🌐EnglishDeutschFrançaisEspañolItalianoPortuguêsNederlands日本語

Privacy Policy

1. Introduction

This Privacy Policy explains how Mostly Tiny Ltd ("we", "us", "our") collects, uses, shares and protects your personal data when you use mostlysign.com, and the rights you have over that data. It applies to personal data for which we act as the controller. Effective date: 2026-10-06.

2. Who we are and how to contact us

Mostly Tiny Ltd is the controller responsible for your personal data. You can contact us about this policy, or to exercise your rights, at privacy@mostlytiny.io.

Studio M, Hackney Depot, 5 Sheep Lane, London E8 4QS, United Kingdom

3. EU/UK representative and Data Protection Officer

Where we are required to designate a representative in the EEA or UK because we are established outside it but offer services to, or monitor, people there, and where we are required to appoint a Data Protection Officer, their contact details are available on request at privacy@mostlytiny.io.

4. Personal data we collect

We collect: information you provide directly (for example your name and email address (from the Mostly Tiny account you sign in with); the documents you upload to send for signature and their contents; the name and email address of each person you send a document to; the signature each signer draws or types; and, for every envelope, an audit trail of the UTC time, IP address and browser of each view, signature and completion event); information collected automatically when you use mostlysign.com, such as your IP address, device and browser type, pages viewed, and cookie identifiers; and, where relevant, information we receive from third parties.

We collect personal data in the categories above for the purposes set out in this policy.

5. Where we get your data

Where we do not collect personal data directly from you, we obtain it from sources such as our service providers, analytics and advertising partners, publicly available sources, and other third parties you have authorised to share it.

6. How and why we use your data

We use your personal data to: provide, operate and improve mostlysign.com and our services; create and manage your account; respond to enquiries and provide support; personalise your experience; send service and, where permitted, marketing messages; keep the service secure and prevent fraud; and comply with our legal obligations.

7. Emails we send you

We email you what you need to use MostlySign: sign-in links, receipts, billing and security notices, and messages about your account. These are part of the service, so you cannot turn them off while your account is open.

We may also send you tips and offers about MostlySign. The sign-up form has a box for these, ticked by default: untick it and we never send them. In the UK this is the "soft opt-in" in regulation 22 of the Privacy and Electronic Communications Regulations; our lawful basis under the UK GDPR is our legitimate interest in telling customers about the product they signed up for, and you can object at any time.

We email you about other Mostly Tiny products (MostlyQR, MostlyPDF, MostlyPrivacy, MostlyRender and Vekta) only if you asked us to, by ticking a box that is never ticked for you, either when you sign up or later in a product. Our lawful basis is your consent. We send at most one such email a month across all of them.

Every marketing email says why you are getting it, has an unsubscribe link, and supports your email app's one-click unsubscribe button. One click stops that kind of email; the linked preferences page lets you choose exactly what you get, or stop all marketing email from every Mostly Tiny product at once. You can also change this in your Mostly Tiny account at id.mostlytiny.io/settings. Withdrawing is as easy as agreeing, and never affects service email.

To show we had your agreement, we record each choice: which box, the exact wording you saw, when, and a keyed one-way hash of your IP address. We store your choices against a one-way hash of your email address. If an address bounces permanently or a message is reported as spam, we stop all marketing email to it. Our do-not-email list keeps only that hash, never your address, so it continues to protect you after you close your account.

8. Our legal bases for processing

Where the EU or UK GDPR applies, we process your personal data on one or more lawful bases under Article 6: your consent; the performance of a contract with you; compliance with a legal obligation; protection of vital interests; the performance of a task in the public interest; or our legitimate interests (or those of a third party), except where overridden by your interests or rights.

Where we rely on legitimate interests, these include operating and securing our services, understanding how they are used, and limited marketing — you may object at any time. Where we process special categories of personal data under Article 9 (for example health or biometric data), we do so only with your explicit consent or another condition permitted by law.

9. Who we share your data with

We share personal data with: service providers and processors who operate mostlysign.com on our behalf (for example Google Firebase and Google Cloud, which host the site, the database, the functions and the stored documents (where, see "Where your data is stored"); Stripe, which processes payments and holds the billing details you enter; Resend, which delivers signature requests, reminders and sign-in email; and DigiCert’s RFC 3161 timestamping authority, which receives only a cryptographic hash of a completed document, never the document or its contents, in order to attest the time it was sealed), who may only use it on our instructions; professional advisers, payment providers, and law-enforcement or regulators where required; and parties to a corporate transaction such as a merger or acquisition. We do not sell your personal data for money.

10. Sale and sharing of personal information

The categories of personal information we have "sold" or "shared" (as defined under the CCPA/CPRA) in the preceding 12 months, and the categories of third parties to whom it was disclosed, are described in the California section below. If we share personal information for cross-context behavioural advertising, you can opt out as described there.

11. International data transfers

Some of our service providers are located outside your country, including outside the EEA, the UK or Australia. Where we transfer personal data internationally we rely on a lawful transfer mechanism — such as an adequacy decision, the EU Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant), or another safeguard permitted by law — and take steps to keep your data protected. Details are available on request at privacy@mostlytiny.io.

12. Where your data is stored

MostlySign runs on Google Cloud and Firebase: the database, the functions and the stored documents and audit trails are in the UK (europe-west2, London).

Sign-in uses Firebase Authentication, which Google runs only in the United States, and your Mostly Tiny account (Mostly Tiny ID), whose database is in the United States. Our website is served from Google's global network (Firebase Hosting).

Transfers to Google LLC in the United States rely on the UK Extension to the EU-US Data Privacy Framework (and, for data under the EU GDPR, on the EU-US Data Privacy Framework), to both of which Google LLC is certified. If you are in the EU, your personal data reaches our servers in the UK under the European Commission's adequacy decision for the UK (Implementing Decision (EU) 2021/1772, as amended by Implementing Decision (EU) 2025/2574).

13. How long we keep your data

We keep personal data only as long as necessary for the purposes described in this policy, after which we delete or anonymise it. The criteria we use to set retention periods include the nature and sensitivity of the data, the purpose of processing, and our legal, accounting and reporting obligations (while your account is open we keep each envelope, its sealed PDF and audit trail, which prove a signature later; closing your account cancels pending requests and API keys at once, and we delete your envelopes, PDFs, audit trails, templates and keys 30 days after you close your account; Stripe keeps payment records as its obligations require; hosting logs are kept up to 12 months).

14. How we protect your data

We use appropriate technical and organisational measures — including encryption in transit, access controls and regular review — to protect personal data against loss, misuse and unauthorised access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

15. Cookies and similar technologies

We use cookies and similar technologies on mostlysign.com. For the cookies we use, their purpose and duration, and how to control them, see our Cookie Policy.

16. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, including profiling, unless permitted by law. Where we ever do, we will tell you, explain the logic involved, and offer the right to obtain human review.

17. Children’s privacy

mostlysign.com is not directed to children. We do not knowingly collect personal data from children below the age of digital consent that applies to them (16 under the GDPR, subject to lower national ages down to 13), and we do not knowingly sell or share the personal information of consumers we know to be under 16. If you believe a child has given us data, contact us at privacy@mostlytiny.io and we will delete it.

18. Your rights under the GDPR

If the EU or UK GDPR applies to you, you have the right to: be informed; access your personal data; have inaccurate data rectified; have your data erased; restrict processing; data portability; and object to processing, including to direct marketing. Where processing is based on consent, you may withdraw it at any time without affecting processing carried out beforehand.

To exercise any of these rights, contact us at privacy@mostlytiny.io. We will respond within one month, which we may extend by up to two further months for complex or numerous requests, telling you within the first month. You also have the right to lodge a complaint with your data protection supervisory authority.

19. UK supervisory authority

If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply, and you may complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

20. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to: know what personal information we collect, use, disclose and sell or share; delete personal information we hold about you; correct inaccurate personal information; opt out of the sale or sharing of your personal information; limit the use and disclosure of your sensitive personal information; and not be discriminated or retaliated against for exercising these rights.

To exercise the right to know, delete or correct, contact us at privacy@mostlytiny.io or use any "Your Privacy Choices" link on mostlysign.com; we will not require you to create an account to make a request, and you may use an authorised agent. To opt out of sale or sharing, use the "Do Not Sell or Share My Personal Information" link on mostlysign.com or send a Global Privacy Control signal, which we honour.

21. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new effective date and, where changes are significant, take reasonable steps to notify you.

22. Contact us

For any privacy question, request or complaint about how we handle your personal data, contact Mostly Tiny Ltd at privacy@mostlytiny.io.

Studio M, Hackney Depot, 5 Sheep Lane, London E8 4QS, United Kingdom