Legal

Privacy Policy

Effective date: January 1, 2025  ·  Last updated: April 24, 2025

1. Introduction

Welcome to StampSig ("we", "us", or "our"). We operate the website stampsig.com — an online tool for adding stamps, signatures, and document effects in your browser.

This Privacy Policy explains what information we collect, how we use it, and your rights with respect to that information. By using our service, you agree to the practices described here.

We are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Data Controller

The data controller responsible for your personal data is:

3. Information We Collect

3.1 Information you provide voluntarily

When you create an account or contact support, we may collect your email address and, optionally, your name. We do not require any government-issued ID or payment card data beyond what is handled by our payment processor.

3.2 Documents you upload

All core operations — uploading, editing, and downloading documents — are performed locally in your browser. Files are not sent to our servers unless you explicitly use a feature that requires server-side processing (e.g., DOCX-to-PDF conversion).

Any file temporarily stored on our servers is automatically deleted within 24 hours of the last user action. We do not read, analyze, or share your document contents.

3.3 Usage and technical data

We collect standard technical data such as browser type, operating system, referring URL, pages visited, and session duration. This data is aggregated and does not identify you personally. Your IP address may be processed for security and fraud-prevention purposes.

3.4 Cookies

We use strictly necessary cookies (e.g., session tokens, theme preference) and, with your consent, analytics cookies (Google Analytics, Yandex Metrica). You can manage or withdraw cookie consent at any time through your browser settings or our cookie banner.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, we process your data on the following legal bases:

  • Contract performance — to provide the service you signed up for (Art. 6(1)(b) GDPR).
  • Legitimate interests — to improve the service, prevent fraud, and ensure security (Art. 6(1)(f) GDPR).
  • Consent — for non-essential cookies and marketing communications (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
  • Legal obligation — when required by applicable law (Art. 6(1)(c) GDPR).

5. How We Use Your Information

  • To create and manage your account.
  • To send verification codes and transactional emails.
  • To process payments via our payment provider (we do not store card details).
  • To improve the service through aggregated analytics.
  • To detect and prevent fraud and abuse.
  • To comply with legal obligations.

We do not sell your personal data to third parties.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will erase your personal data within 30 days, unless retention is required by law.

Uploaded documents stored temporarily on our servers are deleted within 24 hours. Aggregated analytics data (which cannot identify you) may be retained indefinitely.

7. Third-Party Services

We share data only with the following categories of trusted processors:

  • Payment processing — Robokassa (for users in Russia). Card data is handled entirely by the payment provider; we never see or store it.
  • Analytics — Google Analytics and Yandex Metrica, under their respective data processing agreements.
  • Infrastructure — cloud hosting providers that process data strictly on our behalf under confidentiality agreements.

We do not transfer your personal data outside the EEA without appropriate safeguards (Standard Contractual Clauses or equivalent mechanisms) where required by GDPR.

8. Your Rights

Rights under GDPR (EEA residents)

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — request deletion of your data.
  • Restriction — ask us to limit processing in certain circumstances.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — at any time, without affecting prior lawful processing.
  • Lodge a complaint — with your local data protection authority (e.g., your country's DPA or the ICO in the UK).

Rights under CCPA (California residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell.
  • Delete personal information we have collected about you.
  • Opt out of sale — we do not sell personal information.
  • Non-discrimination — we will not discriminate against you for exercising your rights.
  • Correct inaccurate personal information.

To exercise any of these rights, contact us at privacy@stampsig.com. We will respond within 30 days (GDPR) or 45 days (CCPA).

9. Security

We implement industry-standard security measures including HTTPS encryption, access controls, and secure server configurations. No method of transmission over the internet is 100% secure; however, we take all reasonable steps to protect your information.

10. Children's Privacy

Our service is not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

11. Links to Third-Party Sites

Our website may contain links to external sites. We are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available at https://stampsig.com/privacy. Material changes will be communicated via a notice on our website or by email at least 14 days before they take effect. Continued use of the service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

For any privacy-related questions, requests, or complaints, please reach out to us:

Privacy inquiries: privacy@stampsig.com

General support: support@stampsig.com

We aim to respond to all requests within 30 days.

Questions about your data?

Contact us at privacy@stampsig.com to request access, correction, or deletion of your personal data at any time.

Go to the app