Privacy Policy
Last updated: 6 October 2026. This policy explains what data Signguin (signguin.com) collects, why, who helps us process it, how long we keep it and what you can ask us to do with it. Short version: we only use your data to make and deliver your email signature, we never sell it, we don’t use advertising trackers and we don’t use your photo to train AI.
1. Who we are
Signguin is run by Dibsido.com s.r.o., Hlinky 995/70, Staré Brno, 603 00 Brno, Czech Republic, company ID 04779568, VAT ID CZ04779568 (“we”, “us”). We are the controller of your personal data under the EU General Data Protection Regulation (GDPR). Contact for anything about your data: hello@signguin.com.
2. What we collect and why
| Data | Why we use it | Legal basis (GDPR) |
|---|---|---|
| Your work email address, entered when you start | To find your company’s website, logo and colours, to save your signature and to send you login links and messages about your signature. | Contract (Art. 6(1)(b)); for follow-up messages about your unfinished signature, legitimate interest (Art. 6(1)(f)) |
| Signature details you type: name, job title, company, phone numbers, address, website, social and other links, button text, disclaimer | To build your signature. Without an account they stay in your browser only. With an account we store them so you can edit and reinstall your signature. | Contract (Art. 6(1)(b)) |
| Your photo, logo and banner images | To show them in your signature. Signatures in email load images from our servers, so we host them. We remove location and other metadata from uploads and resize them. | Contract (Art. 6(1)(b)) |
| Public data from the website you enter: logo, colours, contact details, social links | To pre-fill your signature. We read the public web page once when you ask us to. | Contract (Art. 6(1)(b)) |
| Account and purchase records: email, sign-in sessions, whether you bought Premium, payment reference | To log you in, unlock Premium and keep accounting records. | Contract (Art. 6(1)(b)); legal obligation for accounting (Art. 6(1)(c)) |
| Team waitlist: email and team size | To tell you when team signatures are available. | Consent (Art. 6(1)(a)); you can withdraw it at any time |
| Product news and tips | Only if you tick the box to receive them. | Consent (Art. 6(1)(a)); unsubscribe in any email |
| Anonymous usage events (for example “design chosen”, “signature copied”), with a random browser ID, language and no name or email | To understand which steps work and improve the product. | Legitimate interest (Art. 6(1)(f)) |
| Technical data: IP address, browser, request logs | To run the service securely, prevent abuse (for example rate limits) and fix errors. | Legitimate interest (Art. 6(1)(f)) |
We do not sell your data, we do not show ads, and we do not use your photo or any of your content to train AI models.
3. Gmail access
If you choose “Add to Gmail automatically”, Google asks you to allow the scope gmail.settings.basic. We use it once, only to set the signature on your default sending address. We cannot read, send or delete your email, we request no other Gmail access, and we do not store the access token: it is used during that one request and discarded. You can revoke the permission at any time in your Google Account under “Third-party apps and services”.
Signguin’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Cookies and browser storage
- Sign-in cookie (
sid): keeps you logged in for up to 180 days after you sign in. Strictly necessary. - Gmail install cookie (
gstate): protects the Gmail connection against forged requests, deleted after 15 minutes. Strictly necessary. - Browser storage (localStorage): your draft signature and a random ID for anonymous usage statistics. It never leaves your device except as described above, and you can clear it in your browser settings.
We use no advertising or cross-site tracking cookies, so we don’t show a cookie banner.
5. Who processes data for us
We use these service providers (processors). Each processes data only on our instructions and under a data processing agreement.
- Vercel Inc. (USA): website hosting and image storage.
- Neon Inc. (USA): database hosting.
- Resend (USA): sending login and service emails.
- Google LLC (USA): the Gmail connection, only if you use “Add to Gmail automatically”; and Google’s public favicon service, which we ask for a website’s icon when a site has no usable logo (it receives the website’s domain, not your data).
- Our payment provider: when you buy Premium, payment is handled by the provider shown at checkout, which processes your payment details under its own privacy policy. We never see or store your card number.
Where data is transferred outside the European Economic Area, the transfer relies on the EU-U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses.
6. How long we keep data
- Login links expire after 30 minutes. A signature parked while you connect Gmail is deleted within a day.
- Your account, saved signatures and uploaded images: until you delete them or ask us to delete your account.
- An email address you entered without creating an account: deleted 24 months after you last used Signguin.
- Anonymous usage events: 24 months.
- Team waitlist entries: until we launch team signatures and tell you, or until you ask us to remove you.
- Purchase and invoicing records: as long as accounting and tax law requires (in the Czech Republic, up to 10 years).
Images in signatures you have already sent are loaded from our servers when someone opens your email. If an image is deleted (for example when your account is deleted at your request), it no longer shows in those emails.
7. Your rights
Under the GDPR you have the right to:
- get a copy of your data and information about how we use it (access);
- have incorrect data corrected;
- have your data deleted;
- restrict processing or object to processing based on legitimate interest;
- receive your data in a machine-readable format (portability);
- withdraw consent at any time, without affecting earlier processing.
You can delete saved signatures yourself under “My signatures”. For anything else email hello@signguin.com; we reply within one month. You can also complain to a data protection authority, in the Czech Republic the Office for Personal Data Protection (uoou.gov.cz), or the authority where you live or work.
8. Security
All connections use HTTPS. Login links and sessions are stored only as one-way hashes, login links work once, and access to production systems is limited to people who need it. Dibsido.com s.r.o. is certified to ISO/IEC 27001.
9. Children
Signguin is meant for work email and is not directed at children under 16.
10. Changes
If we change this policy, we update the date at the top. For significant changes we tell account holders by email before they take effect.