HankoSign Privacy Policy
Effective date: August 1, 2026
Version: 1.0
This Privacy Policy explains how HankoSign LLC ("HankoSign," "we," "us") collects, uses, and shares personal information when you use hankosign.com and our electronic signature services (the "Services"). It applies to account holders ("Customers"), their users, visitors to our website, and people invited to sign or receive documents ("Signers").
Our two roles. For information about Customers, their users, and website visitors, HankoSign is the business/controller and this Policy governs. For documents and Signer information processed at the direction of a Customer (for example, a contract a Customer sends you to sign), the Customer is the controller and HankoSign acts as its processor (service provider), processing that data on the Customer's behalf to provide the Services. If you are a Signer with questions about a document you were asked to sign, or you want it deleted or corrected, please contact the sender first; we support Customers in honoring such requests.
1. Information we collect
Account and profile information. Name, email address, organization name and type, mailing/billing address for paid organizational plans, role, and an optional profile image. Authentication credentials are managed by our identity provider, Amazon Cognito; HankoSign does not store your password or any password hash.
Sign-in via identity providers. If you sign in with Google or Microsoft, we receive your basic profile information from the provider (such as name, verified email address, and a provider account identifier) to authenticate you. We do not receive your provider password.
Documents and signing data. Documents uploaded by Customers; the names and email addresses of Signers and CC recipients designated by Customers; field values entered during signing; signature and initials images (drawn or adopted); consent and decline actions; and completed signed documents and Certificates of Completion.
Supporting documents from Signers. When a Customer asks a Signer to provide supporting files as part of a transaction (for example, an identification document, a W-9, or a certificate of insurance), the files the Signer uploads are collected and processed on the Customer's behalf and made available to the requesting Customer. These files may contain sensitive personal information; we process them solely on the Customer's behalf to make them available to the requesting Customer, and we do not use them for our own purposes. They are automatically and permanently deleted ninety (90) days after the envelope is completed (or ninety (90) days after upload if the envelope is never completed) (see Section 4). A Signer who wants to access, correct, or delete a supporting file should contact the requesting Customer, who controls it; we will assist the Customer in responding.
Audit trail data. To provide tamper-evident evidence of the signing process, we automatically record events such as when a document is sent, viewed, consented to, signed, declined, or completed, together with timestamps, the associated Signer identity, and the IP address from which each action was taken. Audit data is embedded in Certificates of Completion and retained with the envelope record.
Billing information. Paid plans are processed by Stripe. We receive and store subscription status, plan, billing interval, and Stripe identifiers; we do not store your full payment card number — card details are provided directly to and held by Stripe.
Support and communications. Messages you send us, support requests, and email delivery events (such as bounces and spam complaints) reported by mail providers, which we use to maintain deliverability.
Usage and log data. Standard technical data such as browser type, device information, pages accessed, timestamps, and IP addresses, collected through server logs for security and operations.
Cookies. We use strictly necessary cookies only: a session cookie to keep you signed in and protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies, and we do not currently use third-party analytics cookies. Because we do not track you across sites, there is no advertising-tracking behavior to disable; browser "Do Not Track" and Global Privacy Control signals do not change how the Services function, and we do not sell or share personal information for cross-context behavioral advertising in any event.
Payment information (if payments are enabled). If a Customer enables payments, we process payment metadata — amount, currency, transaction identifier, and status — on the Customer's behalf, to present a payment indicator and record whether a payment occurred. Card and bank details are entered directly with the payment processor (Stripe) and never reach HankoSign. Funds are collected on the Customer's own connected processor account; we do not hold funds and do not verify settlement.
Children. The Services are not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
2. How we use information
We use personal information to: provide and operate the Services, including transmitting documents, capturing signatures, generating signed finals and Certificates of Completion, and maintaining audit trails; create and manage accounts and authenticate users; process subscriptions and payments through Stripe; send transactional email (signing invitations, completion notices, verification, password resets, billing and lifecycle notices); provide support; monitor, secure, and debug the Services, and prevent fraud and abuse; comply with legal obligations, including record-integrity obligations relevant to electronic transactions; and, with your choices respected, send limited service or product announcements. We do not sell personal information, and we do not use Customer documents or Signer data for advertising or to train models.
3. How we share information
We share personal information only with:
- Service providers (subprocessors) that host and support the Services under contractual confidentiality and data-protection obligations: Amazon Web Services (cloud hosting, storage, authentication via Amazon Cognito, and email delivery via Amazon SES; data hosted in the United States, us-east-1), Stripe (payment processing), and, if you use them, Google or Microsoft (sign-in). A current subprocessor list is available on request.
- Transaction participants, at the Customer's direction: Signers, CC recipients, and the sending Customer see the document and signing information relevant to their transaction — for example, completed documents and Certificates of Completion (which include signer names, emails, IP addresses, and the audit trail) are delivered to the transaction's participants.
- Customer integrations, at the Customer's direction: where a Customer uses our API or webhooks, we transmit envelope and signing data — such as status, signer information, and completed field values — in API responses to the Customer's authenticated requests and in webhook deliveries to endpoints the Customer configures. The Customer is responsible for the security and use of that data once it reaches the Customer's systems.
- Legal and safety recipients: where required by law, subpoena, or legal process, or where reasonably necessary to protect the rights, safety, or property of HankoSign, our users, or the public.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or successor terms with equivalent protections.
Internal access to a Customer's account by authorized HankoSign personnel to support and operate the Services (see Section 5, "Personnel access") is performed on the Customer's behalf and is not a sale of, or a third-party disclosure of, personal information.
4. Retention
We retain account information for as long as your account is active and as needed thereafter for legitimate business or legal purposes. Completed signed documents, Certificates of Completion, and audit trails are retained under the controlling Customer's account — their evidentiary value depends on integrity, so each signed final is digitally sealed at completion — any later alteration is detectable — and is not altered after completion. Draft and working files are deleted when an envelope is finalized or voided per the product's normal operation. Files that signers upload as supporting or companion documents at the end of signing are automatically and permanently deleted ninety (90) days after the envelope is completed (or ninety (90) days after upload if the envelope is never completed). If an account is closed, Customer Content is available for export for at least 30 days and then deleted, except where longer retention is required by law. When a Customer sends one template to many recipients at once ("bulk send"), the uploaded recipient list is not stored as a file; only the parsed per-recipient send records (name, email, and the resulting envelope's status) are kept as bulk-send bookkeeping and are automatically deleted thirty (30) days after the batch is created. The envelopes those sends create are retained under the normal rules above. Password reset tokens, sessions, and similar operational records expire automatically.
5. Security
We take security seriously: encryption in transit (TLS) and at rest, PKI-based digital sealing of completed documents with trusted timestamps issued by a third-party timestamp authority, which receives only a cryptographic hash of the document and no document content or personal information; authentication handled by our identity provider (Amazon Cognito), tokenized signing links, role-based access controls, tenant isolation, private storage with public access blocked, and least-privilege infrastructure access. No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we work to protect your information and to notify affected parties of any breach as required by law.
Personnel access. Authorized HankoSign personnel may access a Customer's account — including documents and signing information — to provide support and operate the Services. Access to our administrative console requires multi-factor authentication. When personnel view a Customer's account as one of its users, that access is strictly read-only and is limited to personnel who need it; each such session is logged and attributed to the individual staff member. Account-administration actions (such as plan, status, or user changes) are taken through our console and are likewise logged and attributed. Because this internal access is performed by HankoSign on the Customer's behalf, it is not a sale of personal information or a disclosure to a third party (see Section 3).
6. Your privacy rights
Depending on your state of residence (including under the California Consumer Privacy Act as amended, and comparable laws in states such as Texas, Colorado, Connecticut, Virginia, Oregon, New Jersey, and Washington), you may have the right to: know/access the personal information we hold about you; correct inaccurate information; delete personal information; obtain a portable copy; and opt out of sales, sharing for cross-context behavioral advertising, and certain profiling — noting that we do not sell or share personal information for advertising, so there is nothing to opt out of in that respect.
To exercise rights, contact us at support@hankosign.com with your request; we will verify your identity (typically via your account email) and respond within the time required by applicable law. You may use an authorized agent where the law allows. We will not discriminate against you for exercising your rights. If we deny a request, you may appeal by replying to our decision, and residents of some states may contact their state attorney general.
Two scope notes. First, where we process Signer data on behalf of a Customer, applicable law generally directs rights requests to the Customer as the controller; we will route your request to the relevant Customer or assist them in responding. Second, deletion rights are subject to legal exceptions — in particular, audit trails and completed signed documents may be retained where necessary to maintain the integrity and evidentiary value of executed transactions, to comply with law, or to defend legal claims.
7. Where the Services are provided
The Services are operated from the United States, and information is stored on servers located in the United States. The Services are directed to users in the United States. If you access the Services from outside the U.S., you understand that your information will be transferred to and processed in the U.S.
8. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced via the Services or by email before they take effect, and the effective date above will be updated. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
9. Contact us
Questions, requests, or complaints:
HankoSign LLC
Jacksonville, FL 32246
support@hankosign.com · https://hankosign.com
Customer service: (904) 450-5777