This is the privacy policy for SignPad, an online electronic signature service available at signpad.com.au. It explains what personal information we collect about you, how we use it, who we share it with, and the rights you have over it.
We've written it under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in Schedule 1 of that Act. It also covers our obligations under the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) and the Notifiable Data Breaches scheme.
If you use SignPad as an authorised user of a Business workspace, your employer is the controller of the documents you handle through that workspace. Their own privacy policy may also apply to you.
SignPad is operated by Brix Super Group Pty Ltd (ACN 692 753 674). We are an online service platform based out of Broadbeach, Queensland, Australia. We don't run a physical store and we don't take walk-ins, every interaction is via the website, email or in-product chat.
You can reach us any time at sign@signpad.com.au. Our privacy contact is the same address, there's no separate privacy officer because we're small enough that real humans on the team answer.
The personal information we collect about you depends on how you use SignPad. The categories are:
For every action taken on every document, when it's sent, when each recipient opens it, when they consent to electronic signing, when they sign, when it's completed, we record:
If you are on a paid plan, our payment processor (Stripe) collects your card or bank details directly. We see and store only the last four digits of your card, the card brand, the billing email, and the country of issue. We never see or store your full card number, CVV or expiry date.
If you email us, we keep the email thread so we can answer follow-up questions. If you fill in a contact form, we collect whatever you typed in plus the timestamp.
We collect personal information in three ways:
We use your personal information only for the purposes set out below. Each purpose corresponds to a lawful basis under the APPs.
We want to be honest with you here, because lots of services oversimplify this.
All of your personal information, every PDF you upload, every signed copy, and every audit event is stored on infrastructure hosted in Sydney, Australia (AWS region ap-southeast-2). We use Supabase as our database, authentication and file storage provider, and Supabase runs this on AWS Sydney by our explicit configuration. We do not replicate, mirror or back up this data to any other region.
A few parts of the system necessarily touch infrastructure outside Australia. We disclose them upfront:
Where data crosses a border on the way to or from these providers, we rely on each provider's contractual data protection commitments, including the GDPR Standard Contractual Clauses where applicable.
We never sell, rent, license or trade your personal information.
We share it with the following categories of recipient, and only for the purpose listed:
| Recipient | What they receive | Why |
|---|---|---|
| The signers and viewers you nominate | The document you sent and your name as sender | So they can sign it or view the final copy |
| Supabase Inc. | Everything you store with us (encrypted at rest) | Hosted database, auth and file storage |
| Vercel Inc. | Only the static website files, no account data | Website hosting |
| Cloudflare Inc. | Encrypted traffic in transit | TLS termination and DDoS protection |
| Google LLC (Workspace) | Outbound email content (subject, body, links) | Email delivery via SMTP |
| Stripe Inc. | Your name, email, last 4 of card, country (paid plans) | Subscription payment processing |
| Australian law enforcement | The specific data requested | Only if compelled by a valid Australian court order or subpoena |
If we add a new subprocessor or change an existing one, we'll update this list and email every active Business-plan account holder at least 30 days before the change takes effect. Free and Solo customers can subscribe to the same notice list by emailing us. This gives you time to object or to terminate before the new subprocessor receives any of your data.
Section 6 above explains exactly which pieces of personal information move outside Australia and why. Where we transfer your personal information overseas, we take reasonable steps to make sure the overseas recipient handles it consistently with the Australian Privacy Principles, which is what APP 8 requires of us.
If you would prefer not to have any of your data touch overseas infrastructure (which would mean we couldn't email you signing invitations through Google or charge a Stripe subscription), let us know and we'll discuss whether a fully Australian-only configuration is feasible for your use case.
Under APP 11.2 we are required to destroy or de-identify personal information once we no longer need it. Our default is therefore to keep data only for as long as it's useful to you, and to delete on request.
| Data | Retention period |
|---|---|
| Your account profile (name, email, password hash) | For as long as your account is active |
| Signed documents and their audit trails | For as long as your account is active. Both you and every signer also receive a copy of the stamped PDF by email when the document completes, which you should keep for your own records. |
| Unsigned drafts you uploaded but never sent | 90 days from upload, then deleted automatically |
| Payment records | 5 years from the date of issue (ATO record-keeping period for tax records) |
| Support emails | 3 years from the last reply |
| Server logs (including IP) | 30 days, except where attached to an audit event |
| Marketing-consent records | 3 years from withdrawal, so we can prove we honoured your opt-out |
You can ask us to delete your account and everything tied to it at any time, see Section 16. When you click Delete account in the app, we destroy your workspace, documents, signers and audit trails immediately. Stamped PDFs that were sent to signers via email are not affected, those copies live in their inboxes.
Two things we may have to keep even after you delete:
Your own record-keeping obligations for documents you signed through SignPad (for example, contracts of sale you must keep for 5 years under ATO rules) are your responsibility, not ours. Keep your copy of the stamped PDFs and the audit URLs we email you.
We use a single first-party cookie called signpad-session to keep you signed in. It contains only an opaque session token issued by Supabase Auth; no personal information is stored inside the cookie itself.
We do not use third-party advertising cookies, retargeting pixels, behavioural-tracking SDKs, social-media trackers or any analytics product that profiles you (no Google Analytics, no Hotjar, no Mixpanel, no Facebook Pixel). The aggregated server logs we use to count active users are based on our own systems, not a third-party analytics provider.
You can clear the session cookie at any time using your browser's settings; doing so will sign you out of SignPad.
Transactional notices, confirmations, signing invitations, reminders, billing receipts and security alerts, are part of the service. You'll receive these for as long as you have an active SignPad account or are a signer on a live document; they are not marketing under the Spam Act 2003.
If we send you optional product news (new feature announcements, the occasional how-to), we will only do so after you opted in by ticking a clearly labelled box, and every such email will include an unsubscribe link that works on the first click. We will action unsubscribes within five working days. We do not buy or rent marketing lists.
SignPad does not currently use your personal information to make automated decisions that produce legal effects for you (for example, approving or refusing service based on an algorithm).
We do not train any AI model on the contents of your documents, the signatures you collect, or the audit data we record. We do not share document or signature data with any third-party AI provider. If this ever changes, we'll update this policy at least 30 days in advance and give you a clear opportunity to opt out before any model training begins.
SignPad is not intended for anyone under 18. We do not knowingly accept account signups from minors, and senders who use SignPad to collect a signature from a minor must have first obtained the prior written consent of that minor's parent or guardian.
If you believe a child under 18 has registered for an account or had their personal information submitted to us as a signer, contact sign@signpad.com.au and we will delete it promptly.
We take the security of your data seriously. Specific measures include:
No system is 100% secure, but we treat customer data with the same care we'd treat our own and we welcome responsible disclosure of any issue you find, email sign@signpad.com.au and we'll respond within two business days.
If we ever experience a data breach that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in line with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988. The notice will explain what happened, what data was involved, what we've done about it, and what we recommend you do.
You have the right to:
To exercise any of these rights, email sign@signpad.com.au. We will respond within 30 calendar days. We may need to verify your identity before acting on a request, typically by emailing the address on file. If we refuse a request (which is rare and only where the law permits us to), we'll give you the reason in writing.
If you think we've mishandled your personal information, please tell us first. Email sign@signpad.com.au with "Privacy complaint" in the subject line. We'll acknowledge within 5 business days and aim to resolve within 30 days.
If you're not satisfied with how we handle your complaint, you can refer it to the Office of the Australian Information Commissioner:
SignPad is built for the Australian market, but a sender based in Australia may invite a signer based in the European Union or the United Kingdom. If you are an EU or UK signer using SignPad to sign a document, the General Data Protection Regulation (GDPR) and the UK GDPR may apply to the processing of your personal information.
We do not have an EU representative under Article 27 GDPR yet because our processing of EU residents' data is currently low-volume and incidental to Australian-domestic transactions. If that changes, we'll appoint one and update this notice.
If we make a material change, for example, a new category of data we collect, a new subprocessor in a different country, or a new way we use your data, we'll email every account holder at least 30 days before the change takes effect, and we'll bump the version number at the top of this page. Minor edits (typos, formatting) won't trigger an email but will be reflected in the "last updated" date.
Brix Super Group Pty Ltd
based out of Broadbeach, Queensland, Australia
Email: sign@signpad.com.au
We answer every email. If you don't hear back within 5 business days, please send it again, it didn't arrive.