Third Party Index

Snapshot 25063

Document
Privacy policy
URL
https://docspring.com/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
27095 bytes
SHA-256 (raw)
d02e1ef72b491bd7807895854bd46e545ae0c9868e7b009cea1f51a6315fca96
SHA-256 (normalized text)
8467d6566bcf8875acd02022fef15303c01f93a521487dc8b1634bfa997645ec

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Start Free Trial
Sign In Start Free Trial
Dashboard Sign Out
Privacy Policy
Who We Are and How to Contact Us
DocSpring, Inc. is a Delaware corporation. Our mailing address is 9450 SW Gemini Dr, PMB 95273, Beaverton, OR 97008-7105, United States. For privacy questions or requests, contact [email protected].
Our EU representative under Article 27 of the GDPR is Rickert Rechtsanwaltsgesellschaft mbH, Colmantstraße 15, 53115 Bonn, Germany. You may contact our representative at [email protected].
Our Role
DocSpring is the controller for information we use to manage our website, customer accounts, billing, support, and business relationships. When customers use DocSpring to generate documents, collect form responses, or obtain signatures, we handle that content on their instructions as a processor or subprocessor. The customer determines the purposes of that processing and is responsible for its privacy notice and lawful instructions. Our Data Processing Agreement (DPA) governs our handling of that content, subject to any applicable separately executed DPA.
If your information appears in a document or form submitted by one of our customers, contact that organization to exercise your rights. If you contact us, we will help identify the appropriate customer where possible and assist under their instructions and applicable law.
Information We Collect
Account and contact details, including names, email addresses, company details, user identifiers, permissions, and authentication information.
Billing contacts, addresses, invoices, payment status, and payment references. Stripe handles card entry and payment processing.
Support and sales correspondence, including information and attachments you choose to send.
Usage and security information, including IP addresses, browser and device information, request and event records, timestamps, and error reports.
Customer-provided templates, document contents, form answers, and signatures. Form and signing records can also include names, emails, IP addresses, browser information, and completion events.
We receive information from you, your organization's administrators and users, customers who submit documents or forms, and providers involved in authentication, payment, support, and service operation. Some information is collected automatically when you use the service. Account and authentication details are needed for access, and billing details are needed for paid services. Without required information, we may be unable to provide the relevant service. You choose what to include in optional communications.
How and Why We Use Information
Where the GDPR applies to our activities as a controller, we rely on the following legal bases:
Accounts, billing, and requested support: performance of our contract when you are the contracting individual, or our legitimate interests in providing and administering services to your organization.
Security, abuse prevention, troubleshooting, and improvement: our legitimate interests in operating a reliable, secure service and understanding its use, subject to your rights and reasonable expectations.
Business correspondence and administration: our legitimate interests in responding to inquiries, managing relationships, and maintaining necessary records.
Legal obligations and claims: compliance with applicable obligations where they provide a legal basis under the GDPR, and our legitimate interests in establishing, exercising, or defending legal claims.
Optional marketing and tracking: consent where required by law. Where permitted, we may rely on our legitimate interests in communicating relevant information to existing business contacts. You can object to direct marketing at any time.
Customer document contents are processed to provide the requested document, form, signature, storage, delivery, and support services under customer instructions. The legal bases for our own business activities do not authorize unrelated uses of customer document contents.
Service Providers and Other Recipients
We use Amazon Web Services for hosting and storage, Cloudflare for network delivery and security, Stripe for payments, Intercom for support, Postmark for transactional email, and Sentry for error monitoring. Business email and collaboration services include Google Workspace, Slack, and Notion. We use Savio to track customer feedback. We also use tools for development, access control, and compliance. Our Plausible analytics service is hosted on Render. Each provider's access depends on its function and the features you use; a billing or development provider does not necessarily receive document contents.
We may share information with professional advisers where necessary, authorities when legally required, or in connection with a business transfer, subject to applicable privacy requirements. Customer-configured webhooks and integrations deliver information to destinations the customer selects. We do not sell personal information. Our DPA and subprocessor list describe processing on your behalf. Contact us for details of the terms applicable to your use of DocSpring.
International Processing and Transfers
DocSpring, Inc. is a United States company. Customers can select production hosting in the United States (Northern Virginia) or Germany (Frankfurt). These environments have separate databases and document storage. EU database backups are configured in Frankfurt without cross-region copying. Our team operates from New Zealand through DocSpring NZ Limited, a separate service provider for development, operations and support. Authorized personnel may access customer data for those purposes under our instructions and data-protection requirements.
Migrating an account between regions does not by itself confirm that data in the former region has been erased. Source-region account and document data may remain pending separate deletion; recovery copies have their own retention periods. Applicable customer instructions, agreements and retention requirements continue to govern those copies.
Regional document storage does not mean all processing remains in that region. Network and security providers, email, support, billing, and other business services may process information in other countries. Customer-selected delivery destinations may also be outside the EEA.
International transfers subject to the GDPR require an applicable adequacy decision or appropriate safeguards, such as applicable European Commission Standard Contractual Clauses. New Zealand has an EU adequacy decision; it does not cover transfers to our US company or every other provider. We do not rely on the former EU-US Privacy Shield. Contact [email protected] to request details or a copy of the safeguards applicable to your information, with confidential information redacted where necessary.
Retention and Deletion
We retain information for the relevant service or business purpose, considering customer instructions, account status, unresolved support matters, applicable recordkeeping requirements, and legal claims. Different records have different retention periods. Closing an account, expiring a submission, and erasing all associated personal information are separate operations.
Each template has an "Expire Submissions" setting. Automatic expiration is disabled by default. When enabled, it defaults to seven days unless you choose another period. You can also expire a submission through the API. Expiration removes its generated PDF and preview from normal access, clears its submitted data and webhook data, and deletes ordinary submission images. Downloading a PDF does not delete it.
Ordinary submission expiration does not erase signatures, submission metadata, or separately stored data request and event records. Account deletion cancels the subscription and removes normal account access, but some records remain in our systems and business services. For erasure of associated personal information, contact [email protected]. We assess the request and any lawful retention requirements; account closure alone is not confirmation of complete erasure.
Recovery copies have separate configured periods: automated database backups are retained for 30 days, weekly snapshots for 90 days, and monthly snapshots for 365 days. Automated Redis snapshots are retained for 7 days in both regions. One-off snapshots taken for maintenance or migrations are deleted within 30 days of creation. These periods run from creation of each backup. A backup created shortly before live data is erased can therefore remain for almost another 365 days. Previous versions of deleted or replaced document files in Amazon S3 are scheduled for permanent deletion after 180 days as a previous version. S3 lifecycle deletion runs asynchronously. Data removed from the live service can remain in recovery copies until they expire. These descriptions do not override obligations under an applicable DPA or data protection law.
API and webhook database logs are subject to a 90-day deletion schedule. Security and access logs have separate periods, described on our security page. Billing, correspondence, and legal records can require retention after an account closes. Contact us for retention information relating to a particular record or request.
Cookies and Similar Technologies
We use browser storage for account sessions, security, and preferences. We self-host Plausible at pa.docspring.com for usage statistics; it does not use cookies. Two optional purposes use cookies on our website: referral attribution, which remembers the page or campaign that first brought you to us so that we can attribute a later sign-up, and advertising, which lets Google Ads tags measure conversions. In the EEA, UK, and Switzerland, or when we cannot determine your country, these optional cookies wait for your consent. Elsewhere, they may operate unless you decline them or your browser sends a Global Privacy Control signal, which we honour in every region.
Use Cookie settings to allow or decline referral attribution and advertising separately, or to allow or decline both. Your choice is stored in a cookie shared by our website and app and can be changed at any time; declining a purpose removes its cookies. Declining optional cookies does not affect our cookieless Plausible statistics. We retain server-side session and security history, including sign-in attempts and relevant account actions, to operate and secure the service. That history is not browser analytics, uses no optional cookies, and is not controlled by Cookie settings.
Intercom provides the support messenger and is independent of Cookie settings. In the app, it loads for signed-in users as part of the service. On our website, it loads automatically only where consent for optional cookies is not required; elsewhere it loads when you request support through Help or Open Live Chat, and that request is remembered for your browser session. Signing out ends the local Messenger session and removes its cookies. You can also manage stored cookies through your browser and contact us about your privacy choices. Blocking cookies needed for authentication or security may prevent parts of the service from working.
Visual forms can save unfinished answers in your browser so they are available after you reload the page. The saved draft is removed when you successfully submit or clear the form. Otherwise, it can remain until you clear that site's browser storage.
Marketing Choices
Unsubscribe from marketing using the link in a message or by contacting us. Withdrawing marketing consent or objecting to direct marketing does not prevent necessary account, billing, security, or service messages. Permission to use your name, logo, or testimonial for publicity is agreed separately; accepting this privacy policy does not grant it.
Your Privacy Rights
Where the GDPR applies, you may request access, correction, erasure, or restriction of processing. You may request a portable copy of information you provided where processing is automated and based on consent or a contract. These rights are subject to the conditions and exceptions in applicable law.
You may object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Send requests to [email protected] or our EU representative. You do not need a paid account or a particular form. We may ask for information reasonably necessary to verify identity or authority, without collecting unnecessary identification documents. For requests we handle as controller, we respond without undue delay and normally within one month of receipt. If the law permits an extension because of complexity or the number of requests, we will explain the reason and extension within that first month. Requests are normally free; any refusal or permitted fee must meet the conditions in applicable law and will be explained.
You may complain to a supervisory authority, particularly in the EEA country where you habitually reside, work, or believe an infringement occurred. You do not have to contact us first. Contact details are available from the European Data Protection Board.
Security and Restricted Data
Public service connections use HTTPS/TLS. RDS databases, Redis and S3 document storage are encrypted at rest. Our safeguards are described on the security page. Do not submit payment-card information as document or form content. DocSpring is not PCI DSS certified. Requirements for other regulated information, including US protected health information, are described on our security page and in applicable agreements.
Changes to This Policy
We may update this policy as our services or practices change. We will give notice of significant changes through an account email or a prominent website notice. An updated notice does not replace required consent or amend a separately agreed DPA.
Questions?
Contact [email protected] with questions about this policy or your personal information.
Last Modified: