Skip to main content

Privacy Policy

Version 2.0 — Effective from 11 July 2026

1. Who We Are

Squigggle is an electronic signature platform operated by N90 Labs Limited, a company registered in England and Wales (company number 17006232) whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ (“we”, “us”, “our”). We offer the Service to customers in the United Kingdom; documents sent through the Service may reach signatories located elsewhere, including in the EU, whose personal data we process as described in this policy, and we are the data controller for the personal data described in this Privacy Policy except where we act as a processor (see Section 2). This policy is written to comply with the UK GDPR, and with the EU GDPR to the extent it applies to that processing. For data-protection enquiries, contact us at privacy@squigggle.io or by post at our registered office above.

Data Protection Officer. We are not required to appoint, and have not appointed, a statutory Data Protection Officer; we keep a documented assessment of that conclusion on file. You can raise any data-protection matter with us at privacy@squigggle.io.

EU representative. We offer the Service to customers in the United Kingdom and do not target or offer it to customers in the EU. On that basis we are not currently required to appoint a representative in the EU under Article 27 of the EU GDPR. If we begin offering the Service to customers in the EU, we will appoint an EU representative and update this policy.

2. Our Role — Controller and Processor

Our role depends on the data and on whether you are a business or a consumer:

  • Account data (your name, email and login credentials): we are the controller.
  • Verification and audit-trail data (one-time-passcode events, IP addresses, timestamps generated during signing): we are the controller.
  • The contents of documents sent by a business customer: the business customer is the controller and we act as its processor under our Data Processing Addendum.
  • The contents of documents in a consumer signing transaction: we are the controller, because a private individual signing a personal document is generally not acting as a data controller.

Some terms we use

A “Signatory” is someone invited to view, verify or sign a document. A “Recipient” is someone sent a completed copy of a signed document without being a signer. A “Sender” (our Customer) is the person or organisation that sends a document for signature.

3. Data We Collect

3.1 Account Data. Your name, email address, and authentication credentials. If you sign up with Google or Apple, we receive your name and email from those providers.

3.2 Document Data. The document files, signer names and email addresses, signature images, and signing metadata (timestamps, IP addresses, user agents).

3.3 Payment Data. Your Stripe customer ID and payment history. We never store full card numbers.

3.4 Usage Data. Information about how you use the Service, collected via cookies and analytics tools as described in Section 11.

3.5 Signatory Data (received from the Sender).If you are invited to sign, we receive your name, email address and (where a higher signature level or SMS notification is used) mobile number from the Sender, not from you directly. We use it to deliver and verify your one-time passcode and to record the audit trail. This is “indirect collection” under Article 14 of the UK and EU GDPR.

4. How We Use Your Data

  • Service delivery: to provide e-signature services, process documents, send signing invitations, and generate certificates of completion.
  • Authentication: to verify signers (by email one-time passcode) and secure accounts.
  • Payments: to process payments and maintain billing records.
  • Legal compliance: to maintain audit trails and tax records as required by law.
  • Communication: to send transactional emails (invitations, completions, receipts) and, subject to Section 5, marketing to customers.
  • Improvement: to analyse usage patterns and improve the Service.

5. Marketing

We may send marketing about Squigggle to our customers. For business customers we rely on our legitimate interests; for consumers we rely on your consent or, where it applies, the “soft opt-in” for existing customers. Every marketing message has an easy, one-click unsubscribe, and you can opt out at any time by contacting privacy@squigggle.io.

We do not use Signatories’ data for marketing. If you only ever sign a document sent by someone else, we will not send you marketing.

6. Legal Basis for Processing

We process your personal data on the following legal bases under the UK GDPR and EU GDPR:

  • Contract performance: processing necessary to provide the Service to account holders.
  • Legitimate interests:securing the Service, preventing fraud, maintaining the integrity and evidential value of signatures and audit trails, marketing to business customers, and running and improving our business. In particular, where you are a Signatory, we and the Sender rely on our legitimate interests in verifying you by one-time passcode and maintaining the audit trail — you are not a party to a contract with us, so we do not rely on contract performance for that processing.
  • Legal obligation: keeping audit trails, and tax and accounting records, as required by law.
  • Consent: consumer marketing and non-essential cookies. You can withdraw consent at any time.

Document contents (Sender as controller):Where a business or organisation sends a document, that Sender is the controller of the personal data within it and is responsible for its own lawful basis — for example, its contract with the signatory, its legitimate interests, or consent. We process that data only on the Sender’s documented instructions under our Data Processing Addendum; we do not determine or assert the Sender’s lawful basis. Where a private individual sends a personal document, we are the controller of that data and rely on the performance of our contract with that individual to provide the signing service, together with our legitimate interests in delivering and evidencing it.

Providing your data. Providing account and signer contact details is necessary to use the Service and to sign documents; there is no statutory obligation to provide it, but without it you will not be able to use the Service or complete a signature.

7. Data Sharing

We share personal data with:

  • Signing participants: names and email addresses are shared with other signers on the same document.
  • Service providers (sub-processors):Supabase (database, storage and authentication), Vercel (application hosting and compute), Resend (transactional email, including email one-time passcodes), Stripe (payments), Sentry (error monitoring), Google Cloud (document conversion), PostHog (product analytics and masked session replay, processed in the EU), Google Workspace (Gmail — support-email inbox), Linear (support-ticket management) and Anthropic (AI-assisted triage of support requests).
  • Analytics, used only with your consent (see Section 11): we currently use PostHog (listed above). We may introduce additional analytics or marketing tools in future; if we do, they will be off by default, we will ask for your consent, and we will update this policy.
  • Legal authorities: when required by law or court order.

The full, current list — each provider’s purpose, the data it processes, its location and the international-transfer safeguard — is on our Sub-processors page at squigggle.io/legal/sub-processors, which we update with at least 30 days’ notice of changes.

AI-assisted support.When you contact us for support (by email or in-app feedback), we use an AI service (Anthropic) to help categorise your message and draft a suggested reply, which a member of our team reviews before any substantive reply is sent. We send only your support message and contact details for this — we do not send your documents. We receive support email through Google Workspace (Gmail) and manage requests in our ticketing tool (Linear). These providers are in the United States, under the transfer safeguards in Section 9.

8. Data Retention

Audit trail.We retain the audit trail and certificate of completion for each signed document — the verification events, timestamps, IP addresses and related evidence — for 7 years from the date the document is completed — and up to 12 years for a signed deed — as an evidential record, even after the document files are deleted and after your account is closed, unless we must keep it longer by law. This protects the evidential value of your signatures if a signed agreement is later disputed (the limitation period for contract claims in England and Wales is six years, and up to twelve years for deeds).

Signed document files. While your account is open, we keep your signed documents so you can access and download them. If you close your account, we keep the signed document files for 2 years from the date of closure to meet legal, compliance, auditing and security obligations (and longer where the law requires), and then delete them. You are responsible for downloading and keeping your own copies of your signed documents.

Account and other data. If you close your account, you can log back in and export your account and other general personal data for 30 days; after that it is retained but no longer accessible to you, and we permanently delete it by 90 days from closure, except for the signed documents and audit trails above and anything we must keep by law.

Payment and transaction records are retained for 6 years to meet our UK tax-law (HMRC) obligations.

Signing without an account.If you sign, witness or receive a document without a Squigggle account, your personal data is held within the Sender’s document record. For the document contents, the Sender is the controller — to access or erase that data, contact them, and we will assist as processor (or, for consumer transactions, we are the controller — contact us). For the verification and audit-trail data we generate, N90 Labs is the controller, and you can contact us at privacy@squigggle.io. Your data within the document is erased when the document is deleted, subject to the 7-year evidential retention above. Where a document is a signed deed, we may retain witness details for up to 12 years, reflecting the longer limitation period for deeds.

Deletion and backups. When we delete data from our live systems, residual copies may remain in our encrypted backups for up to 7 days until those backups are cycled out; during that time they are isolated and used only for disaster recovery.

Legal holds. We may suspend deletion where documents or records are subject to a legal hold, an ongoing dispute, or a legal or regulatory obligation to preserve them.

9. International Transfers

Some of our sub-processors process personal data outside the UK and the EEA. Where they do, we put appropriate safeguards in place: for transfers from the UK, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; for transfers from the EEA, the EU Standard Contractual Clauses; or reliance on a UK or EU adequacy decision. We assess each restricted transfer on a risk-based basis (in the UK, the “data protection test” introduced by the Data (Use and Access) Act 2025). The mechanism relied on for each provider is set out on our Sub-processors page.

10. Your Rights

Under the UK GDPR and EU GDPR, you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict processing; data portability; object to processing; and withdraw consent at any time. When you make a request, we carry out a reasonable and proportionate search, and we may pause our response time if we reasonably need to clarify your request or verify your identity. Your right to erasure is subject to the retention periods in Section 8 — in particular, we may need to keep signed documents and audit trails for their 7-year evidential period, and records the law requires us to keep. To exercise these rights, contact privacy@squigggle.io. We will respond within one month.

11. Cookies and Tracking

We use these categories of cookies:

  • Essential: session management and authentication (always active).
  • Analytics: PostHog (our current analytics tool, processed in the EU).
  • Marketing: none at present; if we introduce marketing cookies we will ask for your consent and update our Cookie Policy.

Non-essential cookies are off by default. Analytics and marketing cookies require your prior consent. When you first visit, a banner lets you accept all, reject all, or choose analytics and marketing individually — no analytics or marketing tags load until you opt in. Your choice is stored in a first-party cookie and you can change or withdraw it at any time via the “Cookie preferences” link in the footer. We apply Google Consent Mode. (UK law now permits some first-party analytics cookies without consent; we currently ask for consent in all cases.) Full detail is in our Cookie Policy.

12. Automated Decision-Making

We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing without meaningful human involvement. If this changes, we will tell you and provide the safeguards the law requires — including the right to be informed, to make representations, to obtain human review, and to contest the decision.

13. Children

The Service is intended for adults. You must be at least 18 to create an account or to sign a document, and we do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has used the Service, contact us at privacy@squigggle.io and we will delete their data.

14. Our AI Commitment

We do not use your account data, your documents or their contents to train, fine-tune or develop any machine-learning or artificial-intelligence model. This reflects the commitment in our Terms and Acceptable Use Policy. We do use an AI service to help handle support requests (see Section 7); it operates on your support message, not your documents, and we do not permit it to be used to train AI models on your data.

15. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, and regular security assessments. Documents are cryptographically sealed (ECDSA P-256 signing and SHA-256 hashing) so that any later alteration can be detected.

Who can access your documents.We access the contents of your documents only where necessary to provide the Service — for example to convert, display, deliver and store them — to comply with a legal obligation, or as otherwise described in this policy. Access to document contents is restricted to a small number of authorised personnel on a least-privilege, need-to-know basis, is logged, and is subject to binding confidentiality obligations. We do not read your documents for any other purpose, and we do not use your documents or their contents to train any AI or machine-learning model (see Section 14).

16. Complaints

If you have a concern about how we handle your personal data, please contact us first at privacy@squigggle.io. This is an accessible channel for making a data-protection complaint. We will acknowledge your complaint within 30 days and investigate it without undue delay, keeping you informed of the outcome.

You also have the right to complain to a data-protection regulator. In the UK, this is the Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the EU, you may complain to the supervisory authority in your country of residence. We ask that you give us the opportunity to resolve your concern first.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and give at least 30 days’ notice. The latest version, with its effective date, is always available at squigggle.io/privacy, and we keep a version history so you can see what changed.

18. Contact

For privacy enquiries: privacy@squigggle.io, or by post at our registered office. UK regulator: the ICO, ico.org.uk. EU users: your local supervisory authority.

Document control

  • Version 1.0 — March 2026 (superseded)
  • Version 2.0 — 11 July 2026 (current version)