavioral advertising.
9. Children
EsignCenter is not directed at people under 18 and we do not knowingly collect information from them. If you believe a child has given us information, write to support@aceddev.com and we will delete it.
10. How we protect it
- In transit, everything travels over an encrypted connection.
- At rest, files are stored in Amazon S3 with Amazon's server-side encryption, and sensitive settings — signing keys, mail server credentials — are encrypted in our database with a key held outside it.
- Access is limited, and it goes through the audited path. Within EsignCenter, only the people who operate the service can reach customer data, and they reach it through the support sessions described below. The providers listed in section 5 hold what they need in order to provide their service to us, under their own terms.
- Support access is deliberate, audited and visible to you. An operator can only look at an account by starting a support session, and starting one takes a written reason and a live code from their authenticator app. From that moment everything is recorded: the session itself, every change made during it, and every door the session was refused at. A session cannot last more than an hour. Your administrators are emailed the moment one starts, and a Support access card in Settings lists every session there has ever been — when, as which of your people, in read-only or edit mode, for how long, what was changed and why. While a session is running, our operator's own screens carry a banner naming your account and their reason, so they cannot forget whose data they are looking at.
We do not edit an audit trail after the fact, and the signed PDF it is delivered with is sealed with our digital signature and a third-party timestamp — so a copy that has been changed stops verifying at esigncenter.com/verify. That is the guarantee we can actually make: not that a record is impossible to alter, but that an altered one can be told apart from the original by anybody holding it.
No service can promise perfect security, and we do not. If something happens that affects your information, we will tell you — without undue delay, and in any case as the law requires — what we know, what we did, and what you should do.
11. If you are outside the United States
EsignCenter is operated from the United States and your information is stored and processed there, including by the companies in section 5. The laws of your own country may protect it differently. By using EsignCenter, you agree to that transfer.
We do not offer a data processing addendum at this time. If your organization needs one before it can use a service, EsignCenter is not the right service for you yet.
12. Changes to this policy
When we change this policy we bump the version and the effective date at the top of this page, and we email the administrators of every account before the change takes effect. The previous version is kept, so what you agreed to on the day you signed up can always be produced.
13. Contact
Questions, requests and complaints all go to the same place: support@aceddev.com.
By post:
EsignCenter LLC
1666 E Sunshine Street, Springfield, MO 65804