Privacy Policy

Effective 18/03/2026

1. Introduction

PleaseSign Pty Ltd (“PleaseSign”, “we”, “our”, or “us”) is committed to protecting your privacy and handling personal information in a responsible, transparent and secure manner.

PleaseSign is an Australian made, owned and operated electronic digital signature platform trusted by business, enterprise, and government agencies in Australia and Internationally.

PleaseSign is committed to providing quality, secure services to you, the user. This policy outlines our ongoing obligations to you in respect of how we manage your Personal Information.

We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The NPPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information.

This Privacy Policy explains how we govern these principles: collect, use, disclose, store, and protect personal information when you access or use our websites, applications, APIs, electronic signature services, and identity verification features (collectively, the Services as offered by PleaseSign).

A copy of the Australian Privacy Principles may be obtained from the website of The Office of the Australian Information Commissioner at OAIC.

2. Applicable Privacy Law

PleaseSign handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as well as other applicable Australian privacy and data protection laws.

3. Scope

This Privacy Policy applies to:

  • Visitors to our websites
  • Registered users of the PleaseSign platform
  • Individuals who receive or sign documents using PleaseSign
  • Individuals whose identity may be verified through the PleaseSign Identity Verification service
  • Customers using PleaseSign APIs, integrations, and identity verification features

4. Personal Information We Collect

We collect only the personal information reasonably necessary and required to provide and operate our Services. We collect, however is not limited to, the below data collection.

a) Account and Contact Information
  • Full name
  • Email address
  • Phone number
  • Organisation name and role
  • Billing and subscription details
b) Document and Transaction Information
  • Documents uploaded for electronic signing
  • Names, email addresses, and phone numbers of recipients
  • Signature data and signing actions
  • Audit trails, timestamps, document status and transaction history
  • IP addresses and activity logs
c) Identity Verification Information

Identity verification is available within the PleaseSign platform. The decision to use the PleaseSign Identity Verification service for a document or workflow is made by the account holder or authorised users within the account.

Where the PleaseSign Identity Verification service is used, identity-related information may be collected and processed by third-party providers on PleaseSign’s behalf. This may include:

  • Name
  • Date of birth
  • Government-issued identification details
  • Verification results and metadata

PleaseSign does not independently collect identity verification information unless the service is used within a workflow.

d) Technical and Usage Information
  • Device, browser, and operating system details
  • Log files and diagnostic data
  • Cookies and analytics information

5. How We Use Personal Information

We use personal information to:

  • Provide, operate, and maintain the Services
  • Enable secure electronic signatures and document workflows
  • Facilitate identity verification where selected by customers
  • Support customers verifying the identity of end users, clients, prospective clients, contractors, or counterparties
  • Process payments and manage subscriptions
  • Communicate with users and provide customer support
  • Improve platform performance and usability
  • Detect, prevent, and investigate fraud or misuse
  • Meet legal, regulatory, and compliance obligations

6. Identity Verification (Stripe)

PleaseSign integrates Stripe Identity within the platform to support identity verification.

a) Information collected

Where the PleaseSign Identity Verification service is used, Stripe may collect and process information such as:

  • Full name
  • Date of birth
  • Government-issued identification (for example, driver licence or passport)
  • Selfie or biometric comparison images (where applicable)
  • Verification metadata and results

This information is collected directly by Stripe and processed in accordance with Stripe’s own privacy, security, and retention policies.

b) Purpose of verification

The PleaseSign Identity Verification service is available to be used by PleaseSign clients allowing them to verify the identity of individuals, under the “know your customer” requirements (KYC) which may include:

  • End users
  • Customers or clients
  • Prospective customers
  • Contractors
  • Counterparties to a transaction

Identity verification information is used solely to:

  • Confirm the identity of an individual as part of a document workflow
  • Support fraud prevention and risk management
  • Meet regulatory, contractual, or customer compliance requirements and mitigation
c) Data handling, display and audit logging
  • PleaseSign receives verification results and limited metadata only
  • PleaseSign does not store raw identity documents.
  • PleaseSign may display identity verification results within document workflows, dashboards, or related transaction records
  • PleaseSign may reference and record identity verification outcomes and related metadata within audit logs to support document integrity, compliance, dispute resolution, and evidentiary requirements
  • Identity verification data is not used for marketing or profiling
Digital ID clarification

PleaseSign does not issue Digital IDs and is not an accredited Digital ID provider under the Digital ID Act 2024 (Cth).

7. Data Storage and Sovereignty

  • PleaseSign stores all secure document signing and related transaction data sovereignly in Australia
  • Infrastructure is hosted on ISO 27001 certified servers
  • Australian and international customer data is stored within the same Australian-hosted infrastructure
  • PleaseSign does not sell personal information

8. Data Security

We implement enterprise-grade security measures designed to protect personal information, including:

  • Encryption in transit and at rest
  • Secure authentication and access controls
  • Continuous monitoring and audit logging
  • Regular security testing and reviews

PleaseSign maintains SOC 2 Type II attestation and operates in alignment with ISO 27001 security principles and recognised industry best practices.

9. Disclosure of Personal Information

We may disclose personal information to:

  • Trusted service providers and infrastructure partners under strict confidentiality obligations
  • Identity verification providers (including Stripe) where the PleaseSign Identity Verification service is used
  • Payment processors and billing partners
  • Regulatory authorities, courts, or law enforcement where required by law
  • Any personal information disclosed to trusted service providers is stored and handled in accordance with their privacy policies.

We do not disclose personal information for advertising resale or unrelated marketing purposes.

10. International Data Transfers

All secure document signing and related transaction data is stored in Australia. Where third-party service providers are engaged, appropriate contractual and security safeguards are implemented.

11. Access and Correction

You may request access to or correction of personal information we hold about you in accordance with the Privacy Act 1988 (Cth).

Requests can be made using the contact details below.

12. Data Retention

We retain personal information only for as long as necessary to:

  • Provide the Services
  • Meet legal and regulatory obligations
  • Resolve disputes and enforce agreements

Retention periods may vary depending on the type of information and applicable requirements.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The most current version will always be available on our website and will take effect upon publication.

14. Contact Us

For privacy enquiries, access requests, or complaints, contact:

PleaseSign Pty Ltd
📧 privacy@pleasesign.com.au
🌐 Digital Signatures | Electronic Document Signing l PleaseSign