Effective date: September 27, 2026 Last updated: September 27, 2026
This policy explains what personal information Tally Sign collects, why, who we share it with, how long we keep it, and the choices and rights you have. If something isn't clear, email us at privacy@tallysign.com.
The short version
- Got a document to sign? The company that sent it decides what happens to your information, so ask them first. Section 3 explains what we record and who sees it.
- We work for our customers. Documents, and the details of the people who sign them, belong to the business that sent them. We handle them to run Tally Sign for that business, and use a small part of them (such as IP addresses in our logs) to keep the service secure (Section 3.7).
- For our own accounts, billing and website, we're responsible. That covers people who sign up and use Tally Sign, billing contacts and website visitors.
- Signing in with Google, Microsoft, Salesforce or your company's single sign-on. We receive only your name, email address and an account ID, never your password, and we use them only to sign you in and to create or find your Tally Sign account. We don't sell them, use them for ads or use them to train AI (Section 4.3).
- Signing leaves evidence. When you open, view or sign a document, we record the time, your IP address and your browser details. They go into the Certificate of Completion, which everyone on the document receives.
- No ads, no tracking. We don't sell your information or share it for advertising. Our website has no analytics or ad trackers and sets no cookies. The app uses only the cookies it needs to work.
- AI. When someone uses our AI assistant, what they're working on goes to OpenRouter, which passes it to a host running an Anthropic Claude model, so it can write a reply. Tally doesn't keep the chat and doesn't train AI on your content. Under their terms, our AI providers don't train on it either, but they may keep it for a limited time to check for abuse (Section 7).
- Our staff can sign in to accounts when needed. To help when asked, fix a problem, keep things safe or check that our rules are followed, our support staff can sign in as a user. We log each session, and tell the account owner if we did it without being asked (Section 9.4).
- Where data lives. We store data in the United States, and all of the service providers that process it for us do so in the United States (see Subprocessors).
- Paused accounts are deleted after 6 months. Everything in them is deleted for good. We email the account owner and admins about 30 days and again at least 7 days before.
- Your rights. Email privacy@tallysign.com to see, correct or delete your information. If it's in a document someone sent you, we'll pass your request to them.
1. Who we are and what this policy covers
1.1 Who we are. Tally Sign is operated by Tally Integrations LLC, organized in Nevada ("Tally", "we", "us"). Our mailing address is available on request from support@tallysign.com. You can reach us about privacy at privacy@tallysign.com.
1.2 What this policy covers. It covers personal information we handle through:
- our website at https://www.tallysign.com, including the Tally Sign University help guides (the "website"); and
- Tally Sign itself: the app at https://app.tallysign.com (and sign.gettally.io, an earlier address some integrations still use), signing pages, emails we send, the Tally Sign Salesforce package, our API, and connections to AI apps such as ChatGPT and Claude (the "Service").
1.3 Who it covers. It covers three groups of people:
- Website visitors: anyone browsing the website.
- Users: people who sign up for Tally Sign or are invited to a company's account, including owners, admins and members, Salesforce users who are given a Tally Sign seat, and people who join their company's account through its single sign-on.
- Recipients and Signers: a "Recipient" is anyone a customer sends a document to through the Service, whether to sign it or to get a copy. A "Signer" is a Recipient asked to sign. Recipients don't need an account. Section 3 is written for you.
1.4 What it doesn't cover. It doesn't cover how our customers use the information in their own documents, their own Salesforce org, or their other systems. Each customer has its own privacy practices. It also doesn't cover third-party services you choose to use with Tally Sign, such as Google, Microsoft or your company's identity provider when you sign in with them, ChatGPT, Claude, Salesforce, Slack, Microsoft Teams, Discord or Stripe's own pages. Those services have their own privacy policies.
1.5 Related documents. Our Terms of Service govern use of the Service. Our Data Processing Addendum forms part of the Terms and applies to every customer. The companies that process customer data for us are listed in Subprocessors, and our use of cookies is explained in the Cookie Notice. Signers can read the Electronic Records and Signature Disclosure.
2. Our two roles: controller and processor
Privacy laws treat an organization differently depending on who decides why and how data is used.
2.1 When we act for our customers (processor / service provider). Our customers decide what documents to create, what to put in them, who to send them to, and what to do with the signed results. For this information we act as the customer's processor (under the EU and UK GDPR) or service provider (under the California Consumer Privacy Act and similar US state laws). Our Terms call this content "Customer Content". It includes:
- documents, templates, drafts, versions, attachments and uploaded files;
- everything Recipients provide or generate while signing, including field entries, signatures, comments, suggested edits and the audit trail;
- details about Recipients that a customer enters or pulls from its own systems, such as Salesforce;
- content a customer's Users give to the AI assistant.
We process Customer Content to provide and support the Service as the customer instructs, as set out in our Data Processing Addendum. If you are a Recipient and have a question about your information, the business that sent you the document is the right first contact. See Section 3.
2.2 When we decide for ourselves (controller / business). We are the controller (or "business") for:
- account information about Users (name, email, password, role and so on), including what we receive when you sign in with Google, Microsoft, Salesforce or your company's single sign-on (Section 4.3);
- company profile and billing information;
- security and technical records we keep to protect the Service, such as sign-in records, device records and logs, including the limited use of Recipients' information described in Section 3.7;
- AI usage records (who used the assistant, when, and how much, but not what was said);
- our record of administrative and support actions, and internal notes our team keeps about customer accounts;
- support conversations and other messages you send us;
- information about website visitors.
The rest of this policy describes both roles and says which one applies where it matters.
3. If you received a document to sign
This section is for Recipients. You don't have a Tally Sign account, and you never pay us.
3.1 Who is responsible for your information. The business or person that sent you the document (the "sender") decided to send it to you and controls the document and your information in it. Tally provides the signing service to that sender. The sender's own privacy notice explains how it uses your information. The sender's name appears in the signing email and on the signing page, and replies to our emails go to the sender.
3.2 What we collect when you open, view or sign. On the sender's behalf, we collect and store:
- Details the sender entered about you: your name and email address, and possibly your title, company and signing role.
- What you enter: every value you type or choose in the document's fields. These can include anything the document asks for, such as an address or phone number.
- Your signature and initials: a drawn signature is stored as an image; a typed signature is stored as the text and the font you chose.
- Your choices and messages: your agreement to use electronic records and signatures, any reason you give for declining, and any comments or suggested edits you make.
- Audit-trail evidence: the date and time your signing link was first opened (this may be done automatically by your email provider's security scanner, whose IP address is then recorded); each time you viewed the document (a view is recorded once the page is on your screen and you scroll, click, tap or type, so link scanners don't count as views); when you signed or declined; the IP address and browser user agent (a string that describes your browser, its version and your operating system) for each of these; the time zone your browser reports when you sign; and the time you agreed to use electronic signatures, which is currently recorded as the time you signed. We don't record a repeat view from the same IP address and browser within 30 minutes.
- In-person signing: if you sign on the sender's own device, the record shows it was signed in person and who hosted it.
We do not track your physical location, and we don't verify your identity beyond your access to the link sent to your email address. While you're filling in a document, your unfinished entries and signature are kept in your browser's temporary storage for that tab, so you don't lose your work. They are removed when you finish, or when you close the tab.
3.3 Who can see it.
- The sender and its team can see the document, your entries, your signature and the audit trail.
- Everyone on the document receives the finished PDF. It includes a Certificate of Completion that lists, for each Signer: name, email address, title and company, role, the times they agreed, viewed and signed, their IP address, their device and browser details, and their signature type. It also includes the audit trail and the negotiation history. Other Recipients on the same document will see this information about you. The sender decides to use Tally Sign's standard certificate. If you object to what it shows, contact the sender.
- The sender's connected tools may receive it if the sender set them up. For example, the sender can have signing status, names and emails written into its Salesforce org, sent to chat tools such as Slack, or sent to its own systems by webhook.
- AI apps the sender connects. If someone at the sender's company has connected an AI app such as ChatGPT or Claude to Tally Sign, the document, your name, email address, signing status, any decline reason and a link to the signed PDF can be passed to that app and its provider, under the sender's account with that provider.
- Our service providers process it to run the Service. For example, our email provider delivers the emails, including the signed PDF attachment (see Section 9).
3.4 How long it's kept. The sender decides, within the limits in Section 11. A document that has been completed or declined can't be deleted by the sender's team. Before it is completed, the sender can cancel (void) it or unlock it to make changes, which clears any signature you already gave, and can then delete it. You receive your own copy of the signed PDF by email and can download it again from your signing link for as long as the sender's account exists.
3.5 Your rights. Please send requests to access, correct or delete your information to the sender first, because it controls the document. If you contact us instead, we will pass your request to the sender where we can identify it, tell you we've done so, and help the sender respond. We don't edit a signed record ourselves, because that would alter a legal record that belongs to the sender and the other parties. For the information we use for our own purposes (Section 3.7), you can contact us directly. You may also have a right to complain to a regulator (Section 13).
3.6 Emails we send you. Emails about a document (signing requests, reminders, updates, void notices and the completed copy) are sent on the sender's behalf, show the sender's name and branding, and are part of the signing process. They are not marketing from Tally.
3.7 What we do with your information for our own purposes. Besides handling your information for the sender, we use a limited part of it ourselves: your IP address, browser details and email address in our security and server logs, and records of misuse, to protect the Service, prevent fraud, spam and abuse, and establish or defend legal claims. For this we are a controller. Our legal basis is our legitimate interest in keeping the Service and the people who use it safe (Art. 6(1)(f) GDPR). We keep these records for the periods in Section 11.1. You can object or exercise your other rights for this information with us directly at privacy@tallysign.com.
4. Information we collect
4.1 Website visitors
Our website does not use analytics, advertising pixels or cookies, and has no contact forms. The product demos on the website run on sample data inside your browser and don't send what you type back to us. Like any website, our hosting provider receives technical information when your browser requests a page, such as your IP address, the page requested, the time and your browser's user agent.
4.2 Users
- Sign-up and profile: your name, work email address, password (unless you only sign in with a provider, Section 4.3), job title, and the company name you give us. We store your password only as a one-way scrambled value (a "hash"), never in readable form.
- Team information: your role (owner, admin or member), who invited you and when, and invitation emails to people your company invites.
- Sign-in and security records: when you last signed in; for each browser you sign in from, a random device identifier (stored in a cookie and kept by us only in hashed form), your IP address, your browser's user agent, and when we first and last saw that browser; and, when someone asks to reset your password, the time and the IP address of the request.
- API keys: the name and first characters of any API key your company creates, a hash of the key, and when it was created, last used or revoked. Connections to AI apps such as ChatGPT or Claude aren't stored as a list; each connection works through signed tokens tied to your user account.
- Salesforce seats: if your company uses Tally Sign for Salesforce, your Salesforce user ID, name, email and title, whether you have a seat, and any note you add when you request one. Until you're given a seat, we handle these details for your company. When you are given a seat, we create a Tally Sign user for you from them, and we handle that account as its controller.
- AI usage records: each time the AI assistant is used, which User used it, when, for what (for example the template builder or email designer), which AI model answered, how much it was used, how long it took, what it cost, and whether it succeeded. We don't store the prompts or the replies (Section 7).
- Activity in the Service: actions you take are recorded in document audit trails, for example "sent by", "reminder sent" or "voided by". Comments and replies you write are stored with your name and email address.
4.3 Signing in with Google, Microsoft, Salesforce or single sign-on
Instead of (or as well as) a password, you can sign in to Tally Sign with a Google, Microsoft or Salesforce account, or through your company's own identity provider using single sign-on (SAML 2.0 or OpenID Connect), which any company can set up on any plan. When you do, that provider confirms who you are and tells us a few details about you. We never see or receive your password for that provider.
What each provider sends us:
- Google. We ask Google only for basic sign-in information (the "openid", "email" and "profile" scopes). Google sends us your name, your email address, whether Google has verified that email address, and your Google account ID (a number that identifies your Google account). Google may also include your profile picture and your first and last name separately; we don't use or store the picture. We don't ask for, and can't access, your Gmail, Google Drive, Calendar, contacts or any other data in your Google account, and we don't keep any Google access token after you've signed in.
- Microsoft. We ask Microsoft only for basic sign-in information. Microsoft sends us your name, your email address, whether the owner of that email's domain has verified it, and IDs for your account and for your organization's Microsoft directory (the object ID and tenant ID). We don't access your mailbox, files or any other Microsoft data.
- Salesforce. Salesforce sends us your Salesforce user ID and your org's ID, your name, email address, whether Salesforce has verified that email, whether your Salesforce user is active, and your org's name. We use a one-time Salesforce permission to read these details and revoke it straight away. (Signing in with Salesforce is separate from a company connecting its Salesforce org to Tally Sign, described in Sections 4.5 and 9.3.)
- Your company's single sign-on. Your company's identity provider (for example Okta, Microsoft Entra ID, Google Workspace or OneLogin) sends us your email address, your name and an identifier for you that your company's provider chooses. Your company decides which provider it uses and what it sends.
What we keep: your name and email address in your Tally Sign account, and a record linking your account to that sign-in method: the provider, the account ID it gave us, the email address it gave us, and when you last used it. We also keep the same sign-in and security records as for any other sign-in (Section 4.2). When a company sets up single sign-on, we also keep its setup: its identity provider's addresses, certificates and client ID, an encrypted copy of its client secret, and the email domains the company has proven it owns.
How we use it: only to sign you in; to create your Tally Sign account, or to find your existing account, your company's invitation or your Salesforce seat; to keep that link secure (we recognize you by the provider's account ID, so a changed or reused email address can't move your access to someone else); and to apply your company's sign-in rules. For example, a company can require its members (everyone except the account owner) to sign in through its single sign-on, and can let people at its verified email domains join its account as members the first time they sign in. We don't use this information for anything else.
Information from Google. Tally Sign's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use your Google name, email address and account ID only to sign you in and to create or identify your Tally Sign account;
- we don't sell this information, and we don't use or transfer it for advertising, including personalized, retargeted or interest-based ads;
- we don't use it to develop, improve or train artificial intelligence or machine-learning models, and we don't give it to anyone else to do so;
- we don't use it to decide anyone's creditworthiness or for lending;
- we share it only as needed to provide your account: our hosting provider stores it and our email provider delivers your account emails (Section 9.2); your company's owner and admins see your name and email as a member of their account; and your name and email appear where they normally appear in the Service, such as on documents you send. Beyond that, we disclose it only where the law requires or as part of a business transfer (Section 9.6);
- our staff don't read it unless you ask us to, it's needed for security or to investigate abuse, or the law requires it.
We treat the information we receive from Microsoft, Salesforce and company identity providers the same way.
Your choices: you don't have to sign in with a provider; you can always use your email address and a password, unless your company requires its single sign-on. To stop signing in with Google, remove Tally Sign from the third-party connections in your Google Account (myaccount.google.com), and ask us at privacy@tallysign.com to remove the link from your Tally Sign account. The link is deleted automatically when your Tally Sign account is deleted.
Google, Microsoft, Salesforce and your company's identity provider are not our service providers for this. They're services you or your company chose, and their own privacy policies apply to what they collect when you sign in with them.
4.4 Company profile and billing
- Company profile: company name, legal name, address, email, website, governing state, brand color, logo and cover image, and any sender profiles your company sets up (name, email, title, company, phone and address used in documents and emails).
- Subscription and billing: your plan and seat count, trial and billing dates, subscription status, and the Stripe customer and subscription IDs that link your company to its billing records. Stripe collects your card details, billing address and tax ID directly on its own pages. We never receive or store your full card number. We share your company's legal name (or name), the company or subscriber email address, and our internal company ID with Stripe.
- Account status and internal notes: whether the account is active, in its trial, in a grace period or paused, and why; and internal notes our team keeps about a customer account, for example about support or billing. These notes are not shown in the Service, but you can ask for any that are about you (Section 13).
4.5 Customer Content (documents and signing)
We process Customer Content on our customers' behalf (Section 2.1). It includes:
- Document content: titles, text and other content, merge values (for example a client's name, company and prices), email subject lines and messages, pricing tables, uploaded PDF and Word files and their page images, PDF attachments, images, and every version of a document.
- Sending and signing records: a fixed copy of each document at the moment it's sent, with a digital fingerprint (a SHA-256 hash) that lets a copy be checked against the version we recorded; the Recipient information described in Section 3.2; the audit trail; and the final signed PDF with its own fingerprint and the Certificate of Completion.
- Negotiation: comments, suggested edits, change requests and decisions, with the author's name and email.
- Salesforce information (Tally Sign for Salesforce only): fields from the Salesforce record a document is sent from (such as an Opportunity, Quote, Order, Contract or custom object), quote lines, contacts chosen as Recipients, and a link to the record.
- Automations: rules your company sets up, and the addresses and destinations they send to.
4.6 Support and other communications
If you email us or ask for help, we keep your message, your contact details and what we did to help.
5. Where we get information
- From you, when you sign up, use the Service, sign a document, or contact us.
- From your company, when an owner or admin invites you, assigns you a seat or sets up your profile.
- From sign-in providers, when you sign in with Google, Microsoft or Salesforce, or through your company's single sign-on (Section 4.3).
- From a sender, when someone sends you a document to sign or copies you on one.
- From your company's Salesforce org, when your company connects Tally Sign for Salesforce: record fields, contacts, quote lines, and Salesforce user details for seats. We also check periodically whether a Salesforce user with a seat is still active, so unused seats can be freed.
- From Stripe, which tells us about subscription status, payments and cancellations, but not your full card details.
- From AI apps you connect, such as ChatGPT or Claude, which send us the instructions you give them (for example "create an NDA for Jane Doe and send it").
- From public websites, when a User asks the AI assistant about a company by its web domain or a work email address (Section 7.2).
- Automatically, from your browser or device when you use the Service: IP address, user agent, timestamps and the cookies described in Section 8.
6. How we use information and our legal bases
6.1 Customer Content. We use Customer Content to provide the Service to the customer, as the customer instructs: to create, store, send, deliver and complete documents; to produce signed PDFs, certificates and audit trails; to run the integrations, automations and AI features the customer uses; to provide support; to keep the Service secure and prevent abuse; and to comply with the law. We don't use Customer Content for advertising, we don't use it to train AI models, and we don't combine it with data from other customers or other sources except as needed to run the Service. The customer is responsible for having a legal basis to send documents and to process the information of its Recipients. Our limited own use of Recipients' information is described in Section 3.7.
6.2 Our own purposes. For information we control, we use it as follows. If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, the table also shows the legal basis we rely on.
| What we do | Examples | Legal basis (EEA/UK) |
|---|---|---|
| Provide your account and the Service | Create your account, sign you in (including with Google, Microsoft, Salesforce or your company's single sign-on), apply your company's sign-in rules, manage your team, roles and seats, connect Salesforce and AI apps, run the AI assistant | If you signed up and accepted our Terms yourself: performance of our contract with you (Art. 6(1)(b)). If your company invited you, gave you a seat or let you join through its single sign-on: our and your company's legitimate interest in giving your company's staff access to the service it subscribed to (Art. 6(1)(f)) |
| Bill for the Service | Trials, subscriptions, seat changes, invoices, payment reminders, pausing and resuming accounts | Performance of our contract with the subscribing company; legitimate interest in keeping accurate financial records and meeting US tax and accounting rules; legal obligation where EU or UK law requires us to keep the records |
| Send service emails | Welcome and invite emails, password resets, document activity notices, trial and billing notices, deletion warnings | Performance of contract where you signed up yourself; otherwise legitimate interest in keeping Users informed about their company's account |
| Keep accounts and the Service secure | Alerts when you sign in from a new browser, password-reset limits, checking that sign-ins really come from the provider, detecting and stopping abuse, spam and fraud, investigating incidents, security logs (including the use described in Section 3.7) | Legitimate interest in protecting our Users, customers, Recipients and the Service |
| Provide support | Answer questions, fix problems, and, where needed, sign in as a User to see what they see (Section 9.4) | Performance of contract where you signed up yourself; otherwise legitimate interest in resolving problems |
| Manage AI usage | Record AI usage, enforce usage limits, watch costs | Legitimate interest in keeping the AI features available and affordable for all customers |
| Keep the Service working | Diagnose errors from server logs and fix problems | Legitimate interest in running a reliable service. We don't use analytics tools or track which features individual people use |
| Serve the website | Your browser's request, including IP address and user agent, reaches our hosting provider's servers and is logged | Legitimate interest in delivering and securing the website |
| Comply with law and protect rights | Respond to lawful requests, keep required records, enforce our Terms, establish or defend legal claims | Legal obligation where EU or UK law applies; otherwise legitimate interest in protecting our rights and those of others |
| Business transfers | Due diligence and transfer if our business is sold or reorganized (Section 9.6) | Legitimate interest in running and developing our business |
Where we rely on legitimate interests, we have considered your interests and rights and believe they are not overridden. You can ask us for details of that assessment at privacy@tallysign.com, and you can object (Section 13).
6.3 Information you must give us. To create an account we need your name and email address, a password or a sign-in through Google, Microsoft, Salesforce or your company's single sign-on, and your company's name. Without them we can't provide an account. Billing details are needed to subscribe. Other information is optional.
6.4 No automated decisions about you. We don't make decisions that have legal or similarly significant effects on you based solely on automated processing, and we don't profile you. The AI assistant drafts and edits content when a User asks it to; it doesn't make decisions about people.
7. AI features
7.1 The in-app AI assistant. Tally Sign includes an assistant, shown as "Assistant" in the editor and email designer. It is powered by a third-party AI model. When you use it, you are working with an AI system, not a person. It writes and edits templates and drafts, and designs emails, when a User asks it to. AI output can be wrong or incomplete and must be reviewed by a person before use. It is not legal advice.
7.2 What is sent to our AI providers. To answer a request, we send the following to OpenRouter, which passes it to a host that runs the AI model we have selected. Today that's Anthropic's Claude models, served through OpenRouter by Anthropic or by cloud providers OpenRouter routes to (such as Amazon Bedrock or Google Vertex AI), in the United States. The providers are listed in Subprocessors.
- Template builder: the draft or template being edited (its title, theme, layout, page headers and footers, and all its text; images are left out); the signers and people copied on it (their role, name, email address, title and company); the values filled in for its placeholders; the email subject and message it will be sent with; your company's name and legal name; the recent conversation with the assistant; and any pictures the User attaches to the latest message. It works only on drafts and templates, not on documents that have been sent. If the latest message mentions a work email address or a web domain, Tally Sign also reads that company's public website to find its name and address, and includes what it finds. It doesn't do this for free email providers such as Gmail, and the website only receives an ordinary request for its public pages from our servers.
- Email designer: the company name, brand color, whether the company has a logo and cover image, the current email design, the subject and message, the recent conversation, and any pictures the User attaches.
Anything a User has typed into a draft or into the chat, including names, prices or other personal information, can be part of what is sent. Please don't put information into the assistant that you don't need it to see.
7.3 Which provider. We choose which AI model answers. If we move the assistant to a different model provider or host, we first add it to Subprocessors and give our customers 30 days' notice under our Data Processing Addendum. A company can ask us to turn the assistant off for its account, and we'll do so within 5 business days.
7.4 What we keep. We don't store the conversation with the assistant. We store only the usage record described in Section 4.2. Pictures attached in the email designer are saved as images in your company's account so they can appear in your emails. Like other email images, anyone who has the image's link can open it (Section 9.7), so only attach pictures you're happy to show to email recipients.
7.5 Training. We don't use Customer Content or your conversations with the assistant, including in de-identified form, to train, fine-tune or evaluate AI models. OpenRouter and the model hosts process this content to provide the assistant for us. Under their terms, they don't use it to train their models. They may keep it for a limited time to monitor for abuse, as their terms allow.
7.6 Usage limits. AI features are subject to usage limits that we set and may change to protect the Service and other customers. We may slow or pause AI features for an account that reaches them. The assistant is not available while an account is paused.
7.7 ChatGPT, Claude and other connected AI apps. Any User can connect an AI app such as ChatGPT or Claude to Tally Sign, so they can create, edit and send documents from that app. When you connect one:
- you sign in to Tally Sign (with your password, a sign-in provider or your company's single sign-on) and approve the connection; the app then acts as you, only within your company's account;
- the app can read, create and edit documents and templates, and send, remind, void and delete documents (Tally Sign tells the app to ask you before sending, but can't check that it did);
- what the app receives from Tally Sign goes to that app's provider, such as OpenAI or Anthropic, under your own account and agreement with that provider. That can include document and template content, Recipient names, email addresses, titles and companies, signing status and decline reasons, recent audit-trail events (which can include names, email addresses and comment excerpts), data from your Salesforce org, links that let someone sign a pending document as the Recipient, and download links to completed PDFs. A completed PDF includes the Certificate of Completion, which shows each Signer's IP address and device details. That provider is not our subprocessor for this, and its privacy policy applies;
- connections stay active until they are revoked. Only an owner or admin can revoke them, and only all at once for the whole company ("Disconnect all apps" in Settings). You can also remove the connection in the AI app itself. Changing your password or being removed from the company doesn't disconnect an app you approved, so ask an admin if you need one disconnected.
API keys, which owners and admins create in Settings, work in a similar way. They don't expire and give access to your company's account until an owner or admin revokes them.
8. Cookies and browser storage
Tally Sign uses only cookies and browser storage that are needed for it to work. We don't use advertising or analytics cookies, and the website sets no cookies at all. In the Service we use first-party cookies to keep you signed in, to recognize a browser you've used before (so we can alert you about sign-ins from new browsers), to protect a sign-in with Google, Microsoft, Salesforce or single sign-on while it's in progress, to support sign-in inside Salesforce and for our support team, and to connect and work with Salesforce. Signing pages use temporary browser storage (cleared when you close the tab) to remember your consent and unfinished entries.
When you go to a third-party page from Tally Sign, such as Google's, Microsoft's or your company's sign-in page, Stripe Checkout, the Stripe customer portal, a Salesforce login page, or ChatGPT or Claude, that site may set its own cookies under its own policy.
The Cookie Notice lists each cookie, what it's for and how long it lasts.
9. How we share information
9.1 We don't sell or share personal information. We don't sell personal information, and we don't "share" it for cross-context behavioral advertising, as those terms are defined in California law. We don't use targeted advertising.
9.2 Service providers. We use a small number of companies to run the Service. They may process personal information only for us, and we require them by contract to protect it. They are:
| Provider | What they do | Information involved | Location |
|---|---|---|---|
| Railway Corporation | Hosts the Service, our database and our file storage | All information stored in the Service | United States |
| Plus Five Five, Inc. (Resend) | Delivers every email the Service sends | Recipient email address, subject, message, and attachments, including the full signed PDF sent when a document is completed | United States |
| OpenRouter, Inc., and the host that runs our current AI model (Anthropic's Claude models, served by Anthropic or by cloud providers OpenRouter routes to) | Powers the in-app AI assistant | The content described in Section 7.2 | United States |
| Stripe, Inc. | Processes subscriptions and payments for our own billing | Company and billing contact details; card and billing details Stripe collects directly | United States |
Stripe is our own billing provider, not a subprocessor for Customer Content. Stripe also processes some information as an independent controller under its own privacy policy, for example to prevent fraud. The list of subprocessors that process Customer Content, with each one's location, and how we give notice before adding one, is in Subprocessors. If this table and that list differ, that list controls.
Google, Microsoft, Salesforce and a company's own identity provider aren't our service providers when you sign in with them. They're services you or your company use, and they tell us who you are (Section 4.3).
9.3 At the direction of a customer or User. We send information where a customer or its Users tell us to. These destinations are chosen by the customer, not by us, and are governed by the customer's own arrangements with them:
- Recipients of a document receive the document, the signed PDF and the Certificate of Completion (Section 3.3).
- Salesforce: if a customer connects its Salesforce org, we write document status, Recipient names, email addresses, titles and companies, signing times, decline reasons, audit events (without IP addresses), notifications, tasks, record updates and the signed PDF into that org.
- Automations: a customer can send messages to Slack, Microsoft Teams or Discord; send webhooks to its own systems (which can include each Recipient's role, name, email, company, status and signing time); and send emails, with or without the signed PDF, to addresses it chooses.
- Connected AI apps and API keys: see Section 7.7.
9.4 Our team. A small number of authorized Tally staff can access customer accounts to operate the Service. Named platform administrators can also sign in as a User, for up to 2 hours at a time, only to provide support the customer or its Users ask for; to investigate a security, abuse or technical problem, or a suspected breach of our Acceptable Use Policy; or where the law requires it. During a session, the staff member can see what that User can. We log who signed in, as which User, and when. We don't notify the account automatically, but if we sign in without being asked, we tell the account owner within 5 business days, unless the law or an active investigation prevents it. Actions taken during a support sign-in currently appear in document records under the User's name, not the staff member's. The account owner can ask us for a list of support sign-ins in the previous 12 months.
9.5 Your company. If you are a User, your company's owner and admins can see and manage your account, your activity in documents, and your company's documents. They also decide how your company signs in: if your company requires its single sign-on, you sign in through your company's identity provider, and your company controls that access. If you leave, your name and email stay on documents, audit trails and comments you were part of, because those are part of the company's records.
9.6 Legal reasons and business changes. We may disclose information if we believe in good faith it is required by law, subpoena or other legal process, or needed to protect the rights, property or safety of Tally, our customers, Recipients or others, or to investigate fraud or security issues. If Tally is involved in a merger, acquisition, financing, reorganization or sale of assets, information may be transferred as part of that deal, subject to this policy or a notice we give you. Where we act for a customer, we handle legal requests for Customer Content as described in our Data Processing Addendum, including telling the customer where the law allows.
9.7 Links that don't require sign-in. Some files are served without sign-in so they can appear in emails, signing pages, signed PDFs and Salesforce: a company's logo and cover image, images added to documents and emails, and page images of PDF or Word files a User uploads. Each has a web address containing a long random code that can't practically be guessed, but anyone who obtains the address, for example from a forwarded email, can open the file, and the address doesn't expire. The file stays available until it is deleted from the account or the account is deleted. Browsers that have opened it may keep a cached copy for up to a year. Page images of uploaded files show the full content of those pages. Signed PDFs and PDF attachments aren't served this way; they are available only through signed, expiring links.
10. International transfers
10.1 Where we store data. We store and process information in the United States. The app and its database run with our hosting provider in its US West region (California), and files such as signed PDFs, attachments, uploads and logos are kept in its file storage in San Jose, California. All of the service providers in Section 9.2 process information in the United States; see Subprocessors. We don't currently offer a choice of storage location.
10.2 Transfers from the EEA, UK and Switzerland. If you sign up for Tally Sign or use the website yourself, you give us your information directly in the United States. When a customer in the EEA, the UK or Switzerland uses Tally Sign, the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum in our Data Processing Addendum apply between that customer and us, and our service providers are bound by written agreements with the same data protection obligations. We aren't certified under the EU-US Data Privacy Framework. You can ask for a copy of the relevant safeguards at privacy@tallysign.com.
10.3 Representatives and data protection officer. We haven't appointed a representative in the EU or the UK under Article 27 of the EU GDPR or the UK GDPR, and we haven't appointed a data protection officer. Please send any privacy question or request, wherever you are, to privacy@tallysign.com.
11. How long we keep information
11.1 Retention by category.
| Category | How long we keep it |
|---|---|
| Account and profile details of Users | While the account exists, then deleted with the company (Section 11.3). A removed User's account is deleted when they are removed, but their name and email stay in the company's documents (Section 9.5) |
| Links to sign-in providers (provider, account ID, email address, last used) | While the User's account exists; deleted when the User is removed or the company is deleted, or sooner on request |
| Company profile, account status and single sign-on setup | While the account exists, then deleted with the company. A company's single sign-on setup is deleted when its admins remove it |
| Device and sign-in records (device ID hash, IP address, user agent, last sign-in) | 13 months after the browser was last used, then deleted |
| Password-reset records (including the requesting IP address) | 90 days |
| AI usage records | 24 months, or until the company is deleted if that's sooner |
| Our record of administrative and support actions, and internal notes about accounts | 24 months, including after the company is deleted |
| Server logs (which can contain IP addresses, email addresses and email subject lines, including Recipients') | 30 days |
| Database backups | Up to 3 months (Section 11.4) |
| Billing and tax records | 7 years after the end of the tax year they relate to |
| Support messages | While needed to help you and keep a record of what we did, and no longer than 3 years |
| Customer Content (documents and signing records) | As the customer decides while the account exists; deleted 6 months after the account is paused, or sooner on request (Section 11.3) |
11.2 What customers can delete. A customer's team can delete drafts, voided documents, custom templates, attachments and uploads, remove Users, and revoke API keys and invites. A document that is out for signature can be voided or unlocked for editing and then deleted, and its audit trail is deleted with it. Documents that have been completed or declined can't be deleted in the Service, because they are part of a signing record. There is currently no self-service way to delete a whole company account; the account owner can ask us to do it at privacy@tallysign.com, and we'll complete it within 30 days. We won't delay deletion because of unpaid fees.
11.3 Paused accounts and permanent deletion.
- A trial that ends without a paid plan is paused right away.
- If a paid subscription's payment fails or the subscription ends, the account has a 14-day grace period and is then paused.
- While paused, Users can still sign in, view and download documents and signed PDFs, and pay to resume. Recipients can still sign documents that were already sent. Sending documents and the AI assistant are turned off.
- If an account stays paused for 6 months, we permanently delete the company and all of its data in the Service. That includes all documents, drafts, templates, signed PDFs, attachments, uploaded files, images, audit trails, comments, Users, links to sign-in providers, single sign-on settings, API keys, integrations and settings, and the company's files in our storage.
- We email the account owner, the account's admins and its billing email address when the account is paused, about 30 days before deletion, at least 7 days before deletion, and again once it's done. We won't delete the account until at least 7 days after the final warning has been sent, so deletion can happen somewhat later than 6 months.
- Deletion is permanent: we won't restore deleted data, and you can't recover it. Customers are responsible for downloading any signed documents and audit trails they need to keep before then. Before deletion, the account owner or an admin can ask us for a copy of all the account's documents and other data, and we won't delete the account until we've delivered it and they've had at least 14 days to download it (Data Processing Addendum, Section 13.2).
11.4 What remains after deletion. After a company is deleted, some information remains for a limited time or outside our control:
- Backups. Our hosting provider keeps backups of our database on a daily, weekly and monthly schedule. They contain data as it was when each backup was taken, including document content, Recipient details, field values, signatures and audit trails, and, for backups taken before September 25, 2026 (when we moved files to separate file storage), signed PDFs and uploaded files. Deleted data remains in backups until they expire, no more than 3 months after deletion. Files deleted from our file storage may likewise remain in our hosting provider's backups until they are removed, for up to 3 months. We use backups only to recover the Service from a failure. If we restore one, we re-apply every deletion made since it was taken before the data is used, using a minimal record of each deleted account (account ID, name and deletion date) that we keep for as long as we keep backups.
- Server logs, which may contain email addresses and email subjects, are kept for 30 days.
- Our record of administrative and support actions, such as account suspensions, deletions and support sign-ins, which may include names and email addresses, is kept for 24 months for security and accountability.
- Salesforce sync status: a small record of the Salesforce sync steps for each document (Salesforce record IDs and step status), kept for no longer than 12 months.
- Billing records held by Stripe, and our records needed for tax and accounting, are kept for the period in Section 11.1.
- Copies already delivered stay with the people who have them: emails and signed PDFs sent to Recipients, cached copies of images in browsers and email providers, and data written into a customer's Salesforce org or sent to its other tools or AI apps. We can't delete those.
- Service providers' own records, such as email delivery logs, are kept under their terms; see Subprocessors.
11.5 Links and invitations. Password-reset links expire after 1 hour and team invitations after 14 days. Signing links stop working when a document expires, is voided, declined or unlocked. After a document is completed, the signing link still lets Signers view and download the signed PDF for as long as the account exists. Information about website visitors exists only in server logs.
12. How we protect information
We use administrative, technical and organizational measures designed to protect personal information. They include:
- connections to the Service over HTTPS;
- passwords stored only as salted, one-way hashes;
- single sign-on over SAML 2.0 or OpenID Connect, available on every plan, which a company can require for everyone except the account owner;
- for sign-ins with Google, Microsoft, Salesforce or single sign-on: checking the provider's signature on every sign-in, accepting only email addresses the provider has verified, and recognizing people by the provider's account ID rather than by email address;
- signing links, invitation links, password-reset links and API keys built from long random codes, with invitation and reset codes and API keys stored only as hashes;
- email alerts when someone signs in from a new browser, and signing out every browser session when a password is changed or reset;
- stored Salesforce credentials, companies' single sign-on client secrets and our AI provider key encrypted by the Service;
- private file storage, with downloads given only through short-lived links after the Service has checked permission (except the public links in Section 9.7);
- a fingerprint (SHA-256 hash) of each document at sending and of each signed PDF, which lets a copy be checked against the version we recorded, and a block on editing or deleting completed and declined documents;
- limiting every request for company data to the signed-in user's company (except the public links in Section 9.7);
- access by our staff limited to what's needed, with the start of each support sign-in logged.
Tally Sign doesn't have its own multi-factor sign-in. If you sign in with Google, Microsoft or through your company's single sign-on, that provider's own security settings, such as its multi-factor sign-in, apply to your sign-in. Our Data Processing Addendum (Annex II) describes our measures in more detail. No method of storing or sending information is completely secure, and we can't guarantee security. You are responsible for keeping your password safe and for controlling who in your company has access.
Security incidents. If a security incident affects personal information we control, such as account information, we'll notify the relevant data protection authority within 72 hours of becoming aware of it where the law requires, and tell affected people without undue delay if it is likely to put them at high risk or if US state law requires notice. If an incident affects information we process for a customer, such as documents and Recipient details, we notify that customer as set out in our Data Processing Addendum, and the customer decides whether to notify Recipients and regulators. To report a security problem, email security@tallysign.com.
13. Your privacy rights
13.1 Everyone. Wherever you live, you can ask us what personal information we have about you, ask us to correct it, or ask us to delete it, and we'll respond as the law where you live requires. Users can update their own name, email, title and password in the Service. For information in documents a customer sent you, see Sections 3.5 and 13.5.
13.2 EEA, UK and Switzerland. If data protection law in these regions applies, you have the right to:
- access your personal information and receive a copy;
- correct inaccurate or incomplete information;
- delete your information in certain circumstances;
- restrict how we use it in certain circumstances;
- object to our use of it based on legitimate interests;
- data portability: receive information you gave us in a structured, commonly used, machine-readable format, and have it sent to another organization where technically feasible;
- withdraw consent at any time, where we rely on consent (this doesn't affect what we did before);
- complain to a data protection authority, in particular where you live or work or where you think the law was broken. In the UK, you can complain to us first, and we will acknowledge your complaint and respond to it without undue delay; you can also complain to the Information Commissioner's Office (ico.org.uk).
We respond within one month, which the law allows us to extend by up to two more months for complex or numerous requests. We'll tell you if we do.
13.3 California and other US states. If you live in California or another US state with a comprehensive privacy law, you may have the right to:
- know and access the categories and specific pieces of personal information we have collected about you, the categories of sources, our purposes, and the categories of third parties we disclose it to;
- delete personal information we collected from you;
- correct inaccurate personal information;
- portability: receive your information in a portable format;
- opt out of the sale or sharing of personal information, targeted advertising, and profiling for significant decisions. We don't do any of these;
- limit the use of sensitive personal information. We use it only for purposes the law permits without this right (Section 14.4);
- not be discriminated or retaliated against for using your rights.
We'll confirm we received your request within 10 business days and explain how we'll handle it. We respond to California requests within 45 days, which the law allows us to extend by another 45 days where needed; we'll tell you if we do. When we respond to a deletion request, we'll tell you whether we deleted your information and, if we kept any, what and why.
If we deny your request in a state that gives you a right to appeal, you can appeal by replying to our decision or emailing privacy@tallysign.com with "Privacy appeal" in the subject line. We'll respond within the time the law requires. If you're not satisfied, you can contact your state attorney general.
13.4 How to make a request.
- Email: privacy@tallysign.com
- Mail: Tally Integrations LLC, Attn: Privacy. Our mailing address is available on request from support@tallysign.com.
To protect you, we'll verify your identity before acting on a request, usually by confirming you control the email address on file. We may ask for more information if a request involves sensitive information or can't be matched to an account. You can use an authorized agent to make a request for you; we may ask for your signed permission and ask you to confirm your identity with us directly. We currently have no self-service export tool. We fulfil access requests by sending you a copy, and portability requests by sending the information you gave us in JSON or CSV, within the time limits above. Users can also download signed PDFs at any time.
13.5 Requests about Customer Content. If you're a Recipient, or your request is about the content of documents a customer controls, we'll forward your request to that customer, tell you we've done so, and help it respond. We may not be able to act on the request ourselves unless the customer instructs us. If you're a User asking about your own account information, links to sign-in providers, sign-in and device records, AI usage records, support-access records or any internal notes about you (Section 2.2), we're the controller and we'll answer you directly. Some requests can be limited by law, for example where keeping a signed record is needed to establish, exercise or defend legal claims or to meet a legal obligation.
14. Additional information for California residents
14.1 Notice at collection. We link to this policy on the sign-up page, the sign-in page, every signing page and signing email, and the footer of the website, so you can read it before we collect any information. This Section, together with the rest of this policy, is our notice at collection. In the 12 months before the "Last updated" date above, we collected the following categories of personal information, for the purposes in Section 6. We have not sold or shared any of them.
| Category (California law) | Examples | Sources | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Name, email address, IP address, account and device identifiers, account IDs from Google, Microsoft, Salesforce or your company's identity provider, Salesforce user ID | You; your company; sign-in providers; Salesforce; your browser | Service providers |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, signature, address, phone number and other details entered in documents or company profiles | You; your company; a sender | Service providers |
| Commercial information | Plan, seats, subscription and payment history | Your company; Stripe | Service providers (hosting) |
| Internet or other electronic network activity | Browser user agent, sign-in times, audit-trail events, AI usage records, server logs | Your browser; the Service | Service providers |
| Professional or employment-related information | Job title, company, role in the account | You; your company; Salesforce | Service providers |
| Audio, electronic, visual or similar information | Drawn signatures, logos, images and pictures Users upload or attach | You; your company | Service providers |
| Sensitive personal information | Account sign-in details (email and password) | You | Service providers (hosting only) |
| Other information in documents | Anything a customer or Signer chooses to include in a document | Your company; a sender; you | Service providers |
Information in documents and signing records is handled for our customers as their service provider, and customers decide who receives it (Section 9.3). We don't collect precise geolocation, and we don't draw inferences to build profiles about you. Documents can contain any kind of information, including sensitive information, depending on what a customer and its Recipients include. We process that information on the customer's behalf.
14.2 Retention. We keep each category for the period in Section 11.1.
14.3 No sale or sharing; minors. We don't sell or share personal information, and we have no actual knowledge of selling or sharing personal information of consumers under 16. Because we don't sell or share, there's nothing to opt out of. If that ever changes, we will update this policy first and honor opt-out preference signals such as Global Privacy Control.
14.4 Sensitive personal information. We use account sign-in details only to provide the Service and keep it secure, which the law permits without offering a right to limit. We don't use or disclose sensitive personal information to infer characteristics about you.
14.5 Shine the Light. We don't disclose personal information to third parties for their own direct marketing purposes.
15. Children
Tally Sign is a business service. It isn't meant for, or directed to, children, and we don't knowingly collect personal information from children under 16 (or under 13, in the United States). Users must be adults acting for a business. A customer that sends a document to a minor, for example for a parent or guardian to sign on the minor's behalf, is responsible for doing so lawfully. If you believe a child has given us personal information directly, contact us at privacy@tallysign.com and we will take appropriate steps.
16. Emails from us
The emails we send are about the Service: account and security emails, document activity, billing and deletion notices, and emails sent on a customer's behalf to Recipients. We don't currently send marketing emails. If we start, we'll only do so as the law allows and every marketing email will include a way to unsubscribe. You can't opt out of service emails while you have an account, because they carry information you need, such as security alerts and deletion warnings. We don't use open or click tracking in our emails.
17. Changes to this policy
We update this policy when our practices change, and review it at least once every 12 months, as California law requires. We'll post the new version at https://www.tallysign.com/legal/privacy-policy and change the "Last updated" date. If a change is material, we'll give notice before it takes effect, for example by email to account owners or a notice in the Service. Where the law requires your consent to a change, we'll ask for it.
18. Contact us
For privacy questions or requests:
- Email: privacy@tallysign.com
- Mail: Tally Integrations LLC, Attn: Privacy. Our mailing address is available on request from support@tallysign.com.
We haven't appointed an EU or UK representative or a data protection officer (Section 10.3), so please send every privacy request to privacy@tallysign.com.
To report a security problem, email security@tallysign.com. For help with the Service, email support@tallysign.com. For legal notices, email support@tallysign.com.
