Pactly
Legal

Privacy Policy

Effective 1 September 2026

Plain summary. We collect what we need to deliver documents and prove who signed them: your account details, the files you upload, and - at the moment of signing - the signer's IP address, browser, and approximate location. That signing evidence is the point of the product; it's what makes the audit trail hold up. We don't sell any of it.

1. What we collect

CategoryWhat it includesWhy
Account data Name, email address, hashed password, team membership, plan and usage counts To run your account and apply plan limits
Document data PDFs you upload, field positions, signed copies and certificates To render, send, and complete your documents
Signing evidence Signer name and email, IP address, browser user-agent, approximate city/region/country derived from IP, a device fingerprint, timestamps, and document hashes before and after signing To produce a court-ready audit trail and Certificate of Completion
Audit log Every view, sign, decline, reminder, cancellation and change request, linked in a tamper-evident SHA-256 chain To detect tampering and evidence what happened
Billing data Stripe customer and subscription identifiers To manage subscriptions. Card details go to Stripe - we never see or store them

2. How signing evidence is captured

When someone signs, we record their IP address and browser user-agent and resolve the IP to an approximate location (city-level at best - not a GPS position). We compute a device fingerprint by hashing the IP, user-agent and the signer's unique link token together. This information appears on the Certificate of Completion attached to the signed PDF, which is visible to everyone who receives that document.

3. Who we share it with

We don't sell personal data. We share it only with the processors that make the Service work:

We may also disclose data where we're legally required to, or to establish or defend a legal claim.

4. How long we keep it

5. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a data protection authority. You can update your name and email yourself from account settings, and delete templates and requests from the documents page. For anything else, email hello@mypactly.com.

One limit worth stating plainly: we may be unable to delete signing evidence attached to a completed document that another party relies on as proof of execution, because doing so would destroy the integrity of their record.

6. Security

Passwords are hashed, never stored in readable form. Sessions use signed, HTTP-only cookies. Signed PDFs are locked against modification. See our Security page for detail.

7. Children

Pactly is not intended for anyone under 18, and we don't knowingly collect their data.

8. International transfers

Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for those transfers.

9. Changes

If we make a material change we'll notify account holders by email before it takes effect.

10. Contact

Privacy questions: hello@mypactly.com.

Note for the operator: before launch, fill in your legal entity name and address, name your actual sub-processors, and confirm your retention periods. If you have EU or UK users you'll also need to identify your lawful basis for each processing purpose and, if applicable, a representative.