Privacy Notice
In brief. While you are preparing a document, it never leaves your computer. It is uploaded only when you click Send, and then only so that your signer can be emailed a link to it. Once every signer has finished, the stored copy is deleted automatically. We collect only what the delivery requires, we do not read your documents, we do not sell or share personal information, and we do not use your files to train artificial intelligence.
Purpose
This Privacy Notice ("Notice") explains how Gohvio, Inc. ("Gohvio", "we", "us", "our") collects, uses, discloses, retains, and otherwise processes personal information about individuals ("you") who access or use snailsign.com, the Snail Sign web tool, the signing files it generates, and the hosted send-for-signature service (together, the "Services"). By using the Services you acknowledge that we will process personal information as described in this Notice.
Snail Sign is unusual among signing tools in that most of its work happens on your own device rather than on our servers. Understanding that distinction is the key to understanding this Notice, so it is set out explicitly in Section 1.
Where you use the Services to send a document to another person, you determine what that document contains and who receives it. In relation to the contents of your document you act as the controller of that information and we act as a processor, handling it only to carry out the delivery you requested. If your organisation requires a separate data processing agreement, contact us using the details in Section 12.
This Notice does not apply to third-party websites, applications, or services that you may reach from the Services. Please review their own terms and policies before using them.
- Collection of Personal Information
- Use of Personal Information and Lawful Bases for Processing
- Disclosure of Personal Information
- Retention and Deletion of Personal Information
- Your Choices
- Your Privacy Rights
- Children's Privacy
- Notice to California Residents
- How We Protect Your Personal Information
- International Transfers of Personal Information
- Changes to This Privacy Notice
- How to Contact Us
1. Collection of Personal Information
1.1 Information we do not collect: preparing a document
When you open a document in Snail Sign, it is read and rendered entirely inside your own web browser. Placing fields, typing or drawing a signature, and producing a flattened signed PDF all occur on your device. Accordingly:
- If you prepare a document and never click Send, no part of that document is transmitted to us, and we have no record of its existence, its contents, or the people named in it.
- If you use the offline workflow, in which you download a self-contained signing file and email it yourself, the document does not pass through our systems at any point.
- We do not receive, read, index, or scan the contents of any document at any stage.
1.2 Information you provide when you send for signature
Clicking Send for signature is the point at which information leaves your browser. You provide us with the following, for the sole purpose of delivering the document to the people you named:
- Document data. The document itself, packaged as a self-contained signing file, together with its file name.
- Signer contact information. The name and email address of each signer you enter, up to four signers.
- Sender contact information. Your own name and email address, so that you can be copied on the request and sent the completed document.
- Message content. Any note you choose to add to the signature request email.
- Signature data. The typed or drawn signature, dates, and text that each signer applies. These are applied on the signer's device and are returned to us only as part of the completed document file.
Because you supply information about other people when you name your signers, you are responsible for ensuring you have a proper basis for doing so, and for the accuracy of the email addresses you enter.
1.3 Information we collect automatically
- Anonymous counts. The site records two aggregate counters: that a page visit occurred, and that a signing file was downloaded. These carry no name, email address, IP-based identifier, device identifier, or document information, and cannot be traced back to you or to a particular document.
- No cookies or trackers. We do not set cookies, advertising trackers, pixels, web beacons, session replay tools, or third-party analytics on snailsign.com.
- Server logs held by our providers. Our infrastructure providers keep routine operational logs, which may include IP addresses and timestamps, for security and reliability. We do not use those logs for marketing or profiling.
1.4 Information we receive from other sources
- Payment and subscription information. If you subscribe for an access key, Stripe, Inc. processes the payment and provides us with your email address, a customer reference, and subscription status. Card numbers and security codes go directly to Stripe. We never see, receive, or store them.
1.5 Information stored only on your device
The following are saved in your browser's local storage on your own device and are never transmitted to us:
- Your access key, so that you do not have to paste it for every document.
- Your sender email address, so that you do not have to retype it.
- Your letterhead logo, if you upload one.
Clearing your browser storage removes them. This information is scoped to the exact website address you use, so it does not follow you to a different browser, device, or domain.
2. Use of Personal Information and Lawful Bases for Processing
We use personal information only for the purposes below. Where the UK GDPR, EU GDPR, or a similar law applies, the lawful basis is shown alongside each purpose.
| Purpose | Information used | Lawful basis |
|---|---|---|
| Delivering a signature request to the signers you named, in the order you set | Document data, signer and sender contact information, message content | Performance of a contract with you; our legitimate interest in operating the service you requested |
| Returning the completed document to every party | Document data, signer and sender contact information | Performance of a contract with you |
| Issuing, validating, and deactivating access keys | Subscriber email address, access key, Stripe customer reference | Performance of a contract with you |
| Taking payment and keeping statutory billing records | Subscription and billing information held by Stripe | Performance of a contract with you; compliance with tax and accounting law |
| Protecting the service against abuse, spam, and fraud | Access key usage, provider logs | Our legitimate interest in keeping the service secure and available |
| Understanding aggregate usage volume | Anonymous counters only | Our legitimate interest in maintaining the service |
| Responding to your questions and privacy requests | The contact details and content of your message | Our legitimate interest in supporting users; compliance with legal obligations |
What we never do. We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use your documents, signatures, signer details, or message content to train artificial intelligence or machine learning models, whether ours or a third party's. We do not build advertising or marketing profiles about you. We do not read the contents of your documents.
3. Disclosure of Personal Information
We disclose personal information only in the following circumstances.
- To the people you name. Your document, your name, and your email address are disclosed to the signers you enter, because that is the entire purpose of the service.
- To service providers acting on our instructions. The list is deliberately
short:
- Supabase. Storage and the server function that hold documents and signing requests while they are in progress.
- Resend. Delivery of signature request emails and completed document emails.
- Stripe. Subscription payments, invoicing, and receipts.
- GitHub Pages. Hosting of the static website files. The site is served from GitHub's infrastructure, which receives standard web request information.
- Where legally compelled. We may disclose information where we are required to do so by valid legal process, such as a subpoena, court order, or equivalent lawful demand, or where disclosure is reasonably necessary to investigate suspected fraud or a threat to the safety of any person. In practice, and because of the deletion described in Section 4, there is frequently nothing left for us to produce.
- In a business transfer. If Gohvio, Inc. is involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal information may be transferred as part of that transaction. Any recipient would remain bound by this Notice, or by a notice at least as protective, and we would post notice of the change on this page.
4. Retention and Deletion of Personal Information
We keep personal information only for as long as the purpose it was collected for requires, and then delete it.
| Category | Retention period |
|---|---|
| Document file held for an in-progress signing request | Deleted automatically once every signer has completed. If the request is not completed, it is deleted when the signing link expires 14 days after sending. |
| Signer names and email addresses | Deleted with the signing request they belong to, on completion or on expiry after 14 days. |
| Sender email address, file name, and message | Deleted with the signing request they belong to, on completion or on expiry after 14 days. |
| Subscriber email address, access key, and Stripe customer reference | Kept while your subscription is active. After cancellation, retained only as long as tax, accounting, and audit obligations require. |
| Anonymous counters | Retained indefinitely. They contain no personal information. |
| Correspondence with us | Retained as long as needed to handle your enquiry and to keep a record of privacy requests as the law requires. |
Signing links are cryptographically signed. A link therefore cannot be guessed, edited to point at a different document, or altered to last longer than the 14-day period.
Deletion is permanent, so keep your own copy. When a signing request completes or expires, the stored document is destroyed. We do not maintain an archive, a backup copy for your benefit, or a signing audit log, and we cannot recover a document for you afterwards, whoever asks and for whatever reason. The completed PDF is emailed to every signer and to you, and it carries a SHA-256 fingerprint you can use to demonstrate that a copy has not been altered. Save that email somewhere you control. Snail Sign is a delivery tool and is not a system of record.
5. Your Choices
- Use the tool without us. The preparation and signing workflow is free and fully offline. If you download the signing file and email it yourself, we receive nothing at all. This is the most privacy-protective way to use Snail Sign, and it is always available.
- Choose what goes in the document. You control the contents entirely. Please see the caution in Section 9 about sensitive categories of information.
- Choose whether to save anything locally. You may decline to save your key or logo, and you may clear your browser storage at any time.
- Marketing. We do not run marketing email campaigns from Snail Sign. The only emails we send are transactional: signature requests, completed documents, key issuance, billing notices from Stripe, and the change notices described in Section 11.
- Cancel at any time. Cancelling your subscription stops future charges and deactivates your key.
6. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights in relation to personal information we hold about you:
- Access. To ask what personal information we hold about you and obtain a copy.
- Correction. To have inaccurate personal information corrected.
- Deletion. To have personal information erased, subject to records we are legally required to keep.
- Portability. To receive certain information in a portable format.
- Objection and restriction. To object to, or ask us to restrict, processing carried out on the basis of legitimate interests.
- Withdrawal of consent. Where processing rests on consent, to withdraw that consent at any time, without affecting processing already carried out.
- Complaint. To lodge a complaint with your local data protection authority or supervisory body.
To exercise any of these rights, email emilygoh@gohvio.io. We will respond within 30 days, or within any shorter period required by applicable law. We may need to verify your identity before acting on a request, and we may decline a request that is manifestly unfounded, excessive, or that would infringe another person's rights. We will not discriminate against you for exercising any of these rights.
Please note the practical effect of Section 4: because documents and signing requests delete themselves, an access or deletion request made after a request has completed will usually find that there is nothing left to produce or erase. If the information you are asking about sits inside a document that another person sent through Snail Sign, that person is the controller of it, and you should direct your request to them in the first instance.
7. Children's Privacy
The Services are intended for use by adults in a business or personal contracting capacity and are not directed to children.
- We do not knowingly collect, use, or disclose personal information from any individual under the age of 18, and no part of the Services is designed or marketed to appeal to children.
- An access key may be purchased only by a person who is at least 18 years of age and legally able to enter into a binding contract, as set out in our Terms of Use.
- We do not knowingly sell or share the personal information of any individual under the age of 16, and we have no actual knowledge of having done so. We do not engage in any activity that would require parental consent under the Children's Online Privacy Protection Act (COPPA) or equivalent legislation in other jurisdictions.
- Because a document is delivered to whatever email address the sender enters, we have no means of verifying the age of a recipient before delivery. A sender is responsible for ensuring that a document is sent only to a person entitled to receive and, where applicable, to sign it.
If we become aware that we hold personal information relating to a child in circumstances that require its deletion, we will delete it promptly. If you believe that a child has provided personal information to us, or that a document sent through the Services concerns a child in a way that raises a concern, please contact us at emilygoh@gohvio.io and we will investigate and act as required by applicable law.
8. Notice to California Residents
This section supplements the rest of this Notice for residents of California.
- Categories collected. In the preceding twelve months we have collected identifiers, including name and email address; commercial information, being subscription status; and internet or network activity information limited to the anonymous counters and provider logs described in Section 1.3. Documents you send may contain further categories, but those are supplied by you, are not inspected by us, and are deleted as described in Section 4.
- Sources, purposes, and disclosures. These are set out in Sections 1, 2, and 3.
- Sale and sharing. We have not sold personal information, and we have not shared personal information for cross-context behavioural advertising, in the preceding twelve months. We do not do so now, and we do not knowingly do either in respect of anyone under 16 years of age.
- Sensitive personal information. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted without an obligation to offer a right to limit.
- Your rights. You have the rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and be free from retaliation. Because we neither sell nor share, no opt-out mechanism is required, but you may still make any request by emailing us. You may use an authorised agent, in which case we will require written proof of authorisation.
9. How We Protect Your Personal Information
- Client-side processing. The strongest protection is architectural. Your document is not uploaded unless you choose to send it.
- Encrypted transport and controlled storage. Data in transit is encrypted. In-progress documents are held in private, access-controlled storage.
- Signed, short-lived links. Signing links are cryptographically signed and expire after 14 days.
- Locked third-party code. Every external library the tool loads is pinned to a cryptographic fingerprint using Subresource Integrity, and a Content Security Policy restricts the servers the page may contact, so tampered code cannot run and cannot exfiltrate your document.
Limits of these measures. No method of transmission over the internet, and no method of electronic storage, is completely secure. We cannot and do not guarantee absolute security. Two limits deserve to be stated plainly rather than buried:
- Email is not encrypted end to end. Signature requests and completed documents travel by email. Mail in transit between mail servers is not end-to-end encrypted, and anyone controlling a mailbox or mail server in the chain could in principle read it. If a document is highly sensitive, consider whether email is an appropriate channel for it.
- Sensitive categories of information. Snail Sign is a general purpose signing tool. It is not designed, certified, or contractually offered for protected health information under HIPAA, cardholder data under PCI DSS, information subject to export control, or any other category carrying a special legal handling regime, and we do not enter into business associate agreements. You choose what goes into your document, so please do not place such material into one unless you have independently satisfied yourself that doing so is appropriate.
If a breach affecting your personal information occurs, we will notify you, and any regulator, in the manner and within the timeframes that applicable law requires.
10. International Transfers of Personal Information
Gohvio, Inc. is incorporated in the United States, and our service providers listed in Section 3 process data in the United States. If you are located in the United Kingdom, the European Economic Area, Switzerland, or another region with cross-border transfer rules, please treat this as notice that clicking Send will cause the information described in Section 1.2 to be transferred to and processed in the United States. Where required, such transfers are made under appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, as incorporated into our agreements with those providers. You may request further information about these safeguards using the contact details in Section 12.
11. Changes to This Privacy Notice
- We may update this Notice from time to time, including to reflect changes in our practices or in applicable law.
- The revised Notice will be posted on this page and the version date at the top will be updated.
- Where a change is material, we will additionally send an email notice to every person holding an active access key, at the address associated with their subscription, so that no significant change happens quietly.
- Changes take effect on the version date shown. Your continued use of the Services after that date constitutes acceptance of the updated Notice. If you do not accept a change, please stop using the Services and cancel any subscription.
12. How to Contact Us
Gohvio, Inc., trading as Gohvio, is the controller of the personal information described in this Notice, other than the contents of documents you send, for which you are the controller and we are the processor.
- Privacy and data protection enquiries: emilygoh@gohvio.io
- Related documents: Terms of Use
Snail Sign