Last updated 10 September 2026
Privacy
Good Seal handles documents people sign, so the honest version of this page matters more than the long one. Here is everything it stores and why.
What we collect
Only what the service needs to do its job:
- Your account. Your email address, your name if you give one, and the organisation you belong to. There is no password to store — signing in is a one-time code sent to your inbox.
- Documents you upload. The PDF itself, the fields you place on it, and the values signers enter into those fields.
- Recipients. The name and email address of each person you send a document to. They do not need an account, and we do not create one for them.
- An audit trail. For each document: when it was sent, opened, signed and completed, and the IP address and browser user-agent recorded at the moment of signature.
There are no advertising trackers, no analytics scripts and no third-party cookies. The only cookie is the one that keeps you signed in.
Why the audit trail exists
An electronic signature is only as good as the evidence behind it. The timestamps, IP address and user-agent are what make a signature defensible if it is ever questioned — they are attached to the sealed PDF and shown on its certificate page. They are collected for that purpose and are not used to profile anyone.
Where it lives
Documents are stored in private object storage; nothing is publicly listable and every download goes through a short-lived, signed link. Everything else lives in a Postgres database. Transactional email — signing invitations, one-time codes, completed copies — is sent through Resend, which sees the recipient address and the message.
How long we keep it
Completed documents and their audit trails are kept for the retention period set by your organisation, which defaults to seven years — the span most contract and bookkeeping rules assume. You can delete a draft at any time. Deleting your organisation deletes its documents and the stored files behind them.
Who else sees it
Members of your organisation can see the documents it has sent. Each recipient sees the document they were sent and, once it is complete, the sealed copy. Nobody else. We do not sell data, and we do not share it with anyone beyond the providers that run the service — object storage, the database host, and the email sender above. We hand data to authorities only where the law actually requires it.
Your rights
Where the GDPR applies, you can ask for a copy of your data, ask for it to be corrected, or ask for it to be erased. Erasure has one limit worth stating plainly: a signed document is evidence of an agreement between two parties, so we cannot erase one party’s side of a completed contract on request alone while the other party still relies on it and the retention period runs.
Contact
Questions, requests or complaints: [email protected].
Changes
If this policy changes in a way that affects what is collected or how long it is kept, the date at the top changes with it and account holders are told by email.