Last updated: August 24, 2026
This Privacy Policy explains how Upfinity Inc. ("Upfinity," "we," "us") collects, uses, discloses, and protects information in connection with Upfinity Sign, our e-signature and document-workflow platform (the "Service"). It applies to workspace owners and their team members ("Customers"), and to the people Customers send documents to for signature ("Recipients"), who may never create an account of their own.
If you're a Customer (you or your organization created a workspace), this Policy governs your account information and how you use the Service. If you're a Recipient (someone sent a document to sign, review, or approve), this Policy governs the personal information collected from you during that process — you did not choose to use Upfinity Sign, but we still owe you a clear account of what happens to your information, and you have real rights over it (Section 8). Where a Customer directs us to process a Recipient's information on their behalf, the Customer is the data controller and Upfinity acts as data processor — see our Data Processing Agreement for how that responsibility is divided.
Account & workspace information (Customers): name, email address, password (stored as a salted hash, never in plain text — or, if you sign in with Google or Microsoft, we receive your verified email and name from that provider and never see your password at all), company/workspace name, role within your workspace, billing and plan information.
Recipient information: name and email address (provided by the sender), the content you enter into document fields, your signature (typed, drawn, or an uploaded image — never a scan of a handwritten signature on paper unless you choose to upload one), IP address, approximate geolocation derived from that IP, browser/device information, and timestamps of every action you take (opened, filled a field, signed, declined) — this audit trail is what makes a signature legally defensible, not incidental data collection.
Document content: the documents you upload or generate through the Service, and the completed, signed versions of them.
Payment information: processed entirely by our payment processor — we never receive or store your full card number. We retain only what's provided back to us (e.g., a payment confirmation, the last 4 digits for your reference).
AI assistant usage: if you use the in-product AI assistant (to place fields or draft a document from a description), the text you send it and the document context needed to respond are sent to our AI provider to generate a response, and retained for as long as your account is active so your conversation history remains available to you in that panel — see our AI Assistant Notice for the specifics.
Technical & usage information: log data, API usage, and the minimum cookies needed to keep you signed in (Section 6).
We do not sell or share personal information for cross-context behavioral advertising. We share it only with the categories of service providers (sub-processors) below, each bound by contract to protect it and use it only to provide their service to us. We don't publish the specific companies behind each category here, for the same reason a bank doesn't publish its network diagram — but a full named list is available under our Data Processing Agreement for customers who need it for their own compliance review.
A specifically-named list of sub-processors is available to customers on request as part of contracting — see our Data Processing Agreement. We'll provide advance notice before adding a new sub-processor that will handle Customer or Recipient personal data.
We may also disclose information if required by law, to protect the rights, property, or safety of Upfinity, our users, or the public, or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required).
We retain envelope and document data for a minimum of two (2) years, and longer where your plan tier, your jurisdiction's requirements, or an active legal matter requires it — our published tiers currently retain data for up to seven years on Enterprise plans. A workspace can place a legal hold on a specific document to exempt it from deletion entirely — for example, while it's the subject of a dispute — until that hold is explicitly released.
If you request deletion of your account or data (Section 8), we begin a 30-day grace period, after which we delete what we can — but any document still within its required retention window, or under an active legal hold, is retained until that period lawfully ends, not deleted immediately just because deletion was requested.
We use a small, fixed set of cookies — no third-party advertising or tracking cookies:
Disabling cookies in your browser will prevent you from staying signed in. We do not currently respond to browser "Do Not Track" signals, as no common industry standard for interpreting them has been adopted — this has no practical effect for you either way, since we don't use tracking cookies to begin with.
Our infrastructure is hosted in the United States. If you're accessing the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those of your home jurisdiction. Where required for transfers of personal data originating in the EU/UK, we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism with our sub-processors — see our Data Processing Agreement.
Depending on where you live, you may have rights including:
This includes rights under the EU/UK GDPR and the California Consumer Privacy Act, among other applicable frameworks. To exercise any of these rights — whether you're a Customer or a Recipient who never created an account — contact us at privacy@upfinity.ca. We will respond within 30 days (or sooner where a shorter period applies under law). Customers can also export or request deletion of their workspace data directly from Settings → Danger zone. We will honor deletion requests except where retaining information is required by law, by an active legal hold, or to complete a transaction already in progress.
EU/UK representative: for the purposes of Article 27 GDPR and the UK GDPR, Upfinity Inc. acts as its own representative and can be contacted using the details in Section 12.
We encrypt data in transit (TLS is enforced on every connection to our database and between your browser and our servers) and apply access controls, encrypted storage for sensitive credentials (API keys, single sign-on secrets, recipient access tokens), and an immutable audit trail across the Service. No system is perfectly secure; we will notify affected users and relevant authorities of a security breach without undue delay and, in any event, as required by applicable law.
The Service is not directed to, and we do not knowingly collect personal information from, children under the age of 16. If you believe a child has provided us with personal information, contact privacy@upfinity.ca and we will delete it.
We may update this Policy from time to time. We'll post the updated version here with a new "Last updated" date, and where a change is material, we'll provide more prominent notice (such as an email to workspace owners) at least 30 days before it takes effect.
Upfinity Inc.
140 Carlton Street, Toronto, ON M5A 3W7, Canada
privacy@upfinity.ca
Terms of Service · Data Processing Agreement · AI Assistant Notice · Back to Upfinity Sign