Last updated 23 September 2026
This policy explains what personal data e-Sign by Pigee handles, why, and your rights. It covers our website, the e-Sign portal and the signing pages.
Who we are
e-Sign by Pigee is operated by Pigee Inc., 8 The Green, Suite A, Dover, DE 19901, United States. Contact us about privacy at esign@pigeepost.com.
Our role
- For account holders (people who send documents), we are the controller of your account and billing data.
- For signers, the person or business who sent you the document decides what it contains and why it is signed. They are the controller of that data, and we process it on their behalf to provide the signing service. We also keep the audit record needed to prove the signature is genuine.
What we collect
- Account data: name, email address, sender name and title, sign-in details (including Google sign-in if you use it), plan and usage.
- Documents: the documents you upload or write, including PDF page images, and the fields you add.
- Signer data: name, email address, the information typed into fields, the signature (drawn or typed), and any photo ID or files the sender asks for.
- Audit data: dates and times of sending, opening and signing, IP address, browser details, and failed signing attempts.
- Payment data: handled by Stripe. We don't see or store full card numbers.
- Website analytics: our website may use analytics tools to understand visits. Signing pages and the portal are not used for advertising.
Why we use it (lawful basis)
- To provide the service you signed up for, including sending emails, reminders and signed copies (contract).
- To keep a reliable audit trail, prevent fraud and keep the service secure (legitimate interests).
- To meet legal, tax and accounting obligations (legal obligation).
- To send product updates to account holders, which you can opt out of at any time (legitimate interests or consent).
Who we share it with
We never sell personal data. We use trusted providers to run the service: our hosting provider, our email provider (IONOS), Stripe for payments and Google for optional sign-in and website analytics. Each is bound by a contract to protect the data. We may disclose data if the law requires it.
International transfers
Pigee Inc. is a US company, and some of our providers are outside the UK. Where data leaves the UK or EEA, we rely on adequacy decisions or safeguards such as the UK International Data Transfer Addendum and standard contractual clauses.
How long we keep it
- Account data: while your account is open, and up to 12 months after closing it, unless you ask us to delete it sooner.
- Signed documents and audit trails: for as long as the sender keeps them in their account, because they may be needed as evidence.
- Backups: rolling daily backups are kept for about 14 days.
Security
All traffic is encrypted with HTTPS. Signing links are unique and unguessable, every signature is sealed with a tamper-evident HMAC-SHA256 chain, and data is backed up daily.
Your rights
You can ask for a copy of your data, or ask us to correct, delete, restrict or transfer it, or object to how we use it. If you signed a document for someone else, we may pass your request to them, as they control that data. Email esign@pigeepost.com. You can also complain to the UK Information Commissioner's Office at ico.org.uk.
Cookies
We use essential cookies to keep you signed in to the portal and to protect forms. Analytics cookies on our website are optional where the law requires consent.
Changes
We'll update this page when our practices change and show the date at the top.