# Tally Sign Cookie Notice

**Last updated:** September 27, 2026

This notice explains the cookies and similar browser storage that Tally Integrations LLC ("Tally", "we", "us") uses on:

- our website at **www.tallysign.com** (the "website");
- the Tally Sign app at **app.tallysign.com**, and an earlier Tally Sign address that some integrations still use (**sign.gettally.io**) (the "app");
- the pages people use to sign documents sent through Tally Sign ("signing pages"); and
- the Tally Sign screens that appear inside Salesforce ("Salesforce panels").

For how we handle personal data in general, see our [Privacy Policy](/legal/privacy-policy).

---

## 1. The short version

1.1 We only use cookies and browser storage that are **strictly necessary** to make Tally Sign work: to keep you signed in, to protect your account and your sign-ins (including sign-ins with Google, Microsoft, Salesforce or your company's single sign-on), to connect and work with Salesforce, and to keep your place while you sign a document.

1.2 We **don't** use analytics, advertising, social media or tracking cookies. We don't let third parties set cookies on our website or app. We don't use cookies to follow you across other websites, and we don't sell or share cookie data.

1.3 The website sets **no cookies at all**.

1.4 Because we only use strictly necessary cookies and storage, we don't show a cookie consent banner. If we ever add cookies that aren't strictly necessary, we will update this notice first and ask for your consent where the law requires it (see Section 9).

---

## 2. What cookies and browser storage are

2.1 A **cookie** is a small text file that a website asks your browser to keep and send back on later visits. A cookie can last only while your browser is open, or until a set expiry date.

2.2 **Session storage** is space in your browser where a web page can keep information for as long as that browser tab stays open. It is cleared when you close the tab. Unlike cookies, it isn't sent to our servers automatically.

2.3 **First-party** cookies are set by the site you are visiting. **Third-party** cookies are set by a different site. All the cookies in this notice are first-party cookies set by Tally Sign.

2.4 We don't use local storage (browser storage that persists after you close the tab), tracking pixels, web beacons, or device fingerprinting on the website, app or signing pages. Our emails, including signing requests sent on behalf of our customers, don't contain tracking pixels or tracked links, and we don't record when you open an email.

---

## 3. Cookies the app sets

All of these are strictly necessary. Each one is marked "HTTP-only", which means scripts running in the page can't read it. In production each is sent only over secure (HTTPS) connections.

| Cookie | Who gets it | What it's for | How long it lasts |
|---|---|---|---|
| `ts_session` | Anyone who signs in to the app | Keeps you signed in. It holds a signed token that identifies your user account and your company, and it lets us sign you out everywhere when your password changes. | 30 days, or until you sign out |
| `ts_session` (Salesforce panel version) | Tally Sign users who open the editor or automations inside Salesforce | Keeps you signed in to the editor inside Salesforce, separately from your normal app sign-in. It works only for the document (or automations screen) you opened from Salesforce, not the rest of the app. It is a "partitioned" cookie, which means your browser keeps it only for Tally Sign inside Salesforce and doesn't use it anywhere else. | The sign-in inside it lapses after 2 hours without activity; the cookie itself is kept for up to 7 days so the editor can check it's still you when it signs you back in |
| `ts_device` | Anyone who signs in to the app | Recognizes a browser you have signed in from before, so we can email you when someone signs in to your account from a new browser. It holds a random identifier. We store only a scrambled (hashed) copy, along with the browser type and IP address it was used from, and delete that record 13 months after the browser was last used. | 400 days |
| `ts_sso` | Anyone who signs in with Google, Microsoft, Salesforce or their company's single sign-on, and admins testing their company's single sign-on | Protects a sign-in while it's in progress. It holds a signed record of the sign-in you started (random check values, which provider, and the page to return to), so we can confirm that the answer from the provider belongs to the sign-in this browser started. It is sent with cross-site requests (SameSite=None) so it also comes back when a company's identity provider sends its answer from its own site. It is deleted as soon as the sign-in finishes. | 15 minutes |
| `ts_sso_signup` | People who start a new Tally Sign account with Google or Microsoft | Holds the name, email address and account ID that Google or Microsoft sent us, in a signed form that can't be changed, while you name your company to finish signing up. It is deleted when you finish. | 30 minutes |
| `ts_sf_oauth` | Company owners and admins connecting Salesforce | Protects the Salesforce connection process from interference while you sign in to Salesforce and approve the connection. It is sent only to the page that finishes the connection. | 15 minutes |
| `ts_sf_conn` | Users in a company that has connected Salesforce, when they connect an org or choose "Work in this org" | Remembers which of your company's connected Salesforce orgs (production or a sandbox) you work with in the app. It holds the connection's ID, not information about you. | 1 year |
| `ts_session` (support version) and `ts_platform_return` | Tally support staff only | Used only in the browser of a Tally staff member who signs in as a customer's user (see our [Privacy Policy](/legal/privacy-policy), Section 9.4). They let the staff member return to their own account afterwards. These cookies are never set in a customer's browser. | 2 hours (`ts_session`) and 4 hours (`ts_platform_return`) |

**Signing out** deletes the `ts_session` cookie from your browser.

---

## 4. Browser storage the app and signing pages use

All of these use session storage, so they are cleared when you close the browser tab. They are strictly necessary for the feature you are using.

| Storage key | Where | What it's for |
|---|---|---|
| `tally-sign-consent:<link>` | Signing pages | Remembers, for that signing link, that you agreed to use electronic records and signatures, so you aren't asked again each time the page reloads. |
| `tally-sign-draft:<link>` | Signing pages | Keeps the fields you have filled in and the signature or initials you have adopted, so you don't lose your work if the page reloads before you finish. It is removed as soon as you finish signing. |
| `tse-inbox-tab` | Salesforce panels | Remembers whether you were last looking at the Documents or Templates tab. |
| `tally-sign:send:<record>:<template>` | Salesforce panels | Remembers, for up to 15 minutes, a send you started from a Salesforce record, so sending again after a reload doesn't send the same document twice. It holds a random code, not the document. |
| `tse-recover` | Salesforce panels | Counts the times in the last minute the panel reloaded itself to sign you back in, so a panel that can't sign in shows a message instead of reloading forever. |

**If you sign on a shared or public computer,** close the browser tab when you are done. Your in-progress entries stay in that tab until you finish signing or close it.

We don't set any cookies on signing pages. People who receive documents to sign don't need an account. If you are signed in to Tally Sign in the same browser, the signing page reads your `ts_session` cookie only to tell whether someone at the sending company is checking the link, so that isn't recorded as the signer viewing the document.

---

## 5. The website (www.tallysign.com)

5.1 The website sets **no cookies** and uses no analytics or tracking tools.

5.2 The website includes interactive demos that run real Tally Sign screens on made-up sample data. While you try a demo, it may use the same session storage keys listed in Section 4 (for example, to remember what you have typed into a demo form). This stays in your browser tab, isn't sent to us, and is cleared when you close the tab.

5.3 The fonts on the website and app are served from our own servers, so your browser doesn't contact a font provider when you visit.

---

## 6. Salesforce

6.1 When you use Tally Sign inside Salesforce, the Salesforce panels use the cookie and storage described in Sections 3 and 4. Sign-in tokens the Salesforce panels use to talk to Tally Sign are kept only in the page's memory, not in cookies, and are gone when you leave the page.

6.2 Salesforce sets its own cookies on its own pages, including when you sign in to Salesforce to connect it to Tally Sign or to sign in to Tally Sign with Salesforce. Salesforce's cookie policy applies to those.

---

## 7. Other companies' pages

Some actions take you to another company's site, which may set its own cookies under its own policy. We don't control those cookies. They include:

- **Google or Microsoft**, when you sign in to Tally Sign with your Google or Microsoft account;
- **your company's identity provider** (for example Okta, Microsoft Entra ID, Google Workspace or OneLogin), when you sign in through your company's single sign-on;
- **Stripe**, when you subscribe, update a payment method, view invoices or cancel through Stripe's checkout or billing portal;
- **Salesforce**, when you sign in with Salesforce or connect your Salesforce org;
- **ChatGPT, Claude or another AI app**, when you connect it to Tally Sign; and
- any site a document or email links to.

---

## 8. How to control cookies and storage

8.1 **Browser settings.** Most browsers let you see, block and delete cookies and site data. Look for "Cookies and site data" or "Privacy" in your browser's settings. Your browser's help pages explain how.

8.2 **What happens if you block or delete them.** All our cookies are strictly necessary, so blocking them affects how Tally Sign works:

- Blocking or deleting `ts_session` signs you out, and you won't be able to stay signed in to the app.
- Deleting `ts_device` doesn't stop anything working, but the next time you sign in from that browser we will treat it as a new browser and send you a sign-in alert email.
- Blocking `ts_sso` stops you from signing in with Google, Microsoft, Salesforce or your company's single sign-on. You can still sign in with your email and password, unless your company requires single sign-on.
- Blocking `ts_sso_signup` stops you from finishing a new account with Google or Microsoft. You can sign up with your email and a password instead.
- Blocking `ts_sf_oauth` stops you from connecting Salesforce.
- Blocking or deleting `ts_sf_conn` means the app works with your company's production Salesforce org rather than the one you chose.
- If your browser blocks cookies inside embedded frames, the Tally Sign editor inside Salesforce may not stay signed in.
- Blocking session storage means a signing page can't keep your progress if it reloads, and you may be asked to agree to electronic signatures again.

8.3 **Closing the tab** clears everything in session storage.

8.4 **Browser privacy signals.** Some browsers send signals such as Global Privacy Control or "Do Not Track". Because we don't use cookies for advertising, analytics or cross-site tracking, and we don't sell or share personal data, there is nothing for these signals to switch off on our website or app today. If that changes, we will update this notice and honor these signals where the law requires.

---

## 9. Changes to this notice

9.1 We will update this notice whenever we change the cookies or storage we use, and change the "Last updated" date at the top.

9.2 Before we add any cookie or similar technology that isn't strictly necessary (for example, analytics), we will update this notice and, where the law requires, ask for your consent before setting it.

---

## 10. Contact

Questions about this notice: privacy@tallysign.com.

Tally Integrations LLC. Our mailing address is available on request from support@tallysign.com.

We haven't appointed a representative in the EU or the UK, so please send any question about this notice, wherever you are, to privacy@tallysign.com.

Related documents: [Privacy Policy](/legal/privacy-policy), [Terms of Service](/legal/terms-of-service), [Subprocessors](/legal/subprocessors).
