Smart Sign. Check My Contract

Privacy Policy

Last modified: May 27, 2026

Introduction

This Privacy Policy explains how SmartSign (“Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with our websites, platforms, applications, services, software, communications, customer support, marketing activities, and other digital properties that link to this Privacy Policy, collectively, the “Services.”

This Privacy Policy is intended for users, visitors, customers, prospective customers, business contacts, and other individuals whose personal information we process. Where we process personal information on behalf of a customer as a service provider, processor, contractor, or sub-processor, our processing is generally governed by our agreement with that customer, including any applicable Data Processing Addendum.

Categories of Personal Information We Collect

The categories below describe the personal information we may collect. Not every category applies to every individual or use case.

Category Examples Sources Purposes Recipients Retention Approach
Identifiers Name, email address, username, account ID, customer ID, IP address, online identifiers You, your organization, devices, service providers Provide Services, account management, authentication, security, support, compliance Service providers, hosting providers, security providers, affiliates, authorities where required As long as reasonably necessary for Services, security, legal, and business purposes
Contact Information Business email, phone number, mailing address, organization name, job title You, your organization, business partners Communications, sales, support, billing, notices CRM providers, email providers, support vendors, affiliates Duration of relationship plus legal retention period
Account Information Login credentials, account settings, roles, permissions, preferences You, account administrators, systems Account creation, access control, user management, security Hosting providers, identity providers, support providers While account is active and thereafter as needed
Commercial / Customer Relationship Information Subscription plan, order history, contract details, service usage, customer status You, customer organization, payment systems, sales systems Contract performance, billing, renewals, customer success, analytics Payment processors, CRM providers, professional advisers Contract term plus applicable limitation and tax/accounting periods
Payment and Billing Information Billing address, payment method details, invoice data, transaction records You, payment processors, customer organization Payments, invoicing, fraud prevention, tax compliance Payment processors, banks, accounting providers, advisers As required for tax, accounting, audit, and legal purposes
Internet, Device, and Usage Information IP address, browser type, device identifiers, operating system, log data, pages viewed, referring URLs, timestamps, feature usage Devices, cookies, analytics tools, servers Service operation, analytics, debugging, security, fraud prevention, product improvement Hosting providers, analytics providers, security providers Based on operational, security, analytics, and legal needs
Cookies and Similar Technologies Cookies, pixels, SDKs, local storage, analytics identifiers Browser, device, cookie providers, analytics tools Preferences, analytics, advertising if enabled, security, session management Analytics providers, advertising partners if applicable, service providers Based on cookie type and settings; see cookie section
Communications and Support Information Support tickets, emails, chat messages, call notes, feedback, survey responses You, support systems, customer success tools Support, troubleshooting, training, quality assurance, service improvement Support vendors, communication tools, CRM providers As needed for support history, quality, legal, and business needs
User-Generated or Uploaded Content Files, text, records, documents, data sets, messages, content uploaded to the Services You, authorized users, customer systems Provide and operate the Services, process customer instructions, support, security Hosting providers, sub-processors, support providers Controlled by customer settings, contract terms, and backup cycles
Approximate Location Information Approximate location inferred from IP address or account information Devices, IP lookup tools Security, localization, analytics, fraud prevention Hosting, analytics, security providers As needed for operational and security purposes

Purposes of Processing

We may collect, use, disclose, and otherwise process personal information for the following purposes:

  • Providing, operating, maintaining, and improving the Services.
  • Creating, administering, securing, and managing accounts.
  • Providing customer support, troubleshooting, training, and technical assistance.
  • Processing payments, invoices, orders, subscriptions, renewals, and related transactions.
  • Monitoring service performance, debugging, analytics, reporting, and product improvement.
  • Protecting against fraud, misuse, security incidents, unauthorized access, and unlawful activity.
  • Complying with legal obligations, regulatory requirements, subpoenas, court orders, and lawful requests.
  • Sending administrative, transactional, service, and security communications.
  • Sending marketing communications, newsletters, event invitations, and promotional materials where permitted by law.
  • Conducting research, benchmarking, analytics, business intelligence, and internal business planning.
  • Creating and using aggregated, anonymized, or de-identified information.
  • Enforcing agreements, resolving disputes, and protecting rights, property, and safety.
  • Evaluating or completing mergers, acquisitions, financing, reorganizations, bankruptcy, or sales of assets.
  • Any other purpose disclosed at the time of collection or with consent where required.

Aggregated, Anonymized, and De-Identified Data

We may create, receive, use, disclose, retain, sell, license, and otherwise process aggregated, anonymized, or de-identified information for analytics, product improvement, benchmarking, research, service development, business intelligence, security, and other lawful business purposes.

Where we maintain de-identified information, we will take reasonable measures designed to ensure that the information cannot reasonably be associated with an identified or identifiable individual or household, will publicly commit to maintaining and using such information in de-identified form where required by applicable law, and will not attempt to re-identify the information except as permitted by law, including to test whether our de-identification processes satisfy applicable requirements.

Disclosure of Personal Information

We may disclose personal information to the following categories of recipients:

  • Service Providers, Processors, Contractors, and Sub-Processors. Vendors that provide hosting, infrastructure, storage, security, analytics, customer support, communications, payment processing, identity management, and related services.
  • Subcontractors and Sub-Processors. We use subcontractors and sub-processors to provide parts of the Services.
  • Payment Processors. Third-party payment processors and financial institutions for billing, invoicing, payment, fraud prevention, and accounting.
  • Hosting and Infrastructure Providers. Cloud hosting, database, backup, content delivery, monitoring, and infrastructure providers.
  • Analytics Providers. Analytics and measurement providers that help us understand use of our Services.
  • Advertising and Marketing Partners. Where applicable, we may disclose information to advertising or marketing partners subject to applicable consent and opt-out rights.
  • Professional Advisers. Lawyers, accountants, auditors, insurers, bankers, and consultants.
  • Authorities and Regulators. Courts, law enforcement, regulators, public authorities, or other third parties where legally required or necessary to protect rights, safety, and security.

Subcontractors and Sub-Processors

We may engage subcontractors and sub-processors to support the Services. We require such parties to process personal information under appropriate contractual obligations where required by applicable law, including confidentiality, security, limited-use, and data protection obligations. Our current sub-processor list is available at www.smartsign.today/processors.

Cookies and Tracking Technologies

We and our service providers may use cookies, pixels, SDKs, local storage, analytics tools, advertising technologies, and similar technologies to operate the Services, remember preferences, analyze performance, secure the Services, measure campaigns, and, where applicable, provide targeted advertising.

U.S. State Privacy Rights

Depending on your state of residence and our legal obligations, you may have some or all of the following rights:

  • Right to know or access personal information.
  • Right to confirm whether we process your personal information.
  • Right to correct inaccurate personal information.
  • Right to delete personal information.
  • Right to obtain a portable copy of personal information.
  • Right to opt out of sale of personal information.
  • Right to opt out of sharing for cross-context behavioural advertising.
  • Right to opt out of targeted advertising.
  • Right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
  • Right to limit use or disclosure of sensitive personal information, where applicable.
  • Right to withdraw consent, where processing is based on consent.
  • Right to appeal a denied privacy request, where applicable.
  • Right to use an authorized agent, where applicable.

These rights may apply to residents of California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Texas, Florida, Maryland, Minnesota, Montana, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Rhode Island, and other states if additional laws become applicable.

How to Submit a Request

You may submit a privacy request by using:

  • Privacy request form: www.smartsign.today/privacyform
  • Email: privacy@smartsign.today

We may need to verify your identity before responding. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and may ask you to verify your identity directly.

Appeals

Where applicable, if we deny your request, you may appeal by contacting us at appeals@smartsign.today or using www.smartsign.today/privacyappeal and indicating that your submission is an appeal. We will respond within the time required by applicable law.

California Privacy Notice

This section applies to California residents and supplements the rest of this Privacy Policy.

Notice at Collection

At or before collection, we disclose the categories of personal information we collect, the purposes for which we collect and use it, whether we sell or share it, and how long we retain it or the criteria used to determine retention.

Categories Collected

In the preceding 12 months, we may have collected the categories listed in Section 2 above, including identifiers, commercial information, internet or network activity information, geolocation information, professional or employment-related information, sensitive personal information where applicable, and inferences.

Sources

We collect personal information from you, your organization, authorized users, devices, browsers, cookies, service providers, business partners, public sources, and third-party platforms where permitted.

Disclosures for Business Purposes

We may disclose personal information to service providers, contractors, processors, sub-processors, affiliates, advisers, analytics providers, payment processors, hosting providers, security providers, and authorities where required.

Sale or Sharing

We do not sell personal information as “sale” is defined under the CCPA/CPRA. We do not share personal information for cross-context behavioural advertising.

Sensitive Personal Information

We do not use or disclose sensitive personal information for purposes that require a right to limit under California law.

Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide Services, comply with law, resolve disputes, maintain security, and enforce agreements.

Non-Discrimination

We will not discriminate or retaliate against you for exercising your privacy rights.

U.S. State Privacy Regulators and Authorities

State Law Authority Official URL
CaliforniaCCPA/CPRACalifornia Privacy Protection Agency / California Attorney Generalhttps://cppa.ca.gov / https://oag.ca.gov/privacy/ccpa
ColoradoColorado Privacy ActColorado Attorney Generalhttps://coag.gov/resources/colorado-privacy-act/
ConnecticutConnecticut Data Privacy ActConnecticut Attorney Generalhttps://portal.ct.gov/ag
VirginiaVirginia Consumer Data Protection ActVirginia Attorney Generalhttps://www.oag.state.va.us/consumer-protection
UtahUtah Consumer Privacy ActUtah Attorney General / Division of Consumer Protectionhttps://attorneygeneral.utah.gov / https://dcp.utah.gov
TexasTexas Data Privacy and Security ActTexas Attorney Generalhttps://www.texasattorneygeneral.gov
OregonOregon Consumer Privacy ActOregon Attorney Generalhttps://www.doj.state.or.us
MontanaMontana Consumer Data Privacy ActMontana Attorney Generalhttps://dojmt.gov
DelawareDelaware Personal Data Privacy ActDelaware Department of Justicehttps://attorneygeneral.delaware.gov
IowaIowa Consumer Data Protection ActIowa Attorney Generalhttps://www.iowaattorneygeneral.gov
IndianaIndiana Consumer Data Protection ActIndiana Attorney Generalhttps://www.in.gov/attorneygeneral
TennesseeTennessee Information Protection ActTennessee Attorney Generalhttps://www.tn.gov/attorneygeneral
FloridaFlorida Digital Bill of RightsFlorida Attorney General / Department of Legal Affairshttps://www.myfloridalegal.com
MarylandMaryland Online Data Privacy ActMaryland Attorney Generalhttps://www.marylandattorneygeneral.gov
MinnesotaMinnesota Consumer Data Privacy ActMinnesota Attorney Generalhttps://www.ag.state.mn.us
New HampshireNew Hampshire Privacy ActNew Hampshire Attorney Generalhttps://www.doj.nh.gov
New JerseyNew Jersey Data Privacy ActNew Jersey Attorney Generalhttps://www.njoag.gov
KentuckyKentucky Consumer Data Protection ActKentucky Attorney Generalhttps://www.ag.ky.gov
NebraskaNebraska Data Privacy ActNebraska Attorney Generalhttps://ago.nebraska.gov
Rhode IslandRhode Island Data Transparency and Privacy Protection ActRhode Island Attorney Generalhttps://riag.ri.gov

GDPR / UK GDPR Privacy Notice

This section applies where we process personal data of individuals located in the European Economic Area, United Kingdom, or Switzerland, or where the GDPR, UK GDPR, or Swiss data protection law otherwise applies.

Controller Identity

Controller: Mor Peled HLN Nadlan Ltd.
Email: info@smartsign.today

Categories of Personal Data

We may process the categories of personal data described in Section 2.

Purposes and Legal Bases

Purpose Legal Basis
Providing and operating ServicesContract necessity; legitimate interests
Account creation and managementContract necessity; legitimate interests
Customer supportContract necessity; legitimate interests
Billing and paymentsContract necessity; legal obligation; legitimate interests
Security, fraud prevention, debuggingLegitimate interests; legal obligation
Compliance with lawLegal obligation
Analytics and product improvementLegitimate interests; consent where required
Marketing communicationsConsent; legitimate interests where permitted
Cookies and trackingConsent where required; legitimate interests for strictly necessary technologies
Corporate transactionsLegitimate interests; legal obligation
Aggregated, anonymized, or de-identified dataLegitimate interests; not personal data once anonymized

Legitimate Interests

Our legitimate interests may include operating and improving the Services, securing systems, preventing fraud, communicating with customers, analyzing service performance, developing products, enforcing agreements, and managing business operations.

Recipients

Recipients may include service providers, processors, sub-processors, affiliates, payment processors, hosting providers, analytics providers, professional advisers, authorities, and transaction counterparties.

International Transfers

We may transfer personal data to the United States and other countries that may not provide the same level of data protection as your jurisdiction. Where required, we rely on appropriate safeguards, such as adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the UK International Data Transfer Agreement, Swiss transfer adaptations, or other lawful mechanisms.

Retention

We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and as otherwise permitted by law.

Data Subject Rights

Subject to applicable law, you may have the right to access, rectify, erase, restrict processing, object to processing, data portability, withdraw consent, and lodge a complaint with a supervisory authority.

Complaint Rights

You may lodge a complaint with your local EEA supervisory authority, the UK Information Commissioner’s Office, or the Swiss Federal Data Protection and Information Commissioner, as applicable.

Contractual or Statutory Requirement

Providing certain personal data may be necessary to enter into or perform a contract with you or your organization. If you do not provide required information, we may be unable to provide the Services.

Automated Decision-Making

We do not use personal data for automated decision-making that produces legal or similarly significant effects.

International Data Transfers

We may process and store personal information in the United States and other jurisdictions. Where personal information is transferred internationally, we use transfer mechanisms required by applicable law, which may include SCCs, UK Addendum, UK IDTA, adequacy decisions, transfer impact assessments, contractual safeguards, and technical and organizational measures.

Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, or destruction. These safeguards may include access controls, encryption where appropriate, logging, monitoring, vendor diligence, incident response, and personnel confidentiality obligations. However, no method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security.

Retention

We retain personal information for as long as reasonably necessary to provide the Services, operate our business, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent fraud, preserve records, and as otherwise permitted by law. Retention periods vary depending on the type of information, the purpose of processing, contractual requirements, legal obligations, and operational needs.

Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without required parental consent, we will take appropriate steps to delete it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “Last Updated” date. Where required by law, we will provide additional notice or obtain consent for material changes.

Contact Information

Mor Peled HLN Nadlan Ltd.
Email: privacy@smartsign.today
Privacy request form: www.smartsign.today/privacyform