Privacy Policy
Last updated: 2026-06-24
This policy describes how אדיר ביטון ("the operator", "we") processes personal data in the EasySign service. It supplements our Terms of Use.
Who is responsible
אדיר ביטון is the data controller for administrator account data (phone, profile, templates, document metadata).
An administrator who uploads a document is an independent controller for document content and signer data therein. The operator processes that data as a processor to store and operate the service.
Data collected — administrators
When you register and use an administrator account:
- Phone number (required) — SMS verification via Firebase Auth
- Display name, signing intro message, business logo (optional)
- Documents, signatures, templates, document status, timestamps
- E2EE vault salt/verifier — not your master passphrase
- Chat drafts in localStorage and files in IndexedDB (device only)
Data collected — signers
Signers can sign without an account. We then collect: signature image, placement coordinates, optional signer name, signature timestamp.
If the signer chooses to sign in: phone number and signerUid link. Login is shown by default but can be skipped.
For "secure signing" documents: the signer must verify their phone (SMS), and an audit trail is collected including timestamp, a hash of the verified phone, IP address, and browser identification (User Agent). Some of this data (masked phone, IP, browser) is embedded in the audit page of the signed PDF and is available to the document administrator and the signer.
For encrypted documents, the decryption key is in the URL fragment and is never sent to the server.
Encrypted vs non-encrypted documents
End-to-end encryption (E2EE) is optional and enabled from profile settings. When enabled, content is not readable by the operator. Technical metadata (file size, type, status, hash) may remain visible.
Without E2EE: document and signature files are stored in Firebase Storage and are accessible to the operator to run the service.
Cookies and local storage
We use:
- NEXT_LOCALE cookie — language preference
- Firebase Auth browser storage (tokens/session managed by the SDK)
- Google reCAPTCHA Enterprise — loaded on all pages for SMS verification; may collect identifiers and interaction data for fraud prevention
What we do not collect
No Google Analytics or Google Tag Manager (excluded in our content security policy). No marketing cookies.
Service providers
Data may be processed by:
- Google Firebase (Auth, Firestore, Storage) — may process outside Israel
- Google reCAPTCHA Enterprise
- unpkg.com — pdf.js assets; your IP may be exposed
- Cloudflare — website hosting
- WhatsApp (Meta) — external link for upgrades/support; does not process in-app data directly
Legal bases
Contract performance — providing the service to administrators.
Legitimate interest — security, fraud prevention, proper operation.
Consent — optional profile fields.
Administrators are responsible for the legal basis of their document content.
Retention
Account data: while the account is active, and for a reasonable period after deletion for backups and inquiries.
Signed documents: until the administrator deletes them. Infrastructure backups may persist for a limited period.
Security
HTTPS, HSTS, strict Referrer-Policy on the signing page, Content-Security-Policy, optional E2EE, Firestore/Storage rules.
Your rights
Access, correction, and deletion — contact [email protected]. We respond within 30 days.
You may complain to the Israeli Privacy Protection Authority.
International transfers: Firebase/Google — subject to Google terms and Israeli cross-border transfer regulations.
Children
The service is not intended for anyone under 18.
Updates and contact
We may update this policy from time to time. Privacy questions: [email protected], WhatsApp 054-649-4240.