VertiSign
Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how VertiSign (“VertiSign”, “we”, “us”, or “our”) collects, uses, discloses, and protects information in connection with the VertiSign electronic-signature service (the “Service”). It should be read together with our Terms of Service. By using the Service, you consent to the practices described here.
1. Our role and the Sender's role
When a business or individual (the “Sender”, for example a contractor) sends a document to you for signature, the Sender determines what information is requested and how the signed document is used within their own business. In that context we process information on the Sender’s behalf to operate the Service. The Sender is responsible for their own handling of the information and has their own privacy practices, which are not covered by this Policy. For questions about a specific document or how a Sender uses your information, please contact the Sender directly.
2. Information we collect
We collect the following categories of information:
- Identifiers and contact details — such as the signer and co-signer names, email addresses, and company representative details provided by the Sender or entered when signing.
- Signature information — the drawn or typed signature image and typed name you provide, and your consent to sign electronically.
- Document and transaction information — the documents, selected options, prices, notes, and the accepted terms associated with a signing request.
- Verification and audit information — records used to establish the integrity of a signature, including whether a document was signed through a link delivered to a specific email address, the email address the link was delivered to, event timestamps (viewed, signed, declined), and a document fingerprint (hash).
- Technical information — your IP address, browser and device information (user agent), and similar data automatically collected to operate, secure, and audit the Service.
We do not intentionally collect payment-card numbers, government identification numbers, or other sensitive personal information through the Service, and you should not submit them unless requested.
3. How we use information
We use information to:
- Provide, operate, and maintain the Service, including displaying documents, capturing signatures, and generating the signed document and signature certificate;
- Deliver signing invitations, reminders, and copies of signed documents by email;
- Verify the integrity and provenance of a signature (including email-verification and audit records) and detect, prevent, and investigate fraud, abuse, and security incidents;
- Maintain records of transactions and comply with legal, regulatory, and evidentiary obligations;
- Operate, secure, troubleshoot, and improve the Service; and
- Enforce our Terms and protect our rights, our users, and the public.
4. Legal basis and consent
We process information as necessary to provide the Service you or the Sender request, to pursue our legitimate business interests (such as security, fraud prevention, and record-keeping), to comply with legal obligations, and with your consent where required by applicable law, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. Where we rely on consent, you may withdraw it as described below, subject to legal and contractual restrictions.
5. How we share information
We do not sell your personal information. We share it only as follows:
- With the Sender. The signed document, your signature, your notes, verification records, and related transaction data are made available to the Sender that requested the signature.
- With service providers. We use trusted third parties to host our infrastructure and database and to deliver email on our behalf. They may process information only to provide services to us and are bound by confidentiality and data-protection obligations.
- For legal reasons. We may disclose information if required by law, subpoena, or legal process, or where we believe disclosure is reasonably necessary to protect our rights, enforce our Terms, prevent fraud or harm, or ensure the safety and security of the Service and its users.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
6. Data retention
Executed documents and their signature certificates will remain available at their signing link for a period of at least two (2) years from the date of signing, so they stay accessible and verifiable during that time. After that period, VertiSign may, in its sole discretion and without further notice, continue to retain a document or permanently delete it together with its associated records. Because a document may be deleted after this two-year period, you are responsible for downloading and keeping your own copy of any executed document you may need.
Other information is retained for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Verification tokens are stored only as one-way hashes and are not retained in a form that can reconstruct the original link.
7. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information, including transport encryption, access controls, immutable storage of executed documents, and hashing of sensitive tokens. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping signing links confidential and for the security of your own devices and email account.
8. Cookies and tracking
The signing experience uses only the storage strictly necessary to operate (for example, to load and display a document). We do not use the signing pages for third-party advertising or cross-site tracking. The Sender’s own broader website or systems may use their own cookies, which are outside the scope of this Policy.
9. Your privacy rights
Subject to applicable law, you may have the right to access, correct, update, or request deletion of your personal information, to withdraw consent, and to make a complaint to a privacy regulator. Because much of the information is held on behalf of, and controlled by, the Sender, we may direct certain requests to the relevant Sender or ask you to contact them. Note that we may be unable to alter or delete an executed document or its certificate where retention is necessary for the integrity of the record or to meet legal obligations. To exercise a right, contact us using the details below; we may need to verify your identity before responding.
10. Children
The Service is intended for adults and is not directed to individuals under the age of majority in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided information through the Service, contact us and we will take appropriate steps.
11. International transfers
We are based in the Province of Ontario, Canada, and our service providers may process and store information in Canada, the United States, or other countries. Where information is transferred across borders, it may be subject to the laws of those jurisdictions, and we take steps to ensure it remains protected consistent with this Policy and applicable law.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Changes are effective when posted. Your continued use of the Service after changes are posted constitutes acceptance of the updated Policy.
13. Contact us
For privacy questions or to exercise your rights, contact our privacy contact at vertisign@ontarioroofers.org (or support@ontarioroofers.org), or write to VertiSign, Ontario, Canada.
