Aller au contenu
Privacy

What we hold, and why we hold it

A signing tool stores the two things people are most careful about: the document and the proof. Here is exactly what is kept, who else ever sees it, and how long it stays.

Last updated

Read this first

The sections describing how closeit.fast actually works are accurate and were written against the running product. The genuinely legal clauses are marked as awaiting review and are not yet in force: this document is not a substitute for advice from a lawyer, and it should be reviewed by one before anybody relies on it.

01The short version

closeit.fast exists to hold documents that people sign, so almost everything it stores is either the document itself or the evidence that somebody signed it. None of it is sold, none of it is used to build advertising profiles, and none of it is shared with anyone who is not needed to deliver the service.

There is exactly one cookie: the session cookie that keeps you signed in. There are no advertising cookies, no third-party trackers embedded in the app, and no cross-site profiling.

02What we collect

Three categories, and nothing outside them.

Your account. Your email address, the name you give us, and — if you sign in with Google — the profile photo Google returns. If you sign in with a one-time code instead, we store only the email address the code was sent to.

What you send. The documents you upload, the fields you place on them, the subject and message you write, and the names and email addresses of the recipients you send to.

The audit trail. For every event on an envelope, we record who caused it, the IP address the request came from, the browser and operating system that made it, and a UTC timestamp. This is the evidence that makes a signature enforceable, which is why it is recorded and why it cannot be edited afterwards.

03People you send documents to

A recipient never creates an account and is never asked to. When you add somebody to an envelope, you are the one supplying their name and email address, and we process those on your behalf in order to deliver the document to them.

Recipients are identified by a single-use token rather than a login, and that token opens one envelope and nothing else. Their audit entries are recorded on the same basis as yours, because a trail that stopped at the account holder would not be evidence of anything.

04Who else touches it

Four service providers, each doing one job:

  • Google, if and only if you choose to sign in with a Google account. We receive your email address, name and profile photo.
  • Stripe, for payments. Card details go to Stripe and never reach us; we store the subscription status Stripe reports back.
  • Resend, to deliver transactional email: sign-in codes, signing invitations, reminders and completion notices.
  • Modulify, which hosts the application, its database and its file storage.

That is the entire list. There is no analytics vendor embedded in the application, no advertising network, no session-replay tool, and no data broker.

05Cookies

One cookie, and it is strictly necessary: a session cookie that tells the server you are signed in. It is HttpOnly, so no script running in your browser can read it, and it is marked Secure over HTTPS.

Signing out deletes the session on the server and clears the cookie. There is nothing to opt out of and nothing to consent to, because there is no cookie here doing anything other than keeping you logged in.

06How long we keep it

Documents, certificates and audit trails stay in your account for as long as the account is open, including after a subscription ends — cancelling a plan is not a reason to take away a record somebody signed.

Delete an envelope and the underlying file is removed from storage. The audit record of that deletion remains, because a record you can quietly erase is not a record. Sessions expire on their own and are removed when you sign out.

07How it is protected

Documents are encrypted with AES-256-GCM before they are written to storage, and the key that opens each one is held apart from the file itself, so a stored document cannot be read without passing an authenticated route. Passwords, where an account has one, are hashed rather than stored. Completed documents are hashed with SHA-256 so any later change to the file is detectable.

The security page sets out how all of this works in detail, including a list of the assurances we deliberately do not claim.

08Your rights over your data

Awaiting legal review

The rights available to you under the GDPR, the UK GDPR and the CCPA — access, correction, erasure, portability, objection and the rest — and the exact procedure and timescale for exercising each of them, need to be written by a lawyer against the jurisdictions closeit.fast actually operates in. In the meantime, email hello@closeit.fast and a person will answer.

09Lawful basis and international transfers

Awaiting legal review

The lawful basis relied on for each category of processing, the controller and processor relationship between closeit.fast and its customers, the standard contractual clauses covering transfers outside the UK and EEA, and the identity and address of the data controller all require legal drafting before they can be stated.

10Incidents and changes to this policy

Awaiting legal review

Breach notification commitments and their timescales, and the process for notifying you of material changes to this policy, need to be drafted before they can be promised here.

11Contact

Questions about any of this go to hello@closeit.fast, and a person answers them rather than a queue.

Votre première enveloppe est à trois minutes.

Importez un PDF, placez les champs, envoyez les liens — et récupérez un document scellé avec un certificat de fin joint à la dernière page.

Une enveloppe gratuite chaque moisSans carte, sans appel commercial, sans frais par signature