Privacy Policy
Last updated: 14 July 2026
1. Who we are
DocWright ("we", "us", "our") is operated by [COMPANY LEGAL NAME], registered in [JURISDICTION, e.g. England and Wales] at [COMPANY ADDRESS]. We are the data controller for the personal data described in this policy. For any privacy question, contact [PRIVACY/DPO EMAIL, e.g. privacy@docwright.io].
2. Information we collect
- Account data — your name, email address and password (hashed). If you sign in with Google, we receive your name, email address, profile picture and Google account identifier from Google.
- Workspace content — the documents, templates, assets and settings you create or upload.
- Recipient activity — when you send a document, we record recipient actions (opens, views, signature and payment events) and show them to your workspace.
- Billing data — subscription and payment details, handled by our payment provider; we do not store full card numbers.
- Usage & device data — log data, IP address, browser/device information and browser local storage needed to run, secure and improve the Service.
3. Google sign-in
If you choose "Sign in with Google", we use the basic profile information Google provides (name, email, profile picture, account ID) solely to create and authenticate your account. We request only the minimum scopes needed for sign-in, and our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google sign-in data for advertising, and we do not sell it.
4. How we use your information & legal bases
- To provide and operate the Service and your account — performance of a contract.
- To process payments and manage subscriptions — contract / legal obligation.
- To send transactional email (signing requests, receipts, security alerts) — contract / legitimate interests.
- To secure, maintain and improve the Service and prevent abuse — legitimate interests.
- For optional marketing communications, where applicable — consent (you can opt out at any time).
We do not sell your personal data.
5. Cookies & local storage
We do not set any first-party cookies, on this website or in the Service. When you sign in, we keep your session state in your browser's local storage; this is strictly necessary to operate the Service. We do not use analytics or advertising trackers on this website.
Third-party services may set their own cookies, but only when you actively use them: our payment provider Stripe (only when a client starts a payment on a document) and video platforms (only when a viewer clicks play on a video embedded in a document). Because we set no non-essential cookies, no cookie consent tool is required; you can control or delete cookies at any time through your browser settings.
6. Sharing & processors
We share data only with service providers that process it on our behalf under contract, including hosting/infrastructure (Google Cloud Platform), payments (Paddle, Stripe), email delivery, and AI features (Anthropic). Each receives only the data needed for its function. We may also disclose data where required by law. Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention & deletion
We retain your data while your account is active and as needed to provide the Service and meet legal obligations. You can export your data at any time and request deletion of your account and workspace content; on deletion we remove or anonymise your personal data within a reasonable period, subject to legal retention requirements. To delete your account, use in-app account settings or email [PRIVACY EMAIL].
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal data, and to data portability. To exercise them, contact [PRIVACY EMAIL]. If you are in the UK or EEA and are unhappy with our response, you may complain to your data protection authority (in the UK, the Information Commissioner's Office, ico.org.uk).
9. Security
We use technical and organisational measures to protect your data, including encryption in transit, access controls and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to notify you of incidents where required.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here and, for material changes, notify you in-app or by email.
12. Contact
Privacy questions: [PRIVACY/DPO EMAIL, e.g. privacy@docwright.io], [COMPANY LEGAL NAME], [COMPANY ADDRESS].