Skip to content
ProductSecurityPricingDevelopersContact
EN· English
  • EN · English
  • ES · Español
  • DE · Deutsch
  • FR · Français
  • IT · Italiano
  • PT · Português
Sign inStart free
ProductSecurityPricingDevelopersContactSign in
Home/Legal/Privacy Policy

Privacy and data

Privacy Policy

What we collect for accounts, documents, signatures, add-ons, advertising, and support, and how to use your rights.

Updated September 22, 2026Effective September 22, 2026

On this page
  1. Who we are
  2. Scope and roles
  3. Personal data we collect
  4. Why we use it and our legal bases
  5. Cookies, analytics, and advertising
  6. Identity verification and automated decisions
  7. Who we share data with
  8. International transfers
  9. How long we keep data
  10. How we protect data
  11. Your rights
  12. Marketing messages
  13. Children
  14. Changes to this policy

In short

  • We never sell personal data for money, and we never use documents for advertising or AI training.
  • Analytics and advertising tags run only after you accept them, and you can change your mind at any time.
  • For documents and signers, the customer who sends the document decides, and we process the data for them.
  • You can access, correct, delete, or export your data, and complain to your data protection authority.

01Who we are

inSigner is operated by Nubesti LLC, a limited liability company formed in Delaware, United States, with its address at 1111B S Governors Ave STE 23840, Dover, Delaware 19904, United States. For the processing described as ours in this policy, Nubesti is the controller.

Privacy questions and requests go to [email protected] with the subject “Privacy”. That address also reaches the person responsible for data protection at Nubesti, including the encarregado for Brazil, the privacy officer for Quebec, and the grievance officer for India. Where the law requires us to appoint a representative in the European Union or the United Kingdom, the representative’s details will be shown in this section.

02Scope and roles

This policy covers insigner.co, the workspace at app.insigner.co, signing pages at sign.insigner.co, the API, the add-ons, our emails, our advertising, support, and the iOS and Android apps once they are released.

Nubesti is the controller for website visitors, account holders, billing, security, support, and marketing. For documents and for the personal data of people invited to sign, the customer who sends the document is the controller, and Nubesti is a processor or service provider that acts on the customer’s instructions under the data processing agreement. If you signed a document, the sender is usually the right first contact for questions about that document.

03Personal data we collect

Depending on how you use inSigner, we collect the following personal data:

CategoryExamplesSource
Account and contactName, email address, organization, role, language, and sign-in detailsYou
BillingPlan, PayPal subscription status and identifier, invoice details, country, and tax identification numberYou and PayPal
DocumentsFiles, fields, templates, and the names, email addresses, and phone numbers of signersThe customer
Signature evidenceSignature image, consent to sign, timestamps, IP address, device and browser details, and document hashesThe signer and their device
Messaging add-onsPhone number, message status, and the result of a one-time code checkThe customer, the signer, Meta, and carriers
Identity verificationIdentity document images and data, selfie, facial template, liveness result, and registry check resultsThe signer and Didit
Website usage and advertising, with consentCookie identifiers, pages viewed, clicks, ad click identifiers, approximate location derived from the IP address, and device typeYour browser, Google, Microsoft, Meta, and TikTok
Support and communicationsMessages, attachments, and the history of your requestsYou
SecurityIP address, request logs, bot challenge signals, and error reportsYour device and Cloudflare

We do not ask for sensitive data such as health, religion, or political opinions. Identity documents and biometric data are processed only when a customer turns on KYC for a document, as described on the identity verification page.

04Why we use it and our legal bases

When the GDPR, the UK GDPR, the LGPD, or a similar law applies, we rely on these legal bases:

PurposeLegal basis
Create and run your account and workspace, and provide the service you orderedPerformance of a contract
Deliver signing invitations, collect signatures, and keep the evidence record for the customerProcessing for the customer, under the data processing agreement
Take payment, issue invoices, and keep accounting and tax recordsContract and legal obligation
Protect the service, prevent fraud and abuse, and keep security logsLegitimate interests in a safe and reliable service
Answer support requests and send service messagesContract and legitimate interests
Measure how the website is used with Google Analytics and Microsoft ClarityConsent
Show and measure ads with Google Ads, Microsoft Advertising, Meta, and TikTokConsent
Send product news and offersConsent, or legitimate interests for existing customers where the law allows it, with an opt-out in every email
Comply with the law, answer lawful requests, and defend legal claimsLegal obligation and legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights, and you can object at any time. Where we rely on consent, you can withdraw it at any time without affecting processing that happened before.

05Cookies, analytics, and advertising

We use Google Tag Manager, Google Analytics, Google Ads, Microsoft Advertising, Microsoft Clarity, the Meta Pixel, and the TikTok Pixel on our marketing website only after you accept them in the cookie banner. Before you choose, only strictly necessary storage is used, and Google Consent Mode is set to deny all advertising and analytics storage. We do not run analytics or advertising tags on signing pages or inside documents.

When you accept advertising cookies, we may also send a hashed version of the email address you gave us to Google, Meta, TikTok, or Microsoft to measure sign-ups that came from an ad. The cookie policy lists every cookie, its provider, and how long it lasts.

06Identity verification and automated decisions

The KYC add-on uses Didit to compare a selfie with an identity document, check liveness, and, in 36 countries, check data against official or authorized registries. These checks are automated. The result is given to the customer who requested it, who decides what to do. Nubesti does not make decisions that produce legal effects about you based only on automated processing. If a verification affects you, you can ask the sender, or us, for a human review, to express your point of view, and to contest the result.

07Who we share data with

We share personal data only in these situations:

  • Service providers that process data for us, listed on the subprocessors page, under contracts that require confidentiality and security.
  • Advertising and analytics partners, only with your consent. Google, Microsoft, Meta, and TikTok may use the data for their own purposes as independent controllers under their own policies. For data collected through the Meta Pixel, Nubesti and Meta are joint controllers for the collection and transmission, under Meta’s controller addendum.
  • PayPal, which processes payments as an independent controller.
  • The customer who sent a document, the other signers of that document, and anyone the customer chooses to share the completed file with.
  • Professional advisers, such as lawyers, accountants, and auditors, under confidentiality duties.
  • Public authorities, when the law requires it, following the government requests policy.
  • A buyer or successor in a merger, acquisition, or sale of assets, subject to this policy.

We do not sell personal data for money. Some U.S. state laws call the use of advertising cookies a “sale” or “sharing” of personal information, or “targeted advertising”. We use them only with your consent, and you can opt out at any time on the privacy choices page.

08International transfers

Nubesti is based in the United States, and our providers operate in several countries, including through Cloudflare’s global network. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we use the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where the recipient is certified, or the European Commission’s Standard Contractual Clauses of 2021, with the UK International Data Transfer Addendum and the Swiss amendments where needed.

For transfers from other countries, such as Brazil, Argentina, Colombia, Mexico, South Africa, or India, we use the contractual clauses, consent, or other mechanisms that the local law recognizes. We assess the laws of the destination country and add safeguards such as encryption where they are needed. You can ask for a copy of the relevant safeguards at [email protected].

09How long we keep data

We keep personal data only as long as the purpose requires, and then delete or anonymize it:

DataRetention
Account dataWhile the account is open, plus 30 days to export after closure
Documents and signature evidenceAs the customer decides while the workspace is open. After closure, deleted once the 30-day export period ends
BackupsOverwritten on a rolling cycle, within 90 days
Billing, invoices, and tax recordsAs long as tax and accounting laws require, usually 5 to 10 years
Security logsUp to 12 months, unless needed to investigate an incident
Website analyticsUp to 14 months
Advertising cookiesAs listed in the cookie policy, never longer than 13 months
Support messagesUp to 3 years after the last contact
Marketing contactsUntil you unsubscribe, or after 2 years without interaction
Identity verificationAs described on the identity verification page

We may keep data for longer when it is needed to comply with a legal obligation, to preserve evidence for a dispute, or under a legal hold.

10How we protect data

We use encryption in transit, encryption at rest by our storage providers, access limited to people who need it, and monitoring of the systems that store data. No system is perfectly secure. The security overview describes our measures and how we notify customers and authorities of a personal data breach.

11Your rights

Depending on where you live, you have some or all of these rights:

  • Know what personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete data.
  • Delete your data, subject to legal exceptions.
  • Receive your data in a portable format, or have it sent to another provider.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Restrict processing while a request is being reviewed.
  • Withdraw consent at any time, including for cookies.
  • Opt out of the sale or sharing of personal data and of targeted advertising.
  • Not be subject to a decision based only on automated processing that significantly affects you.
  • Not be discriminated against for using your rights.
  • Complain to a data protection authority.

To use a right, write to [email protected] with the subject “Privacy request”, or follow the privacy choices page. We answer within one month, or sooner if your local law requires it, and we may ask for information to confirm your identity. The regional privacy rights page explains the rules for each region and country.

12Marketing messages

Every marketing email includes a link to unsubscribe. Service messages about your account, security, billing, or a document you sent or need to sign are not marketing, and we will keep sending them while they are needed.

13Children

inSigner is a professional service for adults. We do not knowingly collect personal data from children under 16, or under 13 in the United States, and we do not sell or share the data of anyone under 16. If you believe a child has given us personal data, write to [email protected] and we will delete it.

14Changes to this policy

We publish changes on this page with a new date. If a change materially affects how we use personal data, we will tell account holders by email, and we will ask for consent again where the law requires it.

Questions about this policy go to [email protected].

Back to top

Related policies

Cookie Policy

The cookies we use, why, for how long, and how to accept, reject, or change your choice at any time.

Identity verification and biometrics

How the KYC add-on checks identity documents, selfies, and registries, and how biometric data is protected and deleted.

Mobile app data

The iOS and Android apps are planned and not yet a public download. They will follow these same policies.

Data processing agreement

The processor terms for documents and signer data, including the EU Standard Contractual Clauses. Ask if you need a signed copy.

Subprocessors

The companies that host the service, deliver messages, verify identity, take payment, and measure advertising.

Legal center

Terms, privacy, cookies, data processing, identity verification, and signature policies for inSigner, published by Nubesti LLC.

Your documents. Your signatures.
Your control.

A clear electronic signature service for sending, signing, sealing, and verifying important documents.

Start freeDocumentation

Evidence receipt

Agreement completed

Signer
Verified
Timestamp
Recorded
Document hash
7F3A…91C2

01Simple to start

02Unlimited documents

03Evidence-ready

Product

  • Features
  • Pricing
  • Templates
  • API and webhooks
  • Add-ons
  • Signature creator

Resources

  • Documentation
  • Changelog
  • Blog
  • FAQ
  • Help Center
  • Roadmap

Company

  • About inSigner
  • Contact
  • Security
  • Enterprise
  • Legal Center
  • Free signing

Popular Guides

  • Where inSigner is legal
  • E-signature legality
  • How to sign a PDF
  • Sign documents online

Compare inSigner

  • vs Documenso
  • vs DocuSign
  • vs PandaDoc
  • vs Adobe Sign
  • vs HelloSign
  • vs SignNow
  • vs Zoho Sign
  • vs YouSign
  • vs DocuSeal

Countries

  • Australia
  • United Kingdom
  • United States
  • Japan
  • European Union
  • Germany
  • France
  • Spain
  • Italy
  • See all countries
LegalPrivacy PolicyTerms of ServiceDisclaimerSecurityYour privacy choices

© 2026 inSigner. All rights reserved.

EN· English
  • EN · English
  • ES · Español
  • DE · Deutsch
  • FR · Français
  • IT · Italiano
  • PT · Português

Electronic signatures for teams everywhere.

Your privacy, your choice

We use strictly necessary cookies to run this site. With your permission, we also use analytics cookies to improve it and advertising cookies to measure our ads. You can change your choice at any time from Cookie settings in the footer. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

Cookie settings

Choose which optional cookies we may use. Strictly necessary cookies are always on because the site cannot work without them. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

  • Strictly necessary

    Security, bot protection, sign-in, signing sessions, and remembering this choice. Provided by inSigner and Cloudflare.

    Always on
  • Help us understand how the site is used so we can improve it. Provided by Google Analytics and Microsoft Clarity.

  • Measure our ads and show relevant ads on other sites. Provided by Google Ads, Microsoft Advertising, Meta, and TikTok.