Privacy and Cookie Policy
Updated: March 18, 2026
1. INTRODUCTION AND CORE DATA PHILOSOPHY
VestedProof ("we," "us," or "our") is committed to protecting your privacy and the security of your digital documents. This Privacy and Cookie Policy ("Policy") provides a comprehensive, exhaustive disclosure of how we collect, use, store, process, and protect your personal data when you use the VestedProof platform (the "Service").
1.1 Data Control and Ownership
VestedProof operates as a Data Controller for the information related to our Account holders (Users) and a Data Processor for the information uploaded by Users for the purposes of signature and verification. We believe in "Data Sovereignty"—you own your documents and your data; we merely provide the cryptographic infrastructure to validate them.
1.2 "Self-Verifying" Privacy Impact
Our unique "Self-Verifying" architecture is designed with Privacy by Design principles. Instead of storing your documents indefinitely in a central database, our system allows you to download the proof (Hash and Certificate) and verify it independently. This reduces the "Privacy Surface Area" and the risk associated with centralized data breaches.
2. GRANULAR INFORMATION WE COLLECT
We collect information through several channels, categorizing them into Service Information, Usage Information, and Marketing Information.
2.1 Information Provided by You
- Account Registration Data: Full name, primary email address, phone number and password (stored as a one-way salt-hashed string).
- Billing and Financial Data: While we use Stripe to process payments, we may collect billing addresses, VAT numbers (for EU entities), and transaction history.
- Identity Verification Metadata: Phone numbers used for Two-Factor Authentication (2FA) via SMS.
2.2 Data Processed during the Signing Process
- Signatory Information: Full names, primary email addresses and phone numbers of individuals invited to sign a document.
- Document Metadata: File name, file size, and the unique SHA-256 hash. NOTE: Unless you explicitly use our "Vault" storage feature, VestedProof does not read or store the contents of your documents long-term.
- Verification Logs: Timestamps of when a document was viewed, signed, verified, edited or hashed.
2.3 Information Collected Automatically (Usage Data)
- Technical Identifiers: IP addresses (IPv4 and IPv6), browser type (e.g., Chrome, Firefox, Safari), browser version, screen dimensions and operating system.
- Interaction Data: Pages visited, time spent on the Service, click-stream data, and diagnostic crash reports.
- Geolocation Data: Approximate location derived from your IP address to comply with regional data residency requirements.
3. HOW WE USE YOUR INFORMATION
We use the collected data for the following essential and non-essential purposes:
3.1 Provision of the Service
- Authentication: To verify your identity and grant access to your Account.
- Execution of Signatures: To route documents to signers and apply cryptographic certificates.
- Audit Trails: To maintain a legally defensible record of the signing process.
3.2 Platform Improvement
- Triage and Debugging: Analyzing crash logs and usage patterns to fix bugs.
- Feature Optimization: Understanding for example which signature types (SES vs. AdES) are most used to prioritize development.
3.3 Communication and Support
- Support Requests: To respond to your inquiries via email or help desk.
- Security Updates: To notify you of critical changes to our infrastructure or security protocols.
4. LEGAL BASIS FOR PROCESSING (GDPR COMPLIANCE)
If you are a resident of the European Economic Area (EEA), our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
4.1 Performance of a Contract: Most of our processing is necessary to fulfill our obligations under the VestedProof Terms of Service (e.g., executing your signature requests). 4.2 Legitimate Interests: We process data for platform security, fraud prevention, and improving our internal tools, provided these interests do not override your fundamental rights. 4.3 Consent: For non-essential cookies and marketing communications, we rely on your explicit consent granted via our Consent Mode v2 interface. 4.4 Legal Obligation: We may process data to comply with anti-money laundering (AML) or other regulatory requirements.
5. DATA SHARING AND THIRD-PARTY SUB-PROCESSORS
To provide a top-tier e-signature experience, we partner with specialized third-party providers. We have executed Data Processing Agreements (DPAs) with each of these partners.
5.1 Financial Services (Stripe)
- Role: Payment Processor and Fraud Detection.
- Data Shared: Email, Name, Billing Address, Payment Method identifiers...
- Policy: Stripe Privacy Policy
5.2 Communication Services (Postmark)
- Role: Transactional Email Delivery.
- Data Shared: Email address, Signatory Name, Document Title, Document Body....
- Policy: Postmark Privacy Policy
5.3 Infrastructure and Hosting (Google Cloud Platform)
- Role: Cloud Hosting, NoSQL Database, Cloud Run backend, Authentication services, Analytics...
- Data Shared: All Account data and metadata. All processing occurs in us-central1 (Iowa, USA).
- Policy: Google Cloud Privacy
5.4 Analytics and Marketing (Google and Meta)
- Google Tag Manager & Analytics: Used to track user behavior and site performance.
- Google Ads & Meta Pixel: Used to measure advertising ROI and marketing related metrics.
- Consent Note: By entering our website and using our services you accepted all cookies included marketing cookies. In case you do not accept all these cookies we require, please leave the domain vestedproof.com and delete your browser cookies.
- Google Policy: Google Cloud Privacy
- Meta Policy: Meta Privacy Policy
6. COOKIES AND TRACKING TECHNOLOGIES
VestedProof utilizes cookies—small text files stored on your device—to enhance your experience.
6.1 Essential Cookies
Required for Account security, session management, and load balancing. These cannot be disabled as they are necessary for the Service to function.
6.2 Analytical Cookies
Help us understand how many visitors we have and how they move around the site. We use Google Analytics for this purpose.
6.3 Marketing Cookies
Used to deliver relevant advertisements and track their performance.
6.4 Google Consent Mode v2
VestedProof is an early adopter of Google Consent Mode v2. This technology ensures that even if you decline non-essential cookies, your privacy is respected at the browser level, and tracking pings are sent in a "cookieless" anonymized state where legally permitted.
7. DATA RETENTION AND DELETION PROTOCOLS
7.1 Data Retention
We retain personal data and document metadata ONLY as long as your Account remains active or until you explicitly delete the document or account. We do not enforce a mandatory 7-year retention period for your data; you maintain full control over the lifecycle of your information.
7.2 Active Documents
Documents uploaded for signing are kept in our temporary encrypted buffer for at least 30 days post-completion (we currently do not delete any documents, but it may change in the future and long term storage possibly can be charged as add-on).
7.3 Permanent Archival (The "Vault")
We do not provide yet (we currently do not delete any documents, but it may change in the future and long term storage possibly can be charged as add-on).
7.4 Account Termination
Upon Account closure, all your data will be "hard deleted" immediatelly without possibility to restore the account and related data.
8. INTERNATIONAL DATA TRANSFERS
VestedProof is a global service. Your data may be transferred to, and processed in, countries other than the one in which you reside.
8.1 Data Residency
Our primary infrastructure is located in the United States (Iowa). For transfers of data from the EEA to the United States, we rely on Standard Contractual Clauses (SCCs).
9. YOUR PRIVACY RIGHTS
Depending on your jurisdiction (e.g., GDPR in the EU, CCPA in California, LGPD in Brazil), you have specific rights:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can correct inaccurate or incomplete data through your settings.
- Right to Erasure ("Right to be Forgotten"): You can request that we delete your personal data, subject to legal retention requirements for audit logs.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object/Restrict: You can object to processing based on legitimate interests or request a restriction of processing.
To exercise these rights, please contact our Data Protection Officer (DPO) at dpo@vestedproof.com.
10. SECURITY OF YOUR INFORMATION
We implement a "Defense in Depth" strategy:
- Encryption in Transit: All communications are secured via TLS 1.3.
- Encryption at Rest: Documents and sensitive metadata are encrypted using AES-256.
- Access Control: We enforce Least Privilege Access (LPA) for our internal staff.
- Cryptographic Hashing: Using SHA-256 for document integrity verification.
11. CHILDREN'S PRIVACY
VestedProof is intended solely for professional and commercial use by adults. We do not knowingly collect information from children under the age of 18. If we discover such data, it is deleted immediately.
12. CONTACT INFORMATION
Data Controller: VestedProof (Contact via website)
Jurisdiction: State of Delaware, USA
Privacy Inquiries: support@vestedproof.com
DPO Contact: dpo@vestedproof.com
APPENDIX I: DETAILED SUB-PROCESSOR LIST
| Name | Purpose | Location |
|---|---|---|
| Google Cloud | Database, Auth, Hosting | USA (Iowa) |
| Stripe, Inc. | Payment Processing | USA |
| Postmark (AC PM) | Email Infrastructure | USA |
| Google Analytics | Usage Tracking | USA |
| Meta (FB, IG, WA) | Usage Tracking | USA |
APPENDIX II: COOKIE INVENTORY
vp_session: Essential. Stores session ID. (Expires: 24h)vp_lang: Functional. Remembers language choice. (Expires: 1 year)_ga: Analytics. Google tracking ID. (Expires: 2 years)_fbp: Marketing. Meta advertisement tracking. (Expires: 3 months)_gcl_au: Marketing. Google Ads conversion tracking. (Expires: 3 months)ad_storage: Marketing. Advertising related storage. (Expires: Session)analytics_storage: Analytics. Analytics related storage. (Expires: Session)ad_user_data: Marketing. User data for advertising. (Expires: Session)ad_personalization: Marketing. Personalization for advertising. (Expires: Session)personalization_storage: Functional. Personalization related storage. (Expires: Session)functionality_storage: Functional. Functionality related storage. (Expires: Session)security_storage: Essential. Security related storage. (Expires: Session)
APPENDIX III: EXHAUSTIVE GLOSSARY OF PRIVACY TERMS
- Anonymization: The process of either modifying or deleting personally identifiable information to the point where the data can no longer be associated with an individual.
- Behavioral Advertising: The practice of following a user's web-browsing activities over time in order to deliver advertisements that are more relevant to the user's interests.
- Biometric Data: Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person.
- Cloud Computing: The on-demand availability of computer system resources, especially data storage and computing power, without direct active management by the user.
- Data Breach: A security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.
- Data Minimization: The principle that personal data should be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
- DPO (Data Protection Officer): An enterprise security leadership role required by the General Data Protection Regulation (GDPR).
- End-to-End Encryption (E2EE): A system of communication where only the communicating users can read the messages.
- IP Address: A unique string of characters that identifies each computer using the Internet Protocol to communicate over a network.
- LPA (Least Privilege Access): A security concept in which a user is given the minimum levels of access – or permissions – needed to perform his or her job functions.
- PII (Personally Identifiable Information): Any data that could potentially identify a specific individual.
- Profiling: Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.
- Pseudonymization: A data management and de-identification procedure by which personally identifiable information fields within a data record are replaced by one or more artificial identifiers.
- Retention Period: The duration for which an organization keeps personal data.
- Subject Access Request (SAR): A request by an individual to see a copy of the information an organization holds about them.
- Tracking Pixel: A 1x1 image used to track a user's behavior on a website.
APPENDIX IV: EXHAUSTIVE REGIONAL ADDENDA
IV.1 CALIFORNIA CONSUMER PRIVACY ACT (CCPA) AND CPRA
This section provides additional disclosures required by the California Consumer Privacy Act of 2018 ("CCPA") and the California Privacy Rights Act of 2020 ("CPRA").
Categories of Personal Information Collected:
- Identifiers: Name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name.
- Customer Records Information: Name, signature, address, telephone number.
- Commercial Information: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
- Internet or Other Electronic Network Activity Information: Browsing history, search history, and information regarding a consumer’s interaction with an internet website, application, or advertisement.
- Geolocation Data: Physical location or movements.
- Professional or Employment-related Information: Current or past job history or performance evaluations.
- Inferences: Drawn from any of the information identified above to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Your Rights under the CCPA/CPRA:
- Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell.
- Right to Delete: You have the right to request the deletion of your personal information collected or maintained by us.
- Right to Opt-Out of Sale or Sharing: VestedProof does not sell your personal information. However, you have the right to opt-out of the "sharing" of your information for cross-context behavioral advertising.
- Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you.
- Right to Limit Use and Disclosure of Sensitive Personal Information: You have the right to limit the use of sensitive personal information if we use it for certain purposes.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment by us for the exercise of the privacy rights conferred by the CCPA.
IV.2 EUROPEAN UNION AND UNITED KINGDOM (GDPR)
This section applies to individuals located in the European Economic Area ("EEA"), Switzerland, or the United Kingdom.
Data Subject Rights in Detail:
- Right of Access (Article 15 GDPR): You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and specific information regarding the processing.
- Right to Rectification (Article 16 GDPR): You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you.
- Right to Erasure / Right to be Forgotten (Article 17 GDPR): You have the right to obtain from us the erasure of personal data concerning you without undue delay where certain grounds apply (e.g., the data are no longer necessary, you withdraw consent). EXCEPTION: VestedProof maintains audit logs required for the legal validity of signed documents, which may be exempt from immediate deletion requests under legal obligation or for the establishment, exercise or defense of legal claims.
- Right to Restriction of Processing (Article 18 GDPR): You have the right to obtain from us restriction of processing where certain conditions are met (e.g., accuracy of data is contested).
- Right to Data Portability (Article 20 GDPR): You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format.
- Right to Object (Article 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you.
- Right to Withdraw Consent (Article 7(3) GDPR): Where processing is based on consent, you have the right to withdraw your consent at any time.
Supervisory Authority: You have the right to lodge a complaint with a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority in the EEA, UK, or Switzerland.
IV.3 CANADA (PIPEDA)
VestedProof complies with the Personal Information Protection and Electronic Documents Act (PIPEDA). We ensure that personal information is collected for purposes that a reasonable person would consider appropriate in the circumstances.
IV.4 AUSTRALIA (PRIVACY ACT 1988)
For Australian users, we comply with the Australian Privacy Principles (APPs). If you have a complaint about our compliance with the APPs, please contact our DPO.
APPENDIX V: EXHAUSTIVE TECHNICAL SECURITY SPECIFICATIONS
VestedProof implements the following technical controls to ensure the confidentiality, integrity, and availability of your data:
V.1 Network Security
- TLS 1.3 Encryption: All data in transit is encrypted using modern cipher suites.
V.2 Data Security at Rest
- AES-256 Storage: All volumes in our Google Cloud environment are encrypted using FIPS 140-2 validated hardware modules.
- Cryptographic Hashing (SHA-256): Every document is hashed immediately upon secure upload to our encrypted storage environment to ensure technical non-repudiation.
V.3 Access and Administrative Controls
- Multi-Factor Authentication (MFA): Mandatory for all VestedProof employees and contractors accessing production environments.
- Audit Logging: Comprehensive logging of all administrative actions in the VPC environment.
- Disaster Recovery (DR): Daily encrypted backups stored in geographically separate regions (multi-region availability).
APPENDIX VI: COMPREHENSIVE BROWSER AND TRACKING DISCLOSURE
VestedProof uses various tracking technologies to improve the user experience and measure performance.
VI.1 Local Storage and Session Storage
In addition to cookies, we use browser "Local Storage" and "Session Storage" to:
- Persist your session ID during active signing.
- Cache UI preferences (e.g., Dark Mode settings).
- Temporarily store document metadata during the upload process to prevent data loss on page refresh.
VI.2 Tracking Pixels and Web Beacons
We use 1x1 transparent images ("pixels") to:
- Determine if a signature invitation email was opened (via Postmark).
- Track the conversion rate of marketing landing pages.
- Attribute sign-ups to specific advertising campaigns on Meta and Google Ads.
VI.3 Browser Fingerprinting
VestedProof does not engage in invasive cross-site browser fingerprinting for the purpose of identifying individuals. We may collect limited browser attributes (User Agent, Screen Resolution...) solely for the purpose of technical troubleshooting and ensuring correct rendering of the signing interface.
APPENDIX VII: PRIVACY FAQ FOR SIGNERS AND DATA PROCESSING SCENARIOS
To ensure transpareny for individuals invited to sign documents via VestedProof, we provide the following detailed scenarios and answers:
VII.1 I received a signature request. What data does VestedProof have about me?
When a VestedProof User invites you to sign a document, we receive:
- Your name and email address.
- The title of the document you are being asked to sign.
- Any 2FA information (like a phone number) provided by the sender.
Once you interact with the link, we also collect:
- Your IP address and User Agent data.
- The precise time you viewed the document.
- The cryptographic hash of the signature you apply.
VII.2 Does VestedProof sell my contact information to advertisers?
ABSOLUTELY NOT. VestedProof is a B2B service provider. We do not sell, rent, or trade signatory data to third parties for marketing purposes. Your information is used strictly to execute the signature requested by our User.
VII.3 How long is my signature record kept?
VestedProof maintains the "Audit Trail" as long as the associated document exists or the User Account remains active. Deleting an account or a document triggers the removal of associated audit records from our primary systems.
VII.4 Scenario: Multi-Party Signing and Data Exposure
In a scenario where three or more parties (A, B, C...) are signing a document:
- Visibility: All parties will see the names, email addresses, phone numbers, browser data, ip address and user agent data of the other signatories in the final "Certificate of Completion."
- Data Sharing: By participating in a multi-party signature, you consent to this limited disclosure of your identifiers to the other participants for the purpose of validating the mutual agreement.
VII.5 Scenario: International Dispute and Audit Requests
If a document signed via VestedProof is challenged in a court of law:
- Discovery: VestedProof may provide the full technical logs (Audit Trail), but it is not necessary as document itself act as self-sovereign proof.
- Compliance: We will comply with lawful requests from governmental authorities while ensuring that only the minimum necessary data is disclosed.
APPENDIX VIII: COMPREHENSIVE LIST OF DATA TYPES AND PURPOSES
| Data Category | Specific Elements | Processing Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Identity | Name, Email, Phone | Signature Routing, 2FA | Contractual Necessity |
| Technical | IP Address, User Agent | Fraud Prevention, Security | Legitimate Interest |
| Financial | Billing Address, Last 4 digits | Tax Compliance, Billing | Legal Obligation |
| Behavioral | Page Views, Click Paths | UI Optimization | Consent (Marketing) |
| Cryptographic | SHA-256 Hashes | Document Integrity | Contractual Necessity |
APPENDIX IX: DETAILED DATA PROTECTION IMPACT ASSESSMENT (DPIA) SUMMARY
VestedProof has conducted an internal DPIA to assess the risks associated with e-signature processing.
- Risk of Data Loss: Mitigated by AES-256 encryption and multi-region backups.
- Risk of Identity Theft: Mitigated by SMS 2FA and secure audit trailing.
- Risk of Tampering: Mitigated by SHA-256 immutable hashing.
- Risk to Data Subject Rights: Mitigated by one-click data export tools for Users and a dedicated DPO.
APPENDIX X: SELF-VERIFYING TECHNOLOGY TECHNICAL DEEP-DIVE
As part of our commitment to Privacy by Design, VestedProof utilizes a "Self-Verifying" document architecture. This section provides the exhaustive technical details of how this impacts your data privacy.
X.1 The Secure Hashing and Certification Protocol
When a document is uploaded to VestedProof, it is securely transmitted to our Google Cloud infrastructure where our signing engine immediately executes a SHA-256 hash.
- Secure Processing Path: The document is processed within isolated, transient memory environments. While the full document is uploaded for certification, the original content is handled with the highest level of encryption, ensuring that only the generated hash serves as the immutable long-term link.
- Certification: VestedProof signs this hash with our private key and attaches a timestamp from our synchronized Stratum-1 time source.
- Verification: When someone verifies the document later, they provide the file and the Certificate. The verification engine re-calculates the SHA-256 hash of the file and compares it to the signed hash recorded at the time of certification. If the hashes match, the document is proven authentic.
X.2 Impact on Data Retention and "Right to Erasure"
Traditional e-signature providers MUST store your document to verify it. If you exercise your "Right to Erasure" (Article 17 GDPR) with them, the document is deleted, and the signature becomes unverifiable. The VestedProof Advantage: Because the proof is externalized in the Certificate, you can request that we delete your Account data, yet your previously signed documents remain fully verifiable in perpetuity. This allows VestedProof to comply with deletion requests while maintaining the legal integrity of your past transactions.
X.3 Cryptographic Salt and Pepper
To prevent "Rainbow Table" attacks on common document types (like standard NDAs), VestedProof may append a unique, non-secret "salt" (a random string) to the document metadata during the hashing process. This ensures that two identical documents signed by different Users result in different, non-associable hashes.
CONTACT US (GLOBAL REACH)
For any privacy-related matters, regardless of your location, you may reach our centralized privacy team:
VestedProof
Privacy Office: support@vestedproof.com
Global Email: support@vestedproof.com
Jurisdiction: Delaware, USA
Pokud máte jakékoli dotazy týkající se našich privacy policy, kontaktujte nás na
support@vestedproof.com.