Privacy Policy

Effective 18 June 2026

Who we are

OneTapSign is operated by Nexto Tech OÜ, a company registered in Estonia (the “Company”, “we”, “us”). This policy explains how we handle personal data across the OneTapSign API, the signing ceremony, and the account-less send form. Questions or data-rights requests: legal@onetapsign.com.

Our roles

For documents uploaded by our API and dashboard customers, and the signer data attached to those requests, we act as a data processoron the customer’s behalf — the customer is the data controller, and signer requests about that data are handled through the customer.

We act as a data controllerfor our account holders’ own account information, for people who use the account-less send form, and for visitors to our marketing site.

Data we collect

  • Account & dashboard: email address, name, authentication credentials, and API keys.
  • Signers: name, email address, phone number, signature image, and audit events with timestamps (created, viewed, signed, declined) including any decline reason.
  • Document contents: the PDF documents uploaded for signature.
  • Account-less senders: name and email, plus payment details processed by Stripe (we do not store full card numbers).
  • Verification codes: one-time codes sent to signers by SMS.
  • Webhook configuration: the endpoint URL and signing secret you configure.
  • Technical: server logs and a first-party authentication session cookie.

Sub-processors

We share data with the following service providers:

  • TwilioSMS delivery (signing links and one-time codes) (USA — Standard Contractual Clauses)
  • ResendTransactional email delivery (USA — Standard Contractual Clauses)
  • Cloudflare R2Encrypted document storage (EU/global; encrypted at rest)
  • StripePayment processing for account-less send (USA — Standard Contractual Clauses)
  • RailwayAPI hosting and PostgreSQL database (USA — Standard Contractual Clauses)
  • VercelMarketing and dashboard web hosting (USA — Standard Contractual Clauses)
  • Cloudflare Pages / CDNSigner application hosting and content delivery (EU/global)

Legal bases

We process personal data to perform our contract with you, for our legitimate interests in operating and securing the service, with your consent where required, and to comply with legal obligations.

Retention

How long we retain documents and signer personal data is determined by the organization that requested the signature (the data controller), via a retention windowit configures in its account settings. Where an organization has not set a retention window, records are kept until the organization requests their deletion — this may be indefinite. Once an organization’s retention window lapses, the signed document is permanently deleted.

If a signer exercises their right to erasure, we remove their personal data from the request, but the signed document itself is retained — as evidence of the concluded agreement, a lawful basis under the GDPR for the establishment, exercise, or defence of legal claims — until the organization’s retention window lapses, at which point it too is deleted. Account data is retained until the account is closed. Server logs are kept for a short period for security and troubleshooting.

International transfers

Some of our sub-processors operate outside the European Economic Area. Where that is the case, transfers are covered by the European Commission’s Standard Contractual Clauses.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. To exercise these rights, contact legal@onetapsign.com. If your data was provided to us by one of our customers, we will direct your request to that customer. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Security

We encrypt data in transit using TLS, store documents encrypted at rest, restrict internal access, and scope API keys to a single organization. No system is perfectly secure, but we work to protect your data and to respond promptly to issues.

Cookies

We use a single first-party cookie to keep you signed in. We use no advertising or analytics cookies and no third-party trackers.

API and MCP access

Accessing OneTapSign through our API or a Model Context Protocol (MCP) connector is a form of API use and is governed by this policy and your service agreement.

Children

OneTapSign is not directed to anyone under the age of 16.

Changes to this policy

We may update this policy from time to time. We will revise the effective date above and, for material changes, notify account holders.