Privacy Policy
Last modified: May 27, 2026
Introduction
This Privacy Policy explains how SmartSign (“Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with our websites, platforms, applications, services, software, communications, customer support, marketing activities, and other digital properties that link to this Privacy Policy, collectively, the “Services.”
This Privacy Policy is intended for users, visitors, customers, prospective customers, business contacts, and other individuals whose personal information we process. Where we process personal information on behalf of a customer as a service provider, processor, contractor, or sub-processor, our processing is generally governed by our agreement with that customer, including any applicable Data Processing Addendum.
Categories of Personal Information We Collect
The categories below describe the personal information we may collect. Not every category applies to every individual or use case.
| Category | Examples | Sources | Purposes | Recipients | Retention Approach |
|---|---|---|---|---|---|
| Identifiers | Name, email address, username, account ID, customer ID, IP address, online identifiers | You, your organization, devices, service providers | Provide Services, account management, authentication, security, support, compliance | Service providers, hosting providers, security providers, affiliates, authorities where required | As long as reasonably necessary for Services, security, legal, and business purposes |
| Contact Information | Business email, phone number, mailing address, organization name, job title | You, your organization, business partners | Communications, sales, support, billing, notices | CRM providers, email providers, support vendors, affiliates | Duration of relationship plus legal retention period |
| Account Information | Login credentials, account settings, roles, permissions, preferences | You, account administrators, systems | Account creation, access control, user management, security | Hosting providers, identity providers, support providers | While account is active and thereafter as needed |
| Commercial / Customer Relationship Information | Subscription plan, order history, contract details, service usage, customer status | You, customer organization, payment systems, sales systems | Contract performance, billing, renewals, customer success, analytics | Payment processors, CRM providers, professional advisers | Contract term plus applicable limitation and tax/accounting periods |
| Payment and Billing Information | Billing address, payment method details, invoice data, transaction records | You, payment processors, customer organization | Payments, invoicing, fraud prevention, tax compliance | Payment processors, banks, accounting providers, advisers | As required for tax, accounting, audit, and legal purposes |
| Internet, Device, and Usage Information | IP address, browser type, device identifiers, operating system, log data, pages viewed, referring URLs, timestamps, feature usage | Devices, cookies, analytics tools, servers | Service operation, analytics, debugging, security, fraud prevention, product improvement | Hosting providers, analytics providers, security providers | Based on operational, security, analytics, and legal needs |
| Cookies and Similar Technologies | Cookies, pixels, SDKs, local storage, analytics identifiers | Browser, device, cookie providers, analytics tools | Preferences, analytics, advertising if enabled, security, session management | Analytics providers, advertising partners if applicable, service providers | Based on cookie type and settings; see cookie section |
| Communications and Support Information | Support tickets, emails, chat messages, call notes, feedback, survey responses | You, support systems, customer success tools | Support, troubleshooting, training, quality assurance, service improvement | Support vendors, communication tools, CRM providers | As needed for support history, quality, legal, and business needs |
| User-Generated or Uploaded Content | Files, text, records, documents, data sets, messages, content uploaded to the Services | You, authorized users, customer systems | Provide and operate the Services, process customer instructions, support, security | Hosting providers, sub-processors, support providers | Controlled by customer settings, contract terms, and backup cycles |
| Approximate Location Information | Approximate location inferred from IP address or account information | Devices, IP lookup tools | Security, localization, analytics, fraud prevention | Hosting, analytics, security providers | As needed for operational and security purposes |
Purposes of Processing
We may collect, use, disclose, and otherwise process personal information for the following purposes:
- Providing, operating, maintaining, and improving the Services.
- Creating, administering, securing, and managing accounts.
- Providing customer support, troubleshooting, training, and technical assistance.
- Processing payments, invoices, orders, subscriptions, renewals, and related transactions.
- Monitoring service performance, debugging, analytics, reporting, and product improvement.
- Protecting against fraud, misuse, security incidents, unauthorized access, and unlawful activity.
- Complying with legal obligations, regulatory requirements, subpoenas, court orders, and lawful requests.
- Sending administrative, transactional, service, and security communications.
- Sending marketing communications, newsletters, event invitations, and promotional materials where permitted by law.
- Conducting research, benchmarking, analytics, business intelligence, and internal business planning.
- Creating and using aggregated, anonymized, or de-identified information.
- Enforcing agreements, resolving disputes, and protecting rights, property, and safety.
- Evaluating or completing mergers, acquisitions, financing, reorganizations, bankruptcy, or sales of assets.
- Any other purpose disclosed at the time of collection or with consent where required.
Aggregated, Anonymized, and De-Identified Data
We may create, receive, use, disclose, retain, sell, license, and otherwise process aggregated, anonymized, or de-identified information for analytics, product improvement, benchmarking, research, service development, business intelligence, security, and other lawful business purposes.
Where we maintain de-identified information, we will take reasonable measures designed to ensure that the information cannot reasonably be associated with an identified or identifiable individual or household, will publicly commit to maintaining and using such information in de-identified form where required by applicable law, and will not attempt to re-identify the information except as permitted by law, including to test whether our de-identification processes satisfy applicable requirements.
Disclosure of Personal Information
We may disclose personal information to the following categories of recipients:
- Service Providers, Processors, Contractors, and Sub-Processors. Vendors that provide hosting, infrastructure, storage, security, analytics, customer support, communications, payment processing, identity management, and related services.
- Subcontractors and Sub-Processors. We use subcontractors and sub-processors to provide parts of the Services.
- Payment Processors. Third-party payment processors and financial institutions for billing, invoicing, payment, fraud prevention, and accounting.
- Hosting and Infrastructure Providers. Cloud hosting, database, backup, content delivery, monitoring, and infrastructure providers.
- Analytics Providers. Analytics and measurement providers that help us understand use of our Services.
- Advertising and Marketing Partners. Where applicable, we may disclose information to advertising or marketing partners subject to applicable consent and opt-out rights.
- Professional Advisers. Lawyers, accountants, auditors, insurers, bankers, and consultants.
- Authorities and Regulators. Courts, law enforcement, regulators, public authorities, or other third parties where legally required or necessary to protect rights, safety, and security.
Subcontractors and Sub-Processors
We may engage subcontractors and sub-processors to support the Services. We require such parties to process personal information under appropriate contractual obligations where required by applicable law, including confidentiality, security, limited-use, and data protection obligations. Our current sub-processor list is available at www.smartsign.today/processors.
Cookies and Tracking Technologies
We and our service providers may use cookies, pixels, SDKs, local storage, analytics tools, advertising technologies, and similar technologies to operate the Services, remember preferences, analyze performance, secure the Services, measure campaigns, and, where applicable, provide targeted advertising.
U.S. State Privacy Rights
Depending on your state of residence and our legal obligations, you may have some or all of the following rights:
- Right to know or access personal information.
- Right to confirm whether we process your personal information.
- Right to correct inaccurate personal information.
- Right to delete personal information.
- Right to obtain a portable copy of personal information.
- Right to opt out of sale of personal information.
- Right to opt out of sharing for cross-context behavioural advertising.
- Right to opt out of targeted advertising.
- Right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
- Right to limit use or disclosure of sensitive personal information, where applicable.
- Right to withdraw consent, where processing is based on consent.
- Right to appeal a denied privacy request, where applicable.
- Right to use an authorized agent, where applicable.
These rights may apply to residents of California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Texas, Florida, Maryland, Minnesota, Montana, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Rhode Island, and other states if additional laws become applicable.
How to Submit a Request
You may submit a privacy request by using:
- Privacy request form: www.smartsign.today/privacyform
- Email: privacy@smartsign.today
We may need to verify your identity before responding. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and may ask you to verify your identity directly.
Appeals
Where applicable, if we deny your request, you may appeal by contacting us at appeals@smartsign.today or using www.smartsign.today/privacyappeal and indicating that your submission is an appeal. We will respond within the time required by applicable law.
California Privacy Notice
This section applies to California residents and supplements the rest of this Privacy Policy.
Notice at Collection
At or before collection, we disclose the categories of personal information we collect, the purposes for which we collect and use it, whether we sell or share it, and how long we retain it or the criteria used to determine retention.
Categories Collected
In the preceding 12 months, we may have collected the categories listed in Section 2 above, including identifiers, commercial information, internet or network activity information, geolocation information, professional or employment-related information, sensitive personal information where applicable, and inferences.
Sources
We collect personal information from you, your organization, authorized users, devices, browsers, cookies, service providers, business partners, public sources, and third-party platforms where permitted.
Disclosures for Business Purposes
We may disclose personal information to service providers, contractors, processors, sub-processors, affiliates, advisers, analytics providers, payment processors, hosting providers, security providers, and authorities where required.
Sale or Sharing
We do not sell personal information as “sale” is defined under the CCPA/CPRA. We do not share personal information for cross-context behavioural advertising.
Sensitive Personal Information
We do not use or disclose sensitive personal information for purposes that require a right to limit under California law.
Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide Services, comply with law, resolve disputes, maintain security, and enforce agreements.
Non-Discrimination
We will not discriminate or retaliate against you for exercising your privacy rights.
U.S. State Privacy Regulators and Authorities
| State | Law | Authority | Official URL |
|---|---|---|---|
| California | CCPA/CPRA | California Privacy Protection Agency / California Attorney General | https://cppa.ca.gov / https://oag.ca.gov/privacy/ccpa |
| Colorado | Colorado Privacy Act | Colorado Attorney General | https://coag.gov/resources/colorado-privacy-act/ |
| Connecticut | Connecticut Data Privacy Act | Connecticut Attorney General | https://portal.ct.gov/ag |
| Virginia | Virginia Consumer Data Protection Act | Virginia Attorney General | https://www.oag.state.va.us/consumer-protection |
| Utah | Utah Consumer Privacy Act | Utah Attorney General / Division of Consumer Protection | https://attorneygeneral.utah.gov / https://dcp.utah.gov |
| Texas | Texas Data Privacy and Security Act | Texas Attorney General | https://www.texasattorneygeneral.gov |
| Oregon | Oregon Consumer Privacy Act | Oregon Attorney General | https://www.doj.state.or.us |
| Montana | Montana Consumer Data Privacy Act | Montana Attorney General | https://dojmt.gov |
| Delaware | Delaware Personal Data Privacy Act | Delaware Department of Justice | https://attorneygeneral.delaware.gov |
| Iowa | Iowa Consumer Data Protection Act | Iowa Attorney General | https://www.iowaattorneygeneral.gov |
| Indiana | Indiana Consumer Data Protection Act | Indiana Attorney General | https://www.in.gov/attorneygeneral |
| Tennessee | Tennessee Information Protection Act | Tennessee Attorney General | https://www.tn.gov/attorneygeneral |
| Florida | Florida Digital Bill of Rights | Florida Attorney General / Department of Legal Affairs | https://www.myfloridalegal.com |
| Maryland | Maryland Online Data Privacy Act | Maryland Attorney General | https://www.marylandattorneygeneral.gov |
| Minnesota | Minnesota Consumer Data Privacy Act | Minnesota Attorney General | https://www.ag.state.mn.us |
| New Hampshire | New Hampshire Privacy Act | New Hampshire Attorney General | https://www.doj.nh.gov |
| New Jersey | New Jersey Data Privacy Act | New Jersey Attorney General | https://www.njoag.gov |
| Kentucky | Kentucky Consumer Data Protection Act | Kentucky Attorney General | https://www.ag.ky.gov |
| Nebraska | Nebraska Data Privacy Act | Nebraska Attorney General | https://ago.nebraska.gov |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act | Rhode Island Attorney General | https://riag.ri.gov |
GDPR / UK GDPR Privacy Notice
This section applies where we process personal data of individuals located in the European Economic Area, United Kingdom, or Switzerland, or where the GDPR, UK GDPR, or Swiss data protection law otherwise applies.
Controller Identity
Controller: Mor Peled HLN Nadlan Ltd.
Email: info@smartsign.today
Categories of Personal Data
We may process the categories of personal data described in Section 2.
Purposes and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Providing and operating Services | Contract necessity; legitimate interests |
| Account creation and management | Contract necessity; legitimate interests |
| Customer support | Contract necessity; legitimate interests |
| Billing and payments | Contract necessity; legal obligation; legitimate interests |
| Security, fraud prevention, debugging | Legitimate interests; legal obligation |
| Compliance with law | Legal obligation |
| Analytics and product improvement | Legitimate interests; consent where required |
| Marketing communications | Consent; legitimate interests where permitted |
| Cookies and tracking | Consent where required; legitimate interests for strictly necessary technologies |
| Corporate transactions | Legitimate interests; legal obligation |
| Aggregated, anonymized, or de-identified data | Legitimate interests; not personal data once anonymized |
Legitimate Interests
Our legitimate interests may include operating and improving the Services, securing systems, preventing fraud, communicating with customers, analyzing service performance, developing products, enforcing agreements, and managing business operations.
Recipients
Recipients may include service providers, processors, sub-processors, affiliates, payment processors, hosting providers, analytics providers, professional advisers, authorities, and transaction counterparties.
International Transfers
We may transfer personal data to the United States and other countries that may not provide the same level of data protection as your jurisdiction. Where required, we rely on appropriate safeguards, such as adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the UK International Data Transfer Agreement, Swiss transfer adaptations, or other lawful mechanisms.
Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and as otherwise permitted by law.
Data Subject Rights
Subject to applicable law, you may have the right to access, rectify, erase, restrict processing, object to processing, data portability, withdraw consent, and lodge a complaint with a supervisory authority.
Complaint Rights
You may lodge a complaint with your local EEA supervisory authority, the UK Information Commissioner’s Office, or the Swiss Federal Data Protection and Information Commissioner, as applicable.
Contractual or Statutory Requirement
Providing certain personal data may be necessary to enter into or perform a contract with you or your organization. If you do not provide required information, we may be unable to provide the Services.
Automated Decision-Making
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
International Data Transfers
We may process and store personal information in the United States and other jurisdictions. Where personal information is transferred internationally, we use transfer mechanisms required by applicable law, which may include SCCs, UK Addendum, UK IDTA, adequacy decisions, transfer impact assessments, contractual safeguards, and technical and organizational measures.
Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, or destruction. These safeguards may include access controls, encryption where appropriate, logging, monitoring, vendor diligence, incident response, and personnel confidentiality obligations. However, no method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security.
Retention
We retain personal information for as long as reasonably necessary to provide the Services, operate our business, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent fraud, preserve records, and as otherwise permitted by law. Retention periods vary depending on the type of information, the purpose of processing, contractual requirements, legal obligations, and operational needs.
Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without required parental consent, we will take appropriate steps to delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “Last Updated” date. Where required by law, we will provide additional notice or obtain consent for material changes.
Contact Information
Mor Peled HLN Nadlan Ltd.
Email: privacy@smartsign.today
Privacy request form: www.smartsign.today/privacyform