Back to home

Privacy Policy

Last updated: 2026-06-24

This policy describes how אדיר ביטון ("the operator", "we") processes personal data in the EasySign service. It supplements our Terms of Use.

Who is responsible

אדיר ביטון is the data controller for administrator account data (phone, profile, templates, document metadata).

An administrator who uploads a document is an independent controller for document content and signer data therein. The operator processes that data as a processor to store and operate the service.

Data collected — administrators

When you register and use an administrator account:

  • Phone number (required) — SMS verification via Firebase Auth
  • Display name, signing intro message, business logo (optional)
  • Documents, signatures, templates, document status, timestamps
  • E2EE vault salt/verifier — not your master passphrase
  • Chat drafts in localStorage and files in IndexedDB (device only)

Data collected — signers

Signers can sign without an account. We then collect: signature image, placement coordinates, optional signer name, signature timestamp.

If the signer chooses to sign in: phone number and signerUid link. Login is shown by default but can be skipped.

For "secure signing" documents: the signer must verify their phone (SMS), and an audit trail is collected including timestamp, a hash of the verified phone, IP address, and browser identification (User Agent). Some of this data (masked phone, IP, browser) is embedded in the audit page of the signed PDF and is available to the document administrator and the signer.

For encrypted documents, the decryption key is in the URL fragment and is never sent to the server.

Encrypted vs non-encrypted documents

End-to-end encryption (E2EE) is optional and enabled from profile settings. When enabled, content is not readable by the operator. Technical metadata (file size, type, status, hash) may remain visible.

Without E2EE: document and signature files are stored in Firebase Storage and are accessible to the operator to run the service.

Cookies and local storage

We use:

  • NEXT_LOCALE cookie — language preference
  • Firebase Auth browser storage (tokens/session managed by the SDK)
  • Google reCAPTCHA Enterprise — loaded on all pages for SMS verification; may collect identifiers and interaction data for fraud prevention

What we do not collect

No Google Analytics or Google Tag Manager (excluded in our content security policy). No marketing cookies.

Service providers

Data may be processed by:

  • Google Firebase (Auth, Firestore, Storage) — may process outside Israel
  • Google reCAPTCHA Enterprise
  • unpkg.com — pdf.js assets; your IP may be exposed
  • Cloudflare — website hosting
  • WhatsApp (Meta) — external link for upgrades/support; does not process in-app data directly

Legal bases

Contract performance — providing the service to administrators.

Legitimate interest — security, fraud prevention, proper operation.

Consent — optional profile fields.

Administrators are responsible for the legal basis of their document content.

Retention

Account data: while the account is active, and for a reasonable period after deletion for backups and inquiries.

Signed documents: until the administrator deletes them. Infrastructure backups may persist for a limited period.

Security

HTTPS, HSTS, strict Referrer-Policy on the signing page, Content-Security-Policy, optional E2EE, Firestore/Storage rules.

Your rights

Access, correction, and deletion — contact [email protected]. We respond within 30 days.

You may complain to the Israeli Privacy Protection Authority.

International transfers: Firebase/Google — subject to Google terms and Israeli cross-border transfer regulations.

Children

The service is not intended for anyone under 18.

Updates and contact

We may update this policy from time to time. Privacy questions: [email protected], WhatsApp 054-649-4240.