Legal
Privacy Policy
How RubySig handles personal data for which it is the controller.
The short version
- We count page views ourselves, without cookies and without telling anyone else. No advertising, no third-party tracker, no profile of you. There is no cookie banner on this site because we still do not need one.
- We never sell or share your personal data, and we never use the contents of your email for anything except applying your signature to it.
- Your company's directory data belongs to your employer, not to us. This policy does not cover it — see What this policy does not cover below.
Who we are
RubySig LLC, a Texas limited liability company, is the controller of the personal data described in this policy.
- Address: [[TO BE COMPLETED: legal address]]
- Privacy contact: support@rubysig.com
- EU representative (Article 27 GDPR): [[TO BE COMPLETED: EU representative, if EU customers are taken on]]
- UK representative (Article 27 UK GDPR): [[TO BE COMPLETED: UK representative, if UK customers are taken on]]
What this policy does not cover
RubySig applies email signatures for organisations. To do that, we read staff details from our customer's Microsoft directory — names, job titles, email addresses, phone numbers, departments.
For that data, your employer is the controller and we are only the processor. We handle it on their documented instructions and for no other purpose. This policy does not govern it; our Data Processing Agreement does.
If you are an employee of a RubySig customer and you want to know how your details are used, or you want them changed or removed, please contact your own employer. We are not permitted to change or delete a customer's directory data on the instruction of an individual, and we will pass any such request to the customer.
The personal data we do control
1. Portal users
If your organisation subscribes, its administrators get accounts.
What: email address, a hashed password, session data, the role assigned to the account, and records of actions taken in the portal (such as creating a template or issuing an invoice). Why: to give you access, to keep the account secure, and to keep an audit trail of who did what. Legal basis: performance of the contract with your organisation; our legitimate interest in securing and auditing the Service.
2. Billing contacts
What: name, billing email address, billing address, the organisation's details, and the contracts, quotes, invoices, payments and accounting entries associated with them. Why: to bill for the Service and to keep proper accounting records. Legal basis: performance of the contract; compliance with our tax and accounting obligations.
We keep a record of every invoice email we attempt to send, including whether it succeeded and the mail server's message identifier, so that a billing dispute can be answered with evidence.
3. People who contact us
What: whatever you send us — your email address, name, and the content of your message — when you write to support@, billing@, sales@ or enquire about the Service. Why: to answer you, and to keep a record of what was agreed. Legal basis: our legitimate interest in responding to enquiries and supporting customers; steps taken at your request before entering a contract.
4. Visitors to this website
We keep server logs, which include IP addresses and requested URLs, for security and to diagnose faults.
We measure page views ourselves. No third-party analytics, advertising, tracking pixels, session recording, social media embeds or any third-party script run on this site — nothing here reports your visit to anyone else, and no data about your visit leaves our own systems.
What we record for a page view: the page, the site that linked you (if any), campaign tags in the link, your country, and whether you are on a phone or a computer. What we deliberately do not record: your IP address, your browser's user-agent string, any cookie, and any identifier stored on your device. Legal basis: our legitimate interest in knowing which pages are useful.
To count how many people visit rather than how many pages are loaded, we combine your request with a secret that we replace with a new random one every day, and keep only the result. Within a day the same browser produces the same value, so we can count visitors. The next day it produces a different one, so you cannot be recognised or followed — and because the daily secret is never stored, the value cannot be worked backwards even by us.
Cookies and local storage
We use two things, and neither requires your consent:
| What | Purpose | Type |
|---|---|---|
| Supabase authentication session | Keeps you signed in to the portal | Strictly necessary |
rs-theme (browser local storage) |
Remembers whether you chose the light or dark theme | Preference you set yourself |
That is the complete list. We set no advertising, analytics or profiling cookies, so there is no consent banner and nothing to opt out of.
What we never do
- We do not sell personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law.
- We do not use the contents of email passing through our relay for anything other than inserting the signature and forwarding the message. Message content is never written to disk and never logged.
- We do not use customer data or message content to train machine learning models.
- We do not make automated decisions producing legal or similarly significant effects, and we do not profile you.
Who we share data with
We use a small number of service providers. Each processes data only on our instructions, under a written contract.
| Provider | What it does | Where |
|---|---|---|
| Supabase (on Amazon Web Services) | Database, authentication, file storage | United States — Oregon |
| Vercel | Hosts this website and the portal | United States |
| Hetzner Online GmbH | Runs our signature relay | Germany |
| Hetzner Online GmbH | Runs our mail server | United States — Virginia |
| Cloudflare | Authoritative DNS only | Global |
Cloudflare provides name resolution for our domains and nothing else. Our DNS records are not proxied, so Cloudflare is not in the path of any traffic and receives no personal data.
We may also disclose personal data where the law requires it, to enforce our terms, or to a buyer in connection with a merger or sale of the business — in which case we will tell affected customers.
International transfers
We are based in the United States and most of our infrastructure is there. Our signature relay is in Germany.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, and we assess the transfer as required. The clauses we use are set out in full in our DPA.
How long we keep things
| Data | Retention |
|---|---|
| Portal accounts and audit records | While the subscription is active, then 12 months |
| Billing, invoices and accounting records | 7 years, as tax and company law require |
| Support and sales correspondence | 3 years from the last message |
| Website server logs | 30 days |
| Page-view records (no IP, no identifier) | 25 months |
| Relay logs — connecting IP addresses, protocol errors, and the sending domain (never anyone's address) where a message could not be signed or delivered | Rolling, capped by size — typically days |
| Email message content | Not retained at all — processed in transit only |
Security
We protect personal data with measures including: encryption in transit with full certificate verification on every connection; access control enforced in the database itself rather than only in application code, so it holds even for privileged connections; role-based access limited to what each person needs; append-only, immutable records for financial and audit data; and an architecture in which email content is never stored.
Our technical and organisational measures are described in detail in Annex II of the DPA.
Your rights
Depending on where you live, you may have the right to: access your personal data; have it corrected; have it deleted; restrict or object to its processing; receive it in a portable format; and withdraw consent where we relied on it.
If you are in California, you also have the right not to be discriminated against for exercising your rights. We do not sell or share personal data, so there is no opt-out to exercise. If you are in Texas, the Texas Data Privacy and Security Act gives you equivalent rights.
To exercise any of these, email support@rubysig.com. We will respond within one month, or within 45 days for requests under US state law, and we may need to verify your identity first. We do not charge for this.
If your request concerns your employer's directory data, please contact your employer — see above. We will forward the request and tell you we have.
Complaints. If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority: in the EU, the authority in the country where you live or work; in the UK, the Information Commissioner's Office at ico.org.uk.
Children
The Service is sold to organisations and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
If we make a material change to this policy we will give at least 30 days' notice to our customers' administrators, and we will post the updated policy with a new version number and effective date at the top of this page.
Contact
support@rubysig.com — or write to us at [[TO BE COMPLETED: legal address]].