Privacy Policy

Last updated: September 13, 2026

Who we are

RootSign is operated by Goldman Properties LLC. This policy explains what information we collect when you use RootSign to send or sign documents, and how we handle it.

Information we collect

How we use this information

To operate the e-signature workflow: generating signing links, recording who signed what and when, producing the audit trail and Certificate of Completion attached to signed documents, and delivering documents by email to senders and signers. We do not sell your information or use it for advertising.

How long we keep it

RootSign has no accounts, no dashboard, and no document history. Everything is permanently deleted 7 days after a document is created.

Seven days after you upload a document, we automatically and permanently delete it and everything associated with it — the original PDF, the completed/signed PDF, and all signer records (names, email addresses, IP addresses, browser/device information, and viewing and signing timestamps), along with the full audit trail. This happens regardless of whether the document was ever completed. Once deleted, the data is gone and cannot be recovered by us or by you.

Because of this, the completed PDF is delivered to you only by email, and you should save your own copy — after the retention window we no longer have it. The only exception is email: copies of the messages we send may persist in your and the recipients' own mailboxes and with our email provider, outside our control.

Separately from this active-storage deletion, our hosting provider (Render) takes daily infrastructure snapshots of the storage disk for disaster-recovery purposes, and each snapshot is retained for 7 days after it is captured. As a result, a small residual copy of deleted data can persist in these infrastructure backups for up to an additional 7 days beyond the deletion window described above, after which it is also purged. These backups exist solely for infrastructure recovery, are not accessible through the application, and are not used for any purpose other than disaster recovery.

Third parties we use

We rely on a small number of service providers to run RootSign. They process data on our behalf and are bound by their own privacy and security practices:

Aside from these providers, we do not share your documents or personal information with any other third party.

Your rights

You can request access to, or deletion of, your information by emailing privacy@rootsign.io. We will respond within a reasonable time. Note that because all data is automatically deleted 7 days after a document is created, information older than that window no longer exists to be accessed or deleted. If you're in a jurisdiction with specific data rights (e.g. California, the EU, or Colorado), we will honor applicable requests under those laws.

Children's privacy

RootSign is not directed at children under 13, and we do not knowingly collect information from them.

Security

We take reasonable measures to protect your information, but no online service can guarantee absolute security.

Changes

We may update this policy as the product evolves. Material changes will be reflected here with an updated date.

Contact

Questions about this policy? Email privacy@rootsign.io.