Privacy notice · version privacy-2026-07-22
How SignThatUp handles personal data
This notice explains who controls personal data, what SignThatUp processes, why it is needed, where it goes, and the choices available to workspace owners and invited clients.
Data controller
Stancich solutions, spletna prodaja in programiranje, Andrej Stancich s.p.Štihova ulica 13, 1000 Ljubljana, Slovenia
- Registration number
- 7418833000
- Tax number
- 62475959
- Privacy contact
- sales@signthatup.com
- Phone
- +386 40 138 180
1. Data we process
- Account data: authentication identity, name, email, business name, country, language and policy acceptance.
- Workspace and job data: client names, email addresses, job descriptions, line items, notes and revision history.
- Evidence and signing data: original photos and documents, electronic signature actions, wet-ink signature photos, signer attestations, service events, content hashes and sealed records.
- Technical and security data: device and browser information, IP-derived request information, timestamps, authentication and delivery events, and security logs.
- Billing data: plan, usage, Stripe customer and subscription identifiers, billing address, tax ID if supplied, invoice and payment status. SignThatUp does not receive full card details.
- Support and rights requests: messages and the information needed to answer, export, correct, restrict or erase data.
2. Why we process it and our lawful bases
- Contract: create accounts, deliver signing invitations, produce requested records, provide exports, administer subscriptions and support customers.
- Legitimate interests: secure the service, prevent abuse, preserve reliable service events, diagnose failures and defend legal claims, balanced against the rights of affected people.
- Legal obligation: retain billing, accounting, tax, complaint and compliance information where the law requires it.
- Consent: where a specific optional activity legally requires consent. Consent can be withdrawn without affecting earlier lawful processing.
3. Workspace owners and invited clients
The legal role depends on the activity. We act as controller for account, security, billing and direct service administration. A workspace owner determines which job and client information is uploaded and who is invited. For that customer-controlled content, the workspace owner may have separate controller obligations and must give invited people any information required by law.
4. Service providers and recipients
We use Supabase for authentication, database and private storage; Vercel for application hosting; Resend for transactional email; Stripe for checkout, billing and invoices; and Google when a user chooses Google authentication. These providers receive only the information needed to perform their service. Data may also be disclosed to advisers, authorities or counterparties when lawfully required or necessary to establish, exercise or defend legal claims.
5. International transfers
Some providers may process data outside Slovenia or the European Economic Area. Where required, transfers rely on an adequacy decision, approved contractual safeguards such as the European Commission's standard contractual clauses, or another lawful transfer mechanism. Provider locations and safeguards can change, so current details are available on request.
6. Public and private data
Job content and original evidence are private. Public verification is intentionally limited and does not publish client contact details or original evidence. A private bundle link is a sensitive bearer link and should be shared only with the intended recipient.
7. Retention
Account and workspace data is kept while needed to provide the account and the evidence history selected by its owner. Billing and transaction records are kept for the statutory accounting and tax period. Security, delivery and support records are kept only as long as reasonably needed for reliability, fraud prevention, dispute handling and legal claims.
A deletion request is reviewed across active data, provider copies and backups. Data is deleted or anonymised when it is no longer needed, except where continued retention is required for accounting, legal claims, fraud prevention or another legal obligation. Because sealed records are designed as evidence, deletion may be restricted where a lawful retention need outweighs the request. We explain any restriction when responding.
8. Your rights
Depending on the circumstances, a person may request access, correction, deletion, restriction, portability or objection and may withdraw consent. Send a request to sales@signthatup.com. We may need to verify the requester's identity and will respond within the period required by law.
You may complain to the Information Commissioner of the Republic of Slovenia at ip-rs.si, or to another competent supervisory authority where applicable.
9. Security
Workspace authorization is resolved server-side. Private evidence uses restricted storage, records contain content hashes, authenticated responses use private no-store boundaries, and sensitive configuration stays server-side. No internet service can promise absolute security.
10. Cookies and similar storage
SignThatUp currently uses storage needed for authentication, security, session continuity and core application operation. It does not currently use advertising cookies. If non-essential analytics or advertising storage is introduced, the notice and consent controls will be updated before use where required.
11. Children and changes
SignThatUp is a business workflow service and is not directed to children. We may update this notice when the service, providers or legal requirements change. The current version and effective date remain available on this page.