← Back

Privacy Policy

Last updated:

Who we are

ContrSign is operated by IntellManager LLC, a Delaware limited liability company doing business as ContrSign. Throughout this policy, "ContrSign", "we", "us", and "our" all refer to IntellManager LLC dba ContrSign.

What this page covers

This policy describes how data is handled when you visit a public share link sent to you by a business using ContrSign — for example, a link to view an estimate, contract, invoice, or payment request. It also describes the sub-processors that handle parts of your information when you choose to pay or verify your bank account through the link. It also covers the phone number and text-message consent a business owner gives when creating a ContrSign account.

What ContrSign collects

  • Document content — the estimate, contract, or invoice details prepared for you by the business. We host and display this content but do not control it; the business is the controller of the data inside the document.
  • View counts — the number of times the share link is opened and whether the page is read in full (scrolled to the end). No identifiers about you personally are recorded.
  • IP address & browser user-agent — captured only when you sign a contract or approve a request, as part of the legal audit trail for that signature.
  • Information you provide — your name and signature when approving an estimate or signing a contract, plus any free-text fields you fill in.

What ContrSign does NOT collect

  • We don't run advertising trackers, behavioral analytics, or cross-site tracking pixels on these public share pages.
  • We don't sell your data and we don't share it for cross-context behavioral advertising.
  • We don't store full credit-card numbers or bank login credentials — those are handled by the payment processors and bank-verification services described below, never by us.

Payment processing (Stripe)

If you choose to pay a request online, the business may use Stripe as its payment processor. When you click through to pay:

  • You are taken to a Stripe-hosted checkout page or a Stripe Payment Element embedded in our share page. The card or bank-account fields are served by Stripe, not by ContrSign.
  • Stripe collects your payment method details, billing address, and the amount paid. Stripe acts as an independent data controller with respect to fraud prevention and as a service provider to the business with respect to processing the transaction. See Stripe's Privacy Policy.
  • ContrSign receives back from Stripe only the transaction reference, the last 4 digits of the card (for receipts), the status, and any decline reason. We never see or store your full card number, CVV, or bank account number.

Bank account verification (Plaid)

Some payment requests offer the option to pay by ACH bank transfer. If you choose that option, ContrSign uses Plaid Inc. ("Plaid") to securely verify your bank account, on behalf of you and the business you're paying.

  • When you click "Connect bank", you are taken into Plaid Link — Plaid's hosted UI — where you log in to your bank using credentials that go directly to Plaid, never to ContrSign.
  • Plaid collects the information needed to verify your account, including your account and routing numbers, account balance, account holder name, and recent transactions to confirm the account is real and active. Plaid uses this data to provide the linking service and for its own purposes as described in its policy.
  • ContrSign receives back from Plaid only a tokenized reference plus the last 4 digits of the account number, the bank name, and the account type. We never see or store your bank password.
  • Plaid handles end-user data as described in the Plaid End User Privacy Policy. You may review and revoke Plaid's access to your bank at any time through my.plaid.com.
  • Your choice. You are not required to pay by ACH — every payment request that offers a Plaid option also offers a credit/debit card option that doesn't involve Plaid.

Text messaging (SMS)

When you create a ContrSign account you can choose to receive text alerts about that account by ticking an optional checkbox on the sign-up form. The box is unchecked by default, and consent is not a condition of purchase or of using ContrSign.

  • What we send. Account alerts only: new leads, appointments, billing, and support messages, sent to the phone number you gave at sign-up.
  • What we keep. Your mobile number, the date and time you opted in, and a record of the messages sent and received, so we can deliver alerts and honor opt-outs.
  • Frequency & cost. Message frequency varies with your account activity. Message and data rates may apply. Mobile carriers are not liable for delayed or undelivered messages.
  • Opting out. Reply STOP to any message to stop receiving texts; you will get one confirmation and no further messages. Reply HELP for help, or email privacy@contrsign.com.
  • No sharing. We do not sell, rent, or share mobile phone numbers, text-message opt-in data, or consent with third parties or affiliates for their marketing or promotional purposes. This information is shared only with the service providers that deliver the messages for us (our messaging provider and mobile carriers).

Text messages that a business sends to its own customers through ContrSign are sent on that business's behalf; the business is responsible for obtaining its customers' consent.

Sub-processors we use

The business you're working with chooses which optional integrations to enable. Depending on what they've turned on, your data may pass through:

  • Amazon Web Services — hosting infrastructure (United States region).
  • Stripe — credit/debit card and ACH processing. See above.
  • Plaid — bank-account verification for ACH. See above.
  • Square & QuickBooks — alternative payment processors, used only if the business has connected them. Each has its own privacy policy.
  • Twilio — SMS and voice calls, if the business has SMS or call features enabled, and ContrSign account text alerts for account owners who opted in.
  • Google — email delivery, Drive storage of signed contracts, and Calendar sync, only when the business has connected those services.
  • Anthropic / OpenAI / Google AI — optional AI features. The business chooses the provider; relevant text is sent under a zero-retention agreement and is not used to train models.

How we protect your data

  • Encryption in transit. All traffic to and from ContrSign — public share pages, the application, and every third-party API call — is encrypted with TLS (HTTPS). Plain-HTTP access is not served.
  • Encryption at rest. Sensitive credentials — OAuth access and refresh tokens (Google, QuickBooks), payment-provider secrets (Stripe, Square), and messaging credentials — are additionally encrypted at the application layer with authenticated encryption before they are written to the database, on top of disk-level encryption. Decryption keys live only on the server and are never sent to browsers.
  • Access controls. Every record is isolated per business (tenant); server-side checks enforce that users can only reach data belonging to their own business, scoped further by role-based permissions (owner, admin, manager, project manager). Public share links return a minimal, allow-listed view of a single document — never raw records, other parties' contact details, tokens, or internal cost data.
  • Least privilege. Integrations are connected with the narrowest scopes the feature needs (for example, Google Drive access is limited to files the app itself creates, and Calendar access is limited to events, availability, and the calendar list).
  • Auditability. Signature events and money-movement actions are written to append-only audit logs (who, what, when) so both parties can reconstruct what happened.
  • Incident response. If we become aware of a breach affecting your personal data, we will notify the affected business without undue delay so they can notify you, consistent with applicable law.

Google user data (Calendar & Drive)

When a business connects Google Calendar or Google Drive, ContrSign accesses Google user data only to power the features the business turned on:

  • Calendar events (calendar.events) — creating, updating, and cancelling appointment and task events on the connected calendar.
  • Availability (calendar.freebusy) — checking free/busy windows when scheduling, to avoid double-booking.
  • Calendar list (calendar.calendarlist.readonly) — showing the one-time picker used to choose which calendar to sync to.
  • Drive files (drive.file) — storing signed contracts, uploaded photos, and generated documents in files/folders the app itself creates. ContrSign cannot see other files in the connected Drive.

ContrSign's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: the use of raw or derived user data received from Workspace APIs is limited to providing and improving the user-facing features described above; it is never used to create, train, or improve foundational or generalized machine learning or artificial intelligence models; it is not transferred or sold to third parties; and it is not used for advertising. Optional AI features in ContrSign do not read Google Calendar or Drive data. OAuth tokens are encrypted at rest as described above, and a business can disconnect Google at any time in Settings (or revoke access at myaccount.google.com/permissions), which invalidates the stored tokens.

Cookies & local storage

ContrSign uses a single piece of browser storage on share pages: a flag remembering that you dismissed the cookie notice. We do not set advertising cookies on these pages.

If you start a payment through Stripe or connect a bank through Plaid, those services use their own cookies and local storage on their hosted pages — see their privacy policies (linked above) for details.

How long we keep your data

  • Document content & signatures. Retained for the life of the business's account so they can produce records to you on request. Deleted within 90 days of the business's account closure, except where law requires longer retention (e.g. tax records).
  • View & audit logs. Up to 24 months, then deleted.
  • Stripe / Plaid identifiers. Retained for as long as the underlying payment record is retained, then deleted along with it. The tokens themselves are not usable outside of Stripe or Plaid.

See our Terms of Service — Data Retention & Disposal — for the full schedule.

Your choices & rights

  • You can decline the cookie notice; the page still works.
  • You can clear browser storage at any time.
  • To request a copy, correction, or deletion of your data, contact the business listed in the footer of the share link you received — they are the controller. They will route the request to ContrSign if needed.
  • To revoke Plaid's access to your bank, visit my.plaid.com.
  • Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other U.S. states with comprehensive privacy laws have additional rights under their state law (right to know, delete, correct, port, opt out of targeted advertising or sale). ContrSign does not sell personal information.

Children

ContrSign share pages are intended for adults conducting business. We do not knowingly collect information from children under 16. If you believe a child has provided us with information, contact the business that sent you the link or email privacy@contrsign.com and we will delete it.

Contact

For questions about a document or to exercise a privacy right, contact the business listed in the footer of the share link you received. For questions about ContrSign itself, email privacy@contrsign.com.

Legal entity: IntellManager LLC dba ContrSign, a Delaware limited liability company. These Terms and this Privacy Policy are governed by the laws of the State of Delaware. See our Terms of Service for details.