Legal

Privacy Policy

Last updated: July 15, 2026

SumoSign ("we", "us") operates sumosign.app and related applications including app.sumosign.app. This policy describes how we handle personal information when you visit our marketing site, join a waitlist, create an account, or use our e-signature services.

Information we collect

Depending on how you interact with SumoSign, we may collect account details (name, email, organization), billing information processed by our payment provider, documents and envelope metadata you upload, signer contact details you provide, technical logs (IP address, user agent, timestamps), and communications you send to support.

How we use information

We use data to provide and secure the signing service, deliver signing invitations, maintain audit trails and evidence bundles, process payments, respond to support requests, improve the product, and comply with legal obligations. Marketing-site analytics (for example Google Analytics and Meta Pixel) help us understand site usage; you can control cookies through your browser settings.

Document and signer data

Customer-uploaded documents and recipient signing activity are processed to fulfill your instructions. Audit events record actor type, timestamps, and technical context needed for defensible electronic-signature evidence. Organizations control what documents they send and which recipients they invite.

Cookies and consent

On our marketing site we use analytics cookies from Google Analytics and Meta Pixel to understand site usage. For visitors in the European Union, European Economic Area, United Kingdom, and Switzerland, these trackers do not load until you accept them through our consent banner. The banner lets you accept or reject non-essential cookies with equal prominence, and your choice is stored in a first-party ss_consent cookie for twelve months so we do not ask again on every visit. Visitors outside these regions see analytics load as usual. To determine which region you are in, we set a first-party ss_geo cookie derived from your approximate country; when your country cannot be determined we default to requiring consent.

We also set a first-party ss_ai_vid cookie to attribute traffic that arrives from AI assistants and search tools, so we can measure how people discover SumoSign. It holds a random identifier only, is not shared with third parties, and is used under our legitimate interest in understanding referral sources. You can clear these cookies at any time through your browser settings.

Sharing and subprocessors

We use infrastructure and service providers (for example cloud hosting, email delivery, and payment processing) that process data on our behalf under contractual safeguards. We do not sell personal information. We may disclose information when required by law or to protect rights, safety, and security.

Retention and security

We retain data for as long as needed to provide the service, meet legal requirements, and resolve disputes. We apply encryption in transit, tenant-scoped access controls, and append-only audit logging. No method of transmission or storage is completely secure; we work to reduce risk commensurate with the sensitivity of signing data.

Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your personal data, or to object to processing and request portability. Account holders can manage much of their data through the customer portal. Contact us to exercise other rights.

International transfers

SumoSign may process data in countries other than where you reside. Where required, we use appropriate safeguards for cross-border transfers.

Children

SumoSign is a business service not directed at children under 16. We do not knowingly collect personal information from children.

Changes

We may update this policy from time to time. Material changes will be posted on this page with an updated date.

Contact

Questions about privacy: hello@sumosign.app. See also our Terms of Service.